Penetration testing for SOC 2

If you're preparing for a SOC 2 audit, your auditor is going to ask for a penetration test. SOC 2 never uses those words, which is why so many companies find out late. This page explains where the expectation comes from, what a report needs to show, and how to get one this week without a consulting engagement.

Penetration testing for SOC 2

What SOC 2 actually says

The Trust Services Criteria don't list "penetration test" as a control. Two criteria create the expectation. CC4.1 asks you to "perform ongoing and/or separate evaluations" that your controls are present and functioning. CC7.1 asks you to detect "susceptibilities to newly discovered vulnerabilities." Auditors have settled on a practical reading: at least one external penetration test a year (internal too, if your infrastructure is in scope), with a written methodology and evidence that findings were fixed. Show up without one and expect an exception in your report or a delay.

What your auditor needs to see

  • A dated report covering the systems in your SOC 2 scope
  • The methodology used and the severity of each finding
  • Proof that findings were remediated and retested
  • A test performed within the audit period (usually the last 12 months)

Getting it done this week

Clone Systems automated external penetration testing runs attacker techniques against your internet-facing systems, starts in minutes, and produces an executive summary plus technical findings with retesting included. From $1,995 for one asset over 30 days; $3,495 for 10. Add the internal penetration testing from $2,995 if your servers or office network are in scope. If your auditor asks for a human-led test or your product has complex business logic, managed penetration testing by Clone Systems engineers is scoped per environment.

Why Clone Systems

PCI Approved Scanning Vendor since 2007, 100 million vulnerability checks a day, published prices, buy online. Startups on their first SOC 2 can start with the founder package.

Buy a pen test and start today · Request managed pen test scoping

Related

Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. This page is general guidance, not legal or audit advice.

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.