Siam Thanat Hack Co., Ltd.

SOC 2 Type II Penetration Testing and Trust Services Criteria Guide

A definitive technical guide to AICPA SOC 2 Type II compliance, detailing Common Criteria CC4.1 and CC7.1 vulnerability management, annual independent penetration testing expectations, and audit evidence preparation for enterprise SaaS platforms.

Executive Summary and Mandate Overview
Target Audience Technology service providers, cloud platforms, SaaS vendors, fintechs, and data centers hosting or processing customer data
Mandatory Frequency Type II assessment over an operational testing window (typically 6-12 months) with annual CC7.1 penetration testing
Required Scope Security Trust Services Criteria (CC7.1), cloud workloads, production infrastructure, SaaS software, APIs, and CI/CD pipelines
Non-Compliance Risk Qualified auditor opinions, enterprise customer churn, procurement disqualification, and reputational damage

Understanding SOC 2 Type I versus Type II Audits

SOC 2 is the premier auditing standard developed by the AICPA to evaluate vendor risk and internal controls across technology service organizations.

Infographic explaining: Understanding SOC 2 Type I versus Type II Audits
Visual guide: Understanding SOC 2 Type I versus Type II Audits
  • Designed for SaaS providers, cloud infrastructure operators, and managed service organizations handling sensitive customer data.
  • Evaluates controls across 5 Trust Services Categories: Security (Common Criteria) is mandatory for every SOC 2 report; Availability, Processing Integrity, Confidentiality, and Privacy are applicable based on specific service commitments.
  • Type I reports evaluate the suitability of control design at a single point in time, ideal for early-stage startups establishing initial baselines.
  • Type II reports evaluate the operational effectiveness of controls over an extended review window (typically 3 to 12 months), required by enterprise procurement.

Common Criteria CC4.1 and CC7.1: Vulnerability Management and Penetration Testing

SOC 2 is a principles-based standard; while the base criteria text does not prescribe testing tools, the AICPA Points of Focus and CPA audit practices establish rigorous technical verification requirements.

Infographic explaining: Common Criteria CC4.1 and CC7.1: Vulnerability Management and Penetration Testing
Visual guide: Common Criteria CC4.1 and CC7.1: Vulnerability Management and Penetration Testing
  • Criteria CC4.1 (COSO Principle 12): Points of Focus explicitly state that management conducts penetration testing to evaluate whether controls are functioning as designed.
  • Criteria CC7.1 (System Operations): Mandatory baseline requiring ongoing vulnerability scanning across cloud infrastructure, databases, container registries, and application endpoints.
  • De facto audit mandate: CPA audit firms overwhelmingly expect an annual independent third-party penetration testing report as indispensable audit evidence for an unqualified SOC 2 Type II report.
  • Testing scope spans external internet-facing perimeters, web applications, microservices APIs, Kubernetes clusters, cloud IAM, and multi-tenant data isolation.

Deficiency Remediation under CC4.2 and CPA Deliverables

How engineering teams translate offensive test findings into audit-ready remediation evidence and independent attestation letters.

Infographic explaining: Deficiency Remediation under CC4.2 and CPA Deliverables
Visual guide: Deficiency Remediation under CC4.2 and CPA Deliverables
  • Critical and High vulnerabilities identified during testing must be remediated within strict policy SLAs prior to the close of the audit period.
  • Independent re-testing must be performed to provide verifiable proof that identified vulnerabilities have been effectively resolved.
  • The penetration testing partner provides a formal Attestation Letter detailing testing scope, methodologies, and remediation status for inclusion in the SOC 2 report.
  • CPA audit firms scrutinize tester independence, accredited qualifications (OSCP, CREST, CISSP), and methodology rigor to deliver an unqualified audit opinion.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Trust Services Criteria CC7.1 Vulnerability Management and Independent Penetration Testing Regular vulnerability assessments and annual independent third-party penetration testing of cloud infrastructure, APIs, and SaaS applications Continuous vulnerability scanning and annual pentest within the Type II audit testing window
Trust Services Criteria CC6.1 - CC6.3 Logical and Physical Access Controls Evaluate IAM role-based access, least privilege, separation of duties, and ubiquitous MFA enforcement across production systems Evaluated across the sustained Type II period of performance (typically 6-12 months)
Trust Services Criteria CC6.6 - CC6.7 Perimeter Defense and Cryptographic Data Protection Audit boundary firewalls, WAF defenses, transit encryption (TLS 1.3), and at-rest cryptographic controls Assessed regularly and verified during penetration tests
Trust Services Criteria CC7.3 - CC7.4 Incident Detection, Response, and Remediation Tracking Verify formal vulnerability remediation lifecycles, SLA tracking, root cause analyses, and independent retesting evidence Continuous monitoring with full evidence archival for CPA review

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Explore AICPA Trust Services Criteria and SOC 2 Type II audit guidance on the AICPA-CIMA website.

Go to the official source