Skip to content
A group of people in a meeting around a table

Illustrative Walkthrough: A SOC 2 Pentest Pilot, Start to Finish

Posted in :

Tips to Secure Team
Illustrative walkthrough, not a customer engagement. No real client, finding, metric or result is described below. This is an invented example showing how a pilot runs and what an auditor typically asks for. We do not publish customer references without written permission, and we do not publish invented ones. See Principle 5: we refuse a fabricated finding, metric, credential or customer.

First, the thing most vendors get wrong

SOC 2 does not explicitly require a penetration test. The AICPA Trust Services Criteria do not name one as mandatory. What CC4.1 does is list penetration testing as an example of the ongoing and separate evaluations management can use to assess internal control, and CC7.1 addresses identifying vulnerabilities.

So the accurate statement is: a penetration test is strong evidence for criteria you must satisfy some way, not a box the standard tells you to tick. Anyone selling you a test on the claim that SOC 2 mandates it is already misrepresenting something.

An illustrative pilot, stage by stage

Take an invented company: a mid-sized B2B SaaS with one customer-facing web application, preparing for a Type II observation window, with a security questionnaire from a prospect blocking a deal.

Stage 1 – Scoping and allow-listing

The application, its authenticated surface and its API are agreed in writing. Marketing site, third-party subprocessors and anything shared are excluded. The list is loaded into the product as a hard allow-list, so out-of-scope targets cannot be reached even by accident.

Stage 2 – Authorisation

Rules of Engagement and an Authorisation Letter are signed by an officer with demonstrated authority over the systems. Test windows, rate limits, and a named contact for incidents are fixed in the same document. This is the artefact an auditor will ask to see alongside the report.

Stage 3 – Adversarial testing

Three to five business days. Bhedan reasons about the application structure and proposes candidates; a named engineer attempts each one. Anything that cannot be reproduced does not become a finding.

Stage 4 – Attestation and handover

The report carries reproduction calls for confirmed findings, remediation guidance, the scope as agreed, and the section stating what was not proven. It is signed by its author.

What the auditor actually wants from it

  • Evidence the evaluation happened, with dates inside the observation window.
  • Scope, so the test can be judged against the system described in the SOC 2 report.
  • Authorisation, showing the testing was sanctioned.
  • Remediation tracking: what was found, what was fixed, when, and how the fix was verified.

The last item is where teams lose time, and it is why re-runnable findings matter more here than they look. “Fixed” is an assertion. “Fixed, and here is the same call returning a denial” is evidence.

Sources

Tips to Secure Team

View All Articles