SOC 2 Type II and pentesting: what security testing your SaaS needs
By the QuantumSec team
SOC 2 Type II is the benchmark security certification for SaaS companies selling to enterprise customers, particularly in English-speaking markets. It does not explicitly mandate a penetration test, but in practice auditors review evidence of periodic security testing, and large enterprise customers who require the SOC 2 report ask specifically about pentesting. Understanding exactly what they expect saves you time and money.
What SOC 2 is and why enterprise customers ask for it
SOC 2 (System and Organization Controls 2) is an auditing standard created by the AICPA that evaluates the internal security controls of a technology service provider. SOC 2 Type I validates that the controls exist at a given point in time. SOC 2 Type II validates that those controls operate effectively over a period of 6 to 12 months. North American and English-speaking enterprise customers require it as a prerequisite for engaging any SaaS that handles their data. A growing number of European companies request it too.
Where pentesting fits into SOC 2
SOC 2 is built on five Trust Services Criteria (TSC): Security, Availability, Processing Integrity, Confidentiality and Privacy. The Security criterion includes Common Criteria CC7.1: "The entity uses detection and monitoring procedures to identify changes to configurations or the introduction of new vulnerabilities." SOC 2 auditors interpret this as requiring a documented vulnerability management process that includes periodic penetration testing. In practice, auditors ask for evidence of at least one pentest during the audit period.
What kind of pentest a SOC 2 auditor accepts
The SOC 2 standard does not prescribe the exact pentesting methodology, but auditors verify that: the test was carried out by an independent third party (not your own development team), it covers the scope relevant to the audited service (application, APIs, infrastructure), there is a formal report with findings and a severity classification, and there is evidence of a remediation process for the critical and high findings. An internal pentest or a simple automated scan is generally not enough to satisfy the more demanding auditors.
Differences between SOC 2 and ISO 27001 on pentesting
Both SOC 2 and ISO 27001 require periodic security testing, but with different nuances. ISO 27001 (controls A.8.8 and A.5.36) is more prescriptive about risk management and calls for a formal analysis that may include pentesting as a treatment measure. SOC 2 is more oriented towards evidence of operational controls: you need to demonstrate that pentesting is performed, that findings are remediated and that a repeatable process exists. In practice, a single well-documented annual pentest serves as evidence for both certifications.
How to get your SaaS ready for pentesting before the SOC 2 audit
To maximise the value of pentesting as SOC 2 evidence: commission the pentest at least 3 months before the start of the audit period, so you have time to remediate findings; make sure the report includes the scope, the methodology, the findings with CVSS severity and the remediation status; document the finding-tracking process (Jira, GitHub Issues); and, where possible, include a re-test that confirms the critical and high findings have been fixed.
What enterprise customers ask about your SaaS pentesting
Enterprise security questionnaires (SIG, CAIQ or bespoke questionnaires) ask specifically: do you run external pentesting at least annually? Is it performed by an independent third party? Do you share the executive summary of the report? What was the most critical finding and when was it remediated? Do you run a bug bounty programme? Having a recent pentest report from an accredited firm (OSCP-certified team) answers these questions directly and accelerates the enterprise sales process.
FAQ
Is pentesting mandatory to obtain SOC 2 Type II?
It is not technically mandatory under the standard, but in practice it is very hard to pass a SOC 2 Type II audit without evidence of penetration testing. Auditors at firms such as A-LIGN, Schellman or Prescient specifically review vulnerability detection controls and expect to see an annual pentest.
When should I run the pentest relative to the SOC 2 audit period?
Within the audit period (the 12 months the SOC 2 Type II report covers). If your period runs January to December, the pentest should take place within that year. Many companies run it in Q2 or Q3 to leave time to remediate findings before the period closes.
Does the QuantumSec report work as evidence for SOC 2 auditors?
Yes. The report we deliver is designed to be shared with auditors and enterprise customers. It includes an executive summary with scope and methodology, a list of findings with CVSS classification and the remediation status. It is exactly what SOC 2 auditors ask for.