Does SOC 2 Require Penetration Testing?
SOC 2 does not explicitly list "penetration testing" as a named requirement the way NYDFS or PCI DSS do. Instead, the AICPA Trust Service Criteria, particularly CC6 (Logical and Physical Access Controls) and CC7 (System Operations), require organizations to identify and address vulnerabilities in their systems. In practice, auditors interpret this to require independent security testing, and penetration testing is the accepted standard for satisfying that expectation.
As SOC 2 has matured and become table stakes for SaaS companies and service providers handling sensitive data, the bar has risen. Auditors at Big Four firms and major CPA practices increasingly require a penetration test report as part of the audit evidence package, especially for SOC 2 Type II reports, which cover a period of time rather than a point in time.
Which Trust Service Criteria Are Relevant?
- CC6.1: The entity implements logical access security measures to protect against unauthorized access. Penetration testing validates these controls work as intended.
- CC6.6: The entity implements controls to protect against unauthorized access from outside the system boundaries. External penetration testing directly addresses this.
- CC7.1: The entity uses detection and monitoring procedures. Testing validates that detection works as designed.
- A1.2 (Availability): The entity implements controls to prevent and detect unauthorized changes. Testing validates this.
What Auditors Actually Request
During a SOC 2 audit, your auditor will typically request the penetration test report, evidence of when the test was conducted, documentation of findings, and evidence that high and critical findings were remediated within a reasonable timeframe. Some auditors will also ask whether the testing firm is independent from your organization, which rules out testing conducted entirely by internal staff.
Scope Considerations for SOC 2
For SOC 2 purposes, the scope of your penetration test should match the scope of your SOC 2 audit, i.e., the systems and infrastructure that support the service being audited. For a SaaS company, this typically means the web application, its APIs, and the cloud infrastructure hosting it. For a managed services provider, it may include network infrastructure as well.
Grid32 and SOC 2 Clients
Grid32 works with technology companies, SaaS providers, and managed services firms across New York and New Jersey who need penetration testing as part of their SOC 2 program. Our reports include the documentation auditors request, scope, methodology, findings with severity ratings, and a remediation summary, formatted to integrate directly into your audit evidence package.
When Should You Schedule Testing Relative to the Audit?
For a Type II report, schedule the penetration test inside the audit period so the evidence falls within the window the auditor is attesting to. Testing early in the period leaves time to remediate findings and demonstrate the remediation before the period closes, which reads far better in the report than open criticals. For a Type I, test before the as-of date. If you are unsure where your audit window falls, your auditor will tell you exactly what period the evidence must cover; we scope and schedule around it routinely.
What Evidence Does the Auditor Actually Want?
Auditors typically request the penetration test report itself or an attestation letter summarizing scope, methodology, findings, and remediation status. Every Grid32 engagement includes both: a tiered report with an executive summary auditors can read quickly, and attestation documentation built for exactly this handoff. Ask any prospective vendor to show you what their attestation package looks like before you sign.
What Does SOC 2 Penetration Testing Cost?
SOC 2 engagements are scoped and priced like any Grid32 test, since the work is the same and the difference is documentation. External network testing starts at $3,995, internal at $3,995, and web application testing at $4,995, which matters for SaaS companies whose SOC 2 scope centers on the application. Most SOC 2 clients combine an external network test with a web application assessment. Real numbers are in the quote builder and our pricing guide.
Preparing for a SOC 2 audit?
Grid32 provides penetration testing that satisfies SOC 2 auditor requirements. We work with your auditor's timeline and provide documentation formatted for the evidence package.
Get a Quote →