Skip to content
Compliance · SOC 2

Penetration Testing for SOC 2 Security Evidence

CyberZ provides independent technical security testing that organizations can use as supporting evidence within their SOC 2 security program.

Important

CyberZ does not perform SOC 2 examinations or issue SOC 2 reports.

CyberZ provides technical security assessments designed to support SOC 2 evidence collection. How that evidence is used is decided by your organization and your auditor.

How testing fits

Independent testing as part of your SOC 2 evidence program.

Evidence, not certification

SOC 2 is a reporting framework: an independent CPA firm examines your controls and issues the report. Many organizations include independent penetration testing among the evidence that supports their security-related controls. CyberZ performs that testing.

Scoped to what matters

Testing is scoped around the systems in your SOC 2 boundary — typically the production web application, its APIs and supporting infrastructure — so the evidence is directly relevant to the controls you describe.

Reports your auditor can read

The executive summary states scope, methodology, dates, findings by severity and remediation status. The technical report gives your engineers what they need to fix issues before or during the audit period.

Retesting closes the loop

After remediation, retest results document which findings were resolved. That remediation record is often more useful as evidence than the initial findings.

Potential scope

What a SOC 2-oriented engagement may include.

Depending on the agreed scope. Scope is defined around the systems inside your SOC 2 boundary.

  • Web application penetration testing
  • API penetration testing
  • Authentication testing
  • Authorization testing
  • Business logic testing
  • Multi-tenancy testing
  • Vulnerability validation
  • Remediation verification (retesting)
Deliverables

What you can hand to your auditor.

  1. 01Executive Summary
  2. 02Technical Report
  3. 03Findings with severity ratings and CVSS scores
  4. 04Evidence and reproduction steps
  5. 05Business impact per finding
  6. 06Remediation guidance
  7. 07Retest results
  8. 08CyberZ Penetration Testing Certificate
Wording

Claims we do not make.

If you see these phrases from any vendor, ask questions. Accurate wording is part of credible evidence.

“SOC 2 Certified by CyberZ”

CyberZ does not certify SOC 2. The certificate confirms an independent assessment was performed.

“SOC 2 requires a penetration test”

SOC 2 does not universally require penetration testing. Many organizations choose it as evidence for their security controls.

“Our pentest makes you SOC 2 compliant”

Testing supports evidence collection. Compliance status is established through your own audit process.

Questions
When in the SOC 2 timeline should we test?

Most organizations test before the observation period begins or early within it, leaving time to remediate and retest. If you are already in an observation period, testing and retesting inside the period is common. Your auditor can advise on timing; we adapt scope and scheduling accordingly.

Can we share the report with our auditor and customers?

Yes. You own the report. Most organizations share the executive summary or attestation letter externally and keep the technical report internal.

Do we need a Type I or Type II for this?

That is a decision for you and your auditor. Independent testing can support evidence for either; CyberZ is not involved in the examination itself.

Next step

Request testing for your SOC 2 evidence program.

Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.