Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Does SOC 2 require a penetration test?
Last verifiedSOC 2 has no explicit “annual pen test” mandate in the Trust Services Criteria. Testing supports CC4.1, CC7.1, and CC7.2, and many examiners expect it as practice. A scan is not automatically that evidence. This page is not legal advice.
SOC 2 pen testing, last verified 10 September 2026 against the AICPA Trust Services Criteria (2017, rev. 2022) CC4.1, CC7.1, and CC7.2 and AICPA SOC 2 guidance. The TSC does not name “penetration test.” Auditor practice is not the criterion text. Not legal advice. Not a determination that YOU need SOC 2.
The TSC does not say “annual pen test”
Audience: a CISO preparing for SOC 2. This page is not legal advice. Kind of text: the Trust Services Criteria are attestation criteria (AICPA). They are not a statute. They do not contain a line that says “perform an annual penetration test.” Common examiner requests for an independent test are auditor practice / industry best practice, not a named TSC requirement. NIST SP 800-115 remains methodology guidance if you do test. ShipReady Metrics recommendation: collect testing evidence mapped to the criteria you actually claimed — the product does not issue a SOC 2 report.
TSC crosswalk — which criteria testing supports
Support is not a finding that the criterion is met. Last verified 10 September 2026. Not legal advice.
| Criterion | What the TSC is about | How testing can support it | Kind of text |
|---|---|---|---|
| CC4.1 | The entity selects, develops, and performs ongoing evaluations to ascertain whether COSO components are present and functioning. | A scoped independent test is one evaluation input among monitoring activities. | Attestation criterion. “Pen test” is not the TSC wording. |
| CC7.1 | Detection of anomalies and indicators of compromise; evaluation of security events. | Scanning, SAST/DAST, and a pen test all produce detection evidence. They are not interchangeable. | Attestation criterion. |
| CC7.2 | Monitoring of detection-system effectiveness and response to identified issues. | Remediation tickets and retest confirmation show the monitoring loop closed. | Attestation criterion plus auditor practice on evidence quality. |
Auditor-expectation note
Many SOC 2 examiners, especially on Type II periods for internet-facing SaaS, ask for a recent independent penetration test or a documented reason it was not performed. That ask is auditor practice. It is not a silent rewrite of the TSC. Ask your examiner in writing what they expect for THIS period. A vulnerability scan, first-party SAST, or a two-year-old test may or may not be accepted — this page does not predict that. Last verified 10 September 2026. Not legal advice.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Read CC4.1, CC7.1, and CC7.2 in the TSC yourself. Do not rely on a blog that says “SOC 2 requires an annual pen test.”
- Ask the examiner what testing evidence they expect for this period. Document the answer.
- Keep authorization, report, remediation, and retest. Open the evidence-retention guide on this site.
- Compare SOC 2 and ISO 27001 honestly — they are different instruments. Open the compare guide on this site.
Checklist
Question list. Not a SOC 2 opinion. Not legal advice.
- Have we claimed Security, and which complementary criteria?
- What written testing evidence exists inside the review period?
- If no pen test, is the alternative documented and accepted by the examiner?
- Does the obligation map mark SOC 2 in-scope without treating that mark as an applicability determination?
Where this shows up in ShipReady Metrics
SOC 2 evidence collection, review, and the met-verdict overlay store testing artifacts. A controls crosswalk of about 72 canonical controls includes a density-honesty layer — coverage is not certification. Marking SOC 2 in-scope on the obligation map is not a determination that YOU need SOC 2. This product does not issue a SOC 2 report and does not replace an independent pen test.
Primary sources (last verified 10 September 2026)
AICPA Trust Services Criteria (2017, with revised points of focus 2022) CC4.1, CC7.1, CC7.2. AICPA SOC 2 guide materials. Those texts do not name an annual pen test. Not legal advice.