Pentest Today.
compliance framework

Pass your SOC 2 Type II audit

Type II is about evidence over time. Pentest Today gives you the pentest, continuous scans, and control-mapped policies that prove your security program actually ran during the audit period.

What a SOC 2 Type II review asks for

A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.

A point-in-time penetration test plus a retest letter
Continuous vulnerability scanning across the observation window
Policies with version history showing they were in force
Evidence of remediation SLAs being met
Architecture diagrams kept current through the period

SOC 2 Type II, answered

How long is a Type II observation window?

Typically 3 to 12 months. Continuous scanning and dated reports give you evidence across the entire window rather than a single snapshot.

Do I need a retest after fixing findings?

Auditors love proof-of-fix. Our retest workflow verifies each remediated finding and issues a retest letter you can hand straight to the auditor.

Is the pentest a real test or just a scanner dump?

Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.

How fast can I get a report?

Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.

Get the evidence for your SOC 2 Type II review this week.

Start a scan on an approved target and walk in with the report, policies, and diagrams already done.