SOC 2 and security testing

SOC 2 penetration testing

Most companies do not go looking for a pentest until an auditor, or a customer's procurement team, asks what testing they perform. A penetration test is the clearest evidence you have that your controls were actually tried, not just documented.

PentestMe runs on-demand tests against your web apps, APIs, network and cloud, and produces a dated report with the evidence behind every finding.

What SOC 2 actually asks for

SOC 2 is an attestation against the AICPA Trust Services Criteria, not a checklist with named tools. No criterion says the words "you must run a penetration test". What the Common Criteria do require is that you detect vulnerabilities and evaluate whether your controls work: CC7.1 expects detection and monitoring procedures that identify newly introduced and newly discovered vulnerabilities, and CC4.1 expects you to evaluate whether controls are operating as intended.

In practice, auditors treat periodic penetration testing as one of the most direct ways to satisfy those criteria, and many customers now ask for a recent report before they will sign. A Type II report covers a period of time, so testing needs to have happened during that window rather than the week before the audit.

How a pentest supports your SOC 2 audit

CC7.1: identify new and newly discovered vulnerabilities

Testing actively surfaces what changed since your last release, from exposed services to injection and broken access control, rather than waiting for a scanner signature to catch up.

CC4.1: evaluate whether controls are operating

On-demand re-testing after each fix demonstrates that a control was not just designed but works, which is the distinction a Type II report turns on.

Evidence across the observation period

Every test leaves a dated report. Testing on each meaningful release gives your auditor evidence spread across the period instead of a single point in time.

CC7.4: respond to identified issues

Findings arrive prioritised with remediation guidance, so the fix and the re-test are both on record as part of your incident and remediation process.

Evidence your auditor can actually use

The hardest part of any audit is proving what you did and when. PentestMe keeps a dated report for every test, with the finding, the evidence behind it, and the remediation advice. When your auditor asks for testing evidence, or a prospect sends a security questionnaire mid-deal, the proof already exists rather than needing to be arranged. Testing on every release also keeps that evidence current across the whole observation period.

Penetration testing is one technical control among many. It supports a SOC 2 audit but does not, on its own, make an organisation SOC 2 compliant, and this page is not audit or legal advice. Your auditor determines what evidence satisfies the criteria for your specific scope and report type.

Get your testing evidence on file

Run a real, validated pentest on your own systems and get the dated report to prove it. No credit card.

Start your free pentest