All articlesCompliance

Penetration Testing Checklist for SOC 2 and ISO 27001 Audits

2026-09-28 6 min read

A step-by-step checklist to plan, scope and document a penetration test that satisfies SOC 2 and ISO 27001 auditors.

Why auditors ask for a pentest

Neither SOC 2 nor ISO 27001 lists 'penetration test' as a single mandatory control, yet auditors almost always ask for one. For SOC 2 it supports Common Criteria on risk assessment and monitoring such as CC4.1 and CC7.1. For ISO 27001:2022 it supports Annex A control 8.8 on technical vulnerability management and 8.29 on security testing. A good test plus a retest is the cleanest evidence you can provide.

Before testing

Align scope with your SOC 2 system description or ISO 27001 ISMS scope. Include the production application, APIs and cloud account holding customer data. Book the test early enough to fix findings before your audit or inside your Type II observation window. Prepare test accounts for each role and a point of contact. Confirm the vendor's methodology references recognised standards like OWASP, PTES or NIST.

During testing

Keep a record of the testing window and any changes to scope. Respond quickly to tester questions so time is spent testing, not waiting. Ask for early notice of critical findings so you can start fixing immediately.

After testing

Log every finding in your issue tracker and risk register. Fix critical and high findings first, and document risk acceptance for anything you choose not to fix. Complete the retest and keep the final report as audit evidence. Share an attestation letter, not the full report, with customers. Repeat at least annually and after major changes. Scantra maps every finding to SOC 2 and ISO 27001 controls and includes a free retest.

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.