Skip to main content
Back to Blog
October 19, 2025 by Antoine Bouchardy GDPR & conformitate

Do you need a penetration test forSOC2?

Find out what is actually expected from theSOC2, why auditors often ask for a penetration test, and when it’s right to wait.

If you’re preparing for SOC2, you’ve probably asked yourself, “Do we need a penetration test?”

This is a good question, especially if SOC 2 framework never explicitly uses the term “penetration test”. what SOC2 technically requires is Identifying and removing security vulnerabilitiesThis can be done either through a vulnerability assessment or through a penetration test.

However, in practice, security-conscious auditors and customers expect a penetration test.

Key takeaways

  • Not explicitly required, but expected: Penetration testing is not authorized by SOC2, but auditors use it as a standard way to validate security requirements (common criteria).
  • Earlier, you can plan for later.
  • It’s the strongest proof: a pencil test proves that your system can withstand real attacks, not just intentions on paper.
  • There are different types: external, internal, white box, black box. Your choice depends on your infrastructure, your client or prospect application and scopeSOC2.

Why auditors expect a pen test

The Foundation is Security Principlewhich requires systems to be protected against unauthorized access and associated risks.

You can pretend that you are doing vulnerability tests, but a professional penetration test provides objective evidence.

Tipul testului de penetrare

TypeWhat it simulatesWhen it’s useful
External pen testAttacks on the public Internet (API-public websites, web applications).Minimum expected for SOC 2.
Internal pen test

Threats within your network or compromised employee credentials.

More relevant for larger or medium hybrid organs.
Black boxNo system knowledge was provided to the tester.Realistic threat simulation.
White box

Full access to source code, infrastructure, architectural diagrams.

The most complete and effective form.

If you’re early, it’s okay not to do it

You do not need a penetration test andSOC2, if:

  • You are pre-produced or in a very early stage.
  • Your infrastructure is still changing frequently.
  • No customer or partner requests a pen-test.
  • You’re still validating product-market fit.

In fact, taking a pen test too early can be wasted:

  • You will have to fix it when the systems change.
  • Audit evidence becomes outdated quickly.
  • Engineering time is better spent on building the product.

Best practice:
Build your product → implement basic safety hygiene → followSOC2 (and pencil testing) when a customer or partner explicitly requests it. Steps to Compliance, see our dedicated guide.

How the platform helps

The platform does not perform penetration tests directly, but we:

  • Help you choose the right seller and scope.
  • Make sure that the test aligns with the auditor’s expectationsSOC2.
  • Track remediation of vulnerabilities.
  • Organize all evidence in a ready-to-audit format.

So you don’t have to manage another project.

Conclusion

A penetration test is not technically mandatory in SOC2, but it has become the norm in the industry and the auditor’s expectation. However, if your start is still early or nobody asks for it yet, it’s perfectly okay to wait. You need a pencil test forISO27001.

Frequently asked questions

When should I do my penetration test?
After the security checks are in effect, but before the audit window starts, ideally 1-2 months in advance (so that you have time to correct all the findings).

How often is a penetration test required?
SOC2 only requires annual vulnerability tests, but a pen test is considered the gold standard.

Vulnerability Scanning vs. Penetration Test: What’s the Difference?

  • A vulnerability scan is automated and searches for known issues.
  • A penetration test is manual, targeted and simulates real attacks.
    Auditors strongly prefer the latter.

What if the penetration test finds critical vulnerabilities?
Auditors do not expect perfection, but only a process.

  • You prioritize fixes,
  • You remediate issues,
  • You can show evidence that you are doing this.

5. How much does a penetration test cost?
Typically $2,000 to +$25,000+, depending on the scope, the complexity of the infrastructure and the type of testing. For a broader picture of all the costs involved, see How much does compliance cost?.


Scris de Antoine Bouchardy
Antoine Bouchardy He writes about the security, compliance and regulatory challenges faced by growing teams.
Portret Antoine Bouchardy
ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert