Skip to main content
Compliance · SOC 2

SOC 2 penetration testing as evidence your service auditor can evaluate

A SOC 2 examination is performed by a CPA acting as service auditor, who evaluates the controls your management describes against the trust services criteria and expresses an opinion in terms of reasonable assurance. Penetration testing is one of the evaluation types named in the points of focus beneath criterion CC4.1. This page sets out what an engagement produces against that, clause by clause, with every clause read on 14 September 2026.

Whose examination this is

Every sentence here is about the SOC 2 report you are pursuing

The examination is yours. The CPA firm your organisation engages performs it, evaluates the controls your management describes against the trust services criteria, and expresses the opinion at the end of it. What a penetration test contributes is material for the file that evaluation draws on — dated runs, findings with the exchange that proved them, and a retest record. Security Brigade is a security testing firm, and supplying that material is the part of this it does. Issuing an attestation report is separate work, performed by the service auditor under the AICPA attestation standards, and it stays there.

The boundary

Four places this page stops

Compliance copy earns its accuracy at the edges, so the edges are written down rather than left to be inferred.

The position
Whose report it is Yours, and the opinion in it is your service auditor’s. A B-52 engagement contributes evidence to the file. Nothing else about the examination is a vendor’s to determine.
Mapping, not issuing Findings are mapped to the criteria a framework names. The attestation report, and the opinion inside it, are issued by the CPA firm engaged for that purpose — DC Section 200 records that the practitioner performing a SOC 2 examination is a CPA, referred to throughout as the service auditor.
The words used here are AICPA’s Examination, report, service auditor, opinion, reasonable assurance. They are the words the instruments use, and they describe accurately what a reader ends up holding, which is why this page uses them too.
Which evaluations belong in your programme TSP Section 100 ¶.07 puts that on the facts and circumstances of the entity and its environment, in relation to its own objectives. It is settled between your management and your service auditor. What is stated here is what an engagement produces and what it records.

Whose report it is

The position
Yours, and the opinion in it is your service auditor’s. A B-52 engagement contributes evidence to the file. Nothing else about the examination is a vendor’s to determine.

Mapping, not issuing

The position
Findings are mapped to the criteria a framework names. The attestation report, and the opinion inside it, are issued by the CPA firm engaged for that purpose — DC Section 200 records that the practitioner performing a SOC 2 examination is a CPA, referred to throughout as the service auditor.

The words used here are AICPA’s

The position
Examination, report, service auditor, opinion, reasonable assurance. They are the words the instruments use, and they describe accurately what a reader ends up holding, which is why this page uses them too.

Which evaluations belong in your programme

The position
TSP Section 100 ¶.07 puts that on the facts and circumstances of the entity and its environment, in relation to its own objectives. It is settled between your management and your service auditor. What is stated here is what an engagement produces and what it records.

The vocabulary

Five terms the criteria are written in, and what each one binds

A SOC 2 conversation goes wrong at the vocabulary more often than at the facts. These five carry the whole page, so they come first.

Five terms the criteria are written in, and what each one binds
StateWhat it meansWhat follows
Criterion An outcome that controls are evaluated against; CC7.1 and CC4.1 are two of the common criteria. TSP Section 100 ¶.03 states the criteria “set forth the outcomes that an entity’s controls should ordinarily meet to achieve the entity’s unique objectives” and are “intended to be used for evaluation and reporting, regardless of the specific controls implemented by management”. Evaluated against in the examination.
Point of focus A consideration published beneath a criterion to assist management and the service auditor. ¶.07 advises users “to consider the facts and circumstances of the entity and its environment in actual situations in relation to the entity’s objectives” when evaluating subject matter against the criteria. Applied on the entity’s own facts.
Trust services category Security is carried by every SOC 2, through the common criteria. Availability, processing integrity, confidentiality and privacy are elected, and each one elected brings its own control activity criteria alongside the common set. Sets what the examination covers.
Type 1 and type 2 examination A type 1 addresses the system description and the suitability of the design of the controls. A type 2 adds their operating effectiveness, across a period that the report states. Decides what your evidence has to span.
The service auditor’s opinion Terminal Expressed by the CPA firm, in terms of reasonable assurance, over the controls set out in management’s description of the system and over the period stated in the report. What the examination produces at the end.
Key
  • Evaluated against in the examination
  • A consideration, applied on the entity’s facts and circumstances
  • What the examination produces
  • TerminalNo state follows this one

The clauses, as read

What each criterion says, in its own words

The 2017 Trust Services Criteria, with the revised points of focus issued in 2022. AICPA states that the 2022 revision reached the points of focus and that the 2017 criteria “continue to be suitable criteria for use when evaluating controls in any trust services engagement”, so each row dates its wording.

ClauseWhat it says
CC7.1 — System Operations The criterion: “To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.” An outcome, stated as one.
2017 criterion; the text is identical in the 2022 revision. Read 2026-09-14.
CC7.1, point of focus “Conducts Vulnerability Scans” The 2022 wording: “The entity conducts infrastructure and software vulnerability scans designed to identify potential vulnerabilities or misconfigurations on a periodic basis and after any significant changes are made to the environment. Action is taken to remediate identified deficiencies in a timely manner to support the achievement of the entity’s objectives.” The words it uses for cadence are periodic, and after any significant changes are made to the environment.
Point of focus, revised 2022; the 2017 wording carries the same activity — vulnerability scans — in slightly shorter form. Read 2026-09-14.
CC4.1 — Monitoring Activities The criterion, which is COSO Principle 16: “The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.”
2017 criterion, unchanged in the 2022 revision. Read 2026-09-14.
CC4.1, point of focus on evaluation types The 2022 wording: “Management uses a variety of different types of ongoing and separate risk and control evaluations to determine whether internal controls are present and functioning. Depending on the entity’s objectives, such risk and control evaluations may include first- and second-line monitoring and control testing, internal audit assessments, compliance assessments, resilience assessments, vulnerability scans, security assessment, penetration testing, and third-party assessments.” Penetration testing appears here, in a list introduced by “may include”.
The 2017 wording of the same point of focus listed penetration testing alongside independent certification against established specifications and internal audit assessments. Read 2026-09-14.
CC3.2 — Risk Identification Its 2022 points of focus include “The entity identifies the vulnerabilities of system components, including system processes, infrastructure, software, and other information assets”, and a companion addressing threats and vulnerabilities arising from vendors, business partners, customers and other third parties with access to the entity’s information systems.
Points of focus beneath the 2017 criterion. Read 2026-09-14.
TSP Section 100 ¶.03 and ¶.07 ¶.03 states the criteria are “intended to be used for evaluation and reporting, regardless of the specific controls implemented by management”. ¶.07 advises users to weigh “the facts and circumstances of the entity and its environment in actual situations in relation to the entity’s objectives”. Together they are why a point of focus is read against your environment rather than as a shopping list.
Paragraph numbering follows the 2022 version; the same guidance on points of focus is ¶.04 in the 2017 original. Read 2026-09-14.
DC Section 200 — description criteria A separate instrument from the criteria: what the system description in a SOC 2 report is prepared and evaluated against, published 2018 with revised implementation guidance in 2022. It is the source of the type 1 and type 2 distinction above, it records that the service auditor is a CPA, and it notes that the report ordinarily carries an alert restricting its use to specified parties agreed between management and the service auditor.
Read 2026-09-14.

CC7.1 — System Operations

What it says
The criterion: “To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.” An outcome, stated as one.

2017 criterion; the text is identical in the 2022 revision. Read 2026-09-14.

CC7.1, point of focus “Conducts Vulnerability Scans”

What it says
The 2022 wording: “The entity conducts infrastructure and software vulnerability scans designed to identify potential vulnerabilities or misconfigurations on a periodic basis and after any significant changes are made to the environment. Action is taken to remediate identified deficiencies in a timely manner to support the achievement of the entity’s objectives.” The words it uses for cadence are periodic, and after any significant changes are made to the environment.

Point of focus, revised 2022; the 2017 wording carries the same activity — vulnerability scans — in slightly shorter form. Read 2026-09-14.

CC4.1 — Monitoring Activities

What it says
The criterion, which is COSO Principle 16: “The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.”

2017 criterion, unchanged in the 2022 revision. Read 2026-09-14.

CC4.1, point of focus on evaluation types

What it says
The 2022 wording: “Management uses a variety of different types of ongoing and separate risk and control evaluations to determine whether internal controls are present and functioning. Depending on the entity’s objectives, such risk and control evaluations may include first- and second-line monitoring and control testing, internal audit assessments, compliance assessments, resilience assessments, vulnerability scans, security assessment, penetration testing, and third-party assessments.” Penetration testing appears here, in a list introduced by “may include”.

The 2017 wording of the same point of focus listed penetration testing alongside independent certification against established specifications and internal audit assessments. Read 2026-09-14.

CC3.2 — Risk Identification

What it says
Its 2022 points of focus include “The entity identifies the vulnerabilities of system components, including system processes, infrastructure, software, and other information assets”, and a companion addressing threats and vulnerabilities arising from vendors, business partners, customers and other third parties with access to the entity’s information systems.

Points of focus beneath the 2017 criterion. Read 2026-09-14.

TSP Section 100 ¶.03 and ¶.07

What it says
¶.03 states the criteria are “intended to be used for evaluation and reporting, regardless of the specific controls implemented by management”. ¶.07 advises users to weigh “the facts and circumstances of the entity and its environment in actual situations in relation to the entity’s objectives”. Together they are why a point of focus is read against your environment rather than as a shopping list.

Paragraph numbering follows the 2022 version; the same guidance on points of focus is ¶.04 in the 2017 original. Read 2026-09-14.

DC Section 200 — description criteria

What it says
A separate instrument from the criteria: what the system description in a SOC 2 report is prepared and evaluated against, published 2018 with revised implementation guidance in 2022. It is the source of the type 1 and type 2 distinction above, it records that the service auditor is a CPA, and it notes that the report ordinarily carries an alert restricting its use to specified parties agreed between management and the service auditor.

Read 2026-09-14.

Where testing sits

Penetration testing in the criteria, located precisely

Read the criteria document end to end and penetration testing appears once: in the point of focus beneath CC4.1 quoted above, inside a list of evaluation types introduced by “may include”, alongside internal audit assessments, compliance assessments, resilience assessments, vulnerability scans and third-party assessments. CC7.1’s own point of focus addresses something adjacent and different — infrastructure and software vulnerability scans — and running the two together is the mistake a compliance officer spots fastest. What follows is a question about your programme rather than about the document. Management selects the evaluations it performs, describes them in its description of the system, and the service auditor evaluates the controls in that description against the criteria. Where a penetration test is one of the evaluations you have selected, the rest of this page is about the record it leaves behind.

How this page was sourced

The documents behind every clause quoted above

Sources, and the one thing not confirmed at source As of 2026-09-14
  • Every criterion, point of focus and paragraph quoted above was read on 14 September 2026 in AICPA’s red-lined edition of the 2017 Trust Services Criteria with revised points of focus, 2022, which prints the 2017 and 2022 wordings together and makes the difference between them checkable.
  • The criteria cited are the 2017 set. AICPA states that the 2022 revision changed the points of focus and that the 2017 criteria continue to be suitable criteria for a trust services engagement, so this page dates a quotation to 2022 only where the wording it quotes is a revised point of focus.
  • The description criteria are a separate 2018 instrument with revised implementation guidance issued in 2022, read the same day. It governs the system description in the report; the trust services criteria govern the controls.
  • A SOC 2 examination is an attestation examination performed under the AICPA attestation standards, and the practitioner performing it is a CPA acting as service auditor.
  • AICPA publishes the criteria and the attestation standards. The report, and the opinion in it, come from the CPA firm your organisation engages.

Deliberately excluded

  • The specific AT-C section a SOC 2 examination is performed under is not named on this page. The AICPA codification page that would settle it did not resolve on 14 September 2026, so the section number was never read at source, and a clause number nobody has read is worse than an absent one. What is cited above is what was read: the description criteria record that the practitioner is a CPA acting as service auditor, performing an attestation examination under the AICPA attestation standards.
  • Nothing here states what your service auditor will accept. That evaluation is theirs, and it is performed against your own description of your own system.

Criterion by criterion

Three criteria, and what an engagement puts against each

Each panel reads the same way: the clause as written, the output an engagement produces, and what your service auditor is able to do with it.

01 Monitoring activities

CC4.1 — evaluations

The clause
Ongoing and/or separate evaluations, performed to ascertain whether the components of internal control are present and functioning. Its points of focus name penetration testing as one of the evaluation types management may use.
The output
A dated engagement record: the scope agreed and authorised, the coverage classes the run covered, the findings raised out of it, and the retest that closed each one.
What your auditor does with it
Evidence your service auditor can evaluate against CC4.1, read next to your own account of how the evaluation was selected, performed and acted on.
02 System operations

CC7.1 — detection and monitoring

The clause
Detection and monitoring procedures that identify configuration changes introducing new vulnerabilities, and susceptibilities to newly discovered ones. Its point of focus addresses infrastructure and software vulnerability scans, on a periodic basis and after significant change.
The output
Per finding: the request that triggered it and the response that came back, the part of the exchange that demonstrates the defect marked, CVSS v4.0 with the vector printed, and the CWE.
What your auditor does with it
Evidence your service auditor can evaluate against CC7.1, and a record your remediation dates attach to, since the point of focus speaks to action taken on what gets identified.
03 Risk assessment

CC3.2 — risk identification

The clause
Points of focus on identifying the vulnerabilities of system components — processes, infrastructure, software and other information assets — and on threats and vulnerabilities arising from vendors, business partners and other third parties with access to your systems.
The output
Findings tied to the component they were found in and the entry path they were reached through, across all eleven coverage classes rather than one of them.
What your auditor does with it
An input to the risk assessment your description sets out, dated, and attributable to a scope somebody in your organisation signed before the run started.

What mapped means

A test report is an input to an evaluation, not a verdict on one

The service auditor evaluates the controls your management describes against the criteria, and expresses an opinion in terms of reasonable assurance — bounded by those controls and by the period the report states. A penetration test sits a level below that. It is evidence about the state of a system on dated runs, produced under a scope somebody in your organisation authorised, and it becomes useful to an examination by being specific, reproducible and attributable. That is why the framing above is the same in every panel: an engagement produces evidence your service auditor can evaluate against CC4.1 and CC7.1, and the evaluation itself stays where the attestation standards put it. It is also why the delivery model is a live decision rather than a preference, which is the next block.

Which model

Whose verification stands behind the evidence

All three models cover the same eleven classes and produce the same artefacts. What separates them is whether a senior Security Brigade auditor stood behind each finding before it left.

Whose verification stands behind the evidence
StateWhat it meansWhat follows
Autonomous, expert verified Every finding is reviewed by a senior Security Brigade auditor before it is released to you, and the report goes out under the firm’s signature. Start here where the evidence goes to your service auditor.
Human led A senior auditor directs the engagement and B-52 runs beneath them — the model for an unusual environment, or for the deepest scope you take in a period. Signed by the firm, with the depth set by a person.
Fully autonomous Terminal Scope and targets are authorised by a person and the run proceeds on its own from there. No auditor stands behind the findings it raises. Built for coverage between the engagements that go into the file.
Key
  • A senior auditor verified the findings inside the engagement
  • Scope sign-off, then no auditor in the engagement
  • TerminalNo state follows this one

A type 2 covers a period

What the period does to your testing calendar

A type 1 addresses the description and the design of the controls. A type 2 adds operating effectiveness across a stated period, and a period is a different shape of problem from a point in time: evidence concentrated in one week of it says less about the rest than evidence spread through it. That is the practical reason the three models combine rather than compete. Autonomous runs give coverage across the period, at an entry price of $500 for one scan of one application or target, and a verified engagement produces the signed record that goes into the file. Which combination fits your period is a scoping conversation, and it starts from the expert-verified model wherever the report leaves your organisation.

What you receive

What goes into the file your auditor draws on

Five things, each of them checkable by somebody who was not in the room when the testing happened. That is the only property that makes a test report useful to an examination.

Per finding

The exchange that proved it

The request that triggered the defect and the response that came back, with the proving portion marked, and reproduction steps written for whoever is going to fix it.

Per finding

Severity that can be recomputed

CVSS v4.0 with the vector string printed rather than the score on its own, plus the CWE — so the rating can be re-derived by your engineers or questioned by your auditor instead of taken on trust.

Per finding

A state, carried through to closure

Open, fixed, retested, closed. A finding closes on a retest that cannot reproduce it, which is what turns a remediation claim into a dated record of one.

Per engagement

Scope, authorisation and the gates

The agreed scope, who authorised it, the dates each run covered, and the record of the three approval gates — destructive or state-changing actions, persistence and movement past the entry host, and live credentials or real customer data.

Per engagement

Coverage across all eleven classes

Which classes the run covered and what each returned, so the file shows the breadth of the evaluation and not only the findings that came out of it.

Scope the evidence your SOC 2 examination will draw on

A scoping call settles which criteria the engagement is producing evidence against, what period it has to cover, and which delivery model the file needs. Where the report leaves your organisation, start from the expert-verified model.