SOC 2 Compliance Services title card with a star icon in the Affordable Pentesting brand style.

SOC 2 Compliance Services: What You Actually Need

Companies searching for SOC 2 compliance services are often looking for the wrong thing. SOC 2 is an attestation, only a licensed CPA firm can issue it, so what most businesses actually need first is help getting ready for that audit, and penetration testing is a core part of that prep work.

The phrase covers at least four different products sold by four different kinds of company, and they aren't interchangeable. What follows is a breakdown of what each one is and what it can legally deliver, so you buy the piece you're actually missing instead of paying twice for the same thing.

What SOC 2 Compliance Actually Requires

SOC 2 measures your controls against five trust services categories: security, availability, processing integrity, confidentiality, and privacy. A licensed CPA firm reviews your evidence and issues the actual SOC 2 report, they're the only ones who can. Before that review happens, you need to have real controls in place and proof that they work, not just policies sitting in a folder.

Two details trip people up. First, only the security category, the common criteria, is required. The other four are optional, and you include one because a customer asked or because it describes what you sell. Adding all five because it sounds thorough just multiplies the evidence you have to produce. Second, there are two report types. A Type 1 describes whether your controls are suitably designed at a single point in time. A Type 2 tests whether they operated effectively across a window, commonly three to twelve months. Customers who ask for a SOC 2 almost always mean a Type 2.

The Four Things Sold As SOC 2 Compliance Services

When a search for SOC 2 compliance services returns a page of vendors, you're looking at four distinct categories. Knowing which is which is most of the battle.

The CPA firm that issues the report

SOC 2 reports are issued under AICPA attestation standards, and only a licensed CPA firm can sign one. This is the only category that produces the document your customer asked for. Everything else on this list is preparation. Independence rules also limit how much of your control environment the same firm can build for you and still attest to it, which is why most firms keep readiness work and the audit separate, or hand one of them off entirely.

Readiness and gap assessment work

A readiness assessment maps your current state against the criteria you plan to include and tells you what's missing before the auditor finds out. Done well, it's a list of specific gaps with owners and dates against your actual systems. Done badly, it's a generic control matrix you could have downloaded. Ask what the deliverable looks like and whether it names your systems by name.

Compliance automation platforms

These tools connect to your cloud accounts, HR system, and ticketing, then collect evidence continuously and flag drift. They're genuinely useful for the evidence grind, and they cut the screenshot chase down to something manageable. What they don't do is make control decisions for you, and they don't issue anything. Auditors treat platform output as evidence, not as an audit.

Technical testing providers

This is where penetration testing sits, along with vulnerability scanning and code review. It's a separate purchase from all three categories above, and it's the one buyers most often assume is bundled somewhere. A compliance platform can track that you have a pentest report. It can't perform the test.

Where Penetration Testing Fits Into SOC 2

The security category expects you to identify and address vulnerabilities on an ongoing basis. Be precise about the wording here, because vendors overstate it constantly: the trust services criteria mention penetration testing only in the points of focus under CC4.1, which covers ongoing and separate evaluations. It isn't a stated requirement of SOC 2. What's true in practice is that auditors routinely ask for a recent test as evidence that your monitoring and vulnerability management controls actually run, and enterprise customers reviewing your report often ask directly.

That's the honest version, and it doesn't change the recommendation. A penetration test is the cleanest evidence most small companies have that an independent party tried to break in, documented what was found, and confirmed the fixes. It's rarely the thing that fails an audit, and it's frequently the thing that unblocks a stalled security review. SOC 2 penetration testing is scoped around exactly that evidence need.

Common SOC 2 Mistakes Companies Make

The biggest mistake is waiting until right before the audit to test anything, leaving no time to fix what gets found. Another common one is treating the pen test as a checkbox instead of actually remediating the findings, which auditors will notice. Some companies also confuse a vulnerability scan with a real penetration test, and the two aren't the same thing at all.

  • Starting the observation window before the controls exist. A Type 2 tests what happened during the window. Turning on access reviews in month five of a six month window gives the auditor one month of evidence.
  • Scoping in all five categories. Every category you add means more controls, more evidence, and more that can go wrong. Add privacy or availability because a contract requires it, not for completeness.
  • Buying a platform and calling it done. The platform tells you a control is failing. Someone on your team still has to fix it.
  • Assuming the auditor will accept last year's pentest. Most want a test that covers the current window and the current architecture.
  • Leaving remediation undocumented. A finding with no record of the fix looks worse than the finding did on its own.

What To Confirm Before You Buy Any Of It

Whatever category you're buying, these are the questions that stop you from purchasing the same capability twice.

  • Who signs the report? If the answer isn't a named licensed CPA firm, you're buying preparation, not an attestation. That's fine, as long as you know it going in.
  • Is penetration testing included, or just tracked? Read the scope line closely. Pentest management and penetration testing are different products at very different prices.
  • Will my auditor accept this evidence? Ask your CPA firm before you buy the platform, not after you've wired the money.
  • Which criteria does this cover? A readiness assessment priced for the security category won't cover privacy, and nobody will mention that until you ask.
  • Who does remediation? Confirm whether the vendor fixes things, tells you to fix things, or reviews your fixes. All three exist and they are not the same engagement.

How Affordable Pentesting Supports SOC 2 Readiness

We don't issue SOC 2 attestations, that's not our role and we won't pretend otherwise. What we do is run the penetration test your CPA firm and auditors expect to see, with a report back in about a week instead of the month long waits common at bigger firms. Our testers hold OSCP, CEH, and CREST certifications, so the findings hold up under real audit scrutiny.

If you're still working out which piece you're missing, the SOC 2 help page lays out where testing sits relative to the rest of the program, and what evidence comes out of it.

SOC 2 Service Questions Buyers Get Wrong

Is SOC 2 a certification?

No, and the distinction matters the moment a customer's procurement team reads your paperwork. SOC 2 is an attestation report written by a CPA firm about your controls. Nobody issues a SOC 2 certificate and there's no registry to look you up in. If a vendor offers to certify you, that's a sign they don't work in this space often.

Can one vendor handle readiness and the audit?

Sometimes, but with limits. Auditor independence rules restrict a CPA firm from attesting to controls it designed and implemented itself. Some firms run both sides with a wall between the teams, others won't touch it. Ask the question directly during scoping, because discovering the answer late can cost you an audit window.

Does a compliance platform mean we don't need a penetration test?

No. Platforms collect evidence and monitor configuration. Some resell testing through a partner, which is worth checking, but the subscription itself doesn't include anyone attacking your application. If your auditor or your customer asks for a report, you still need a test performed by people.

Do we need a Type 1 before a Type 2?

Not technically, and plenty of companies go straight to Type 2. A Type 1 is useful when a deal is stuck and you need something credible in hand fast, or when you want a checkpoint on control design before committing to a long observation window. If nobody's waiting on you, the money usually goes further on getting controls right and running a single Type 2.

Which trust services categories should we include?

Start with security, since it's required, and add others only when a customer contract or your product genuinely calls for them. Confidentiality is a common second for companies handling customer data under NDA. Processing integrity matters if you're doing calculations others rely on. Privacy is the heaviest lift and it's rarely worth adding speculatively.

Buying The Right Piece First

Most companies that feel stuck on SOC 2 aren't missing a vendor. They're missing clarity about which of the four categories they've already paid for. Write the four down: an auditor, a readiness plan, a platform, a test. The empty slot is your next purchase, and for a lot of teams the empty slot is the test.

If that's you, the fastest unblock is a scoped test with a delivery date you can hand your auditor. Start with a compliance quote and get the report into your evidence package before the window closes.

FAQ

Get your pentest quote today

Manual & AI Pentesting for SOC2, HIPAA, PCI DSS, NIST, ISO 27001, and More