SOC 2 CC7.1 — Why a Single Pentest Isn't Enough for a Type II Report
Reviewed: 2 August 2026 — reviewed quarterly · General information, not authoritative TSC guidance
Quick Answer
SOC 2's CC7.1 criterion expects an ongoing process for detecting vulnerabilities, evidenced through activities like scanning and testing. For a Type II report, which opines on the whole review period, a single test dated near the audit isn't enough on its own — auditors expect evidence a testing cadence ran throughout the period, not just at one point in time.
What Does CC7.1 Ask For?
CC7.1 falls under the monitoring-of-controls area of the Trust Services Criteria and, broadly, expects an organisation to have a process to detect and identify new vulnerabilities affecting its systems — commonly evidenced through vulnerability scanning, penetration testing, or a combination of both, feeding into a defined response process. As with most SOC 2 criteria, it doesn't prescribe a specific tool or vendor; the auditor is assessing whether the process exists, is followed, and produces evidence.
Type I vs Type II — What Changes for Testing Evidence?
| Type I | Type II | |
|---|---|---|
| What's being assessed | Whether controls are suitably designed, as of a single point in time | Whether controls are suitably designed and were operating effectively across a period (typically 6–12 months) |
| What testing evidence looks like | A single test report dated near the assessment date can be sufficient | Evidence must span the review period — a single test near the end of the window is generally not enough on its own |
| Typical auditor expectation | One dated Vulnerability Assessment or penetration test report, recent to the point-in-time date | Multiple dated reports, or a documented recurring testing process with records covering the full period |
| Common gap auditors flag | Report is too old relative to the assessment date | Only one test exists for a 12-month window, with no evidence testing happened earlier in the period |
Checklist Before Your Type II Review Period Closes
Need testing evidence that spans your review period, not just one date? Our Vulnerability Assessment can be scheduled on a recurring cadence, with each report structured the same way for easy auditor comparison. See also our security testing glossary.
Start with Vulnerability Assessment