AICPA · SOC 2 (System and Organization Controls 2)
Does SOC 2 require a penetration test?
SOC 2 is an attestation report produced by a licensed CPA firm against the AICPA Trust Services Criteria. It is the report most North American enterprise buyers ask a software vendor for.
The short answer
SOC 2 does not explicitly require a penetration test. The Trust Services Criteria never use the phrase. In practice most auditors accept a penetration test as the evidence for CC4.1, which calls for evaluations to confirm that controls are present and functioning, and CC7.1, which covers detecting vulnerabilities in the system. A startup that shows up with no testing evidence at all should expect questions.
Who it applies to
Software companies that hold or process customer data and are asked for security assurance during procurement. It is not a law, and no regulator compels it. Customers do.
In detail
The Trust Services Criteria are written as outcomes, not as a checklist of tools. That is deliberate, and it is why two auditors can reach different conclusions about the same control environment. CC4.1 asks the organization to select, develop and perform ongoing or separate evaluations to ascertain whether the components of internal control are present and functioning. CC7.1 asks it to use detection and monitoring procedures to identify changes to configurations and new vulnerabilities.
Neither criterion names a penetration test. Both are routinely satisfied by one, because a report that documents scope, method, findings, severity and remediation is a clean, dated artifact that an auditor can put in a workpaper. A vulnerability scan alone often will not carry CC4.1, because a scan confirms that a tool ran rather than that a control works.
The practical answer is that the auditor sets the bar, and the bar has risen. Enterprise customers reading the report have started asking whether testing was performed by someone independent of the engineering team that built the system. That is worth settling before the observation window opens rather than during it.
What to have in scope
- External network and public application surface in the system description
- Authentication, session handling and access control between tenants
- The systems that produce the evidence, not just the ones that hold the data
- A retest after remediation, so the report shows a closed loop rather than an open finding
Questions people ask
Does SOC 2 require a penetration test?
No. The AICPA Trust Services Criteria do not name penetration testing anywhere. A penetration test is the most common evidence used to satisfy CC4.1 and CC7.1, and most auditors expect some form of security testing, but the requirement is for an evaluation that shows controls are functioning, not for a specific technique.
How often do I need to test for SOC 2?
Annually is the norm, and once per observation window is the practical floor for a Type II. If the architecture changes materially inside the window, expect the auditor to ask what was tested after the change.
Can I use an automated scan instead of a penetration test?
Sometimes, for a Type I, with a cooperative auditor. It is a weaker artifact: a scan demonstrates that a tool ran, while CC4.1 asks whether a control is present and functioning. Buyers reading the report increasingly tell the difference.
Does the tester need to be independent?
The criteria do not say so directly, but independence from the team that built the system is what makes the evaluation meaningful under CC4.1, and enterprise reviewers have begun asking about it explicitly.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.