SOC 2 penetration testing

A pen test scoped to your SOC 2 system boundary, with a report your auditor can review and a letter you can share with customers.

Last reviewed October 2026

Does SOC 2 require a penetration test?

Not by name. Your auditor decides what evidence it accepts for a Type I or Type II report, so ask early. A current pen test scoped to your system boundary can support your auditor’s evaluation of how you monitor controls and manage vulnerabilities.

What your auditor will want to see

  • The scope, matched to your SOC 2 system boundary
  • Testing dates, ideally inside your Type II observation period
  • The methodology and standards the testers followed
  • Findings with severity, evidence, and recommended fixes
  • Retest results showing which findings you fixed

Reports document the scope, methodology, and dates that assessors typically look for.

Planning around your audit period

  1. Check your dates. For a Type II report, plan for the final report to land inside your observation period. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
  2. A free scoping call, then a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
  3. Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
  4. Final report delivered within 5 business days after testing ends. We walk your team through the findings on a call.
  5. Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and attestation letter.

What it costs

  • Web application, including its own APIFrom $5,000 per application
  • Separate public or partner APIFrom $8,000 per API
  • Cloud environmentFrom $10,000 per environment

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.

See starting prices for every service

What you get for your audit

  • A full report: executive summary, scope, dates, methodology, and findings with evidence and fixes
  • An attestation letter with the test dates, scope, method, and results, to share with customers who ask about your SOC 2
  • A retest report and an updated letter once you’ve fixed the findings
  • A walkthrough call with your team after the report

See an example report and attestation letter

Why customers ask vendors for testing

Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”[1]

Questions about SOC 2 pen testing

Do we need a pen test for Type I or only Type II?

SOC 2 doesn’t require a pen test by name for either report type. If your auditor or customers expect one, plan it so the final report lands inside your Type II observation period. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.

What should be in scope?

The systems inside your SOC 2 system boundary that customers rely on, usually your production web app, its API, and the cloud accounts that run them. We confirm the scope with you on the scoping call.

How often should we test?

Check what your auditor and your customer contracts ask for, since they set the schedule. Beyond that, test after significant changes to the systems in your boundary, such as a new product, a major release, or a new cloud environment.

Can we share the results with customers?

Yes. Share the attestation letter with the customers who ask, and keep the full technical report for your team or share it under NDA.

Tell us what you need tested.

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.