What SOC 2 actually says
The Trust Services Criteria don't list "penetration test" as a control. Two criteria create the expectation. CC4.1 asks you to "perform ongoing and/or separate evaluations" that your controls are present and functioning. CC7.1 asks you to detect "susceptibilities to newly discovered vulnerabilities." Auditors have settled on a practical reading: at least one external penetration test a year (internal too, if your infrastructure is in scope), with a written methodology and evidence that findings were fixed. Show up without one and expect an exception in your report or a delay.
What your auditor needs to see
- A dated report covering the systems in your SOC 2 scope
- The methodology used and the severity of each finding
- Proof that findings were remediated and retested
- A test performed within the audit period (usually the last 12 months)
Getting it done this week
Clone Systems automated external penetration testing runs attacker techniques against your internet-facing systems, starts in minutes, and produces an executive summary plus technical findings with retesting included. From $1,995 for one asset over 30 days; $3,495 for 10. Add the internal penetration testing from $2,995 if your servers or office network are in scope. If your auditor asks for a human-led test or your product has complex business logic, managed penetration testing by Clone Systems engineers is scoped per environment.
Why Clone Systems
PCI Approved Scanning Vendor since 2007, 100 million vulnerability checks a day, published prices, buy online. Startups on their first SOC 2 can start with the founder package.
Buy a pen test and start today · Request managed pen test scoping
Related
- A real penetration test used to cost $10,000
- Penetration testing for HIPAA
- Penetration testing for ISO 27001
- Penetration testing for PCI DSS Requirement 11.4
Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. This page is general guidance, not legal or audit advice.
