Does SOC 2 Type II require a penetration test?

No. The Trust Services Criteria do not name penetration testing as a required control, and no clause obliges you to run one. In practice most auditors expect some form of independent technical testing as evidence for the monitoring criteria, so the honest answer is that it is not required but is commonly requested — and refusing outright tends to cost you more explaining than the test would have.

The criteria that auditors usually anchor this to concern the evaluation and monitoring of controls. A penetration test is one way to evidence that; a well-run vulnerability management programme with documented remediation can be another.

What matters is that you can show an independent check happened and that findings went somewhere. A pen test report with no remediation trail is weaker evidence than a smaller scan programme with tickets, owners and closure dates.

Sources

  • AICPA Trust Services Criteria (2017, revised 2022) — Common Criteria

Drafted with the tools on this site, then checked against the sources above by a practitioner before publishing. Reviewed 2026-08-07. Found something wrong? It should be corrected — this page is only worth as much as its accuracy.

Related