SOC 2

    SOC 2 Penetration Testing: Is It Required and What Auditors Expect

    By Santhosh K, Chief Operating Officer, CyberWave GRC
    Published
    Last updated
    SOC 2

    Reviewed by Santhosh K, Chief Operating Officer, CyberWave GRC · CISA, CISM, CCISO, HITRUST CCSFP, CHQP, ISO/IEC 27001 Lead Auditor

    SOC 2 does not explicitly require a penetration test. But most auditors and enterprise customers expect one. This guide explains why, what to test, and how to make the test useful as audit evidence.

    Does SOC 2 require a penetration test?

    No — not explicitly. The Trust Services Criteria list penetration testing as one way to evaluate controls. In practice, most auditors and enterprise customers expect one.

    What auditors and customers expect

    They expect a penetration test of the systems in your SOC 2 scope, high-risk findings fixed, and evidence of the retest. They also expect the test to be repeated every year.

    What to test

    Test the systems in the SOC 2 scope:

    • The web application
    • APIs
    • The cloud environment

    Penetration test versus vulnerability scan

    Vulnerability scanPenetration test
    How it is doneAutomatedManual testing by a person
    How oftenRepeated oftenTypically yearly
    What it doesFinds known weaknessesTries to exploit weaknesses

    They are not the same, and auditors treat them differently.

    When to run it

    Run the test before or during the audit period. Fix the high-risk findings and keep the retest evidence. Repeat the test every year.

    What the report must contain

    The report should show what was tested (the systems in scope), the findings, and evidence that high-risk findings were fixed and retested. That retest evidence is what turns the test into useful audit evidence.

    What it costs

    In our SOC 2 engagements, penetration testing and tools together are typically $2,000 to $3,000.

    Next step

    Learn about our security testing services and VAPT services, or see how testing fits into the full SOC 2 engagement. You can also book a 30-minute call.

    Frequently asked questions

    Not explicitly. The Trust Services Criteria list it as one way to evaluate controls, and most auditors and enterprise customers expect one.

    No. They are not the same, and auditors treat them differently.

    Before or during the audit period. Fix the high-risk findings, keep the retest evidence and repeat the test every year.
    Hi! I'm your AI Assistant 💬