Art of Vector · Guides
SOC 2 Type I vs Type II: when do you need a pen test?
Type I evaluates controls at a point in time. Type II evaluates how those controls operated over a period. Penetration testing supports both, but the timing and evidence expectations change.
Type I vs Type II in plain terms
SOC 2 Type I asks whether your security controls are suitably designed on a specific date. SOC 2 Type II asks whether those controls operated effectively over a defined observation window, often three to twelve months.
- Type I — design snapshot; faster first attestation for early enterprise deals
- Type II — operating effectiveness over time; stronger buyer signal for ongoing trust
When penetration testing is needed
SOC 2 does not always name “penetration test” as a mandatory line item, but auditors commonly treat independent testing as evidence for monitoring and vulnerability management expectations. Enterprise security questionnaires also ask for a recent pen test report.
Most seed to Series A SaaS teams should plan a pen test when:
- Starting Type I and needing credible technical evidence fast
- Entering or preparing a Type II observation window
- An enterprise buyer blocks a deal on missing pen test proof
- Major product, auth, or multi-tenant changes shipped since the last test
Recommended timing
- Before Type I fieldwork — test, fix critical issues, then share an audit-ready report.
- Early in Type II planning — leave room for remediation and retest evidence.
- After material product changes — refresh evidence so buyers and auditors see current risk reduction.
Related pages
FAQ
Do I need a pen test for SOC 2 Type I?
Often yes. Many auditors and enterprise buyers expect recent penetration testing evidence even for Type I, especially for SaaS products handling customer data.
Is the pen test different for Type II?
The technical testing approach is similar, but Type II timing matters more. Teams usually want findings remediated and retested before the observation window or audit fieldwork.
When should startups schedule testing?
Before auditor kickoff when possible, so critical issues can be fixed and documented. For Type II, plan testing early enough to leave remediation time inside or before the review period.
Start with a free Security Health Check
Tell us about your app and we will follow up with next steps for web, API, and AI application security — with optional SOC 2 mapping.
Get a Free Security Health Check