Guide · SOC 2 & ISO 27001

Penetration testing for SOC 2 & ISO 27001

SOC 2 and ISO 27001 don't certify a report — they certify that you run a defensible security process. Neither names a price or a specific vendor. What they need is evidence you find vulnerabilities and act on them. Here's exactly what the controls ask for, and how an audit-ready automated pentest answers them.

What the controls require

The specific clauses auditors look at

SOC 2 · CC7.1

Detect vulnerabilities and monitor for new ones. A pentest that finds and rates issues is standard evidence.

SOC 2 · CC4.1

Evaluate whether controls are operating. Proof of attacks attempted and held — not just failures — is exactly this.

ISO 27001 · A.8.8

Manage technical vulnerabilities: identify, assess, remediate, verify. A dated, re-tested report demonstrates the full loop.

How Aegis maps to them

An audit-ready report, built to answer the clause

Auditor wantsIn the Aegis report
Defined scope & methodologyOwnership-verified target, documented test suite
Dated findings with severityEvery finding timestamped, CVSS-rated, retained 18 months
Evidence & remediationReproduction steps and a specific fix per finding
Control verificationVerified Controls — attacks attempted and found safe
Re-testingFree re-test after you remediate

See the full control mapping in our methodology.

The honest caveat

Your auditor decides — and sometimes needs a human

No report is "SOC 2 compliant" on its own; SOC 2 certifies organisations, not documents. Most auditors accept audit-ready automated pentest evidence, but the final call is theirs. And specific mandates — PCI DSS 11.4, some government procurement — require a named human tester. We'd rather say that plainly than sell you something that won't clear your audit. Here's exactly when we're the wrong choice.

Minutes, not months

Get an audit-ready pentest for $999.

Verify a domain, accept the rules, and Aegis does the rest. Free to start; no sales call.