Short answer: technically no, practically yes.
Here's the longer version, because the "technically" part confuses a lot of people and occasionally gets someone into trouble halfway through an audit.
What the criteria actually say
SOC 2 audits are based on the AICPA's Trust Services Criteria. Nowhere do they say "you must perform an annual penetration test." SOC 2 isn't a checklist like that. It says you have to have controls that meet certain goals, and you and your auditor agree on how you meet them.
The criteria do mention pen testing, though. Under CC4.1, which covers how you monitor whether your controls actually work, penetration testing is listed as one of the ways to do that. CC7.1 covers finding vulnerabilities in your systems, and a pen test is the standard way to show that.
So it's not a hard requirement on paper. But it's named in the criteria, and it's the most common way to satisfy them.
What happens in practice
Most auditors expect one. If you don't have a pen test, you need another convincing way to show you're finding and fixing vulnerabilities, and that's a harder conversation than just getting the test done.
And even if your auditor lets it slide, your customers won't. Just about every enterprise security questionnaire asks some version of "have you had an independent penetration test in the last 12 months?" The SOC 2 report gets you in the door. The pen test answers the next question.
What auditors look for
When an auditor looks at your pen test, they're checking a few things:
- Independence. Someone outside your engineering team did it. Your own dev running a scanner doesn't count.
- Timing. It happened within the audit period, or at least within the last 12 months.
- Scope. It covers the systems that are in scope for your SOC 2. If your product is the web app, the web app should be tested.
- Method. There's a recognized methodology behind it, like OWASP.
- Follow-through. Findings were tracked and fixed, or there's a documented reason they weren't. This is the one people forget. A report full of high-severity findings that nobody touched looks worse than no report at all.
When to schedule it
For a Type 1, which looks at your controls at a single point in time, get the pen test done before the audit date, with enough time to fix what it finds. A couple of weeks is usually plenty for a small app.
For a Type 2, which looks at whether your controls worked over a period of months, the test needs to fall inside that window. Doing it early is better. That leaves room to fix things and show the fixes during the same period.
The most common mistake is leaving it to the last week. Then the report comes back with findings, there's no time to fix them, and now those findings are sitting in front of the auditor.
What to hand over
Auditors usually want the attestation letter (who tested, when, what scope, what method) and access to the full report. Customers usually just need the attestation letter. You don't have to send every customer your full list of findings, and generally you shouldn't. Offer the full report under NDA if they push.
The easy part
SOC 2 is a lot of work. Policies, access reviews, vendor management, evidence collection. The pen test is one of the few pieces you can knock out in a day.
Our SOC 2 pen test is $495 and includes the report and the attestation letter, delivered within 24 hours. It's one less thing on the list.