Setting up scheduled App Scan testing

Last updated: February 3, 2026

As part of your SOC 2 audit preparation, you can configure scheduled App Scan testing to automatically monitor your application for security vulnerabilities and improve your evidence for Incident Response Alerts.

Configuring Scheduled App Scans

Follow these steps to create a scheduled scan:

  1. Navigate to App Scan from the left Mycroft menu

  2. Select the Scan Jobs tab

  3. Select the Managed scheduled scans button

  4. Select the + Schedule scan button

  5. Fill out the fields in the Schedule scan form:

    • Targets

    • Date

    • Frequency: Weekly scanning is recommended for continuous monitoring

    • Scan Name

    • Notifications: Recommend Automatic alerts to be sent when significant vulnerabilities are detected

      • Alert Level: Recommend High and Critical findings only to focus on the most important security issues

Benefits for Compliance

Scheduled App Scan testing provides several compliance benefits:

  • Continuous security monitoring of your application

  • Automated evidence collection for Incident Response controls

  • Regular vulnerability assessments that demonstrate ongoing security practices

  • Documentation of your proactive security monitoring efforts

Reviewing Scan Results

After your first scheduled scan completes, review the report to ensure the configuration meets your needs. You can request adjustments to:

  • Scan frequency (daily, weekly, monthly)

  • Alert thresholds (which severity levels trigger notifications)

  • Notification recipients

  • Specific scan parameters

Contact your vendor if you need to modify any of these settings after reviewing your initial scan results.