SOC 2 penetration testing
SOC 2 (System and Organization Controls 2)
The independent penetration test report your CPA firm files as evidence for the monitoring and vulnerability criteria.
Engagement at a glance
Drives testing
CC4.1 and CC7.1: Monitoring activities and vulnerability detection
Cadence
At least annually, and after significant change, inside the review period
Typical duration
2 to 3 weeks of testing, plus retest after your fixes land
Region
Global, US origin
Issued by
Opinion issued by an independent licensed CPA firm
2
Criteria directly evidenced
0
Open findings once retest closes
v4.0
CVSS scoring standard
Annual
Recommended cadence
The requirement
What SOC 2 asks for
CC4.1 and CC7.1 · Monitoring activities and vulnerability detection
The entity selects, develops and performs ongoing and separate evaluations to ascertain whether controls are present and functioning (CC4.1), and detects and monitors changes and vulnerabilities that could affect the system (CC7.1).
SOC 2 does not use the words "penetration test" in the Trust Services Criteria, which surprises people. What it does require is that you perform separate evaluations of your controls (CC4.1) and that you detect vulnerabilities in your system (CC7.1). In practice, every CPA firm and every enterprise buyer reads that as an independent penetration test.
The report only counts if it is built correctly. Auditors check that the tester is independent of your engineering team, that the scope matches the system boundary in your description, that the testing dates fall inside the review period, and above all that findings were fixed and independently retested. An open critical finding at period end is a conversation you do not want to have in fieldwork.
XHack delivers that report. We scope it against your system description, test it, rate every finding with CVSS v4.0, work with your team through remediation, retest each finding to closure and sign an attestation letter. Your CPA firm issues the opinion. We give them the evidence they need to do it.
What your auditor checks
The report has to clear every one of these
These are the questions a SOC 2 auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.
Performed by a third party independent of the client and its developers
Testers qualified and named, with certifications stated
Scope aligned to the system boundary in the SOC 2 description
Testing dates falling inside the Type II review period
Recognised methodology: PTES, OWASP WSTG, NIST SP 800-115
Consistent severity rating with CVSS v4.0 vectors published
Manual validation of every finding, not raw scanner output
Remediation recorded for each finding
Independent retest verifying every finding is closed
Signed attestation letter from the testing firm
Point in time limitations stated plainly
What we test
Where the testing effort concentrates
The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.
Web application and authenticated roles
Business logic, access control, session handling
95%
API layer
REST, GraphQL, authorization and rate limiting
90%
External perimeter
Internet-facing services and boundary protection
80%
Cloud configuration
IAM, storage exposure, network posture
70%
Internal network
Where the system boundary includes it
55%
Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.
How the engagement runs
Scope, test, close, attest
Typically 2 to 3 weeks of testing, plus retest after your fixes land. The retest is included, because a report full of open findings is not evidence of anything.
Scope against the system description
We read your SOC 2 system description and scope the test to match the boundary exactly, so the auditor never has to ask why an in-scope asset was not tested.
Test under signed rules of engagement
Grey-box testing across the application, API and perimeter, following PTES, OWASP WSTG and NIST SP 800-115. Every finding is manually validated through safe exploitation.
Report with CVSS v4.0 and criteria mapping
Each finding gets a severity, a vector, evidence, reproduction steps and remediation guidance, mapped to the Trust Services Criteria it touches.
Remediation support
Your engineers fix. We answer questions, review the fixes and escalate anything critical the day we find it rather than holding it for the report.
Retest and attestation letter
Every finding is retested with the original proof of concept and marked resolved on verification. The signed attestation letter is the page your CPA firm files.
Where the effort goes
Share of a typical engagement, by phase
Scoping & rules of engagement
15%
Testing & exploitation
45%
Reporting & mapping
20%
Retest & attestation
20%
What we bring
Built for the SOC 2 auditor specifically
The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.
Written for the auditor, not for us
Attestation letter, independence statement, scope statement and criteria mapping, in the structure CPA firms expect to receive.
Retest included, always
A report full of open findings creates audit problems. Ours closes clean, with each fix independently verified.
Monitoring evidence too
Our testing shows up in your logs. Where you run the XHack SOC Dashboard, that becomes supporting CC7.2 evidence in the same engagement.
We talk to your CPA firm
If the auditor wants different wording, a specific scope statement or a follow-up answer, we deal with it directly.
The deliverable
What lands on your auditor's desk
A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.
In the report
Signed letter of attestation from the testing firm
Scope, rules of engagement and testing window
Methodology and tester qualifications with independence statement
Findings with CVSS v4.0 vectors, evidence and reproduction steps
Remediation implemented for each finding
Independent retest result per finding, closing the register
Trust Services Criteria mapping per finding
Control mapping
How the report evidences each control
CC4.1
An independent, periodic penetration test is the separate evaluation the criterion calls for.
CC7.1
Vulnerabilities detected, rated and reported, then tracked to remediation.
CC6.1 and CC6.6
Access control and boundary protection findings, tested and closed.
CC7.2
Test activity captured in your monitoring, evidencing that detection works.
CC8.1
Remediations deployed through your change process and verified on retest.
Where our work stops, and who takes it from there
XHack provides the penetration testing evidence for CC4.1 and CC7.1. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For SOC 2, that sits with: Opinion issued by an independent licensed CPA firm. Staying independent of them is exactly what makes our evidence worth something when they review it.
Questions
SOC 2 testing, answered
Not by name. The criteria require separate evaluations of controls (CC4.1) and vulnerability detection (CC7.1). Every CPA firm we work with, and virtually every enterprise buyer, treats an independent penetration test as the way to evidence both. If you skip it, expect questions in fieldwork and in security reviews.
No. We deliver the penetration testing evidence, not the full compliance programme. We scope to your system description, test, report, support remediation, retest and attest. Your CPA firm runs the examination and issues the opinion.
Early enough that findings can be remediated and retested before the period ends. Testing in the final two weeks leaves no room to close anything, which is the most common scheduling mistake we see.
We change it. Different CPA firms want different scope statements, attestation wording or mapping tables. Tell us who is signing and we match their format, and we answer their follow-up questions directly.
Other frameworks we test for
Get the SOC 2 evidence sorted
Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.