Last updated: July 26, 2026
Getting Ready · Compliance Q&A

Do I need a penetration test for SOC 2?

Not strictly. The AICPA's SOC 2 framework never names a penetration test as a required control, but most auditors and enterprise buyers expect one as evidence of vulnerability management, so in practice it is nearly standard.

The full answer

There is no line in the SOC 2 framework that says 'run a penetration test.' SOC 2 is built on the AICPA's Trust Services Criteria, which describe outcomes — like identifying and remediating vulnerabilities — rather than prescribing specific tools. So technically you could satisfy the criteria other ways.

In practice, a pentest is close to expected. Auditors look for evidence that you actively find and fix weaknesses, and a third-party penetration test (often paired with regular vulnerability scans) is the most recognized way to show it. Enterprise customers reviewing your report frequently ask whether one was performed, so skipping it can cost you deals even if your auditor accepts alternatives.

Independence shapes who does the test. Under AICPA independence rules, the CPA firm issuing your attestation cannot design or operate the controls it audits, which is why penetration testing and remediation are typically handled by a separate security vendor rather than the audit firm itself. Keep those engagements distinct.

Plan the test to fit your report window. For a Type 2, which covers an observation window of three to twelve months, run the pentest early enough that results and any remediation fall inside the period. When you request SOC 2 quotes through the AuditNex network — where audits start at $2,500 promotional and average about $5,000 — confirm whether pentest evidence is expected for your scope.

Go deeper

Short answer not enough? These pages cover the full picture:

Complete SOC 2 guide ›  ·  SOC 2 timeline estimator ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

Can a two-person startup get SOC 2?

Yes. SOC 2 has no minimum headcount; a two-person startup can earn a report. Controls simply scale to your size — the auditor assesses whether your controls fit your operations, not whether you have a large team.

Does SOC 2 cover remote work and BYOD?

Yes. SOC 2's Security criteria apply wherever your team works, so remote work and BYOD fall in scope. Auditors expect controls like endpoint protection, encryption, MDM or access policies, and secure authentication regardless of device location.

Does SOC 2 require MFA?

Effectively yes, though not by name. SOC 2's Trust Services Criteria require strong logical access controls without naming MFA, but auditors and customers treat multi-factor authentication as the baseline, so nearly every SOC 2 program enables it.

Does SOC 2 require a vendor management program?

Yes, in practice. SOC 2's Common Criteria include managing risks from vendors and subservice organizations, so auditors expect a vendor management process — inventory, risk-based due diligence, and monitoring — even though no single rule dictates its exact form.

Does SOC 2 require annual security training?

Not by a named rule. SOC 2's Trust Services Criteria require security awareness training but never specify a frequency; auditors and customers treat training at onboarding plus at least annually as the standard, so most companies run it yearly.

Does SOC 2 require background checks?

Not by name. SOC 2's Trust Services Criteria expect you to hire and retain trustworthy personnel but never mandate background checks specifically; auditors treat pre-employment screening as the standard way to evidence that control, so most companies run them.

All compliance questions ›

Sources: AICPA Trust Services Criteria (2017, rev. 2022); AICPA SSAE No. 18 attestation standards; AuditNex network rate card, 2026. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.