Requirements for a SOC 2 Penetration Test

Last updated: October 8, 2025

Context

When pursuing SOC 2 compliance, organizations are recommended to conduct a Penetration Test as part of their security assessment. Understanding the specific requirements for an acceptable penetration test is crucial for meeting the SOC 2 criteria for vulnerability management (Common Criteria 7.1)

Answer

A SOC 2 compliant penetration test must meet the following key requirements:

  1. Must be conducted by an independent third-party tester

  2. Must be performed manually by a human tester (automated scans alone are not sufficient)

  3. Can be unauthenticated (authenticated testing is not required)

Important considerations:

  • Automated vulnerability scanning tools (like ZAP) alone do not qualify as a penetration test

  • The tester can be located anywhere globally - there are no geographical restrictions

  • The tester should be properly accredited, though specific certifications are not mandated

  • SOC 2 Compliance require annual audits, meaning pen-tests are an annual requirement during your audit observation period

When selecting a penetration testing provider, you have several options:

  • Use an established security testing firm

  • Work with independent accredited security professionals

  • Partner with specialized penetration testing companies

The penetration test should be completed or actively in progress before your SOC 2 audit. Make sure to obtain a full report documenting the findings and remediation efforts, as a simple attestation letter is not sufficient for audit purposes.

Penetration Tests are available through Mycroft in Success Packages and as an annual subscription. Contact us for more information.

Pen-Tests with Mycroft

After purchasing a Pen-Test with Mycroft, you will receive a request for more information so we can send a formal Rules of Engagement (ROE) form to outline the terms for the penetration test. A signed ROE is required before we can begin the pen-test.

Download our Rules of Engagement Template here

How quickly can I schedule my Pen-Test?

If you have everything ready, the range to schedule is 1-4 weeks, depending on demand and availability of our pen-testers.

Reach out to Mycroft for the next available pen-test date, or to inquire if your preferred date is available. As they are subject to availability, we cannot guarantee dates and recommend making arrangements in advance. Pen-test dates are secured after the Rules of Engagement letter is signed.

If your preferred date is not available, or you would like a pen-test sooner, we can keep you informed of dates that are tentatively booked (pending signed ROE), or of last minute changes/cancellations.

How long does a Mycroft Pen-Test take?

A minimum of 5 business days for all testing and reporting. Complex pen-tests would be scoped beforehand and a timeframe would be provided if it exceed 5 business days.

How do I receive my Pen-Test results?

Your Pen-Test draft report is uploaded to your Mycroft Platform as evidence. You will have the opportunity to review it and add any comments before we upload a final version to your Trust Center. Documents in your Trust Center not accessible to Third-Parties unless access is granted.