Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Compliance pentest

SOC 2 penetration testing your auditor will actually read

SOC 2 penetration testing is not named as mandatory, but around 85 percent of Type II reports include one. So if a SOC 2 auditor sent you here, this is what they usually expect to see.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Soc 2 penetration testing: match the scope, test and report and retest letter

Why SOC 2 penetration testing is expected

The SOC 2 framework asks you to show that security controls work, not just that they exist. A penetration test is the clearest evidence of that, so most auditors ask for one. The AICPA SOC 2 overview describes the criteria your auditor tests against.

Also, the firm auditing you cannot run your test, because independence rules forbid it. Therefore buying the two separately is normal.

What SOC 2 penetration testing should cover

Scope the test to the systems in your SOC 2 boundary. Usually that means the product customers use and the internet edge around it.

  • The customer-facing application and its login
  • The API behind the application
  • The external network, including remote access
  • Cloud configuration, if your auditor asks for it

SOC 2 penetration testing readiness

Tick what is true today. Then send the open items with your scope, so we can plan around them.

Your result appears here as you tick, so you can see what is still open.

Which package fits a SOC 2 audit

Most SOC 2 buyers need the Standard pentest, because it covers up to three assets. However, a company with a single app and no API may only need the Essential package.

PackageFitsFrom
EssentialOne application or one external network.$5,900.
StandardApp, API and external network together, so most SOC 2 scopes.$14,500.
AdvancedAdds internal, cloud or mobile, because some auditors ask for more.$29,000.

Timing SOC 2 penetration testing in your audit window

For a Type II, the test should fall inside the observation period. So plan it early, because fixes and the retest also need to land before the period ends. In addition, book four to six weeks ahead in the fourth quarter.

What you hand the auditor

You hand over the report, or the attestation letter if the auditor accepts it, plus the retest letter. The retest letter matters most, because it shows the findings were closed rather than only found.

SOC 2 penetration testing questions

Is SOC 2 penetration testing mandatory?

Not by name. However, auditors expect evidence that controls work, so most Type II reports include a test.

Can our auditor run the test?

No, because independence rules stop the auditing firm from also testing you.

How often is SOC 2 penetration testing needed?

Annually is the norm, so most companies repeat it each audit cycle.

Will the attestation letter be enough?

Some auditors accept it, while others ask for the full report. So check with yours first.

Related guides

Get a fixed fee for SOC 2 penetration testing

Tell us your SOC 2 boundary and observation dates. We reply with a fixed fee, usually within four working hours, so you can plan the audit.

Get my fixed-fee quote