Art of Vector · Guides

SOC 2 penetration testing requirements

Auditors care less about a logo on a PDF and more about whether scope matches your system boundary, testing was real, and critical findings were fixed with evidence.

Get a Free Security Health Check

What “required” means in practice

SOC 2 does not always spell out “you must commission a penetration test.” The Trust Services Criteria do expect you to evaluate whether security controls work. Penetration testing is one of the clearest ways to show that evaluation happened under realistic attack conditions.

That is why CPA firms and enterprise security reviewers often ask for a recent report even when the criteria language is flexible. For startups, the practical requirement is buyer and auditor acceptance, not a single magic sentence in the standard.

Criteria auditors commonly connect to pen tests

  • CC4.1 — ongoing or separate evaluations of controls, including independent testing
  • CC6.1 — logical access and authorization controls under attack
  • CC7.1–CC7.4 — detecting vulnerabilities, anomalies, and responding to issues found

You do not need a novel-length mapping for every finding. You do need a report that an auditor can connect to your control story without guessing.

What a SOC 2-ready engagement usually must show

  1. Scope matches the system boundary — the apps and APIs in your SOC 2 description, not a random subset that leaves customer data paths untested.
  2. Recognized methodology — for SaaS, OWASP-aligned web and API testing is the baseline auditors understand.
  3. Independent testing — not only an internal scan run by the same team that built the product.
  4. Actionable findings — severity, impact, reproduction detail, and remediation guidance.
  5. Remediation and retest evidence — especially for critical and high issues before Type II period close or deal review.

Startup checklist before you hire

  • List customer-facing apps and APIs in SOC 2 scope
  • Confirm staging or production rules and test accounts
  • Schedule testing early enough to fix and retest
  • Ask what the report contains for auditors and buyers
  • Confirm retest is part of the engagement, not an afterthought

FAQ

Does SOC 2 explicitly require a penetration test?

Not always by name. Trust Services Criteria emphasize monitoring and vulnerability management. In practice, many auditors and enterprise buyers treat a recent independent pen test as expected evidence.

Which Trust Services Criteria relate to pen testing?

Commonly CC4.1 (monitoring and evaluations), CC6.1 (logical access), and CC7.1–CC7.4 (system operations and vulnerability detection). Your auditor may emphasize different points based on your system description.

How often should startups run a SOC 2 pen test?

At least annually is common, plus after major product or infrastructure changes. For Type II, keep the test inside the observation period with time left to remediate.

Start with a free Security Health Check

Tell us about your app and we will follow up with next steps for web, API, and AI application security — with optional SOC 2 mapping.

Get a Free Security Health Check