SOC 2 penetration testing
A pen test scoped to your SOC 2 system boundary, with a report your auditor can review and a letter you can share with customers.
Last reviewed October 2026
Does SOC 2 require a penetration test?
Not by name. Your auditor decides what evidence it accepts for a Type I or Type II report, so ask early. A current pen test scoped to your system boundary can support your auditor’s evaluation of how you monitor controls and manage vulnerabilities.
What your auditor will want to see
- The scope, matched to your SOC 2 system boundary
- Testing dates, ideally inside your Type II observation period
- The methodology and standards the testers followed
- Findings with severity, evidence, and recommended fixes
- Retest results showing which findings you fixed
Reports document the scope, methodology, and dates that assessors typically look for.
Tests to consider
- Web applications Your production app, including its own API: authorization between users, roles, and customer accounts, plus business logic.
- APIs Public and partner APIs inside your system boundary.
- Networks and Active Directory Internet-facing systems, and internal networks if they’re in your boundary.
- Cloud (AWS, Azure, Google Cloud) The AWS, Azure, or Google Cloud accounts that run production.
- Code review and threat modeling Design and code review of the systems in your boundary, before big changes ship.
- Vulnerability assessments Recurring scans between pen tests, reviewed by a tester.
- Security training Hands-on security training for the developers who build your product.
Planning around your audit period
- Check your dates. For a Type II report, plan for the final report to land inside your observation period. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
- A free scoping call, then a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
- Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends. We walk your team through the findings on a call.
- Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and attestation letter.
What it costs
- Web application, including its own APIFrom $5,000 per application
- Separate public or partner APIFrom $8,000 per API
- Cloud environmentFrom $10,000 per environment
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
What you get for your audit
- A full report: executive summary, scope, dates, methodology, and findings with evidence and fixes
- An attestation letter with the test dates, scope, method, and results, to share with customers who ask about your SOC 2
- A retest report and an updated letter once you’ve fixed the findings
- A walkthrough call with your team after the report
Why customers ask vendors for testing
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”[1]
Questions about SOC 2 pen testing
Do we need a pen test for Type I or only Type II?
SOC 2 doesn’t require a pen test by name for either report type. If your auditor or customers expect one, plan it so the final report lands inside your Type II observation period. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
What should be in scope?
The systems inside your SOC 2 system boundary that customers rely on, usually your production web app, its API, and the cloud accounts that run them. We confirm the scope with you on the scoping call.
How often should we test?
Check what your auditor and your customer contracts ask for, since they set the schedule. Beyond that, test after significant changes to the systems in your boundary, such as a new product, a major release, or a new cloud environment.
Can we share the results with customers?
Yes. Share the attestation letter with the customers who ask, and keep the full technical report for your team or share it under NDA.
Tell us what you need tested.
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.