The SOC 2 Type II pentest checklist. What auditors actually demand.
Direct Answer: For SOC 2 Common Criteria 7.1 (CC7.1), CPA auditors require third-party technical penetration testing that proves vulnerability monitoring and configuration controls hold against manual exploitation. Automated scanner dumps are routinely rejected. Compliance requires: (1) An independent CREST-aligned testing team; (2) Manual testing aligned to OWASP WSTG and API Top 10; (3) Testing dated within your observation window; and (4) A signed Letter of Attestation confirming verified retest closure.
External CPA examination teams (A-LIGN, Schellman, Prescient Security, Johanson Group, Sensiba) mandate third-party penetration testing evidence. Kangsol delivers audit-ready packages mapped directly to CC7.1 with a free 60-day retest included.
> Control: CC7.1 Vulnerability Management
> Evidence: Manual Third-Party Penetration Test
> Scope: Web App, Authenticated API & Cloud IAM
> Methodology: OWASP WSTG + NIST SP 800-115
> Artifact 1: Signed Letter of Attestation
> Artifact 2: Executive Summary Report
> Artifact 3: Remediation & Retest Verification Log
✓ 100% CPA auditor acceptance rate
✓ Compatible with Vanta, Drata, Secureframe
Audit-ready deliverable structure accepted by top tier accounting and GRC audit firms.
Technical audit requirements checklist for SOC 2 CC7.1.
Relying solely on automated vulnerability scanners (like Snyk, Wiz, AWS Inspector, or Nessus) is one of the most common causes of audit exceptions. Here is how CPA examination teams evaluate your technical testing evidence:
| Requirement Area | Auditor Demand | What Passes Audit Inspection | What Fails Audit Inspection |
|---|---|---|---|
| Independence | Tested by an objective party outside the operating team. | Third-party accredited testing team (CREST-aligned) with written rules of engagement. | Self-testing by internal developers, or scan reports without third-party validation. |
| Methodology | Systematic, industry-recognised testing framework. | Manual exploitation aligned to OWASP WSTG, OWASP API Top 10, and NIST SP 800-115. | Automated scanner dumps without false-positive elimination or manual verification. |
| Observation Window | Testing executed inside the audited observation window. | Penetration test completed and dated within the 3–12 month observation period. | Stale report dated outside the audit window, or failure to maintain annual cadence. |
| Remediation & Retest | Proof that vulnerabilities were remediated and verified. | Retest report confirming verified closure, dated retest logs, and Letter of Attestation. | Report showing open Critical or High findings without evidence of re-testing. |
| Scope Boundaries | Explicit perimeter covering customer data and production paths. | Clear scope statement covering web endpoints, APIs, cloud IAM, and Kubernetes workloads. | Ambiguous scope statements or omission of core authentication and database paths. |
SOC 2 Type I vs. Type II penetration testing expectations.
The timing and evidence expectations differ significantly between the two audit stages:
SOC 2 Type I: Point-in-Time Design
Evaluation Goal: Validates whether security controls are designed properly at a specific point in time.
Pentest Deliverable: An external penetration test executed immediately prior to or on the designated audit date. The report demonstrates that attack surfaces and API authorization mechanisms were subjected to adversarial testing.
Required Evidence: Executive summary report and signed Letter of Attestation on letterhead.
SOC 2 Type II: Operational Effectiveness
Evaluation Goal: Evaluates whether security controls operated effectively over an observation window (typically 3, 6, or 12 months).
Pentest Deliverable: A penetration test completed within the audit window. Auditors check vulnerability remediation SLAs (e.g. Criticals patched in 48 hours, Highs in 14-30 days) and require a verified retest before closing the report.
Required Evidence: Original finding report, dated developer remediation commits, and updated retest attestation proving verified closure.
The 3 artifacts included in Kangsol's SOC 2 deliverable pack.
Auditors and procurement officers do not want 80-page raw vulnerability dumps. We structure your deliverables for instant compliance sign-off:
Letter of Attestation
A formal, signed document on tester letterhead confirming independent testing occurred, detailing scope, methodology, dates, and tester credentials. Safe to share with enterprise buyers and upload directly to Vanta or Drata.
Executive Summary Report
A high-level risk overview designed for auditors, board members, and executives. Summarises vulnerability counts, control performance under attack, and verified remediation closure.
Full Technical Report
For your engineering team. Step-by-step reproduction instructions, HTTP request/response payloads, and verified remediation code samples tailored to your stack (Node, Go, Python, Kubernetes, Terraform).
SOC 2 CC7.1 penetration testing FAQ.
Does SOC 2 explicitly require a penetration test?
While the AICPA Trust Services Criteria do not explicitly use the words "penetration test," standard audit practice for Common Criteria 7.1 (CC7.1) requires independent technical testing evidence to prove that vulnerability identification and monitoring procedures operate effectively. External CPA firms (such as A-LIGN, Schellman, Prescient Security, and Sensiba) routinely mandate a third-party penetration test before issuing an unqualified SOC 2 report.
What is the difference between Type I and Type II pentest requirements?
SOC 2 Type I tests control design at a single point in time, requiring a current penetration test report before the designated audit date. SOC 2 Type II evaluates operating effectiveness over an observation window (typically 3 to 12 months), requiring testing completed during the audit period, documented SLA remediation times, and verified retesting before the window closes.
Why do auditors reject automated vulnerability scans for CC7.1?
Automated vulnerability scanners (like Snyk, Wiz, or Nessus) only check for known signatures. They cannot test business logic, exploit Broken Object-Level Authorization (BOLA/IDOR), verify privilege escalation, or confirm remediation closure. Auditors require independent, human-led verification with proof-of-concept evidence.
What documents must be uploaded to compliance platforms like Vanta or Drata for SOC 2?
Compliance platforms require two primary artifacts for the penetration testing control: (1) A signed Letter of Attestation on tester letterhead detailing scope, methodology, dates, and tester credentials; and (2) The full Executive Summary report detailing finding severities and verified retest closure.
How much does a SOC 2 penetration test cost?
At Kangsol, SOC 2 penetration tests start from AUD 9,500 ex GST for standard web application and API environments. Cloud configuration audits and Kubernetes audits start from AUD 12,000. All engagements include an audit-ready executive summary, Letter of Attestation, and a free 60-day retest.
Need audit-ready SOC 2 penetration testing evidence?
Testing is delivered by a CREST-certified team, with a signed Letter of Attestation and a free 60-day retest included. Get a fixed quote within one business day.