Penetration testing evidence for your SOC 2 report

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

SOC 2 measures your controls against the AICPA Trust Services Criteria, and penetration testing is the technical evidence auditors expect that those controls hold under a real attack. Strike tests continuously with AI-led execution and expert human validation, across your entire observation period. Strike supports the audit; your CPA firm issues the report.

Built for the Type II observation period

SaaS and fintech teams whose enterprise deal is waiting on a report their prospect's procurement team already demanded.

Organisations inside a Type II window that need dated evidence across the whole period, not one report at the edge of it.

Teams that want a single testing programme feeding SOC 2, ISO 27001 and PCI DSS instead of three disconnected engagements.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.
[ SOC 2 ]

What SOC 2 asks for — and where penetration testing fits

SOC 2 is not a certification. It is an attestation report, written and signed by a licensed CPA firm, on how your controls map to the AICPA Trust Services Criteria — the 2017 criteria, still current, with their points of focus revised in 2022. Nowhere in those criteria is a penetration test named as a required control. It appears once, as one example among several kinds of evaluation management can run. That single mention is why almost every SOC 2 audit includes one anyway.

[ TYPE I VS TYPE II — WHERE TESTING ACTUALLY MATTERS ]

A Type I report describes whether your controls are suitably designed on one specific date. A Type II report says whether they operated effectively across an observation period, usually three to twelve months. For a Type I, a recent test report is normally enough. For a Type II the auditor is sampling a window — and a single test dated four weeks before that window opened says nothing about the months that follow it.

[ WHERE THE CRITERIA TOUCH TESTING ]

CC4.1 — Monitoring activities. Management is expected to run ongoing and separate evaluations confirming that internal control is present and working. The points of focus list the options: internal audit, compliance assessments, vulnerability scans, security assessments and penetration testing. It is a menu, not a mandate — and penetration testing is the item on that menu an auditor recognises fastest.

CC7.1 — Detection. You have to detect configuration changes that introduce new vulnerabilities, and identify newly discovered ones in your components. Scanning satisfies the letter of it. Testing that chains findings into a working exploit is what tells you which of those vulnerabilities actually matters.

Depending on your scope, the access-control criteria in CC6 and the incident criteria in CC7.2 also lean on testing evidence: controls that resist real attempts to bypass them, and anomalies that get detected rather than logged and ignored.

[ THE DEAL ON THE OTHER SIDE OF THE REPORT ]

Most SOC 2 programmes do not start with a security goal. They start with an enterprise prospect whose procurement team will not sign without the report. That deadline is what shapes the testing decision: teams book the cheapest test that closes the gap, get a PDF, and find out at the Type II that the auditor wanted evidence across the whole period rather than one dated document.

[ WHAT YOU HAND THE AUDITOR ]

Scope and methodology, the qualifications of the testers, each finding with its severity, the date it was remediated, and evidence that the fix was retested and held. For a Type II, dates matter more than anything else: the auditor is checking that your evidence covers the observation window, not only its edges.

[ WHERE STRIKE FITS — AND WHERE IT DOES NOT ]

Strike does not issue SOC 2 reports and never will — only a licensed CPA firm can. What Strike delivers is the technical evidence behind them: continuous penetration testing executed by AI and validated by expert hackers at 97% precision and under 3% false positives, a documented retest attached to every finding, and a dated evidence trail that runs the length of your observation period instead of stopping after one engagement.

[ HOW THE OPTIONS COMPARE ]
Criterion
Annual pre-audit pentest
Bug bounty
Strike continuous
Evidence across the observation period
One dated report
Unpredictable, depends on researchers
Dated evidence across the whole window
Time to first report
Weeks to scope, then weeks to test
Whenever someone submits
Setup in under 5 minutes, findings in 1–2 hours
Validation of findings
Yes, by the testing team
Varies by submission
Every finding validated by expert hackers
False positives
Low, but narrowly scoped
Duplicates and out-of-scope noise
Under 3%
Remediation retest
Usually billed separately
The researcher decides
Included, tied to each finding
Predictability of cost
Fixed per engagement, repeated yearly
Variable bounty spend
One predictable subscription
[ FAQ ]

SOC 2 and penetration testing, answered

Does SOC 2 require a penetration test?

No. The Trust Services Criteria never list one as a required control. Penetration testing appears as one example of the evaluations management may run under CC4.1, alongside vulnerability scans, internal audit and compliance assessments. In practice most auditors ask for one, and most buyers reading your report expect to see it.

Type I or Type II — what changes for the testing?

Type I examines control design on a single date, so a recent test report usually satisfies it. Type II examines operating effectiveness across three to twelve months, so the auditor wants evidence spread across that window. That is exactly where an annual test starts to fall short and continuous testing starts to pay for itself.

What evidence do I actually hand the auditor?

The report itself, plus scope, methodology, tester qualifications, severity ratings, remediation dates and retest evidence. If your findings show up as fixed and re-verified with dates that fall inside the observation period, the conversation is short.

When should we run the testing?

Before the observation period opens if you are heading into a Type II, and then continuously through it. Testing only at the end leaves the earlier months unevidenced, and a critical finding discovered late turns into a remediation scramble against your report date.

Does Strike issue the SOC 2 report?

No. SOC 2 reports are issued by licensed CPA firms after their own examination. Strike supplies the penetration testing evidence, the retest records and the audit-ready documentation that the examination relies on.

How much does it cost and how long does it take?

Strike is a continuous subscription scoped to your attack surface rather than a fixed-price project, so cost follows scope and assets. Setup takes under 5 minutes once the target information and access are ready, and initial findings typically arrive within 1–2 hours of testing beginning, for supported scopes — fast enough to matter when a deal is waiting on the report.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Gartner 4
Gartner review, Head of Engineering, Banking

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Gartner 3
Gartner review, Product Security Leader Cybersecurity, Hardware

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Gartner 2
Gartner review, Chief Information Security Officer, Retail

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Gartner 1
Gartner Review, Chief Technical Officer, Banking

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Ozan Özgür Özyüksel
Information Security Officer, Plum

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

Miguel Langone
CTO at Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Ileana Barrionuevo
Sr AppSec Red Team, NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate PedidosYa.”

Eduardo Gimenez
CISO, Pedidos Ya

“For us at pier, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

Andras Hejj
CEO & CTO, Pier

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo