SOC 2 does not explicitly require a penetration test. But most auditors and enterprise customers expect one. This guide explains why, what to test, and how to make the test useful as audit evidence.
Does SOC 2 require a penetration test?
No — not explicitly. The Trust Services Criteria list penetration testing as one way to evaluate controls. In practice, most auditors and enterprise customers expect one.
What auditors and customers expect
They expect a penetration test of the systems in your SOC 2 scope, high-risk findings fixed, and evidence of the retest. They also expect the test to be repeated every year.
What to test
Test the systems in the SOC 2 scope:
- The web application
- APIs
- The cloud environment
Penetration test versus vulnerability scan
| Vulnerability scan | Penetration test | |
|---|---|---|
| How it is done | Automated | Manual testing by a person |
| How often | Repeated often | Typically yearly |
| What it does | Finds known weaknesses | Tries to exploit weaknesses |
They are not the same, and auditors treat them differently.
When to run it
Run the test before or during the audit period. Fix the high-risk findings and keep the retest evidence. Repeat the test every year.
What the report must contain
The report should show what was tested (the systems in scope), the findings, and evidence that high-risk findings were fixed and retested. That retest evidence is what turns the test into useful audit evidence.
What it costs
In our SOC 2 engagements, penetration testing and tools together are typically $2,000 to $3,000.
Next step
Learn about our security testing services and VAPT services, or see how testing fits into the full SOC 2 engagement. You can also book a 30-minute call.
