Trust services

SOC 2 Penetration Testing

Independent testing evidence for the SOC 2 Common Criteria — and for the vendor security questionnaires that gate every enterprise deal.

Overview

How testing supports SOC 2

SOC 2 does not list ‘penetration test’ as a line item, but a credible report expects evidence that security controls were verified rather than assumed. The Common Criteria around change management and risk (CC7) and logical access (CC6) are where an assessor looks for proof of testing, and enterprise buyers increasingly ask for a recent penetration test directly alongside the report. One engagement satisfies both.

Where it maps

What a test evidences

A single engagement produces evidence across these areas of SOC 2.

CC6 — logical access

Testing the access controls, authentication and authorization the criteria expect to be effective.

CC7 — system operations

Evidence that vulnerabilities are identified and managed, which independent testing directly supports.

Vendor questionnaires

A current test plus a completed SIG or CAIQ is usually what unblocks an enterprise procurement review.

Type I and Type II

Testing supports both the point-in-time and the period-of-operation report, and is repeatable annually.

One engagement

Evidence for every framework at once

Most organizations answer to several frameworks, not one.

We scope a single penetration test so its findings and evidence serve SOC 2 alongside the other standards your auditors, customers and insurers ask about — instead of running overlapping engagements for each.

soc-2-evidence.pdf
FindingSeverityMaps to
Cross-tenant data accessCriticalS2
Over-privileged accessHighS2
Weak session handlingMediumS2
Questions

SOC 2 testing, answered

Does SOC 2 legally require a penetration test?

No standard mandates it word-for-word, but auditors and customers expect evidence that controls were tested. In practice a penetration test is the standard way organizations provide that evidence for CC6 and CC7.

How often should we test for SOC 2?

Annually, and after any significant change to in-scope systems. That cadence matches what most auditors and enterprise customers expect to see.

Testing for SOC 2?

Tell us the framework and the deadline. We scope to the evidence your assessor needs.