Is a penetration test required for SOC 2?
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · SOC 2
Strictly, SOC 2 asks for a vulnerability management program — not a specific pen test. In practice, buyers ask for the pen test report, so most teams run one.
What the criteria actually say
The Common Criteria expect you to identify and manage vulnerabilities — a vulnerability management program — rather than a single named test. So a pen test is not strictly mandatory the way an ASV scan is for some PCI environments. But auditors look for evidence the program is real, and enterprise buyers very often ask to see a recent penetration test report directly.
Why most teams run one anyway
Between auditor expectations and customer security reviews, an annual third-party penetration test has become the de facto standard for a credible SOC 2. It is also the strongest single piece of evidence that your vulnerability management is more than a scanner — a skilled tester confirming the controls hold.
Scan and test together
The durable answer is both: continuous or frequent vulnerability scanning to catch known issues as they appear, plus a periodic (typically annual) penetration test for depth. They answer different questions and together cover the criteria comfortably. Remediate the exploitable findings and re-test.
Keep the evidence
Retain the pen test report, the remediation tickets, and the re-test confirmation; keep the scan history. That package satisfies the auditor and answers the customer questionnaire in one move. SentinelPanda tracks the test cadence and stores the reports as evidence against the control.