🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · SOC 2

SOC 2 CC7.1 — Why a Single Pentest Isn't Enough for a Type II Report

Reviewed: 2 August 2026 — reviewed quarterly · General information, not authoritative TSC guidance

Quick Answer

SOC 2's CC7.1 criterion expects an ongoing process for detecting vulnerabilities, evidenced through activities like scanning and testing. For a Type II report, which opines on the whole review period, a single test dated near the audit isn't enough on its own — auditors expect evidence a testing cadence ran throughout the period, not just at one point in time.

What Does CC7.1 Ask For?

CC7.1 falls under the monitoring-of-controls area of the Trust Services Criteria and, broadly, expects an organisation to have a process to detect and identify new vulnerabilities affecting its systems — commonly evidenced through vulnerability scanning, penetration testing, or a combination of both, feeding into a defined response process. As with most SOC 2 criteria, it doesn't prescribe a specific tool or vendor; the auditor is assessing whether the process exists, is followed, and produces evidence.

Type I vs Type II — What Changes for Testing Evidence?

Type IType II
What's being assessedWhether controls are suitably designed, as of a single point in timeWhether controls are suitably designed and were operating effectively across a period (typically 6–12 months)
What testing evidence looks likeA single test report dated near the assessment date can be sufficientEvidence must span the review period — a single test near the end of the window is generally not enough on its own
Typical auditor expectationOne dated Vulnerability Assessment or penetration test report, recent to the point-in-time dateMultiple dated reports, or a documented recurring testing process with records covering the full period
Common gap auditors flagReport is too old relative to the assessment dateOnly one test exists for a 12-month window, with no evidence testing happened earlier in the period

Checklist Before Your Type II Review Period Closes

Testing evidence spans the whole review period, not just a single date near the end
A recurring cadence was established before the review period opened, not started in response to the audit
Findings from earlier in the period show they were tracked to remediation, not just noted
Both automated scanning and at least one manually validated assessment are represented
Reports name the systems in scope clearly enough to map to the audited environment

Need testing evidence that spans your review period, not just one date? Our Vulnerability Assessment can be scheduled on a recurring cadence, with each report structured the same way for easy auditor comparison. See also our security testing glossary.

Start with Vulnerability Assessment

Frequently Asked Questions

What does CC7.1 actually require?+
CC7.1 sits within the Trust Services Criteria's monitoring-of-controls area and, broadly, expects the organisation to have a process for detecting and identifying vulnerabilities in its systems — including through activities such as vulnerability scanning and penetration testing — as part of monitoring whether controls remain effective. It doesn't mandate one specific method or vendor; it expects a functioning, evidenced process.
Why does a single penetration test not satisfy CC7.1 for a Type II report?+
A Type II report opinion covers whether controls operated effectively across the whole review period, not just at one moment. A single test dated near the end of that period tells an auditor about that one point in time, but says nothing about whether vulnerability monitoring was happening earlier in the window — which is the actual question a Type II opinion is answering.
How many tests are needed to cover a 12-month Type II period?+
There's no single fixed number mandated by the criteria itself — what matters is that the evidence, taken together, demonstrates the monitoring process operated throughout the period. In practice this is often satisfied by a combination of continuous or recurring vulnerability scanning plus at least one more thorough Vulnerability Assessment or penetration test within the window, rather than by test count alone.
Is a Type I report easier to satisfy from a testing perspective?+
In terms of testing evidence specifically, yes — a Type I report assesses design as of a point in time, so a single recent, dated test report is typically sufficient. A Type II report requires evidence across the review period, which is why organisations preparing for their first Type II often need to start their testing cadence well before the audit window opens, not just before the audit itself.
Does automated scanning alone satisfy CC7.1?+
Automated scanning contributes evidence of an ongoing detection process, which is relevant to CC7.1, but auditors commonly also expect evidence that findings were reviewed and acted on, not just detected. A combination of scanning plus periodic, manually validated assessment tends to present a stronger monitoring story than either alone.
What's the most common finding auditors raise related to CC7.1?+
The most frequent gap is evidence concentrated at one point near the end of the review period, with nothing demonstrating the process ran earlier in the window — effectively treating a Type II requirement like a Type I one. The fix is straightforward: establish a recurring testing cadence early enough that the evidence naturally spans the full period being audited.