What SOC 2 actually requires for penetration testing
SOC 2 doesn't literally mandate a pentest, but your auditor almost certainly expects one. Here's what's really required, and why.
"Does SOC 2 require a penetration test?" is one of the most common questions we get, and the honest answer is not exactly, but yes in practice. Here's what that means.
SOC 2 doesn't name "penetration test," but it expects the evidence
SOC 2 is built on the Trust Services Criteria, not a checklist of specific tools. It doesn't say "you must run an annual pentest." What it does require is that you identify, assess, and manage security risks, and that you have controls to detect and respond to vulnerabilities.
A penetration test is the most widely accepted way to evidence several of those criteria. When an auditor asks how you validate that your controls actually resist a real attacker, "we had an independent penetration test" is the answer they're looking for.
The criteria a pentest helps satisfy
- CC4.1, Monitoring controls: a pentest is independent evidence that your security controls work.
- CC7.1 / CC7.2, Detecting and responding to vulnerabilities: testing surfaces the vulnerabilities you then remediate.
- Risk assessment criteria: a pentest feeds real, prioritized risk into your assessment.
What auditors want to see in the report
An auditor isn't just checking a box that a test happened. They want to see a credible scope, findings with severity, evidence of remediation, and, increasingly, a retest confirming issues were fixed. A one-page "we found nothing" letter from an automated scan rarely satisfies a thorough auditor.
Scan or pentest? Both.
SOC 2 maturity generally means continuous vulnerability scanning plus a periodic penetration test, typically annually and after any major change. (We break down the difference in pentest vs. vulnerability scan.)
How often
The common cadence is annually and on major change: a significant new feature, an architecture change, or a move to a new environment. If your product changes constantly, talk to your auditor about the right rhythm.
Key takeaways
- SOC 2 doesn't literally mandate a pentest, but auditors routinely expect one.
- A pentest evidences the monitoring, risk-assessment, and vulnerability-management criteria.
- Give the auditor a real report: scope, findings, remediation, retest.
- Scan continuously; pentest annually and on major change.
Want a report your auditor will accept? See our sample penetration test report to benchmark the format, then book a scoping call to plan yours.