COMPLIANCE

SOC 2

SOC 2 is an attestation report based on the AICPA Trust Services Criteria, commonly required by SaaS and technology companies selling to enterprise buyers. Penetration testing is a baseline control activity that supports the Security and, where applicable, Availability and Confidentiality criteria.

WHAT SOC 2 REQUIRES

What does SOC 2 require of our organisation?

SOC 2 is an attestation report issued by a licensed CPA firm that assesses whether a service organisation's controls are suitably designed (Type I) and operating effectively over time (Type II) against the AICPA Trust Services Criteria. The criteria cover Security (the Common Criteria, required in every engagement), and the optional categories of Availability, Confidentiality, Processing Integrity, and Privacy.

The criteria do not mandate a specific tool or frequency. Auditors expect testing to be performed at planned intervals documented in the control narrative, with findings tracked through to closure. For Type II, testing and remediation evidence must fall within the defined observation period.

Which Trust Services Criteria need testing evidence?

The Common Criteria (Security) expect vulnerability management and monitoring controls, including periodic penetration testing and timely remediation. Availability and Confidentiality criteria may also reference testing where they are in scope and relevant to the system description.

Type I or Type II — when do we test?

For Type I, testing demonstrates control design at a point in time. For Type II, testing and remediation evidence should fall within the observation period. We align testing timing with your CPA firm's examination plan so evidence lands inside the window.

HOW TESTING MAPS TO SOC 2

How does penetration testing map to the Trust Services Criteria?

Penetration testing does not by itself satisfy SOC 2. It supports specific Common Criteria controls around vulnerability management and monitoring. A SOC 2 report covers the full control environment across the in-scope Trust Services Criteria, of which testing is expected evidence, not the report itself.

Does a penetration test satisfy SOC 2?

No. A penetration test supports specific Common Criteria controls around vulnerability management. A SOC 2 report covers the full control environment across the in-scope Trust Services Criteria. Testing is expected evidence, not the attestation itself.

How often should we test for SOC 2?

Annual penetration testing is the common baseline, with the cadence documented in the control narrative. Higher-risk or rapidly changing systems may warrant more frequent testing. The cadence should align with the Type II observation period.

Which VariHunt services support which criteria?

  • Web Application Penetration Testing supports vulnerability management for the application layer.
  • API Security Testing covers API surfaces, often a key evidence area for SaaS.
  • Mobile Application Penetration Testing supports mobile client surfaces in scope.
  • SOC 2 Readiness & Advisory scopes the Trust Services Criteria, builds the control environment, and prepares evidence.
  • IT Security & Audit Services supports the broader control environment and evidence programme.

EVIDENCE

What evidence do SOC 2 auditors expect?

SOC 2 auditors expect a current penetration test report, a vulnerability management process, evidence of remediation and retesting, and an annual testing cadence documented in the control narrative. Reports should include scope, severity ratings, and remediation status aligned to the system description.

What should the test report include for SOC 2?

The report should include scope aligned to the system description, severity ratings, proof of concept, remediation guidance, and remediation status with retest evidence. Auditors look for evidence that findings are tracked to closure within the observation period, not only at a point in time.

Is a retest included?

Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price.

ENGAGEMENT STRUCTURE

How does VariHunt structure a SOC 2 engagement?

A SOC 2 engagement typically begins with scoping the Trust Services Criteria and the system description, followed by a control environment gap analysis, control design and implementation guidance, and an evidence collection programme. The output is a prioritised remediation roadmap and an evidence set aligned to the chosen criteria.

What does the advisory deliverable contain?

The deliverable includes the Trust Services Criteria scoping, the gap analysis against chosen criteria, control design guidance, and an evidence collection programme. Where testing is included, findings are mapped to the relevant criteria with remediation status tracked within the observation period.

Do you issue the SOC 2 report?

No. SOC 2 reports are issued by a licensed CPA firm after an examination. VariHunt provides readiness advisory and supports evidence collection; the attestation is the CPA firm's responsibility.

GETTING STARTED

What do we need to provide before a SOC 2-aligned engagement?

Before starting, we need the system description, the in-scope Trust Services Criteria, and the environments and test accounts. The observation period and examination timeline help us align testing to your CPA firm's plan. Rules of engagement and points of contact are agreed during scoping.

Can you help scope the Trust Services Criteria?

Yes. The SOC 2 Readiness & Advisory service scopes Security, Availability, Confidentiality, Privacy, and Processing Integrity criteria and builds the control environment and evidence programme aligned to your system description.

FAQ

Frequently asked questions

How long does SOC 2 testing take?

Duration depends on the in-scope Trust Services Criteria, the number of systems, and whether testing supports a Type I or falls within a Type II observation period. A precise timeline is agreed during scoping and aligned to your CPA firm's examination plan and observation window.

What methodology do you follow?

Testing follows OWASP WSTG for web and OWASP MASVS for mobile, with CVSS v3.1 for severity. Findings are mapped to the relevant Trust Services Criteria, primarily the Common Criteria, so auditors can trace evidence to the controls in your system description and evidence programme.

Is a retest included?

Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price and the engagement is not closed until complete.

What does the report contain?

The report includes an executive summary and a technical section. Each finding has its CVSS severity, proof of concept, root cause, and remediation guidance. Findings are mapped to the relevant Trust Services Criteria with remediation status tracked within the observation period.

How does this map to SOC 2?

Findings map to the Trust Services Criteria, primarily the Common Criteria for Security, and where applicable Availability and Confidentiality. This lets your CPA firm trace testing evidence to the controls in the system description, the control narrative, and the evidence programme.

What do you need from us before starting?

We need the system description, the in-scope Trust Services Criteria, the environments and test accounts, and the observation period and examination timeline. Rules of engagement and points of contact are agreed during scoping before any active testing begins.

Discuss your compliance timeline

Book a scoping call to align testing with your audit or regulatory deadlines.