Does SOC 2 Require Penetration Testing?

SOC 2 does not explicitly list "penetration testing" as a named requirement the way NYDFS or PCI DSS do. Instead, the AICPA Trust Service Criteria — particularly CC6 (Logical and Physical Access Controls) and CC7 (System Operations) — require organizations to identify and address vulnerabilities in their systems. In practice, auditors interpret this to require independent security testing, and penetration testing is the accepted standard for satisfying that expectation.

As SOC 2 has matured and become table stakes for SaaS companies and service providers handling sensitive data, the bar has risen. Auditors at Big Four firms and major CPA practices increasingly require a penetration test report as part of the audit evidence package — especially for SOC 2 Type II reports, which cover a period of time rather than a point in time.

Which Trust Service Criteria Are Relevant?

  • CC6.1 — The entity implements logical access security measures to protect against unauthorized access. Penetration testing validates these controls work as intended.
  • CC6.6 — The entity implements controls to protect against unauthorized access from outside the system boundaries. External penetration testing directly addresses this.
  • CC7.1 — The entity uses detection and monitoring procedures. Testing validates that detection works as designed.
  • A1.2 (Availability) — The entity implements controls to prevent and detect unauthorized changes. Testing validates this.

What Auditors Actually Request

During a SOC 2 audit, your auditor will typically request the penetration test report, evidence of when the test was conducted, documentation of findings, and evidence that high and critical findings were remediated within a reasonable timeframe. Some auditors will also ask whether the testing firm is independent from your organization — which rules out testing conducted entirely by internal staff.

Scope Considerations for SOC 2

For SOC 2 purposes, the scope of your penetration test should match the scope of your SOC 2 audit — i.e., the systems and infrastructure that support the service being audited. For a SaaS company, this typically means the web application, its APIs, and the cloud infrastructure hosting it. For a managed services provider, it may include network infrastructure as well.

Grid32 and SOC 2 Clients

Grid32 works with technology companies, SaaS providers, and managed services firms across New York and New Jersey who need penetration testing as part of their SOC 2 program. Our reports include the documentation auditors request — scope, methodology, findings with severity ratings, and a remediation summary — formatted to integrate directly into your audit evidence package.

Preparing for a SOC 2 audit?

Grid32 provides penetration testing that satisfies SOC 2 auditor requirements. We work with your auditor's timeline and provide documentation formatted for the evidence package.

Get a Quote →