Penetration Testing Checklist for SOC 2 and ISO 27001 Audits
A step-by-step checklist to plan, scope and document a penetration test that satisfies SOC 2 and ISO 27001 auditors.
Why auditors ask for a pentest
Neither SOC 2 nor ISO 27001 lists 'penetration test' as a single mandatory control, yet auditors almost always ask for one. For SOC 2 it supports Common Criteria on risk assessment and monitoring such as CC4.1 and CC7.1. For ISO 27001:2022 it supports Annex A control 8.8 on technical vulnerability management and 8.29 on security testing. A good test plus a retest is the cleanest evidence you can provide.
Before testing
Align scope with your SOC 2 system description or ISO 27001 ISMS scope. Include the production application, APIs and cloud account holding customer data. Book the test early enough to fix findings before your audit or inside your Type II observation window. Prepare test accounts for each role and a point of contact. Confirm the vendor's methodology references recognised standards like OWASP, PTES or NIST.
During testing
Keep a record of the testing window and any changes to scope. Respond quickly to tester questions so time is spent testing, not waiting. Ask for early notice of critical findings so you can start fixing immediately.
After testing
Log every finding in your issue tracker and risk register. Fix critical and high findings first, and document risk acceptance for anything you choose not to fix. Complete the retest and keep the final report as audit evidence. Share an attestation letter, not the full report, with customers. Repeat at least annually and after major changes. Scantra maps every finding to SOC 2 and ISO 27001 controls and includes a free retest.
