Compliance / SOC 2

SOC 2 and the penetration test

Auditor-expectedthe evidence your assessor expects to see

For a SOC 2 Type II, your auditor reads a penetration test as the independent evaluation that proves your controls actually operate over the audit window. It is what CC4.1 points to, and a report scoped to your system boundary and dated inside the observation period is what turns “we have controls” into evidence they hold.

SOC 2, in one panel

Standard
AICPA Trust Services Criteria (2017, revised 2022)
Pentest status
Auditor-expected · the evidence your assessor expects to see
Where it lives
TSC CC4.1, supported by CC7.1
Frequency
Annually, inside the observation window
Scope
The application and infrastructure inside the boundary described in your SOC 2 system description. Internal and social-engineering testing are not mandated by the criteria.
What the assessor wants
An independent report, scoped to the system description, run against a recognized methodology, with risk-rated findings and, above all, retest evidence that high and critical issues were closed inside the audit period.

What SOC 2 is

SOC 2 is not a certification you pass or fail. It is an independent examination, performed by a CPA firm, that reports on how well your controls meet the AICPA Trust Services Criteria over a period of time. “SOC 2” is the report; the criteria are the TSC.

A Type I opinion covers a single point in time. A Type II covers a window, usually 6 to 12 months, and tests that the controls actually operated. That distinction is where the pentest enters.

Where the pentest fits

CC4.1 asks management to run separate, independent evaluations to confirm controls are working, and its point of focus lists penetration testing as the leading example. That is where your auditor looks for the test.

Because that is where a penetration test fits the criteria, auditors routinely expect one in a Type II, and a report dated outside the observation window is commonly rejected.

How an AI-native pentest meets it

Uvy produces the independent, methodology-based evaluation CC4.1 points to: verified findings, proof of exploit, and an audit-ready report scoped to your system boundary.

Because it runs on every release rather than once a year, the evidence stays inside your observation window instead of aging out of it.

To be precise

A penetration test evidences CC4.1 and CC7.1; the full examination covers more. Uvy delivers that evidence in the exact form an auditor accepts, scoped to your system boundary and current inside the window.

What a seasoned assessor knows

The test that satisfies SOC 2 is scoped to your system description and dated inside the observation window. A report against the wrong boundary, or one that lands outside that window, is the single thing an auditor sends back, which is why running on every release beats a once-a-year engagement.

Find every way in, before an attacker does

Uvy runs continuous offense and defense across your applications, agents, and embodied AI, at machine speed, and hands your team proof and the exact fix. Start with an application pentest, or talk to sales to cover the rest.

Free to test. No card to start.

Or write to [email protected]