Most companies do not go looking for a pentest until an auditor, or a customer's procurement team, asks what testing they perform. A penetration test is the clearest evidence you have that your controls were actually tried, not just documented.
PentestMe runs on-demand tests against your web apps, APIs, network and cloud, and produces a dated report with the evidence behind every finding.
SOC 2 is an attestation against the AICPA Trust Services Criteria, not a checklist with named tools. No criterion says the words "you must run a penetration test". What the Common Criteria do require is that you detect vulnerabilities and evaluate whether your controls work: CC7.1 expects detection and monitoring procedures that identify newly introduced and newly discovered vulnerabilities, and CC4.1 expects you to evaluate whether controls are operating as intended.
In practice, auditors treat periodic penetration testing as one of the most direct ways to satisfy those criteria, and many customers now ask for a recent report before they will sign. A Type II report covers a period of time, so testing needs to have happened during that window rather than the week before the audit.
Testing actively surfaces what changed since your last release, from exposed services to injection and broken access control, rather than waiting for a scanner signature to catch up.
On-demand re-testing after each fix demonstrates that a control was not just designed but works, which is the distinction a Type II report turns on.
Every test leaves a dated report. Testing on each meaningful release gives your auditor evidence spread across the period instead of a single point in time.
Findings arrive prioritised with remediation guidance, so the fix and the re-test are both on record as part of your incident and remediation process.
The hardest part of any audit is proving what you did and when. PentestMe keeps a dated report for every test, with the finding, the evidence behind it, and the remediation advice. When your auditor asks for testing evidence, or a prospect sends a security questionnaire mid-deal, the proof already exists rather than needing to be arranged. Testing on every release also keeps that evidence current across the whole observation period.
Penetration testing is one technical control among many. It supports a SOC 2 audit but does not, on its own, make an organisation SOC 2 compliant, and this page is not audit or legal advice. Your auditor determines what evidence satisfies the criteria for your specific scope and report type.
Run a real, validated pentest on your own systems and get the dated report to prove it. No credit card.
Start your free pentest