AICPA · SOC 2 Type II
Does SOC 2 Type II require a penetration test?
A SOC 2 Type II reports on whether controls operated effectively across an observation window, usually three to twelve months. It is the report most enterprise procurement teams treat as the real one.
The short answer
A Type II does not name penetration testing either, but the observation window changes the practical answer. The test needs to fall inside the window, and if findings were raised, the report reads far better when a retest inside the same window shows them closed.
Who it applies to
Companies selling into enterprise, regulated industries, or any buyer whose vendor review has a security questionnaire attached.
In detail
The difference between Type I and Type II is time. A Type II asks whether the controls ran, repeatedly, over a period the auditor observes. That turns a penetration test from a snapshot artifact into part of a cycle: test, remediate, retest, and show the dates.
Most first Type II windows are three months, because that is the shortest period an auditor will usually accept and startups are under deal pressure. Renewal windows are typically twelve. A three-month window leaves very little room to find a critical issue, fix it and prove the fix, which is the argument for testing before the window opens as well as inside it.
The part teams underestimate is the retest. An open critical finding sitting in a Type II report is a conversation with every prospect who reads it. A closed one with a dated retest is a demonstration that the vulnerability management control actually works, which is what CC7.1 is asking about in the first place.
What to have in scope
- A test dated inside the observation window, not before it
- Remediation tracked with dates, owners and evidence
- A retest inside the same window for anything rated high or critical
- Coverage of material architecture changes made during the window
Questions people ask
Does a SOC 2 Type II require a penetration test?
Not explicitly. The Trust Services Criteria do not name the technique. In practice auditors expect security testing evidence inside the observation window, and a penetration test with a documented retest is the artifact that satisfies CC4.1 and CC7.1 most cleanly.
When in the observation window should the test happen?
Early enough to leave room to remediate and retest before the window closes. Testing in the final weeks is the most common scheduling error, because a critical finding then has nowhere to go but into the report.
How long is a SOC 2 Type II observation window?
Three to twelve months. First-time reports are often three months to get something in front of buyers quickly; renewals are usually twelve so the reports form a continuous chain with no gap between them.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.