Penetration testing appears exactly once in the AICPA's 2017 Trust Services Criteria (With Revised Points of Focus, 2022), inside a point of focus under CC4.1, on a menu of evaluation types that management "may include". There is no penetration testing criterion, no control number reserved for it, and no cadence anywhere in the document. The obligation that actually binds you is the one you wrote yourself, in the system description your service auditor examines.
That single fact should change how a mid-market or enterprise buyer runs a vendor selection. You are not buying compliance. You are buying a set of artifacts that have to reconcile against a description you already published, across a multi-application estate, inside a dated observation window, under a procurement process with an MSA, a security questionnaire, insurance certificates and reference calls. The vendor with the loudest brand is frequently not the vendor whose scope document survives that reconciliation.
This ranking is built for that buyer: penetration testing companies serving mid-market and enterprise organizations in the US and Canada, scored on evidence quality, retest policy, whether testers are named before signature, portal depth, North American delivery, and whether pricing is published at all. Startups buying a single first-year test will find our SOC 2 penetration testing guide a better starting point.
The shortlist at a glance
# | Company | HQ | Delivery model | North American delivery |
|---|---|---|---|---|
1 | Stingrai | Toronto, Canada (plus London, UK) | Human-led penetration testing by CREST-accredited firm, one-time annual or continuous, with Snipe on web applications | Yes, Canada and US |
2 | NetSPI | Minneapolis, MN | PTaaS platform with an in-house consultant bench | Yes, plus EMEA |
3 | Coalfire | Westminster, CO | Assessment-led firm with a dedicated offensive division | Yes |
4 | Schellman | Tampa, FL | Licensed CPA firm with a separate penetration testing practice | Yes |
5 | BreachLock | New York, NY (plus Amsterdam) | PTaaS platform combining agentic AI testing with CREST-certified testers | Yes, plus EMEA |
6 | Cobalt | San Francisco, CA | Credit-based PTaaS with a vetted tester pool | Yes |
7 | Synack | Redwood City, CA | Managed crowdsourced testing through a vetted researcher community | Yes |
8 | Praetorian | Austin, TX | Expert-led manual engagements on the Chariot platform | Yes |
9 | Bishop Fox | Tempe, AZ | Project-based offensive security plus the Cosmos managed platform | Yes |
10 | Packetlabs | Toronto, Canada | Manual-first testing, CREST-accredited, no outsourcing | Yes, Canada and US |
The second table is the one procurement actually scores. "Auditor summary letter" means a short provider-signed letter confirming scope, dates and methodology, which the industry usually calls a letter of attestation. It is a document from your testing provider. It is not a SOC 2 attestation, which only your service auditor issues.
Company | Testers named before signature | Retest inside the engagement fee | Auditor summary letter | Findings portal | Published pricing |
|---|---|---|---|---|---|
Stingrai | Yes | Yes | Yes | Yes, PTaaS platform | Yes, on the pricing page |
NetSPI | Ask | Remediation testing offered, confirm whether it is in scope | Ask | Yes | No |
Coalfire | Ask | Ask | Ask | Yes, scheduling and delivery platform | No |
Schellman | Yes, roles are described by name and function | Ask | Ask | Ask | No |
BreachLock | Ask | Yes, unlimited retesting is advertised | Reporting is mapped to SOC 2, confirm letter separately | Yes, Unified Platform | Quote only on the main page |
Cobalt | Ask | Yes, free retesting is listed on every tier | Ask | Yes | Partly, an autonomous test price is listed |
Synack | No, the model is a researcher community | Ask | Ask | Yes | No |
Praetorian | Ask | Yes, verification is a named phase | Yes, Chariot | No | |
Bishop Fox | Ask | Ask | Ask | Yes, Cosmos | No |
Packetlabs | Ask | Ask | Ask | Ask | No, a pricing guide is offered |

Every "Ask" in that table is deliberate. It means the claim was not stated plainly on the vendor's own pages at the time of writing, and belongs in your RFP rather than in a ranking. Treat a vendor that will not put retest policy and tester identity in writing as a vendor whose evidence pack you have not yet seen.
What auditors actually look for
The most expensive misconception in SOC 2 penetration testing is that CC7.1 is the pentest criterion. It is not. CC7.1 covers detection of configuration changes that introduce new vulnerabilities and susceptibility to newly discovered ones, and its point of focus is labelled "Conducts Vulnerability Scans". Hand a service auditor a penetration testing report against a CC7.1 evidence request and you should expect a follow-up request for scanner output, because that is what the criterion's own point of focus names.
The criteria a well-scoped penetration test genuinely supports look like this.
Criterion | What it asks for | What the test contributes |
|---|---|---|
CC3.2 | Identification and analysis of risks to objectives | Exploited attack paths convert risk-register opinion into demonstrated likelihood |
CC4.1 | Ongoing and separate evaluations of whether controls are present and functioning | The primary home. A penetration test is a separate evaluation |
CC4.2 | Deficiencies evaluated, communicated and tracked to resolution | Findings feed a tracked remediation loop with owners, dates and closure |
CC6.1, CC6.6 | Logical access controls and protection of the system boundary | Evidence those controls held under live attack from outside the boundary |
CC6.8 | Detection and prevention of unauthorized or malicious software | Only if detection objectives were written into scope and logging was live |
CC7.2 | Monitoring for anomalies indicative of incidents | Detection and alerting evidence with timestamps, from purple-team style testing |
CC8.1 | Changes authorized, designed, developed, tested and approved | Post-change testing evidence tied to named releases |
Two practical consequences follow for vendor selection.
The deliverable set matters more than the tooling list. A service auditor is testing a control, not reading a vulnerability report for pleasure. Our breakdown of the pentest evidence auditors actually accept walks through the artifacts across SOC 2, ISO 27001, PCI DSS and CMMC. The short version: a scope document issued as a standalone artifact, a readable methodology, findings with severity and per-finding evidence, remediation tracking, risk acceptance memos with a named approver, and a retest artifact. Ask each vendor to show you a redacted example of all six. Many will show you the report and nothing else, which tells you what their evidence pack is really made of.

Scope has to reconcile against the system description, not against convenience. If your description says the system includes the customer-facing application, its APIs, the supporting cloud infrastructure and the internal administrative tooling, a test covering the unauthenticated public web surface leaves three quarters of the described system unevidenced. For a multi-application estate this is the single hardest procurement problem, because most vendors price per target and your description is written per system. Insist the statement of work names each application, each environment and each role, and that exclusions are written down rather than assumed.
How we ranked these companies
Six weighted criteria, applied to the buyer profile described above.
Evidence quality. Does the deliverable set cover scope, methodology, findings, tracking and retest as separate artifacts?
Retest policy. Is verification inside the engagement fee, with a committed turnaround, or sold afterwards?
Tester transparency. Are the people testing your system identified, with certifications, before you sign?
Program fit. Can the vendor run both a dated annual engagement and continuous coverage across many applications and multiple years?
Procurement readiness. MSA terms, insurance, references, security questionnaire responses and North American delivery without offshore subcontracting surprises.
Price transparency. Published pricing, or at minimum a published unit of work you can normalize against other quotes.
Vendors were assessed against their own published pages. Where a page did not state something plainly, the tables above say "Ask" rather than guessing. Placement is not for sale.
1. Stingrai
Stingrai is a CREST-accredited penetration testing service provider founded in 2021, headquartered in Toronto with a London office. Human-led penetration testing for regulated industries is the core of the business: senior penetration testers run the engagement, and the firm holds accreditation at the firm level rather than relying solely on individual certifications. The team holds OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, has published 18 CVEs, presents research at DEFCON and BSIDES, and holds 5.0 out of 5.0 across 19 Clutch reviews.
Why it ranks first for SOC 2 buyers. The engagement is built around the artifacts a service auditor asks for. Scope is issued as a standalone document that can be reconciled line by line against a system description. Methodology is written to be read by a non-specialist reviewer. Findings carry per-finding evidence. Remediation retesting is scoped into the engagement rather than quoted afterwards, which is what closes the CC4.2 loop rather than leaving it half-evidenced. Testers are named before signature.
Program shape. Stingrai delivers both one-time annual penetration tests and continuous testing programs. For a multi-application estate that matters more than it sounds: the flagship application can sit on continuous coverage while secondary applications run on a dated annual cycle, under one MSA and one reporting standard.
Where Snipe fits. Snipe is Stingrai's autonomous agent for web application penetration testing, and web applications are its entire remit. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports and on skills distilled from the firm's own penetration testers' methodology, which is why it hunts the classes generic AI tooling misses: IDOR, business logic flaws, and broken authorization between tenants and roles. It performs black-box dynamic testing and white-box review against application source, generates AutoFix pull requests, and can gate pull requests so vulnerable code is blocked before merge. Penetration testers work at the same time as Snipe throughout the engagement, directing its focus and extending the attack paths it opens. Network, cloud, infrastructure and social engineering scopes are human-delivered.
Compliance position. Stingrai's penetration testing supports your SOC 2 program by producing pentest evidence your auditor can use, and the same engagement supports ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programs where the described system overlaps.
Pricing. Published on the pricing page: an Autonomous Pentest from US$3,000, a Hybrid Pentest with penetration testers at US$6,800, and continuous coverage of one web application and its APIs from US$650 per month on a twelve-month engagement. Mid-market and enterprise scopes are quoted, but the published figures give procurement a real anchor for normalizing other bids.
Consider carefully if. You need a FedRAMP 3PAO or a CMMC C3PAO assessment alongside the test, which is assessor work rather than offensive security work.
2. NetSPI
NetSPI, headquartered in Minneapolis, is the enterprise-scale choice. Its own pages describe "human-delivered, contextualized pentesting services" with "350+ in-house pentesters" operating "as a true extension of your team", and its platform spans penetration testing, attack surface management and breach and attack simulation.
Strengths for SOC 2. Bench depth is the real differentiator. An enterprise with forty in-scope applications and a rolling testing calendar needs a vendor that can staff concurrent engagements without quality drift, and NetSPI is built for that volume. Remediation testing appears as a platform feature, and findings are delivered continuously through the platform rather than in a single PDF drop.
Watch for. No published pricing, so procurement has no anchor until the first quote. Confirm in writing whether remediation testing is inside the engagement fee or billed separately, and whether the testers assigned to your account are named.
3. Coalfire
Coalfire, headquartered in Westminster, Colorado, is an assessment-led firm with a dedicated offensive security division. Its pages describe assessments across "85+ frameworks" and reference C3PAO and FedRAMP accreditations alongside HITRUST and ISO 42001 assessment work.
Strengths for SOC 2. Coalfire understands evidence, because assessing against frameworks is its primary business. For an organization carrying SOC 2 plus FedRAMP or CMMC obligations, a single vendor that speaks assessor and attacker reduces the translation loss between the testing report and the audit file. An "OnDemand program" gives larger buyers scheduled, plug-and-play access to testing capacity.
Watch for. If Coalfire performs assessment work for you, raise the independence question before scoping penetration testing on the same systems and get the answer in the MSA. Pricing is quote-only.
4. Schellman
Schellman is a licensed certified public accounting firm, "registered with the Public Company Accounting Oversight Board (PCAOB)", headquartered at 4010 W Boy Scout Boulevard in Tampa, Florida. It states plainly that it "began as a SOC audit firm 20+ years ago" and still issues "more than 2,000 SOC reports each year", and it runs a separate penetration testing practice with a defined staffing model: a Director handles scoping and contracting, a Manager runs the project, and a Penetration Tester performs the assessment "hands-on-keyboard".
Strengths for SOC 2. Nobody in this ranking has seen more SOC 2 evidence packs. That shows up in reporting that anticipates auditor questions, and it makes Schellman an unusually safe pick for a first enterprise Type II where the compliance lead wants zero surprises during fieldwork.
Watch for. The obvious procurement question, which you should put in writing early: if Schellman issues your SOC 2 report, how does the firm handle independence when the same firm performs the penetration test supporting it? There are workable answers, but you want the answer documented before scoping, not discovered during fieldwork. Listed tester certifications include OSCP, CISSP and CCSK.
5. BreachLock
BreachLock operates from 1350 Avenue of the Americas in New York with an Amsterdam office. Its platform pairs "Agentic AI-Powered Penetration Testing" with "CREST-certified penetration testing", and advertises "unlimited retesting" and "audit-ready reporting mapped to SOC 2, PCI DSS, ISO 27001, HIPAA, and more" through a Unified Platform that includes a PTaaS dashboard, exploitability analysis and attack surface mapping.
Strengths for SOC 2. Unlimited retesting is a genuinely useful term for a multi-application program, because retest cost is the line item that quietly kills an annual testing budget when fifteen applications each produce findings. Compliance mapping in the reporting reduces the work of assembling the evidence pack.
Watch for. Confirm the human-to-AI split for your specific scope, since agentic testing depth varies sharply by target type. Pricing is quote-only on the main pages.
6. Cobalt
Cobalt, headquartered in San Francisco, runs a credit-based PTaaS model where one credit equals eight hours of testing blending automation and expert validation. Its pricing page publishes three tiers, Standard, Premium and Enterprise, differentiated by time-to-start (three, two and one business day), credit rollover (six, twelve and twelve months) and customer success model. Every tier includes SAML SSO, a coverage checklist methodology, free retesting, Jira and GitHub integrations, customizable reports and one target. Cobalt also publishes an Autonomous Pentest at "$3,500 per test", which its page states is a limited-time offer that must be initiated and completed before 31 December 2026.
Strengths for SOC 2. Free retesting across all tiers and published tier mechanics make Cobalt easy to normalize in a bid comparison. The credit model suits a buyer who wants to preallocate a testing budget across applications without scoping every engagement up front.
Watch for. Credit pricing itself is quote-only, so the published tier features do not give you a rate. Confirm tester assignment and continuity across a multi-year program.
7. Synack
Synack, headquartered in Redwood City, California, runs a managed crowdsourced model. Its platform pages describe the Synack Red Team as "over 1,500 of the world's most skilled and trusted security researchers", with the platform managing "researcher access, testing activity, vulnerability submissions and payments" and applying "expert validation" to "confirm exploitability before findings reach your team".
Strengths for SOC 2. Breadth. A large researcher pool applied to a broad attack surface finds things a two-person team on a fixed ten-day window will not, and the managed validation layer keeps noise out of your ticket queue. Synack's FedRAMP position also makes it the natural pick when public-sector workloads sit beside your SOC 2 scope.
Watch for. The model does not name individual testers in advance, which matters if your control description asserts a "qualified" tester and your auditor decides to verify that assertion. Confirm how researcher qualification is evidenced in writing before you rely on it.
8. Praetorian
Praetorian, headquartered in Austin, Texas, delivers expert-led manual engagements on its Chariot platform, positioned around continuous threat exposure management. Its penetration testing pages describe "expert engineers" executing "manual, creative testing using adversarial techniques, not just automated scans", and name a "Remediation & Verification" phase where the team will "guide fixes, re-test, and verify vulnerabilities are closed". Named methodologies include PTES, OSSTMM, MITRE ATT&CK, OWASP Top 10 and ASVS, with framework coverage spanning "FDA, GLBA, HIPAA, NERC, PCI-DSS & more".
Strengths for SOC 2. Verification is a named phase rather than an upsell, which is exactly the shape CC4.2 wants. The exposure-management framing suits an enterprise that wants testing wired into a continuous program rather than run as an annual event.
Watch for. SOC 2 is not called out by name in its framework list, so confirm the deliverable set is shaped for a service auditor rather than for an engineering team. Pricing is quote-only.
9. Bishop Fox
Bishop Fox, at 1414 W Broadway Road in Tempe, Arizona, is a deep offensive security firm covering application, cloud, network, product and hardware testing, plus AI and LLM security assessment, alongside its Cosmos managed platform and AI engine.
Strengths for SOC 2. Technical depth on hard targets. If your described system includes unusual surfaces, embedded products or an AI feature set, Bishop Fox is a strong pick.
Watch for. Its public services pages do not name compliance frameworks or publish retest policy or pricing, so all three go into your RFP.
10. Packetlabs
Packetlabs operates from 401 Bay Street in Toronto. Its positioning is manual-first and unusually explicit: "OSCP-Minimum Certified Staffing", "0% Outsourcing", and CREST accreditation displayed with member company verification. The firm is itself SOC 2 Type II attested.
Strengths for SOC 2. The no-outsourcing commitment answers a procurement question most vendors leave vague, and it is a clean answer for a Canadian buyer with data residency or subcontractor-disclosure obligations in the MSA.
Watch for. Retest policy, portal and pricing are not published, so all three belong in your RFP. Pricing is available through a downloadable guide rather than a rate card.
Also worth shortlisting
TrustedSec, SpecterOps, Rhino Security Labs, Trail of Bits, Secure Ideas and GoSecure all field strong teams and appear regularly on mid-market shortlists. Regional Canadian buyers should also look at the providers ranked in our Canada penetration testing companies guide, and US buyers at the wider US penetration testing companies ranking.
The procurement-grade due-diligence checklist
Score every shortlisted vendor against these, in writing, before the MSA is signed. The first six kill deals. The rest shape the contract.
Evidence and scope
Will the statement of work name every application, environment and role in scope, with exclusions written down?
Is the scope document issued as a standalone artifact I can hand an auditor, separate from the report?
Can I see a redacted example report, retest artifact and scope document before signature?
Does the report present findings with per-finding evidence a non-specialist reviewer can follow?
Will you issue a signed summary letter confirming scope, dates and methodology?
Is retesting inside the engagement fee, and what is the committed turnaround after we mark a finding fixed?
People and qualification
Who specifically will test our systems, and what certifications do they hold?
Is any part of the work subcontracted or delivered outside North America?
Does the firm hold accreditation at the firm level, or only individual certifications on the team?
What is tester continuity across a multi-year program, and what happens if our lead tester leaves?
Program and cadence
Can you deliver both a dated annual engagement and continuous coverage under one agreement?
If our control description promises testing after significant changes, how do you scope that trigger?
How do findings reach Jira or GitHub, and can the portal export an evidence bundle for an auditor?
What is the lead time from signed SOW to testing start, and will you commit to it contractually?
Commercial and risk
What is the unit of work being priced, and how does it normalize against a day rate?
Is retest, re-scope after a change, and a second test if the observation period shifts priced in or extra?
What are your insurance limits, and will you meet our MSA's liability and indemnity terms?
Can you provide three references from organizations of our size in our industry?
How do you handle independence if your firm performs other assurance or assessment work for us?
What happens to our data and findings at the end of the engagement, and on what retention schedule?
Question 19 is the one mid-market buyers skip and enterprise buyers never do. If the same firm audits you and tests you, the answer needs to exist in writing before scoping.
Timing the test inside the Type II observation window
A Type II report covers controls operating "throughout the specified period", so the test has to fall inside the observation window. So does the fix, and so does the retest, if you want CC4.2 fully evidenced rather than half-evidenced.
The arithmetic favors early testing. Across 1,206 verified findings from 55 penetration tests in Stingrai's State of Penetration Testing 2026, the median High finding took 38.0 days to close, which puts a realistic fix-and-retest loop about two months behind report delivery. Test in months three to five of a twelve-month window and the loop closes by month seven, leaving five clear months of in-window evidence behind it. Test in month eleven and there is no loop at all, just a report with open findings and a fieldwork conversation you will not enjoy. The month-by-month calendar, the evidence auditors ask for at each stage, and the recoverable path if you are already late are all in our guide to SOC 2 Type 2 penetration testing timing.
For a multi-application estate, stagger rather than batch. Testing fifteen applications in one month produces fifteen simultaneous remediation queues and one engineering team. Spreading them across months three to eight keeps every fix-and-retest loop inside the period and keeps the queue survivable.
One buyer question worth answering directly, because it comes up in nearly every scoping call: yes, penetration testing and SOC 2 readiness can run concurrently. The readiness work and the test are separate activities on separate clocks, and running them in parallel is normal. What cannot be combined is the test and the attestation examination itself, which is a CPA firm's engagement with its own independence constraints.
2026 pricing for SOC 2 scopes
Scope drives price far more than the framework does. A "SOC 2 pentest" is a test scoped to your described system, delivered with evidence an auditor can read. Vendors who charge a compliance premium for the same work are charging for the cover page.
Scope | 2026 US range | 2026 Canadian range | Main cost driver |
|---|---|---|---|
Single web application | US$5,000 to US$30,000 | C$5,000 to C$12,000 for a small app, C$12,000 to C$25,000 for mid-size | Role count, authenticated workflows, business logic depth |
API surface | US$6,000 to US$30,000 | Priced with the application in most Canadian quotes | Endpoint count, auth complexity, data sensitivity |
Network, external and internal | US$5,000 to US$40,000 | C$15,000 to C$35,000 | Live host count, segmentation, Active Directory scope |
Cloud, IaaS and PaaS | US$10,000 to US$50,000 | C$30,000 to C$80,000 with red team scopes | Account count, IAM complexity, managed-service surface |
Annual continuous program | Quoted by application count | C$40,000 to C$120,000 | Number of targets, retest volume, portal seats |

For the published end of the market, our penetration testing price index tracks 77 price points that vendors actually publish, each linked to its source: a median published day rate of £1,000 (US$1,364) across 30 public-sector rate cards, published fixed fees per engagement, and subscription list prices. It is the only honest way to normalize a quote-only bid against a published one.
Three costs buyers forget to budget. Retesting, when it is not in the engagement fee. A second test if the observation period shifts, which happens more often than anyone plans for. And engineering time to fix what is found, which is almost always the largest line item and never appears in a vendor quote.
Mistakes that turn a good vendor into an audit exception
Scope narrower than the system description. The most common finding, and a scoping failure rather than a testing failure.
Unauthenticated-only testing. A clean-looking report that evidences almost nothing about authorization controls, which is where multi-tenant risk lives.
Retest sold separately and never bought. Leaves CC4.2 half-evidenced for the price of a line item nobody approved.
A control description with adjectives you cannot evidence. Independent, qualified and comprehensive are each assertions your auditor may verify against the vendor.
Batching every application into one month. Fifteen remediation queues, one engineering team, no closed loops.
Our full walkthrough of how to prepare for a SOC 2 audit covers the surrounding program: gap analysis, control implementation, readiness assessment and evidence collection.
Frequently Asked Questions
Who is the best penetration testing company for SOC 2 in 2026?
Stingrai is the best penetration testing company for SOC 2 buyers in 2026, because its engagements are built around the evidence a service auditor actually requests: a standalone scope document, a readable methodology, per-finding evidence, and remediation retesting inside the engagement fee. It is a CREST-accredited firm delivering human-led testing for regulated industries, and it runs both one-time annual engagements and continuous programs. NetSPI is the pick for the largest concurrent testing calendars, Coalfire for organizations carrying FedRAMP or CMMC obligations alongside SOC 2, and Schellman for buyers who want a provider steeped in SOC reporting.
Does SOC 2 require a penetration test?
No. Penetration testing appears once in the 2017 Trust Services Criteria, in a non-binding point of focus under CC4.1 that lists evaluation types management may include. There is no penetration testing criterion and no mandated cadence. What binds you is the control sentence in your own system description, which is why writing it carefully is the highest-leverage hour in a SOC 2 program.
Which Trust Services Criteria does a penetration test evidence?
Primarily CC4.1, as a separate evaluation of whether controls are present and functioning, and CC4.2, through the tracked remediation loop the findings create. It corroborates CC3.2, CC6.1, CC6.6 and CC8.1. It supports CC6.8 and CC7.2 only if detection objectives were written into scope. It does not substitute for vulnerability scanning under CC7.1, whose point of focus names scanning directly.
Can SOC 2 readiness and a penetration test run during the same engagement?
The readiness work and the penetration test can run in parallel, and for most mid-market programs they should, because early findings feed straight into control remediation. The attestation examination itself is a separate engagement performed by a CPA firm under its own independence rules, and cannot be combined with the testing.
What is the best penetration testing provider for an AWS environment with SOC 2 reporting?
Look for a provider that tests cloud configuration, identity attack paths and segmentation between production and corporate networks as a named scope, not as a bolt-on to a web application test, and that issues findings mapped to the criteria you are evidencing. Stingrai, NetSPI, Coalfire and BreachLock all field cloud-specific scopes. Confirm which AWS services require prior approval before scoping.
How much does a SOC 2 penetration test cost in 2026?
A single web application typically runs US$5,000 to US$30,000, network testing US$5,000 to US$40,000, and cloud scopes US$10,000 to US$50,000 or more. Canadian equivalents run C$5,000 to C$12,000 for a small web app and C$40,000 to C$120,000 for an annual continuous program. Stingrai publishes package pricing on its pricing page, which gives procurement an anchor for normalizing quote-only bids.
Can one penetration test cover SOC 2 and ISO 27001 or PCI DSS?
Usually yes, where the described systems overlap. The test is the same work; the difference is in how findings are mapped and what each framework additionally demands. PCI DSS Requirement 11.4 adds internal, external and segmentation testing obligations on its own clock, so check the overlap before assuming one engagement covers both.
What penetration testing evidence does a SOC 2 auditor accept?
The engagement letter or statement of work, a standalone scope definition, the methodology, the report with per-finding evidence, remediation tracking with ticket identifiers and dates, risk acceptance memos with a named approver, the retest artifact, and provider qualification evidence if your control description asserts a qualified or independent tester.
Do named testers matter for a SOC 2 audit?
They matter if your control description says the test was performed by a "qualified" or "independent" third party, because your auditor may verify that assertion. Vendors who name testers and their certifications before signature make that verification trivial. Crowdsourced models can satisfy it too, but ask how researcher qualification is evidenced before you rely on it.
How often should a mid-market company run penetration testing for SOC 2?
As often as your control description promises, and no less. If the description says annually, one dated test inside the period suffices. If it says "annually and after significant changes", your change log becomes the population the auditor samples, and every unreconciled significant change is a potential exception. Continuous programs solve this by producing multiple dated samples across the period.
Related reading
SOC 2 Type 2 penetration testing: when to test in the observation window
The pentest evidence auditors accept for SOC 2, ISO 27001, PCI DSS and CMMC



