This question comes up in almost every SOC 2 engagement: "Do we actually need a penetration test?" The technically-correct answer surprises people, and then the practical answer overrides it. Let me give you both, because the gap between them is where startups get tripped up.
SOC 2 does not contain a control that says "thou shalt run a penetration test." The framework is built on the Trust Services Criteria, which describe outcomes, you must identify vulnerabilities, monitor your systems, and manage risk, without mandating a specific tool or test. In principle, you could satisfy the relevant criteria with a robust vulnerability management program and no formal pentest.
In practice, almost nobody does, and here is why.
Three forces turn "not required" into "you need one":
This trips up a lot of teams. An automated vulnerability scan runs a tool against your systems and produces a list of known issues. A penetration test is a human actively trying to compromise your application, chaining together the broken access control, the IDOR, the auth logic flaw, and the misconfigured cloud role that no scanner strings together on its own. Auditors and serious customers can tell the difference, and a scan report submitted as a "pentest" tends to invite scrutiny rather than close it.
If you are getting a pentest specifically to support SOC 2 and customer reviews, make sure the engagement produces:
Annually is the baseline expectation, plus after any significant change to your architecture. For a fast-moving startup shipping major features, a test before a big enterprise deal or a funding round often pays for itself immediately by clearing the security review that would otherwise block it.
So: SOC 2 does not force you to run a pentest, but your auditor, your customers, and your own risk posture all effectively do. Treat it as a required part of the program, scope it as manual testing rather than a scan, and make sure it produces something you can actually hand to a customer.
Need a pentest your auditor and customers will accept? I run manual penetration tests for SaaS and startups and deliver a report plus a letter of attestation you can drop straight into a security review.
See penetration testing services →