SOC 2 vs ISO 27001: Which Needs a Pentest?
Neither SOC 2 nor ISO 27001 says the words "you must run a penetration test" anywhere in their official text — but in practice, almost every company that gets certified pays for one anyway.
This is for founders who've been told by a customer, investor, or sales prospect "we need your SOC 2" or "we need your ISO 27001 certificate" and are now trying to figure out whether a pentest is actually a line item on that checklist, and when to budget for it. You'll get a plain breakdown of what each framework's actual text requires, what auditors realistically expect anyway, and a timeline for when to book the test so it doesn't delay your audit.
The short answer
| Framework | Does the written standard require a pentest? | Will your auditor expect one anyway? |
|---|---|---|
| SOC 2 (AICPA Trust Services Criteria) | No — it requires ongoing vulnerability monitoring and detection, not a named "penetration test" | Almost always yes, especially for Type II reports and any company handling customer data |
| ISO 27001:2022 | No explicit mandate, but Annex A control 8.29 ("Security testing in development and acceptance") is hard to satisfy without one | Yes — certification bodies routinely ask for evidence of security testing, and pentesting is the standard way to show it |
Both frameworks are risk-based and outcome-based, not checklists of specific tools. That's the root of the confusion: they describe an outcome ("know your vulnerabilities," "test your security controls") and leave the how up to you. A penetration test just happens to be the most common, most credible way to produce that evidence.
What SOC 2 actually requires
SOC 2 is built on the AICPA's Trust Services Criteria, organized around five categories: security, availability, processing integrity, confidentiality, and privacy. Every SOC 2 report covers the Security category at minimum.
Two criteria within the Common Criteria ("CC") series are the ones that pull pentesting into scope indirectly:
- CC4.1 (Monitoring Activities) — the organization must evaluate whether its controls are actually operating as designed.
- CC7.1 (System Operations) — the organization must identify vulnerabilities in its systems on an ongoing basis.
Neither criterion names a penetration test. You could, in theory, satisfy them with automated vulnerability scanning, code review, and bug bounty findings alone. But in practice, most SOC 2 auditors will flag the absence of an independent, human-led penetration test as a gap — particularly for a Type II report, which covers your controls operating over a 3–12 month window rather than a single point in time. If your customers send security questionnaires (most B2B SaaS buyers do), "do you conduct annual penetration testing?" is one of the first questions, and a SOC 2 report without one raises eyebrows during due diligence even if it technically passed.
What ISO 27001 actually requires
ISO 27001 works differently: it's a certifiable management-system standard, not an audit of specific criteria. You build an Information Security Management System (ISMS), run a risk assessment, and then justify which of the 93 Annex A controls apply to you in a document called the Statement of Applicability (SoA).
The control most directly relevant to pentesting is Annex A 8.29, "Security testing in development and acceptance" — introduced in the 2022 revision. It requires you to define and implement a security testing process for new and changed systems. Alongside it, Annex A 8.8, "Management of technical vulnerabilities," requires you to obtain timely information about technical vulnerabilities in the systems you use and respond appropriately.
You can mark a control "not applicable" in your SoA if you have a documented, risk-based justification. But if you run a website, a customer-facing app, or any internet-exposed infrastructure, excluding 8.29 is very difficult to defend to a certification body auditor — they'll ask what alternative evidence proves your software is tested for exploitable flaws before it ships. For almost every SaaS company, a penetration test (or at minimum a structured vulnerability assessment) becomes the practical answer.
Side-by-side comparison
| Question | SOC 2 | ISO 27001:2022 |
|---|---|---|
| Explicit pentest requirement in the text? | No | No |
| Closest control(s) | CC4.1, CC7.1 | Annex A 8.8, 8.29 |
| Can you avoid it entirely? | Rarely — auditors treat it as standard evidence | Only with a strong, documented risk-based exclusion |
| Typical expected frequency | Annually (aligned to Type II audit period) | Annually, or after significant system changes |
| Who checks the evidence | Your SOC 2 auditor (CPA firm) | Your ISO 27001 certification body auditor |
| Report becomes audit evidence? | Yes — attach or reference the pentest report and remediation | Yes — cited as evidence for the relevant Annex A controls |
When to actually book the test
Don't wait until your auditor asks. Pentest reports take time to schedule, execute, and remediate findings from — and a fresh critical vulnerability sitting unfixed in your report looks worse than not having tested at all.
- 8–12 weeks before your audit kickoff — book the test. Manual testers (not just automated scanners) often have multi-week queues.
- 4–6 weeks before kickoff — receive the report, triage findings by severity, and fix anything high or critical.
- 2 weeks before kickoff — have your remediation evidence (tickets closed, patches deployed, retest confirmation) ready to hand your auditor.
- Ongoing — re-test annually, and again after any major architecture change, new product launch, or when a customer contractually requires it.
If you're unsure whether your current setup even has obvious holes before you spend money on a formal audit-grade pentest, a free passive security check is a reasonable first pass — it won't replace what your auditor needs, but it'll tell you if there's something urgent to fix first.
What auditors actually accept as "a pentest"
Not every scan qualifies. Auditors for both frameworks generally want to see:
- A human-led test, not purely automated (see our breakdown of manual vs. automated penetration testing for why the distinction matters to auditors)
- A dated, written report with findings, severity ratings, evidence, and remediation guidance
- Proof that high/critical findings were remediated or formally risk-accepted
- Testing scoped to production or production-equivalent systems, not just a staging sandbox
- A tester independent from the team that built the system
Methodology matters too. Testers commonly reference the OWASP Web Security Testing Guide and NIST SP 800-115 as recognized frameworks for how a test should be structured — citing one of these in your report adds credibility during audit review.
If you're budgeting for the first time, our guide on how much a penetration test costs breaks down typical pricing so you're not caught off guard by enterprise pentest firm quotes that assume a much larger scope than a single web app.
Key takeaways
- Neither SOC 2 nor ISO 27001 explicitly mandates a "penetration test" by name — both are risk-based standards that require evidence of vulnerability testing and monitoring.
- SOC 2's CC4.1 and CC7.1, and ISO 27001's Annex A 8.8 and 8.29, are the controls that make a pentest the practical, expected answer for almost every company.
- Book your pentest 8–12 weeks before your audit so you have time to fix findings before the auditor sees them.
- Auditors want a human-led test with a written report and proof of remediation — automated scans alone usually aren't enough.
- Retest annually and after major changes; a stale pentest report is nearly as bad as none.
If you're not sure where your site actually stands before you commit to a full compliance push, Bug Circuit's $49 Circuit audit gets a real person manually testing your site with a full written report of what's wrong and how to fix it — a solid, honest starting point before you book a formal compliance-grade pentest.
A real human security engineer audits your whole site by hand and sends a full report — every issue, its severity, and the exact fix. From $49, with a 14-day money-back guarantee.
See pricing