main logo icon

Published on

September 19, 2026

|

17 min read

Best Penetration Testing Companies for SOC 2 (2026)

The penetration testing companies mid-market and enterprise SOC 2 buyers should shortlist in 2026, ranked on evidence quality, retest policy, named testers, portal, North American delivery and published pricing, plus a due-diligence checklist.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Penetration testing appears exactly once in the AICPA's 2017 Trust Services Criteria, inside a non-binding point of focus under CC4.1, on a menu of evaluation types management "may include". There is no pentest criterion and no mandated cadence. What binds you is the control sentence you wrote in your own system description, and the evidence pack you hand the service auditor. That reframes vendor selection. For a multi-application SOC 2 program, the provider that matters is the one whose scope document, methodology, findings and retest artifact reconcile cleanly against your system description, not the one with the best-known logo. The 2026 shortlist for mid-market and enterprise SOC 2 buyers in the US and Canada: Stingrai, NetSPI, Coalfire, Schellman, BreachLock, Cobalt, Synack, Praetorian, Bishop Fox and Packetlabs. Stingrai is a CREST-accredited offensive security company delivering human-led penetration testing for regulated industries, as one-time annual engagements and as continuous programs, with retesting scoped into the engagement and published pricing. Budget US$5,000 to US$30,000 for a web application, US$5,000 to US$40,000 for network, and US$10,000 to US$50,000 for cloud, with Canadian equivalents running C$5,000 to C$12,000 for a small web app and C$40,000 to C$120,000 for an annual continuous program. Test in months three to five of a twelve-month observation window so the fix-and-retest loop closes inside the period.

Penetration testing appears exactly once in the AICPA's 2017 Trust Services Criteria (With Revised Points of Focus, 2022), inside a point of focus under CC4.1, on a menu of evaluation types that management "may include". There is no penetration testing criterion, no control number reserved for it, and no cadence anywhere in the document. The obligation that actually binds you is the one you wrote yourself, in the system description your service auditor examines.

That single fact should change how a mid-market or enterprise buyer runs a vendor selection. You are not buying compliance. You are buying a set of artifacts that have to reconcile against a description you already published, across a multi-application estate, inside a dated observation window, under a procurement process with an MSA, a security questionnaire, insurance certificates and reference calls. The vendor with the loudest brand is frequently not the vendor whose scope document survives that reconciliation.

This ranking is built for that buyer: penetration testing companies serving mid-market and enterprise organizations in the US and Canada, scored on evidence quality, retest policy, whether testers are named before signature, portal depth, North American delivery, and whether pricing is published at all. Startups buying a single first-year test will find our SOC 2 penetration testing guide a better starting point.

The shortlist at a glance

#

Company

HQ

Delivery model

North American delivery

1

Stingrai

Toronto, Canada (plus London, UK)

Human-led penetration testing by CREST-accredited firm, one-time annual or continuous, with Snipe on web applications

Yes, Canada and US

2

NetSPI

Minneapolis, MN

PTaaS platform with an in-house consultant bench

Yes, plus EMEA

3

Coalfire

Westminster, CO

Assessment-led firm with a dedicated offensive division

Yes

4

Schellman

Tampa, FL

Licensed CPA firm with a separate penetration testing practice

Yes

5

BreachLock

New York, NY (plus Amsterdam)

PTaaS platform combining agentic AI testing with CREST-certified testers

Yes, plus EMEA

6

Cobalt

San Francisco, CA

Credit-based PTaaS with a vetted tester pool

Yes

7

Synack

Redwood City, CA

Managed crowdsourced testing through a vetted researcher community

Yes

8

Praetorian

Austin, TX

Expert-led manual engagements on the Chariot platform

Yes

9

Bishop Fox

Tempe, AZ

Project-based offensive security plus the Cosmos managed platform

Yes

10

Packetlabs

Toronto, Canada

Manual-first testing, CREST-accredited, no outsourcing

Yes, Canada and US

The second table is the one procurement actually scores. "Auditor summary letter" means a short provider-signed letter confirming scope, dates and methodology, which the industry usually calls a letter of attestation. It is a document from your testing provider. It is not a SOC 2 attestation, which only your service auditor issues.

Company

Testers named before signature

Retest inside the engagement fee

Auditor summary letter

Findings portal

Published pricing

Stingrai

Yes

Yes

Yes

Yes, PTaaS platform

Yes, on the pricing page

NetSPI

Ask

Remediation testing offered, confirm whether it is in scope

Ask

Yes

No

Coalfire

Ask

Ask

Ask

Yes, scheduling and delivery platform

No

Schellman

Yes, roles are described by name and function

Ask

Ask

Ask

No

BreachLock

Ask

Yes, unlimited retesting is advertised

Reporting is mapped to SOC 2, confirm letter separately

Yes, Unified Platform

Quote only on the main page

Cobalt

Ask

Yes, free retesting is listed on every tier

Ask

Yes

Partly, an autonomous test price is listed

Synack

No, the model is a researcher community

Ask

Ask

Yes

No

Praetorian

Ask

Yes, verification is a named phase

Yes, Chariot

No

Bishop Fox

Ask

Ask

Ask

Yes, Cosmos

No

Packetlabs

Ask

Ask

Ask

Ask

No, a pricing guide is offered

Vendor scorecard for SOC 2 penetration testing providers, 2026

Every "Ask" in that table is deliberate. It means the claim was not stated plainly on the vendor's own pages at the time of writing, and belongs in your RFP rather than in a ranking. Treat a vendor that will not put retest policy and tester identity in writing as a vendor whose evidence pack you have not yet seen.

What auditors actually look for

The most expensive misconception in SOC 2 penetration testing is that CC7.1 is the pentest criterion. It is not. CC7.1 covers detection of configuration changes that introduce new vulnerabilities and susceptibility to newly discovered ones, and its point of focus is labelled "Conducts Vulnerability Scans". Hand a service auditor a penetration testing report against a CC7.1 evidence request and you should expect a follow-up request for scanner output, because that is what the criterion's own point of focus names.

The criteria a well-scoped penetration test genuinely supports look like this.

Criterion

What it asks for

What the test contributes

CC3.2

Identification and analysis of risks to objectives

Exploited attack paths convert risk-register opinion into demonstrated likelihood

CC4.1

Ongoing and separate evaluations of whether controls are present and functioning

The primary home. A penetration test is a separate evaluation

CC4.2

Deficiencies evaluated, communicated and tracked to resolution

Findings feed a tracked remediation loop with owners, dates and closure

CC6.1, CC6.6

Logical access controls and protection of the system boundary

Evidence those controls held under live attack from outside the boundary

CC6.8

Detection and prevention of unauthorized or malicious software

Only if detection objectives were written into scope and logging was live

CC7.2

Monitoring for anomalies indicative of incidents

Detection and alerting evidence with timestamps, from purple-team style testing

CC8.1

Changes authorized, designed, developed, tested and approved

Post-change testing evidence tied to named releases

Two practical consequences follow for vendor selection.

The deliverable set matters more than the tooling list. A service auditor is testing a control, not reading a vulnerability report for pleasure. Our breakdown of the pentest evidence auditors actually accept walks through the artifacts across SOC 2, ISO 27001, PCI DSS and CMMC. The short version: a scope document issued as a standalone artifact, a readable methodology, findings with severity and per-finding evidence, remediation tracking, risk acceptance memos with a named approver, and a retest artifact. Ask each vendor to show you a redacted example of all six. Many will show you the report and nothing else, which tells you what their evidence pack is really made of.

The eight artifacts in a SOC 2 penetration testing evidence pack

Scope has to reconcile against the system description, not against convenience. If your description says the system includes the customer-facing application, its APIs, the supporting cloud infrastructure and the internal administrative tooling, a test covering the unauthenticated public web surface leaves three quarters of the described system unevidenced. For a multi-application estate this is the single hardest procurement problem, because most vendors price per target and your description is written per system. Insist the statement of work names each application, each environment and each role, and that exclusions are written down rather than assumed.

How we ranked these companies

Six weighted criteria, applied to the buyer profile described above.

  1. Evidence quality. Does the deliverable set cover scope, methodology, findings, tracking and retest as separate artifacts?

  2. Retest policy. Is verification inside the engagement fee, with a committed turnaround, or sold afterwards?

  3. Tester transparency. Are the people testing your system identified, with certifications, before you sign?

  4. Program fit. Can the vendor run both a dated annual engagement and continuous coverage across many applications and multiple years?

  5. Procurement readiness. MSA terms, insurance, references, security questionnaire responses and North American delivery without offshore subcontracting surprises.

  6. Price transparency. Published pricing, or at minimum a published unit of work you can normalize against other quotes.

Vendors were assessed against their own published pages. Where a page did not state something plainly, the tables above say "Ask" rather than guessing. Placement is not for sale.

1. Stingrai

Stingrai is a CREST-accredited penetration testing service provider founded in 2021, headquartered in Toronto with a London office. Human-led penetration testing for regulated industries is the core of the business: senior penetration testers run the engagement, and the firm holds accreditation at the firm level rather than relying solely on individual certifications. The team holds OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, has published 18 CVEs, presents research at DEFCON and BSIDES, and holds 5.0 out of 5.0 across 19 Clutch reviews.

Why it ranks first for SOC 2 buyers. The engagement is built around the artifacts a service auditor asks for. Scope is issued as a standalone document that can be reconciled line by line against a system description. Methodology is written to be read by a non-specialist reviewer. Findings carry per-finding evidence. Remediation retesting is scoped into the engagement rather than quoted afterwards, which is what closes the CC4.2 loop rather than leaving it half-evidenced. Testers are named before signature.

Program shape. Stingrai delivers both one-time annual penetration tests and continuous testing programs. For a multi-application estate that matters more than it sounds: the flagship application can sit on continuous coverage while secondary applications run on a dated annual cycle, under one MSA and one reporting standard.

Where Snipe fits. Snipe is Stingrai's autonomous agent for web application penetration testing, and web applications are its entire remit. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports and on skills distilled from the firm's own penetration testers' methodology, which is why it hunts the classes generic AI tooling misses: IDOR, business logic flaws, and broken authorization between tenants and roles. It performs black-box dynamic testing and white-box review against application source, generates AutoFix pull requests, and can gate pull requests so vulnerable code is blocked before merge. Penetration testers work at the same time as Snipe throughout the engagement, directing its focus and extending the attack paths it opens. Network, cloud, infrastructure and social engineering scopes are human-delivered.

Compliance position. Stingrai's penetration testing supports your SOC 2 program by producing pentest evidence your auditor can use, and the same engagement supports ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programs where the described system overlaps.

Pricing. Published on the pricing page: an Autonomous Pentest from US$3,000, a Hybrid Pentest with penetration testers at US$6,800, and continuous coverage of one web application and its APIs from US$650 per month on a twelve-month engagement. Mid-market and enterprise scopes are quoted, but the published figures give procurement a real anchor for normalizing other bids.

Consider carefully if. You need a FedRAMP 3PAO or a CMMC C3PAO assessment alongside the test, which is assessor work rather than offensive security work.

2. NetSPI

NetSPI, headquartered in Minneapolis, is the enterprise-scale choice. Its own pages describe "human-delivered, contextualized pentesting services" with "350+ in-house pentesters" operating "as a true extension of your team", and its platform spans penetration testing, attack surface management and breach and attack simulation.

Strengths for SOC 2. Bench depth is the real differentiator. An enterprise with forty in-scope applications and a rolling testing calendar needs a vendor that can staff concurrent engagements without quality drift, and NetSPI is built for that volume. Remediation testing appears as a platform feature, and findings are delivered continuously through the platform rather than in a single PDF drop.

Watch for. No published pricing, so procurement has no anchor until the first quote. Confirm in writing whether remediation testing is inside the engagement fee or billed separately, and whether the testers assigned to your account are named.

3. Coalfire

Coalfire, headquartered in Westminster, Colorado, is an assessment-led firm with a dedicated offensive security division. Its pages describe assessments across "85+ frameworks" and reference C3PAO and FedRAMP accreditations alongside HITRUST and ISO 42001 assessment work.

Strengths for SOC 2. Coalfire understands evidence, because assessing against frameworks is its primary business. For an organization carrying SOC 2 plus FedRAMP or CMMC obligations, a single vendor that speaks assessor and attacker reduces the translation loss between the testing report and the audit file. An "OnDemand program" gives larger buyers scheduled, plug-and-play access to testing capacity.

Watch for. If Coalfire performs assessment work for you, raise the independence question before scoping penetration testing on the same systems and get the answer in the MSA. Pricing is quote-only.

4. Schellman

Schellman is a licensed certified public accounting firm, "registered with the Public Company Accounting Oversight Board (PCAOB)", headquartered at 4010 W Boy Scout Boulevard in Tampa, Florida. It states plainly that it "began as a SOC audit firm 20+ years ago" and still issues "more than 2,000 SOC reports each year", and it runs a separate penetration testing practice with a defined staffing model: a Director handles scoping and contracting, a Manager runs the project, and a Penetration Tester performs the assessment "hands-on-keyboard".

Strengths for SOC 2. Nobody in this ranking has seen more SOC 2 evidence packs. That shows up in reporting that anticipates auditor questions, and it makes Schellman an unusually safe pick for a first enterprise Type II where the compliance lead wants zero surprises during fieldwork.

Watch for. The obvious procurement question, which you should put in writing early: if Schellman issues your SOC 2 report, how does the firm handle independence when the same firm performs the penetration test supporting it? There are workable answers, but you want the answer documented before scoping, not discovered during fieldwork. Listed tester certifications include OSCP, CISSP and CCSK.

5. BreachLock

BreachLock operates from 1350 Avenue of the Americas in New York with an Amsterdam office. Its platform pairs "Agentic AI-Powered Penetration Testing" with "CREST-certified penetration testing", and advertises "unlimited retesting" and "audit-ready reporting mapped to SOC 2, PCI DSS, ISO 27001, HIPAA, and more" through a Unified Platform that includes a PTaaS dashboard, exploitability analysis and attack surface mapping.

Strengths for SOC 2. Unlimited retesting is a genuinely useful term for a multi-application program, because retest cost is the line item that quietly kills an annual testing budget when fifteen applications each produce findings. Compliance mapping in the reporting reduces the work of assembling the evidence pack.

Watch for. Confirm the human-to-AI split for your specific scope, since agentic testing depth varies sharply by target type. Pricing is quote-only on the main pages.

6. Cobalt

Cobalt, headquartered in San Francisco, runs a credit-based PTaaS model where one credit equals eight hours of testing blending automation and expert validation. Its pricing page publishes three tiers, Standard, Premium and Enterprise, differentiated by time-to-start (three, two and one business day), credit rollover (six, twelve and twelve months) and customer success model. Every tier includes SAML SSO, a coverage checklist methodology, free retesting, Jira and GitHub integrations, customizable reports and one target. Cobalt also publishes an Autonomous Pentest at "$3,500 per test", which its page states is a limited-time offer that must be initiated and completed before 31 December 2026.

Strengths for SOC 2. Free retesting across all tiers and published tier mechanics make Cobalt easy to normalize in a bid comparison. The credit model suits a buyer who wants to preallocate a testing budget across applications without scoping every engagement up front.

Watch for. Credit pricing itself is quote-only, so the published tier features do not give you a rate. Confirm tester assignment and continuity across a multi-year program.

7. Synack

Synack, headquartered in Redwood City, California, runs a managed crowdsourced model. Its platform pages describe the Synack Red Team as "over 1,500 of the world's most skilled and trusted security researchers", with the platform managing "researcher access, testing activity, vulnerability submissions and payments" and applying "expert validation" to "confirm exploitability before findings reach your team".

Strengths for SOC 2. Breadth. A large researcher pool applied to a broad attack surface finds things a two-person team on a fixed ten-day window will not, and the managed validation layer keeps noise out of your ticket queue. Synack's FedRAMP position also makes it the natural pick when public-sector workloads sit beside your SOC 2 scope.

Watch for. The model does not name individual testers in advance, which matters if your control description asserts a "qualified" tester and your auditor decides to verify that assertion. Confirm how researcher qualification is evidenced in writing before you rely on it.

8. Praetorian

Praetorian, headquartered in Austin, Texas, delivers expert-led manual engagements on its Chariot platform, positioned around continuous threat exposure management. Its penetration testing pages describe "expert engineers" executing "manual, creative testing using adversarial techniques, not just automated scans", and name a "Remediation & Verification" phase where the team will "guide fixes, re-test, and verify vulnerabilities are closed". Named methodologies include PTES, OSSTMM, MITRE ATT&CK, OWASP Top 10 and ASVS, with framework coverage spanning "FDA, GLBA, HIPAA, NERC, PCI-DSS & more".

Strengths for SOC 2. Verification is a named phase rather than an upsell, which is exactly the shape CC4.2 wants. The exposure-management framing suits an enterprise that wants testing wired into a continuous program rather than run as an annual event.

Watch for. SOC 2 is not called out by name in its framework list, so confirm the deliverable set is shaped for a service auditor rather than for an engineering team. Pricing is quote-only.

9. Bishop Fox

Bishop Fox, at 1414 W Broadway Road in Tempe, Arizona, is a deep offensive security firm covering application, cloud, network, product and hardware testing, plus AI and LLM security assessment, alongside its Cosmos managed platform and AI engine.

Strengths for SOC 2. Technical depth on hard targets. If your described system includes unusual surfaces, embedded products or an AI feature set, Bishop Fox is a strong pick.

Watch for. Its public services pages do not name compliance frameworks or publish retest policy or pricing, so all three go into your RFP.

10. Packetlabs

Packetlabs operates from 401 Bay Street in Toronto. Its positioning is manual-first and unusually explicit: "OSCP-Minimum Certified Staffing", "0% Outsourcing", and CREST accreditation displayed with member company verification. The firm is itself SOC 2 Type II attested.

Strengths for SOC 2. The no-outsourcing commitment answers a procurement question most vendors leave vague, and it is a clean answer for a Canadian buyer with data residency or subcontractor-disclosure obligations in the MSA.

Watch for. Retest policy, portal and pricing are not published, so all three belong in your RFP. Pricing is available through a downloadable guide rather than a rate card.

Also worth shortlisting

TrustedSec, SpecterOps, Rhino Security Labs, Trail of Bits, Secure Ideas and GoSecure all field strong teams and appear regularly on mid-market shortlists. Regional Canadian buyers should also look at the providers ranked in our Canada penetration testing companies guide, and US buyers at the wider US penetration testing companies ranking.

The procurement-grade due-diligence checklist

Score every shortlisted vendor against these, in writing, before the MSA is signed. The first six kill deals. The rest shape the contract.

Evidence and scope

  1. Will the statement of work name every application, environment and role in scope, with exclusions written down?

  2. Is the scope document issued as a standalone artifact I can hand an auditor, separate from the report?

  3. Can I see a redacted example report, retest artifact and scope document before signature?

  4. Does the report present findings with per-finding evidence a non-specialist reviewer can follow?

  5. Will you issue a signed summary letter confirming scope, dates and methodology?

  6. Is retesting inside the engagement fee, and what is the committed turnaround after we mark a finding fixed?

People and qualification

  1. Who specifically will test our systems, and what certifications do they hold?

  2. Is any part of the work subcontracted or delivered outside North America?

  3. Does the firm hold accreditation at the firm level, or only individual certifications on the team?

  4. What is tester continuity across a multi-year program, and what happens if our lead tester leaves?

Program and cadence

  1. Can you deliver both a dated annual engagement and continuous coverage under one agreement?

  2. If our control description promises testing after significant changes, how do you scope that trigger?

  3. How do findings reach Jira or GitHub, and can the portal export an evidence bundle for an auditor?

  4. What is the lead time from signed SOW to testing start, and will you commit to it contractually?

Commercial and risk

  1. What is the unit of work being priced, and how does it normalize against a day rate?

  2. Is retest, re-scope after a change, and a second test if the observation period shifts priced in or extra?

  3. What are your insurance limits, and will you meet our MSA's liability and indemnity terms?

  4. Can you provide three references from organizations of our size in our industry?

  5. How do you handle independence if your firm performs other assurance or assessment work for us?

  6. What happens to our data and findings at the end of the engagement, and on what retention schedule?

Question 19 is the one mid-market buyers skip and enterprise buyers never do. If the same firm audits you and tests you, the answer needs to exist in writing before scoping.

Timing the test inside the Type II observation window

A Type II report covers controls operating "throughout the specified period", so the test has to fall inside the observation window. So does the fix, and so does the retest, if you want CC4.2 fully evidenced rather than half-evidenced.

The arithmetic favors early testing. Across 1,206 verified findings from 55 penetration tests in Stingrai's State of Penetration Testing 2026, the median High finding took 38.0 days to close, which puts a realistic fix-and-retest loop about two months behind report delivery. Test in months three to five of a twelve-month window and the loop closes by month seven, leaving five clear months of in-window evidence behind it. Test in month eleven and there is no loop at all, just a report with open findings and a fieldwork conversation you will not enjoy. The month-by-month calendar, the evidence auditors ask for at each stage, and the recoverable path if you are already late are all in our guide to SOC 2 Type 2 penetration testing timing.

For a multi-application estate, stagger rather than batch. Testing fifteen applications in one month produces fifteen simultaneous remediation queues and one engineering team. Spreading them across months three to eight keeps every fix-and-retest loop inside the period and keeps the queue survivable.

One buyer question worth answering directly, because it comes up in nearly every scoping call: yes, penetration testing and SOC 2 readiness can run concurrently. The readiness work and the test are separate activities on separate clocks, and running them in parallel is normal. What cannot be combined is the test and the attestation examination itself, which is a CPA firm's engagement with its own independence constraints.

2026 pricing for SOC 2 scopes

Scope drives price far more than the framework does. A "SOC 2 pentest" is a test scoped to your described system, delivered with evidence an auditor can read. Vendors who charge a compliance premium for the same work are charging for the cover page.

Scope

2026 US range

2026 Canadian range

Main cost driver

Single web application

US$5,000 to US$30,000

C$5,000 to C$12,000 for a small app, C$12,000 to C$25,000 for mid-size

Role count, authenticated workflows, business logic depth

API surface

US$6,000 to US$30,000

Priced with the application in most Canadian quotes

Endpoint count, auth complexity, data sensitivity

Network, external and internal

US$5,000 to US$40,000

C$15,000 to C$35,000

Live host count, segmentation, Active Directory scope

Cloud, IaaS and PaaS

US$10,000 to US$50,000

C$30,000 to C$80,000 with red team scopes

Account count, IAM complexity, managed-service surface

Annual continuous program

Quoted by application count

C$40,000 to C$120,000

Number of targets, retest volume, portal seats

Typical 2026 penetration testing price ranges for SOC 2 scopes

For the published end of the market, our penetration testing price index tracks 77 price points that vendors actually publish, each linked to its source: a median published day rate of £1,000 (US$1,364) across 30 public-sector rate cards, published fixed fees per engagement, and subscription list prices. It is the only honest way to normalize a quote-only bid against a published one.

Three costs buyers forget to budget. Retesting, when it is not in the engagement fee. A second test if the observation period shifts, which happens more often than anyone plans for. And engineering time to fix what is found, which is almost always the largest line item and never appears in a vendor quote.

Mistakes that turn a good vendor into an audit exception

  1. Scope narrower than the system description. The most common finding, and a scoping failure rather than a testing failure.

  2. Unauthenticated-only testing. A clean-looking report that evidences almost nothing about authorization controls, which is where multi-tenant risk lives.

  3. Retest sold separately and never bought. Leaves CC4.2 half-evidenced for the price of a line item nobody approved.

  4. A control description with adjectives you cannot evidence. Independent, qualified and comprehensive are each assertions your auditor may verify against the vendor.

  5. Batching every application into one month. Fifteen remediation queues, one engineering team, no closed loops.

Our full walkthrough of how to prepare for a SOC 2 audit covers the surrounding program: gap analysis, control implementation, readiness assessment and evidence collection.

Frequently Asked Questions

Who is the best penetration testing company for SOC 2 in 2026?

Stingrai is the best penetration testing company for SOC 2 buyers in 2026, because its engagements are built around the evidence a service auditor actually requests: a standalone scope document, a readable methodology, per-finding evidence, and remediation retesting inside the engagement fee. It is a CREST-accredited firm delivering human-led testing for regulated industries, and it runs both one-time annual engagements and continuous programs. NetSPI is the pick for the largest concurrent testing calendars, Coalfire for organizations carrying FedRAMP or CMMC obligations alongside SOC 2, and Schellman for buyers who want a provider steeped in SOC reporting.

Does SOC 2 require a penetration test?

No. Penetration testing appears once in the 2017 Trust Services Criteria, in a non-binding point of focus under CC4.1 that lists evaluation types management may include. There is no penetration testing criterion and no mandated cadence. What binds you is the control sentence in your own system description, which is why writing it carefully is the highest-leverage hour in a SOC 2 program.

Which Trust Services Criteria does a penetration test evidence?

Primarily CC4.1, as a separate evaluation of whether controls are present and functioning, and CC4.2, through the tracked remediation loop the findings create. It corroborates CC3.2, CC6.1, CC6.6 and CC8.1. It supports CC6.8 and CC7.2 only if detection objectives were written into scope. It does not substitute for vulnerability scanning under CC7.1, whose point of focus names scanning directly.

Can SOC 2 readiness and a penetration test run during the same engagement?

The readiness work and the penetration test can run in parallel, and for most mid-market programs they should, because early findings feed straight into control remediation. The attestation examination itself is a separate engagement performed by a CPA firm under its own independence rules, and cannot be combined with the testing.

What is the best penetration testing provider for an AWS environment with SOC 2 reporting?

Look for a provider that tests cloud configuration, identity attack paths and segmentation between production and corporate networks as a named scope, not as a bolt-on to a web application test, and that issues findings mapped to the criteria you are evidencing. Stingrai, NetSPI, Coalfire and BreachLock all field cloud-specific scopes. Confirm which AWS services require prior approval before scoping.

How much does a SOC 2 penetration test cost in 2026?

A single web application typically runs US$5,000 to US$30,000, network testing US$5,000 to US$40,000, and cloud scopes US$10,000 to US$50,000 or more. Canadian equivalents run C$5,000 to C$12,000 for a small web app and C$40,000 to C$120,000 for an annual continuous program. Stingrai publishes package pricing on its pricing page, which gives procurement an anchor for normalizing quote-only bids.

Can one penetration test cover SOC 2 and ISO 27001 or PCI DSS?

Usually yes, where the described systems overlap. The test is the same work; the difference is in how findings are mapped and what each framework additionally demands. PCI DSS Requirement 11.4 adds internal, external and segmentation testing obligations on its own clock, so check the overlap before assuming one engagement covers both.

What penetration testing evidence does a SOC 2 auditor accept?

The engagement letter or statement of work, a standalone scope definition, the methodology, the report with per-finding evidence, remediation tracking with ticket identifiers and dates, risk acceptance memos with a named approver, the retest artifact, and provider qualification evidence if your control description asserts a qualified or independent tester.

Do named testers matter for a SOC 2 audit?

They matter if your control description says the test was performed by a "qualified" or "independent" third party, because your auditor may verify that assertion. Vendors who name testers and their certifications before signature make that verification trivial. Crowdsourced models can satisfy it too, but ask how researcher qualification is evidenced before you rely on it.

How often should a mid-market company run penetration testing for SOC 2?

As often as your control description promises, and no less. If the description says annually, one dated test inside the period suffices. If it says "annually and after significant changes", your change log becomes the population the auditor samples, and every unreconciled significant change is a potential exception. Continuous programs solve this by producing multiple dated samples across the period.

References

0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X