Security
Testing expected by auditors

SOC 2 penetration testing

SOC 2 (System and Organization Controls 2)

The independent penetration test report your CPA firm files as evidence for the monitoring and vulnerability criteria.

Sample report

Engagement at a glance

Drives testing

CC4.1 and CC7.1: Monitoring activities and vulnerability detection

Cadence

At least annually, and after significant change, inside the review period

Typical duration

2 to 3 weeks of testing, plus retest after your fixes land

Region

Global, US origin

Issued by

Opinion issued by an independent licensed CPA firm

2

Criteria directly evidenced

0

Open findings once retest closes

v4.0

CVSS scoring standard

Annual

Recommended cadence

The requirement

What SOC 2 asks for

CC4.1 and CC7.1 · Monitoring activities and vulnerability detection

The entity selects, develops and performs ongoing and separate evaluations to ascertain whether controls are present and functioning (CC4.1), and detects and monitors changes and vulnerabilities that could affect the system (CC7.1).

SOC 2 does not use the words "penetration test" in the Trust Services Criteria, which surprises people. What it does require is that you perform separate evaluations of your controls (CC4.1) and that you detect vulnerabilities in your system (CC7.1). In practice, every CPA firm and every enterprise buyer reads that as an independent penetration test.

The report only counts if it is built correctly. Auditors check that the tester is independent of your engineering team, that the scope matches the system boundary in your description, that the testing dates fall inside the review period, and above all that findings were fixed and independently retested. An open critical finding at period end is a conversation you do not want to have in fieldwork.

XHack delivers that report. We scope it against your system description, test it, rate every finding with CVSS v4.0, work with your team through remediation, retest each finding to closure and sign an attestation letter. Your CPA firm issues the opinion. We give them the evidence they need to do it.

What your auditor checks

The report has to clear every one of these

These are the questions a SOC 2 auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.

Performed by a third party independent of the client and its developers

Testers qualified and named, with certifications stated

Scope aligned to the system boundary in the SOC 2 description

Testing dates falling inside the Type II review period

Recognised methodology: PTES, OWASP WSTG, NIST SP 800-115

Consistent severity rating with CVSS v4.0 vectors published

Manual validation of every finding, not raw scanner output

Remediation recorded for each finding

Independent retest verifying every finding is closed

Signed attestation letter from the testing firm

Point in time limitations stated plainly

What we test

Where the testing effort concentrates

The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.

Web application and authenticated roles

Business logic, access control, session handling

95%

API layer

REST, GraphQL, authorization and rate limiting

90%

External perimeter

Internet-facing services and boundary protection

80%

Cloud configuration

IAM, storage exposure, network posture

70%

Internal network

Where the system boundary includes it

55%

Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.

How the engagement runs

Scope, test, close, attest

Typically 2 to 3 weeks of testing, plus retest after your fixes land. The retest is included, because a report full of open findings is not evidence of anything.

01

Scope against the system description

Week 1

We read your SOC 2 system description and scope the test to match the boundary exactly, so the auditor never has to ask why an in-scope asset was not tested.

02

Test under signed rules of engagement

Weeks 1 to 3

Grey-box testing across the application, API and perimeter, following PTES, OWASP WSTG and NIST SP 800-115. Every finding is manually validated through safe exploitation.

03

Report with CVSS v4.0 and criteria mapping

Week 3

Each finding gets a severity, a vector, evidence, reproduction steps and remediation guidance, mapped to the Trust Services Criteria it touches.

04

Remediation support

Weeks 3 to 6

Your engineers fix. We answer questions, review the fixes and escalate anything critical the day we find it rather than holding it for the report.

05

Retest and attestation letter

Week 6 onward

Every finding is retested with the original proof of concept and marked resolved on verification. The signed attestation letter is the page your CPA firm files.

Where the effort goes

Share of a typical engagement, by phase

100%EFFORT

Scoping & rules of engagement

15%

Testing & exploitation

45%

Reporting & mapping

20%

Retest & attestation

20%

What we bring

Built for the SOC 2 auditor specifically

The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.

Written for the auditor, not for us

Attestation letter, independence statement, scope statement and criteria mapping, in the structure CPA firms expect to receive.

Retest included, always

A report full of open findings creates audit problems. Ours closes clean, with each fix independently verified.

Monitoring evidence too

Our testing shows up in your logs. Where you run the XHack SOC Dashboard, that becomes supporting CC7.2 evidence in the same engagement.

We talk to your CPA firm

If the auditor wants different wording, a specific scope statement or a follow-up answer, we deal with it directly.

The deliverable

What lands on your auditor's desk

A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.

In the report

  • Signed letter of attestation from the testing firm

  • Scope, rules of engagement and testing window

  • Methodology and tester qualifications with independence statement

  • Findings with CVSS v4.0 vectors, evidence and reproduction steps

  • Remediation implemented for each finding

  • Independent retest result per finding, closing the register

  • Trust Services Criteria mapping per finding

Control mapping

How the report evidences each control

CC4.1

An independent, periodic penetration test is the separate evaluation the criterion calls for.

CC7.1

Vulnerabilities detected, rated and reported, then tracked to remediation.

CC6.1 and CC6.6

Access control and boundary protection findings, tested and closed.

CC7.2

Test activity captured in your monitoring, evidencing that detection works.

CC8.1

Remediations deployed through your change process and verified on retest.

Where our work stops, and who takes it from there

XHack provides the penetration testing evidence for CC4.1 and CC7.1. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For SOC 2, that sits with: Opinion issued by an independent licensed CPA firm. Staying independent of them is exactly what makes our evidence worth something when they review it.

Questions

SOC 2 testing, answered

Not by name. The criteria require separate evaluations of controls (CC4.1) and vulnerability detection (CC7.1). Every CPA firm we work with, and virtually every enterprise buyer, treats an independent penetration test as the way to evidence both. If you skip it, expect questions in fieldwork and in security reviews.

No. We deliver the penetration testing evidence, not the full compliance programme. We scope to your system description, test, report, support remediation, retest and attest. Your CPA firm runs the examination and issues the opinion.

Early enough that findings can be remediated and retested before the period ends. Testing in the final two weeks leaves no room to close anything, which is the most common scheduling mistake we see.

We change it. Different CPA firms want different scope statements, attestation wording or mapping tables. Tell us who is signing and we match their format, and we answer their follow-up questions directly.

Get the SOC 2 evidence sorted

Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.

All frameworks