Reviewed by Sergio Martin for technical accuracy, clarity, and alignment with authorized security assessment practices.
August 13, 2026
Prepare your SaaS platform for SOC 2 security reviews with independent penetration testing designed to identify vulnerabilities, document findings, and support your security program.
Why SOC 2 Companies Need Penetration Testing
SOC 2 does not prescribe one specific penetration testing procedure for every organization. Instead, SOC 2 examinations focus on controls relevant to areas such as security, availability, processing integrity, confidentiality, and privacy.
For SaaS companies pursuing or maintaining SOC 2, independent penetration testing can provide useful security evidence as part of a broader security program.
Enterprise customers may also request evidence of independent security testing during vendor or security reviews. Having a recent assessment report can help provide documented information about identified vulnerabilities, remediation priorities, and the organization’s security testing practices.
What’s Covered
Web Application Testing
Your core SaaS application can be assessed for security weaknesses affecting authentication, authorization, application logic, data handling, and other relevant controls.
See our web application penetration testing service for dedicated application testing.
Multi-Tenant Isolation Testing
Multi-tenant SaaS platforms require appropriate separation between customers, organizations, and user roles.
Where included in scope, testing can evaluate whether authorization and access controls appropriately separate tenant data and functionality.
API Security Testing
SaaS platforms commonly depend on APIs to support application functionality and integrations.
API security testing can assess authentication, authorization, endpoint security, data exposure, input handling, and other relevant controls.
See our API security testing service for dedicated API-focused assessments.
Cloud Infrastructure Testing
Where cloud infrastructure forms part of the assessment scope, relevant security controls and configurations can be evaluated across AWS, Azure, or GCP environments.
See our cloud security testing service for a dedicated cloud security assessment.
Authentication and Access Control
Authentication and authorization controls can be assessed to determine whether users and roles are appropriately restricted within the approved environment.
Depending on the architecture, this can include relevant SSO, role-based access, session management, and access-control mechanisms.
Our SOC 2 Penetration Testing Process
A structured assessment helps ensure the testing is aligned with your application, environment, and security objectives.
Scope and Authorization
The engagement begins by defining the applications, environments, domains, APIs, infrastructure, user roles, and other components included in the assessment.
Written authorization and agreed testing boundaries should be established before testing begins.
Security Assessment
Testing combines appropriate automated assessment techniques with manual analysis within the authorized scope.
The objective is to identify meaningful security weaknesses while minimizing unnecessary impact on systems and users.
Finding Validation
Potential findings are reviewed and validated before inclusion in the final report.
This helps reduce false positives and provides clearer information about the security significance of identified issues.
Reporting
Findings are documented with relevant severity, affected components, supporting evidence, potential impact, and remediation guidance.
The resulting documentation can help security teams, technical stakeholders, and appropriate reviewers understand the assessment results.
Remediation and Retesting
After remediation, previously identified findings can be reviewed again when retesting is included in the agreed engagement.
This can provide additional evidence that relevant corrective actions have been implemented.
What You Receive
Depending on the agreed scope, deliverables can include:
- Executive summary
- Detailed technical findings
- Severity or risk information
- Affected applications or components
- Supporting evidence
- Business impact context
- Remediation recommendations
- Retesting results where included
- Documentation of the assessment scope and methodology
The goal is to provide security documentation that is useful for both technical teams and organizations preparing for security reviews.
Why Independent Security Testing Matters for SaaS
SaaS platforms often combine web applications, APIs, cloud infrastructure, authentication systems, databases, and third-party integrations.
Testing these components within an appropriate authorized scope can provide an independent view of the security controls supporting the service.
A recent security assessment can also help organizations identify remediation priorities before vulnerabilities become more significant business risks.
Frequently Asked Questions
Is Penetration Testing Required for SOC 2?
SOC 2 does not prescribe one universal penetration testing requirement for every organization.
However, organizations may use independent security testing as part of their broader security program and may also encounter penetration testing requirements from customers, contracts, internal policies, or other security frameworks.
The appropriate testing scope depends on the organization, its systems, and the requirements it needs to address.
How Often Should We Perform Penetration Testing for SOC 2?
The appropriate frequency depends on the organization’s environment, security program, risk profile, contractual requirements, and applicable assessment expectations.
Many organizations perform periodic testing and repeat assessments after significant changes to applications, infrastructure, or security controls.
Can You Help Before an SOC 2 Audit?
Yes. Security testing can provide documented findings and remediation information that may support broader preparation activities.
The testing scope should be established according to the systems and security objectives relevant to the engagement.
Do You Test Staging or Production Environments?
Either environment may be considered, depending on the application architecture, testing objectives, and risk tolerance.
Production testing should be carefully scoped with appropriate Rules of Engagement and safeguards.
Do You Test SaaS and Multi-Tenant Applications?
Yes, where the application and testing objectives are included in the authorized scope.
Testing can consider relevant authorization, tenant separation, authentication, application functionality, and related controls.
What Does the Final Report Include?
Depending on the engagement, the report can include an executive summary, technical findings, severity information, affected components, supporting evidence, business impact, and remediation recommendations.
Do You Provide Retesting?
Retesting can be included when agreed as part of the engagement.
The purpose is to determine whether previously identified security weaknesses have been addressed following remediation.
Request a SOC 2 Penetration Testing Assessment
Preparing for a SOC 2 review or enterprise security assessment?
Tell us about your SaaS platform, application architecture, APIs, cloud environment, and assessment objectives.
We can help define an appropriate SOC 2 penetration testing scope based on your environment and requirements.
Confidential consultation · Authorized security testing · Professional reporting