Penetration Testing for SOC 2 Security Evidence
CyberZ provides independent technical security testing that organizations can use as supporting evidence within their SOC 2 security program.
Important
CyberZ does not perform SOC 2 examinations or issue SOC 2 reports.
CyberZ provides technical security assessments designed to support SOC 2 evidence collection. How that evidence is used is decided by your organization and your auditor.
Independent testing as part of your SOC 2 evidence program.
Evidence, not certification
SOC 2 is a reporting framework: an independent CPA firm examines your controls and issues the report. Many organizations include independent penetration testing among the evidence that supports their security-related controls. CyberZ performs that testing.
Scoped to what matters
Testing is scoped around the systems in your SOC 2 boundary — typically the production web application, its APIs and supporting infrastructure — so the evidence is directly relevant to the controls you describe.
Reports your auditor can read
The executive summary states scope, methodology, dates, findings by severity and remediation status. The technical report gives your engineers what they need to fix issues before or during the audit period.
Retesting closes the loop
After remediation, retest results document which findings were resolved. That remediation record is often more useful as evidence than the initial findings.
What a SOC 2-oriented engagement may include.
Depending on the agreed scope. Scope is defined around the systems inside your SOC 2 boundary.
- Web application penetration testing
- API penetration testing
- Authentication testing
- Authorization testing
- Business logic testing
- Multi-tenancy testing
- Vulnerability validation
- Remediation verification (retesting)
What you can hand to your auditor.
- 01Executive Summary
- 02Technical Report
- 03Findings with severity ratings and CVSS scores
- 04Evidence and reproduction steps
- 05Business impact per finding
- 06Remediation guidance
- 07Retest results
- 08CyberZ Penetration Testing Certificate
Claims we do not make.
If you see these phrases from any vendor, ask questions. Accurate wording is part of credible evidence.
“SOC 2 Certified by CyberZ”
CyberZ does not certify SOC 2. The certificate confirms an independent assessment was performed.
“SOC 2 requires a penetration test”
SOC 2 does not universally require penetration testing. Many organizations choose it as evidence for their security controls.
“Our pentest makes you SOC 2 compliant”
Testing supports evidence collection. Compliance status is established through your own audit process.
When in the SOC 2 timeline should we test?
Most organizations test before the observation period begins or early within it, leaving time to remediate and retest. If you are already in an observation period, testing and retesting inside the period is common. Your auditor can advise on timing; we adapt scope and scheduling accordingly.
Can we share the report with our auditor and customers?
Yes. You own the report. Most organizations share the executive summary or attestation letter externally and keep the technical report internal.
Do we need a Type I or Type II for this?
That is a decision for you and your auditor. Independent testing can support evidence for either; CyberZ is not involved in the examination itself.
Request testing for your SOC 2 evidence program.
Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.