Pentest Today.
compliance framework

Pass your SOC 2 audit

Walk into your SOC 2 audit with the evidence already assembled. Pentest Today runs the penetration test, scans your environment, and generates the policies and diagrams your auditor maps straight to the Common Criteria.

What a SOC 2 review asks for

SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.

An independent penetration test of in-scope systems
Vulnerability scanning with tracked remediation
Written security policies mapped to CC6–CC9 controls
System architecture and data-flow diagrams
Evidence of access control, change management, and incident response

SOC 2, answered

Does SOC 2 require a penetration test?

A pentest isn't strictly mandated by the AICPA, but most auditors expect one as evidence for the risk-assessment and monitoring criteria. Pentest Today delivers a report formatted for exactly that.

What's the difference between Type I and Type II?

Type I assesses control design at a point in time; Type II tests operating effectiveness over a window (usually 3–12 months). We generate evidence for both.

Is the pentest a real test or just a scanner dump?

Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.

How fast can I get a report?

Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.

Get the evidence for your SOC 2 review this week.

Start a scan on an approved target and walk in with the report, policies, and diagrams already done.