SOC 2 never uses the words penetration test, yet nearly every SOC 2 audit expects one. This guide explains why, how the test maps to the Trust Services Criteria, when to run it, and where continuous autonomous testing strengthens your evidence.
Technically no, practically yes. SOC 2 is an attestation against the Trust Services Criteria, and a penetration test is the most common way to prove the Security criterion is met by controls that actually resist attack, not just controls that exist on paper.
Every SOC 2 covers the Security criterion. A penetration test is standard evidence that access controls, boundary protection, and change management hold up against a real adversary.
Run the test inside the audit period with room to remediate. Open critical findings with no fix are the fastest way to complicate a report.
External and internal surfaces, the application, and the boundaries that protect customer data. Black, grey, and white box are all acceptable; agree the scope with your auditor.
A SOC 2 report covers a period, not a moment. Continuous autonomous testing produces dated, reproducible evidence across that whole period, which is stronger than a single point in time snapshot and exactly the ongoing diligence auditors have started to expect.
Operator hardens the surface before the formal engagement and keeps testing after it, and a certified practitioner signs the assessment where your auditor needs a human behind it.
Not by name. SOC 2 is built on the Trust Services Criteria, and neither AICPA nor the criteria mandate a penetration test outright. In practice, auditors routinely expect one as evidence that your controls work, so most organizations treat it as required.
Before the audit evidence window closes, with enough time to remediate significant findings and, ideally, retest them before the report is issued. Running it too late leaves open findings visible to the auditor with no fix in place.
Yes, as continuous evidence of ongoing diligence between engagements, and to harden the surface before the formal test. Where your auditor wants an assessment a person stands behind, a certified practitioner reviews and signs the report.
SOC 2 does not name a specific test in the framework text. A penetration test is the accepted way to satisfy the risk assessment and monitoring criteria (notably CC4.1 and CC7.1) by demonstrating that controls are tested against real attack techniques. Auditors expect a scoped assessment against a recognized methodology, findings rated by severity, and evidence that issues were remediated and retested, usually once a year and after significant change.
A SOC 2 focused penetration test typically runs from about 8,000 to 30,000 US dollars depending on the size of the in-scope system, sitting in the upper half of general market ranges because of the added documentation and retesting an auditor expects. See our penetration testing cost guide for the full breakdown.
Continuous coverage before and after the engagement, with evidence your auditor recognizes.