SOC 2 Penetration Testing

SOC 2 Penetration Testing

CREST-accredited penetration testing that gives your SOC 2 auditor the evidence they expect under the Trust Services Criteria. You get a fixed price, a named UK-based tester, and a report timed to your reporting period. Free retests are included.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CC7.1
The Trust Services criterion for detecting and monitoring vulnerabilities
CC4.1
The criterion for evaluating whether your controls actually work
2017
The AICPA Trust Services Criteria in force, revised 2022
Type II
A report on how your controls operated over a period, typically 6 to 12 months
Named client references

When the deadline cannot move, these named UK teams chose EJN Labs and got the result on the timeline they needed

Real EJN Labs clients, named with their permission. They chose us for accreditations they can verify and a CREST team that replies fast, not a sales pipeline.

SquareOne
I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.
Imran SaghirProject Lead, SquareOne
Cellori
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
Dan WilcocksonCo-Founder, Cellori
  • CREST approval, publicly verifiable
  • IASME Cyber Essentials body
  • Active testing within 24 hours
  • 100% UK-based testers

Further references, including under NDA, are available on your scoping call.

WHY IT MATTERS
2

the Trust Services criteria a single penetration test gives your auditor evidence for: CC7.1, detecting vulnerabilities, and CC4.1, evaluating that your controls work.

SOC 2 never names a penetration test. Your auditor still expects one

The AICPA Trust Services Criteria behind a SOC 2 report do not list penetration testing as an explicit, line-item control. A vendor who says SOC 2 does not require a pen test is technically correct. For the full breakdown, read our guide on whether SOC 2 requires penetration testing.

The useful answer is that a penetration test is the evidence auditors expect to see. CC7.1 covers detecting and monitoring for new vulnerabilities; CC4.1 covers evaluating whether your controls are working. A structured test from an independent tester is the clearest way to produce evidence against both.

We scope every engagement to the criteria in your report and time it to your reporting period, so the deliverable is current evidence your auditor can rely on. Findings are triaged by exploitability, remediation is practical, and a retest to confirm your fixes is included.

SOC 2 TRUST SERVICES CRITERIA

What a SOC 2 Penetration Test Covers

SOC 2 is about evidence, not a fixed checklist. Here is how a penetration test produces evidence against the criteria your auditor examines.

CC7.1

Vulnerability detection

evidence that you actively find and manage new vulnerabilities across the systems in scope, not just file an annual scan.

CC4.1

Control evaluation

independent testing that tries to defeat your controls, rather than a self-assessment, to confirm they operate.

API

APIs

the interfaces your service exposes and consumes.

CLOUD

Cloud environment

the AWS, Azure or GCP configuration your service runs on.

APP

Applications

the web applications in your SOC 2 scope, tested for business-logic and access-control flaws.

NET

Infrastructure

external and internal network, hosts and services in scope.

CHG

Significant-change testing

a material change to the application, infrastructure or cloud in scope is a trigger for a fresh test.

METHODOLOGY

How a SOC 2 Engagement Runs

From mapping the systems in your SOC 2 scope to an auditor-ready report and the retest that confirms your fixes, here is how the engagement runs.

01

Scope

We map the systems in your SOC 2 scope, agree the criteria to evidence (CC7.1, CC4.1 and related), and fix the price and timeline.

02

Test

Applications, APIs, cloud and infrastructure, with findings shared live to your portal.

03

Report

An auditor-ready report with an executive summary, technical detail, and each finding tied to the criterion it evidences, dated inside your reporting period.

04

Retest

We verify your remediation and issue a retest confirmation letter for your auditor.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get your fixed-price quote in 24 hours from a CREST-certified consultant, with no sales pipeline to chase

A fixed-price quote back in one working day, from a CREST-certified consultant. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed, scope-based price from £1,200 for a small penetration test scope, agreed up front. Certifications such as Cyber Essentials are priced separately. In our experience most engagements run £3,000 to £8,000. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
Nazia Khaleeq, Chief Revenue Officer Nazia KhaleeqChief Revenue Officer
  1. Nazia replies the same working dayYou will receive a fixed quote prepared by a CREST-certified consultant.
  2. You approve the scopeEngagement date is set, usually within 24 hours.
  3. Live findings land in your client portalTesting is live with free retests for every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed-price quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one working day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are explicitly tagged to the relevant control reference. Your audit team submits the report directly without translation work.

PCI DSS v4.0 Requirement 11.4

if you handle card data, the same test evidences Requirement 11.4.

ISO 27001 A.8.29

The same evidence supports secure-testing controls for your ISMS.

SOC 2 CC7.1 and CC4.1

penetration testing evidence auditors expect for vulnerability detection and control evaluation.

UK GDPR Article 32

Regular testing of the effectiveness of your security measures.

Cyber Essentials Plus

a separate UK Government-backed certification we also deliver, not a substitute for SOC 2.

NIST SP 800-115

The technical testing methodology behind the engagement.

PRICING

Transparent SOC 2 Pen Test Pricing

Priced on scope, as a fixed price agreed up front. No day-rate surprises, no hidden extras.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Retest confirmation letter
SMALL
From £2,400
2-day engagement

A single application or a focused SOC 2 scope.

Get a fixed quote
ENTERPRISE
From £9,600
8-day engagement

A large or multi-service platform.

Get a fixed quote

See how pricing is calculated

WHY EJN LABS

What You Get From a SOC 2 Pen Test

Six concrete differentiators competitors don’t all match.

Fixed price in 24h

Send your SOC 2 scope and we return a fixed price and timeline within one working day.

Named CREST-accredited UK tester

Every engagement is run by a named, CREST-accredited, UK-based tester.

Evidence your auditor accepts

Auditor-ready evidence, mapped finding by finding to the criteria your auditor examines.

Live findings to your portal

Findings land in your portal as we test, so remediation can start straight away.

Free retests

We retest your fixes to confirm they held, at no extra charge.

Retest confirmation letter

A retest confirmation letter on completion, for your auditor and your records.

FAQ

Frequently Asked

How long does a SOC 2 penetration test take?

Typically 2 to 8 days, depending on your SOC 2 scope. We confirm the timeline with your fixed quote.

Do I get a named tester?

Yes. A named, CREST-accredited, UK-based consultant runs your test.

Which criteria does the test evidence?

Mainly CC7.1, detecting and monitoring vulnerabilities, and CC4.1, evaluating that your controls work.

When should we test relative to our reporting period?

Aligned to your reporting period, and again after any significant change to the systems in scope, so the evidence is current.

Is a vulnerability scan enough?

A scan carries less weight than a structured test with manual validation; auditors weigh the quality of the evidence.

Will the report help our auditor?

It is structured as auditor-ready evidence, mapped to the criteria and dated within your reporting period, in the format auditors expect for CC7.1 and CC4.1.

What happens if you find vulnerabilities?

We triage by exploitability, give practical remediation, and a retest to confirm the fixes is included.

How much does a SOC 2 penetration test cost?

Priced on scope, as a fixed price agreed up front. Request a fixed quote in 24 hours.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get your SOC 2 pen test scoped in 24 hours

Send us your SOC 2 scope and reporting period and we will return a fixed price, a timeline, and the name of the CREST-accredited tester who will run it.