Compliance

SOC 2 Penetration Testing.

Manual penetration testing scoped, executed, and documented for SOC 2 Type II audits. Evidence your examiner can rely on.

File · What SOC

What SOC 2 actually requires

SOC 2 does not mandate a penetration test by name, but the Trust Services Criteria (specifically CC4.1 monitoring and CC7.1 detection of system changes) require evidence of independent security testing of the in-scope systems. Most auditors operationalize that as an annual third-party penetration test with manual validation, attack-path narratives, and remediation evidence.

Operator Note

Where SOC 2 evidence actually gets tested

The examiner's question is narrow and specific: what would an adversary have done with each finding inside the system boundary? A coverage report cannot answer that, and neither can a scanner. If your last SOC 2 pentest report read like a Nessus export with a logo on it, it was a scan, and in our experience examiners are increasingly catching the difference. What survives review is manual testing that ties each finding, and the attack path behind it, back to a Trust Services Criterion.

File · How we

How we scope a SOC 2 pentest

  • [01] System boundary alignment. Scope matches the SOC 2 system description, not the network diagram.
  • [02] Manual validation on every finding. Scanner-only evidence does not pass review with examiners who know the difference.
  • [03] Attack-path narrative per finding. Auditors increasingly ask what an adversary would do with each finding, not just its CVSS score.
  • [04] Remediation evidence packaged for the audit. Each retest produces a written delta document mapped to the original finding.

File · FAQ

Frequently Asked Questions

Q1 How often does SOC 2 require a pentest?

Most auditors expect annual, with retesting after material system changes. We scope around your audit window.

Q2 Does the report meet SOC 2 evidence requirements?

Yes. The technical report, executive summary, and retest delta are the artifacts examiners ask for.

Q3 Can you align with our existing audit timeline?

Yes. We scope around your audit window so evidence lands before fieldwork.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.