COMPLIANCE
SOC 2 is an attestation report based on the AICPA Trust Services Criteria, commonly required by SaaS and technology companies selling to enterprise buyers. Penetration testing is a baseline control activity that supports the Security and, where applicable, Availability and Confidentiality criteria.
WHAT SOC 2 REQUIRES
SOC 2 is an attestation report issued by a licensed CPA firm that assesses whether a service organisation's controls are suitably designed (Type I) and operating effectively over time (Type II) against the AICPA Trust Services Criteria. The criteria cover Security (the Common Criteria, required in every engagement), and the optional categories of Availability, Confidentiality, Processing Integrity, and Privacy.
The criteria do not mandate a specific tool or frequency. Auditors expect testing to be performed at planned intervals documented in the control narrative, with findings tracked through to closure. For Type II, testing and remediation evidence must fall within the defined observation period.
The Common Criteria (Security) expect vulnerability management and monitoring controls, including periodic penetration testing and timely remediation. Availability and Confidentiality criteria may also reference testing where they are in scope and relevant to the system description.
For Type I, testing demonstrates control design at a point in time. For Type II, testing and remediation evidence should fall within the observation period. We align testing timing with your CPA firm's examination plan so evidence lands inside the window.
HOW TESTING MAPS TO SOC 2
Penetration testing does not by itself satisfy SOC 2. It supports specific Common Criteria controls around vulnerability management and monitoring. A SOC 2 report covers the full control environment across the in-scope Trust Services Criteria, of which testing is expected evidence, not the report itself.
No. A penetration test supports specific Common Criteria controls around vulnerability management. A SOC 2 report covers the full control environment across the in-scope Trust Services Criteria. Testing is expected evidence, not the attestation itself.
Annual penetration testing is the common baseline, with the cadence documented in the control narrative. Higher-risk or rapidly changing systems may warrant more frequent testing. The cadence should align with the Type II observation period.
EVIDENCE
SOC 2 auditors expect a current penetration test report, a vulnerability management process, evidence of remediation and retesting, and an annual testing cadence documented in the control narrative. Reports should include scope, severity ratings, and remediation status aligned to the system description.
The report should include scope aligned to the system description, severity ratings, proof of concept, remediation guidance, and remediation status with retest evidence. Auditors look for evidence that findings are tracked to closure within the observation period, not only at a point in time.
Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price.
ENGAGEMENT STRUCTURE
A SOC 2 engagement typically begins with scoping the Trust Services Criteria and the system description, followed by a control environment gap analysis, control design and implementation guidance, and an evidence collection programme. The output is a prioritised remediation roadmap and an evidence set aligned to the chosen criteria.
The deliverable includes the Trust Services Criteria scoping, the gap analysis against chosen criteria, control design guidance, and an evidence collection programme. Where testing is included, findings are mapped to the relevant criteria with remediation status tracked within the observation period.
No. SOC 2 reports are issued by a licensed CPA firm after an examination. VariHunt provides readiness advisory and supports evidence collection; the attestation is the CPA firm's responsibility.
GETTING STARTED
Before starting, we need the system description, the in-scope Trust Services Criteria, and the environments and test accounts. The observation period and examination timeline help us align testing to your CPA firm's plan. Rules of engagement and points of contact are agreed during scoping.
Yes. The SOC 2 Readiness & Advisory service scopes Security, Availability, Confidentiality, Privacy, and Processing Integrity criteria and builds the control environment and evidence programme aligned to your system description.
FAQ
Duration depends on the in-scope Trust Services Criteria, the number of systems, and whether testing supports a Type I or falls within a Type II observation period. A precise timeline is agreed during scoping and aligned to your CPA firm's examination plan and observation window.
Testing follows OWASP WSTG for web and OWASP MASVS for mobile, with CVSS v3.1 for severity. Findings are mapped to the relevant Trust Services Criteria, primarily the Common Criteria, so auditors can trace evidence to the controls in your system description and evidence programme.
Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price and the engagement is not closed until complete.
The report includes an executive summary and a technical section. Each finding has its CVSS severity, proof of concept, root cause, and remediation guidance. Findings are mapped to the relevant Trust Services Criteria with remediation status tracked within the observation period.
Findings map to the Trust Services Criteria, primarily the Common Criteria for Security, and where applicable Availability and Confidentiality. This lets your CPA firm trace testing evidence to the controls in the system description, the control narrative, and the evidence programme.
We need the system description, the in-scope Trust Services Criteria, the environments and test accounts, and the observation period and examination timeline. Rules of engagement and points of contact are agreed during scoping before any active testing begins.
Book a scoping call to align testing with your audit or regulatory deadlines.