
UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.
SOC 2 Type II Service Organization Control · North America
SOC 2 is an auditing framework developed by the AICPA that evaluates a service organisation's controls relevant to security, availability, processing integrity, confidentiality, and privacy (the Trust Services Criteria). SOC 2 Type II reports are increasingly required by enterprise customers evaluating SaaS vendors, cloud service providers, and managed service providers.
Penetration testing is a critical component of demonstrating compliance with the Common Criteria (CC) 4.1, which requires organisations to evaluate and test the design and operating effectiveness of controls. Regular penetration testing provides evidence that security controls are working as intended and helps identify gaps before they are found during the SOC 2 audit.
Many SOC 2 auditors specifically look for annual penetration testing as evidence of a mature security programme. Testing should cover the systems and services described in the SOC 2 report scope, including infrastructure, applications, APIs, and access controls.

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.
US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.

Penetration testing firm trusted by nine of the top ten US banks, with the Resolve platform for continuous attack surface management.
CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.

Global managed security provider with the elite SpiderLabs penetration testing team and deep PCI DSS compliance expertise.

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Offensive security firm founded by former NSA operator David Kennedy, delivering CREST-accredited penetration testing, red teaming, and adversary simulation to Fortune 500 and government clients.

US-headquartered cybersecurity consultancy with 800+ employees, serving ~40% of the Fortune 500. FedRAMP 3PAO, PCI QSA, and HITRUST accreditations.

Creators of Metasploit offering enterprise penetration testing integrated with their comprehensive vulnerability management and security operations platform.

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

Compliance-focused cybersecurity advisory firm and FedRAMP 3PAO specializing in penetration testing that meets stringent regulatory requirements.

CREST and CHECK-accredited European managed services provider delivering penetration testing with deep infrastructure and cloud hosting expertise.
While not explicitly required by the Trust Services Criteria, penetration testing is strongly expected by most auditors as evidence of meeting CC4.1 (monitoring of controls) and CC7.1 (identification and response to security incidents).
Web application, network, and API penetration testing are most relevant. The scope should align with the systems and services covered in your SOC 2 report.
Pen test results should be within the audit period (typically 12 months). Most organisations schedule annual pen tests to coincide with their SOC 2 audit cycle.