Requirements for a SOC 2 Penetration Test
Last updated: October 8, 2025
Context
When pursuing SOC 2 compliance, organizations are recommended to conduct a Penetration Test as part of their security assessment. Understanding the specific requirements for an acceptable penetration test is crucial for meeting the SOC 2 criteria for vulnerability management (Common Criteria 7.1)
Answer
A SOC 2 compliant penetration test must meet the following key requirements:
Must be conducted by an independent third-party tester
Must be performed manually by a human tester (automated scans alone are not sufficient)
Can be unauthenticated (authenticated testing is not required)
Important considerations:
Automated vulnerability scanning tools (like ZAP) alone do not qualify as a penetration test
The tester can be located anywhere globally - there are no geographical restrictions
The tester should be properly accredited, though specific certifications are not mandated
SOC 2 Compliance require annual audits, meaning pen-tests are an annual requirement during your audit observation period
When selecting a penetration testing provider, you have several options:
Use an established security testing firm
Work with independent accredited security professionals
Partner with specialized penetration testing companies
The penetration test should be completed or actively in progress before your SOC 2 audit. Make sure to obtain a full report documenting the findings and remediation efforts, as a simple attestation letter is not sufficient for audit purposes.
Penetration Tests are available through Mycroft in Success Packages and as an annual subscription. Contact us for more information.
Pen-Tests with Mycroft
After purchasing a Pen-Test with Mycroft, you will receive a request for more information so we can send a formal Rules of Engagement (ROE) form to outline the terms for the penetration test. A signed ROE is required before we can begin the pen-test.
How quickly can I schedule my Pen-Test?
If you have everything ready, the range to schedule is 1-4 weeks, depending on demand and availability of our pen-testers.
Reach out to Mycroft for the next available pen-test date, or to inquire if your preferred date is available. As they are subject to availability, we cannot guarantee dates and recommend making arrangements in advance. Pen-test dates are secured after the Rules of Engagement letter is signed.
If your preferred date is not available, or you would like a pen-test sooner, we can keep you informed of dates that are tentatively booked (pending signed ROE), or of last minute changes/cancellations.
How long does a Mycroft Pen-Test take?
A minimum of 5 business days for all testing and reporting. Complex pen-tests would be scoped beforehand and a timeframe would be provided if it exceed 5 business days.
How do I receive my Pen-Test results?
Your Pen-Test draft report is uploaded to your Mycroft Platform as evidence. You will have the opportunity to review it and add any comments before we upload a final version to your Trust Center. Documents in your Trust Center not accessible to Third-Parties unless access is granted.