BlogCompliance

What SOC 2 actually requires for penetration testing

SOC 2 doesn't literally mandate a pentest, but your auditor almost certainly expects one. Here's what's really required, and why.

"Does SOC 2 require a penetration test?" is one of the most common questions we get, and the honest answer is not exactly, but yes in practice. Here's what that means.

SOC 2 doesn't name "penetration test," but it expects the evidence

SOC 2 is built on the Trust Services Criteria, not a checklist of specific tools. It doesn't say "you must run an annual pentest." What it does require is that you identify, assess, and manage security risks, and that you have controls to detect and respond to vulnerabilities.

A penetration test is the most widely accepted way to evidence several of those criteria. When an auditor asks how you validate that your controls actually resist a real attacker, "we had an independent penetration test" is the answer they're looking for.

The criteria a pentest helps satisfy

  • CC4.1, Monitoring controls: a pentest is independent evidence that your security controls work.
  • CC7.1 / CC7.2, Detecting and responding to vulnerabilities: testing surfaces the vulnerabilities you then remediate.
  • Risk assessment criteria: a pentest feeds real, prioritized risk into your assessment.

What auditors want to see in the report

An auditor isn't just checking a box that a test happened. They want to see a credible scope, findings with severity, evidence of remediation, and, increasingly, a retest confirming issues were fixed. A one-page "we found nothing" letter from an automated scan rarely satisfies a thorough auditor.

Scan or pentest? Both.

SOC 2 maturity generally means continuous vulnerability scanning plus a periodic penetration test, typically annually and after any major change. (We break down the difference in pentest vs. vulnerability scan.)

How often

The common cadence is annually and on major change: a significant new feature, an architecture change, or a move to a new environment. If your product changes constantly, talk to your auditor about the right rhythm.

Key takeaways

  • SOC 2 doesn't literally mandate a pentest, but auditors routinely expect one.
  • A pentest evidences the monitoring, risk-assessment, and vulnerability-management criteria.
  • Give the auditor a real report: scope, findings, remediation, retest.
  • Scan continuously; pentest annually and on major change.

Want a report your auditor will accept? See our sample penetration test report to benchmark the format, then book a scoping call to plan yours.

See what a finding looks like in a real reportDownload our free sample pentest report →

READY WHEN YOU ARE

See what an attacker sees.

Book a free 30-minute scoping call, or download our sample report first.