SOC 2 Penetration Testing
Independent testing evidence for the SOC 2 Common Criteria — and for the vendor security questionnaires that gate every enterprise deal.
How testing supports SOC 2
SOC 2 does not list ‘penetration test’ as a line item, but a credible report expects evidence that security controls were verified rather than assumed. The Common Criteria around change management and risk (CC7) and logical access (CC6) are where an assessor looks for proof of testing, and enterprise buyers increasingly ask for a recent penetration test directly alongside the report. One engagement satisfies both.
What a test evidences
A single engagement produces evidence across these areas of SOC 2.
CC6 — logical access
Testing the access controls, authentication and authorization the criteria expect to be effective.
CC7 — system operations
Evidence that vulnerabilities are identified and managed, which independent testing directly supports.
Vendor questionnaires
A current test plus a completed SIG or CAIQ is usually what unblocks an enterprise procurement review.
Type I and Type II
Testing supports both the point-in-time and the period-of-operation report, and is repeatable annually.
Evidence for every framework at once
Most organizations answer to several frameworks, not one.
We scope a single penetration test so its findings and evidence serve SOC 2 alongside the other standards your auditors, customers and insurers ask about — instead of running overlapping engagements for each.
| Finding | Severity | Maps to |
|---|---|---|
| Cross-tenant data access | Critical | S2 |
| Over-privileged access | High | S2 |
| Weak session handling | Medium | S2 |
SOC 2 testing, answered
Does SOC 2 legally require a penetration test?
No standard mandates it word-for-word, but auditors and customers expect evidence that controls were tested. In practice a penetration test is the standard way organizations provide that evidence for CC6 and CC7.
How often should we test for SOC 2?
Annually, and after any significant change to in-scope systems. That cadence matches what most auditors and enterprise customers expect to see.
Other frameworks we test against
PCI DSS 4.0
Requirement 11.4 internal and external testing, plus segmentation validation where you rely on it.
HIPAA
The technical half of a Security Rule risk analysis for providers, payers and digital health.
CMMC 2.0
NIST SP 800-171 and DFARS evidence for defense contractors handling controlled unclassified information.
Testing for SOC 2?
Tell us the framework and the deadline. We scope to the evidence your assessor needs.