SOC 2

SOC 2 penetration testing: requirements, timing, and what auditors expect

SOC 2 never uses the words penetration test, yet nearly every SOC 2 audit expects one. This guide explains why, how the test maps to the Trust Services Criteria, when to run it, and where continuous autonomous testing strengthens your evidence.

The Requirement

Is a penetration test required for SOC 2?

Technically no, practically yes. SOC 2 is an attestation against the Trust Services Criteria, and a penetration test is the most common way to prove the Security criterion is met by controls that actually resist attack, not just controls that exist on paper.

Security

The common criterion

Every SOC 2 covers the Security criterion. A penetration test is standard evidence that access controls, boundary protection, and change management hold up against a real adversary.

Timing

Before the window

Run the test inside the audit period with room to remediate. Open critical findings with no fix are the fastest way to complicate a report.

Scope

What the auditor sees

External and internal surfaces, the application, and the boundaries that protect customer data. Black, grey, and white box are all acceptable; agree the scope with your auditor.

Where Operator Fits

Evidence between annual attestations

A SOC 2 report covers a period, not a moment. Continuous autonomous testing produces dated, reproducible evidence across that whole period, which is stronger than a single point in time snapshot and exactly the ongoing diligence auditors have started to expect.

Operator hardens the surface before the formal engagement and keeps testing after it, and a certified practitioner signs the assessment where your auditor needs a human behind it.

  • Continuous, dated evidence across the audit period, not one snapshot.
  • Mapped to recognized method so findings trace to NIST SP 800-115 and CVSS.
  • Human signed where the auditor requires an accredited person.
  • Retest included, so fixed findings are verified before the report.
FAQ

Common questions

Does SOC 2 require a penetration test?

Not by name. SOC 2 is built on the Trust Services Criteria, and neither AICPA nor the criteria mandate a penetration test outright. In practice, auditors routinely expect one as evidence that your controls work, so most organizations treat it as required.

When should we run the SOC 2 penetration test?

Before the audit evidence window closes, with enough time to remediate significant findings and, ideally, retest them before the report is issued. Running it too late leaves open findings visible to the auditor with no fix in place.

Can autonomous testing be used for SOC 2?

Yes, as continuous evidence of ongoing diligence between engagements, and to harden the surface before the formal test. Where your auditor wants an assessment a person stands behind, a certified practitioner reviews and signs the report.

What are the SOC 2 penetration testing requirements?

SOC 2 does not name a specific test in the framework text. A penetration test is the accepted way to satisfy the risk assessment and monitoring criteria (notably CC4.1 and CC7.1) by demonstrating that controls are tested against real attack techniques. Auditors expect a scoped assessment against a recognized methodology, findings rated by severity, and evidence that issues were remediated and retested, usually once a year and after significant change.

How much does a SOC 2 penetration test cost?

A SOC 2 focused penetration test typically runs from about 8,000 to 30,000 US dollars depending on the size of the in-scope system, sitting in the upper half of general market ranges because of the added documentation and retesting an auditor expects. See our penetration testing cost guide for the full breakdown.

Get Started

Walk into your SOC 2 audit prepared

Continuous coverage before and after the engagement, with evidence your auditor recognizes.