Skip to content

SOC 2 · Track A

SOC 2 does not require a penetration test. You will still be asked for one.

The Trust Services Criteria do not mandate penetration testing. CC4.1 asks that you evaluate your controls, and a test is one illustrative way to do that among several. Plenty of companies pass SOC 2 without one.

That is worth knowing before you spend money. The reason you are being asked is almost never the framework. It is a security reviewer at the enterprise customer you are trying to close, reading your report and looking for evidence that somebody independent actually tried.

Who is asking

Find out who wants this before you buy it.

The three sources of the request want different things, and only one of them is the auditor. Knowing which one you are answering changes the scope, and occasionally means you do not need the test at all.

  • Your customer’s security reviewer

    The most common source of the request, and the one people misattribute to the auditor. An enterprise buyer reads your SOC 2 report, notices there is no independent testing behind CC4.1, and asks for one before signing.

  • Your auditor, sometimes

    Some CPA firms ask for a penetration test as their preferred CC4.1 evidence. Others accept vulnerability scanning plus internal review. Ask yours what they will accept before you buy anything. It is a five-minute email that can save five figures.

  • Your own board or investors

    Common around a funding round or a first enterprise contract, where the question is less about the framework than about whether anyone competent has actually looked.

The boundary

This is the test, not the opinion.

A SOC 2 attestation can only be issued by a licensed CPA firm. That work is permanently out of scope here, which is exactly why an auditor can refer this engagement without hedging.

SOC 2 evidence pentest

from $14,000

A manual, human-led test producing evidence against CC4.1, and the artifact your enterprise customers ask for by name once they have read your SOC 2 report.

  • External and application scope
  • Manual exploitation
  • TSC-mapped findings
  • One retest

Typical duration · 6 days

Scope a SOC 2 test

Questions

What people ask before they scope this.

Does SOC 2 require a penetration test?
No. The Trust Services Criteria do not require a penetration test. CC4.1 requires that the organisation evaluates its controls, and a penetration test is one illustrative way to do that among several. Many organisations achieve SOC 2 without one. The pressure to have a test usually comes from customers reading the report rather than from the auditor.
Can Zero Harbor Security issue our SOC 2 report?
No. A SOC 2 attestation can only be issued by a licensed CPA firm. Zero Harbor Security performs the penetration test that feeds CC4.1 evidence and provides a signed attestation letter describing that test. It does not compete with your auditor and never issues an opinion.
What does a SOC 2 evidence penetration test cost?
A SOC 2 evidence penetration test is $14,000 as a fixed fee, covering 6 days of testing with one round of retesting included. The price is published rather than quoted on request.
How long does it take?
10 business days from signed authorisation. Scoping happens first and is agreed in writing; the clock starts at signed authorisation rather than at first contact, because scoping and your own legal review are not under the tester's control.
Do we need a Type I or Type II test?
Type I and Type II describe the audit period, not the penetration test. The same test supports either. What changes is timing: for Type II the test needs to fall inside the observation window, so agree the date with your auditor before scheduling.
What do we actually receive?
An executive summary written to be forwarded without editing, a technical report with evidence and remediation steps, a remediation status record, a signed attestation letter naming the practitioner, a coverage record showing what was tested including the checks that found nothing, and one retest.