10 Best Penetration Testing Companies for SOC 2 Compliance in 2026
Updated:
August 25, 2026
In 2026, 53% of security leaders say point-in-time penetration testing can become outdated before teams act on the results, according to research from Omdia.
For companies pursuing SOC 2 compliance, penetration testing can provide practical evidence that security controls work against real-world attack techniques while exposing vulnerabilities that automated scans may miss. Although, SOC 2 does not explicitly require a penetration test.
The right provider should offer qualified testers, SOC 2 experience, clear reporting, remediation support, and retesting that fits your audit timeline.
Below, we compare 10 of the best penetration testing companies for SOC 2 compliance in 2026, including their capabilities and the organizations they are best suited for.
Note: This Is Not a Ranked List. The Numbering and Placement of the Companies Do Not Indicate Superiority or Preference. All Firms Included Have the Capabilities and Experience to Provide Penetration Testing Services for SOC 2 Compliance.
Quick Comparison of SOC 2 Penetration Testing Companies
| Provider | Best For (Company Size) | Testing Model | Published Pricing | Retesting Included | Website |
|---|---|---|---|---|---|
| Bright Defense | Startups, SMBs, regulated SaaS | Consultant-led manual testing with automated support | $2,750 to $9,250 | Support included; fixed count and window not published | brightdefense.com |
| UnderDefense | Startups and mid-market | Manual-led project testing | From $5,000 | Included in original price | underdefense.com |
| Prescient Security | SMBs, mid-market, regulated SaaS | Human-led compliance or traditional testing | From $3,000 or $6,000 | Complimentary retests; extra Cait retests cost $250 | prescientsecurity. com |
| BreachLock | Startups and mid-market | In-house PTaaS with AI support | Custom quote | One manual retest plus platform retesting | breachlock.com |
| Software Secured | SaaS and product teams | Full-time manual testing | $5,400 or $10,800 starting price | One or three rounds; unlimited with PTaaS | softwaresecured. com |
| Cobalt | Release-driven SaaS and mid-market | Vetted tester community through PTaaS | Annual credits; custom total | Unlimited during contract term | cobalt.io |
| Packetlabs | Mid-market and regulated teams | In-house, 95% manual testing | Custom quote | Included; timing set in the engagement | packetlabs.net |
| NetSPI | Large enterprises | 350+ in-house experts through PTaaS | Custom quote | Included in every current engagement | netspi.com |
| Bishop Fox | Complex enterprises | Expert-led offensive security consulting | Custom quote | Optional, not listed as a default benefit | bishopfox.com |
| Coalfire | Regulated enterprises | DivisionHex threat-informed testing | Custom quote | Project-specific | coalfire.com |
1. Bright Defense: Startups, SMBs, and Regulated SaaS Companies
Bright Defense is a cybersecurity and compliance firm founded in 2023 by Tim Mektrakarn and John Minnix in Culver City, California. The company combines web application, API, network, and cloud penetration testing with SOC 2 readiness, vulnerability management, continuous compliance, and vCISO support.
Its strongest purchasing advantage is a fully published three-tier price card. Buyers can compare testing hours, application coverage, user roles, and price before a scoping call.
| Attribute | Details |
|---|---|
| Headquarters | Culver City, California |
| Founded | 2023 |
| Founder or CEO | Co-founders Tim Mektrakarn and John Minnix |
| Testing Coverage | Web applications, APIs, networks, and AWS, Azure, or Google Cloud environments |
| Delivery Model | Consultant-led manual testing supported by automated reconnaissance and scanning |
| Methodology Standards | NIST SP 800-115, OWASP Web Security Testing Guide, OWASP Top 10, and PTES |
| Retesting | Retest support is included; public materials do not state a fixed round count or window |
| Attestation Letter | No public issuance policy was found |
| Compliance Support | SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and NIST |
| Accreditations | ISO/IEC 27001:2022 certified; Drata Gold Partner |
| Pricing | $2,750 to $9,250 |
| Website | brightdefense.com |
Best For
Bright Defense is best for startups, SaaS companies, SMBs, and regulated organizations that want penetration testing and SOC 2 readiness managed through one security partner.
Penetration Testing Services
Testing combines automated surface analysis with manual validation of authentication, authorization, business logic, exposed services, cloud permissions, vulnerable software, and network configurations. The documented approach uses planning, reconnaissance, controlled exploitation, reporting, and retesting phases.
The deliverable includes an executive summary, scope and rules of engagement, testing methodology, severity totals, technical findings, proof of exploitation, affected assets, remediation steps, and evidence suitable for audit review. A fixed calendar range is not published. The three plans allocate 48, 96, or 176 testing hours, so the engagement schedule depends on scope and access.

Key Features
- Published testing-hour packages with fixed prices.
- Web application, API, network, and multi-cloud coverage.
- Manual exploit validation for high-value findings and business logic flaws.
- Executive and technical reporting with remediation guidance.
- SOC 2 readiness, vulnerability management, and vCISO support from the same firm.
Pros
- The only provider in this ranking with a fully published three-plan matrix that pairs hours and prices.
- Combines the penetration test with SOC 2 readiness and audit evidence planning.
- Uses recognized methodology standards in its documented reporting process.
- Provides a report structure designed for executives, engineers, compliance teams, and auditors.
Limitations
- Bright Defense has a shorter public offensive-security track record than the firms founded before 2010.
- Published materials do not state the number of included retest rounds or the remediation window.
- A standard post-test attestation letter is not described on the public service page.
- Individual offensive-security tester certifications are not publicly listed.
Pricing
Bright Defense publishes three fixed-scope penetration testing plans. Final scope can change when a project contains extra applications, APIs, roles, cloud accounts, network segments, or testing constraints.
| Plan | Testing Hours | Published Price |
|---|---|---|
| Ignite | 48 hours | $2,750 |
| Elevate | 96 hours | $5,250 |
| Summit | 176 hours | $9,250 |
Bright Defense for Startups Needing Testing and SOC 2 Readiness Together
Bright Defense is the most practical first choice for a smaller company that values price visibility and wants the test connected to the wider SOC 2 program. Buyers should place the exact retest allowance and attestation-letter requirement in the statement of work before signing.
| Get a SOC 2 Penetration Test With Published PricingBright Defense provides fixed-scope penetration testing plans from $2,750 and can connect the assessment to SOC 2 readiness, remediation, and audit evidence planning.Penetration Testing Services |
|---|
2. UnderDefense: Startups and Mid-Market Companies
UnderDefense is a cybersecurity company started in 2016 by Nazar Tymoshyk. It provides penetration testing, managed detection and response, incident response, cloud security, vCISO services, and compliance support through teams in the United States and Europe.
UnderDefense ranks highly for SOC 2 buyers due to its published starting prices, included remediation retest, and signed letter of attestation after remediation.
| Attribute | Details |
|---|---|
| Headquarters | New York office, with teams in Jacksonville and Krakow |
| Founded | 2016 |
| Founder or CEO | Founder and CEO Nazar Tymoshyk |
| Testing Coverage | Web, mobile, API, internal and external infrastructure, cloud, Active Directory, and social engineering |
| Delivery Model | Manual-led project testing with scanning support and attack-path analysis |
| Methodology Standards | OWASP testing guidance, PTES, NIST SP 800-115, and MITRE ATT&CK |
| Retesting | Included in the original price |
| Attestation Letter | Signed letter issued after remediation |
| Compliance Support | SOC 2, ISO 27001, PCI DSS, HIPAA, and related customer reviews |
| Accreditations | Company materials cite more than 120 certified security engineers |
| Pricing | Starting at $5,000 |
| Website | underdefense.com |
Best For
UnderDefense is best for startups and mid-market companies that need a defined compliance deliverable, a remediation retest, and a signed letter for an auditor or enterprise customer.
Penetration Testing Services
UnderDefense tests applications, APIs, networks, cloud environments, Active Directory, and external infrastructure. Testers validate exploitation, privilege escalation, lateral movement, and realistic attack paths, then document evidence and corrective actions.
Published packages describe fieldwork durations of up to five days, about two weeks, or about three to four weeks. The provider includes the retest in the original price and issues a signed attestation letter that summarizes scope, results, and the post-remediation security status.

Key Features
- Included remediation retest and signed attestation letter.
- Published starting prices and package durations.
- Application, API, infrastructure, cloud, and Active Directory testing.
- Technical evidence, reproduction steps, and remediation instructions.
- Optional MDR, incident response, vCISO, and compliance services.
Pros
- Pairs a bundled retest with a signed post-remediation letter in the standard buying flow.
- Publishes starting prices and estimated package durations.
- Can continue from testing into monitoring, incident response, or compliance support.
- Covers both product security and internal infrastructure risk.
Limitations
- Published figures are starting prices, so broad application or cloud scopes can cost more.
- The package descriptions do not state a universal cap on the number of findings covered in the retest.
- Hardware and product-device testing are not central services.
- Companies seeking a narrow test may not need the wider managed security portfolio.
Pricing
UnderDefense publishes three common starting points. Final price depends on asset count, authenticated roles, network size, cloud accounts, depth, and engagement constraints.
| Package | Typical Duration | Starting Price |
|---|---|---|
| External Perimeter | Up to 5 days | $5,000 |
| Standard | About 2 weeks | $8,000 |
| Professional | About 3 to 4 weeks | $12,000 |
UnderDefense for Buyers Who Need a Retest and Signed Attestation Letter
UnderDefense offers one of the clearest evidence packages in this ranking. The service suits a company that wants the initial report, remediation support, validation of fixes, and a signed document for external review under one engagement.
3. Prescient Security: SMBs, Mid-Market Companies, and Regulated SaaS
Prescient Security was founded in 2018 and is led by co-founder and CEO Fabrice Mouret. Co-founder Sammy Chowdhury serves as chief compliance officer. The group separates cybersecurity services from audit and attestation work through Prescient Security LLC and the licensed CPA firm Prescient Assurance LLC.
The company reports more than 4,800 penetration tests and more than 3,600 SOC 2 audits across its group. Its public pricing separates a focused compliance test from a deeper traditional engagement.
| Attribute | Details |
|---|---|
| Headquarters | United States operations with leadership across the U.S., Europe, and APAC |
| Founded | 2018 |
| Founder or CEO | Co-founder and CEO Fabrice Mouret; co-founder and CCO Sammy Chowdhury |
| Testing Coverage | Web applications, APIs, mobile apps, networks, cloud systems, red teaming, and social engineering |
| Delivery Model | Human-led compliance or traditional testing, with an optional AI testing service |
| Methodology Standards | OWASP, PTES, NIST SP 800-115, and OSSTMM |
| Retesting | Complimentary retests for human-led services; Cait includes up to two within 30 days and charges $250 for extras |
| Attestation Letter | Included with human-led compliance and traditional services |
| Compliance Support | SOC 2, ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, and more than 25 frameworks across the group |
| Accreditations | CREST and CSA STAR certified organization |
| Pricing | Compliance testing from $3,000; traditional testing from $6,000 |
| Website | prescientsecurity.com |
Best For
Prescient Security is best for SMBs, mid-market companies, and regulated SaaS teams that want public starting prices, letters of attestation, and access to a related licensed CPA firm under a separated practice structure.
Penetration Testing Services
Human-led services cover application, API, mobile, network, and cloud testing. Compliance testing focuses on audit-grade evidence for SOC 2, ISO 27001, and customer due-diligence reviews, while traditional testing provides deeper coverage for complex or high-risk systems.
Published timelines range from one day to two weeks for compliance testing and one day to six weeks for traditional testing. Both human-led services include preliminary and follow-up reports, letters of attestation, and required supporting documents. The separate Cait service provides recurring AI-assisted testing with defined retest limits.

Key Features
- Two human-led service levels with public starting prices.
- Letters of attestation and follow-up reports included.
- CREST and CSA STAR organizational credentials.
- Optional recurring testing through Cait.
- Licensed CPA audit services through a separate affiliate.
Pros
- Combines a cybersecurity firm and a licensed CPA affiliate under a documented separated practice structure.
- Publishes distinct starting prices for compliance and traditional tests.
- Includes attestation letters with both human-led service types.
- Publishes broad timeline ranges before scoping.
Limitations
- The $3,000 starting price applies to a focused compliance scope, not every application or infrastructure environment.
- Additional Cait retests cost $250 after the two included retests within 30 days.
- The audit and advisory teams must maintain independence when one client uses both affiliates.
- AI-assisted testing does not cover every business logic, mobile, binary, or social engineering scenario.
Pricing
Prescient Security publishes starting prices for its main testing models. Human-led retest pricing is described as complimentary, while Cait uses a fixed monthly or one-time price with defined retest allowances.
| Service | Published Starting Price | Retest Terms |
|---|---|---|
| Compliance Penetration Testing | $3,000 | Complimentary retests |
| Traditional Human-Led Testing | $6,000 | Complimentary retests |
| Cait Subscription | $850 per asset per month | Up to 2 within 30 days |
| One-Time Cait Assessment | $1,500 per asset | Up to 2 within 30 days |
Prescient Security for Testing and Audit Services Within One Provider Group
Prescient Security is useful when vendor coordination is a major concern and the buyer wants a focused compliance test or a deeper assessment. The engagement structure must preserve the independence of Prescient Assurance when that affiliate performs the SOC 2 examination.
4. BreachLock: Startups and Mid-Market Companies
BreachLock is a New York penetration testing company founded in 2019 by Seemant Sehgal. Its platform combines in-house certified pentesters, AI-supported reconnaissance, real-time findings, remediation support, and report generation across one-time or recurring engagements.
The current service publishes unusually clear post-test terms: one free manual retest, unlimited automated retesting in the platform, and a letter of attestation that clients can generate after each penetration test.
| Attribute | Details |
|---|---|
| Headquarters | New York, New York |
| Founded | 2019 |
| Founder or CEO | Founder and CEO Seemant Sehgal |
| Testing Coverage | Web, mobile, API, network, cloud, IoT, DevOps, LLM, and red team engagements |
| Delivery Model | 100% in-house certified pentesters through a PTaaS platform with AI support |
| Methodology Standards | NIST SP 800-115, OWASP testing guidance, PTES, OSSTMM, and CREST practices |
| Retesting | One free manual retest plus unlimited automated platform retesting |
| Attestation Letter | Generated from the platform after each penetration test |
| Compliance Support | SOC 2, PCI DSS, ISO 27001, HIPAA, HITRUST, and GDPR |
| Accreditations | CREST-certified service; tester credentials include OSCP, OSCE, CISSP, CEH, GSNA, and eJPT |
| Pricing | Custom quote |
| Website | breachlock.com |
Best For
BreachLock is best for startups and mid-market teams that want fast launch, in-house testing, a live remediation portal, a free manual retest, and self-service attestation documentation.
Penetration Testing Services
BreachLock tests applications, APIs, mobile apps, networks, cloud systems, IoT devices, DevOps environments, and LLM systems. Findings appear in the platform during testing with evidence, severity, risk context, and remediation guidance.
Tests can launch within 24 to 48 hours after scoping and scheduling. The company states that most engagements take from a few days to a couple of weeks, depending on technology and scope. One manual retest is included, platform retesting is available as remediation progresses, and updated audit-ready reports can be produced after validation.

Key Features
- One free manual retest plus unlimited automated platform retesting.
- Letter of attestation generation after each test.
- In-house certified pentesters with no crowdsourced delivery.
- Launch in 24 to 48 hours after scope approval.
- Real-time findings and direct tester communication.
Pros
- Publishes the clearest mix of manual retesting, platform retesting, and self-service attestation in this ranking.
- Uses an entirely in-house testing team with named hands-on certifications.
- Offers rapid scheduling for urgent audit or customer deadlines.
- Covers more asset types than many SMB-focused firms.
Limitations
- Project pricing is not published before the scoping process.
- Automated retesting cannot validate every business logic or multi-step exploit path.
- The distinction between platform retesting and the single full manual retest requires careful project planning.
- Broader red team or continuous programs can require a larger commitment than one annual compliance test.
Pricing
BreachLock uses custom pricing based on asset type, size, complexity, testing cadence, and required coverage. Every listed penetration test includes one free manual retest, platform access, audit-ready reports, and online remediation support.
BreachLock for Fast PTaaS Delivery and Self-Service Attestation
BreachLock fits a buyer that values speed and wants the reporting, retesting, and attestation workflow inside one platform. The statement of work should distinguish the full manual retest from automated validation of individual findings.
5. Software Secured: SaaS and Product Teams
Software Secured is an Ottawa penetration testing company started in 2010 by founder and CEO Sherif Koussa. It focuses on full-time manual testing for SaaS products, applications, APIs, mobile systems, networks, cloud environments, AI, IoT, and hardware.
The company publishes starting prices for black-box and gray-box testing, the number of included retest rounds, scheduling expectations, and report delivery timing.
| Attribute | Details |
|---|---|
| Headquarters | Ottawa, Ontario, Canada |
| Founded | 2010 |
| Founder or CEO | Founder and CEO Sherif Koussa |
| Testing Coverage | Web, API, mobile, network, cloud, secure code review, AI, IoT, and hardware |
| Delivery Model | Full-time Canadian pentesters with manual testing and targeted automation |
| Methodology Standards | OWASP Web Security Testing Guide, OWASP Top 10, OWASP ASVS, and NIST SP 800-115 as applicable |
| Retesting | One round for black box, three for gray box, and unlimited for PTaaS; current service pages state requests within six months |
| Attestation Letter | No public post-test attestation-letter policy; a letter of engagement is available before testing |
| Compliance Support | SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and customer security reviews |
| Accreditations | SOC 2 attested company; full-time certified pentesters |
| Pricing | Black box from $5,400; gray box from $10,800 |
| Website | softwaresecured.com |
Best For
Software Secured is best for SaaS and product teams that want public application-testing prices, clear retest counts, detailed engineering support, and predictable report delivery after fieldwork.
Penetration Testing Services
Software Secured performs black-box, gray-box, and white-box assessments with emphasis on authentication, authorization, tenant isolation, business logic, attack chaining, and code-level risk. Gray-box testing includes an external black-box network test and an attack-chain summary.
Meetings are generally available within three days, quotes within 48 hours, and testing is commonly scheduled three to six weeks ahead. The final report is issued within 48 to 72 hours after testing. Current service pages state that retesting can be requested within six months and is scheduled within two weeks.

Key Features
- Public black-box and gray-box starting prices.
- One, three, or unlimited retest rounds based on service type.
- Full-time manual testing team with SaaS specialization.
- Initial report and executive summary within 48 to 72 hours after testing.
- Portal, Slack communication, ticketing integration, and compliance mapping.
Pros
- Publishes exact starting prices and included retest counts for its core service models.
- Provides deep gray-box testing for SaaS roles, workflows, and tenant boundaries.
- Gives product teams a defined post-test report and retest schedule.
- Offers code review, AI, IoT, and hardware testing beyond the normal SaaS scope.
Limitations
- The normal three-to-six-week scheduling lead time may not suit a near-term audit deadline.
- A standard post-test letter of attestation is not described in current public materials.
- Public materials conflict on whether retesting remains available for six months or 12 months.
- The application-led model may not suit a large global infrastructure program.
Pricing
Software Secured publishes two common starting prices. The scope, number of roles, architecture, lines of code, integrations, and testing cadence determine the final quote.
| Service | Starting Price | Included Retesting |
|---|---|---|
| Black-Box Penetration Test | $5,400 | 1 round |
| Gray-Box Penetration Test | $10,800 | 3 rounds |
| PTaaS | Custom | Unlimited during the service |
Software Secured for SaaS Teams That Want Published Retest Counts
Software Secured provides an unusually measurable application-testing purchase. Buyers can compare starting price, service depth, report timing, and retest allowance before procurement. A post-test attestation letter should be added to the contract when an auditor or customer requires one.
6. Cobalt: Release-Driven SaaS and Mid-Market Companies
Cobalt delivers human-led penetration testing through a PTaaS platform and a vetted community of more than 500 Cobalt Core pentesters. The company reports more than 5,000 tests each year and uses 13 years of exploit data to support human-led and autonomous testing products.
Cobalt is designed for teams that need tests to start quickly, findings to reach engineering tools during fieldwork, and fixes to receive repeated validation throughout an annual contract.
| Attribute | Details |
|---|---|
| Headquarters | Boston, Massachusetts, with an Oxford office in the United Kingdom |
| Founded | 2013 |
| Founder or CEO | CEO Sonali Shah; founders include Christian Hansen, Jakob Storm, Esben Friis Jensen, and Jacob Hansen |
| Testing Coverage | Web, mobile, desktop, API, network, cloud, AI, and LLM systems |
| Delivery Model | Vetted Cobalt Core tester community through a PTaaS platform |
| Methodology Standards | OWASP ASVS, OWASP Web Security Testing Guide, OWASP Top 10, and OSSTMM for network testing |
| Retesting | Unlimited on-demand retesting during the contract term, with a seven-day service target |
| Attestation Letter | Full report, customer letter, and attestation templates available |
| Compliance Support | SOC 2, PCI DSS, ISO 27001, HIPAA, and customer reviews |
| Accreditations | CREST-certified services; ISO 27001 and SOC 2 Type II corporate assurance |
| Pricing | Annual Cobalt Credit packages; one credit equals eight testing hours |
| Website | cobalt.io |
Best For
Cobalt is best for release-driven SaaS and mid-market companies that need several tests each year and want unlimited retesting, fast launch, direct tester access, and development-tool integrations.
Penetration Testing Services
Cobalt tests applications, APIs, networks, cloud environments, mobile apps, desktop apps, and AI systems. Findings appear in the platform during testing and can move directly into Jira, GitHub, ServiceNow, or other engineering workflows.
Human-led testing can begin within 24 hours for suitable scopes. A standard broad assessment commonly uses a seven-day or 14-day format, depending on the delivery option. Annual packages include platform access, expert validation, reporting, and unlimited retesting throughout the contract term.

Key Features
- More than 500 vetted Cobalt Core pentesters.
- Unlimited retesting with a seven-day service target.
- Launch within 24 hours for qualified scopes.
- Real-time findings, tester communication, and more than 50 integrations.
- Full report, customer letter, and attestation output options.
Pros
- Operates one of the largest vetted pentester communities and completes more than 5,000 tests each year.
- Gives release-driven teams unlimited retesting during the active contract.
- Can begin testing quickly and publish findings before the final report.
- Provides several external-facing report formats for audit and customer review.
Limitations
- Annual credits do not roll into the next contract year.
- Pricing depends on credit volume and platform terms, so a one-time buyer cannot compare a fixed price online.
- The tester community model may not satisfy procurement rules that require only permanent employees.
- Smaller companies may purchase more platform capacity than one annual test needs.
Pricing
Cobalt sells annual credit packages. One Cobalt Credit represents eight testing hours, and credits cover platform access, test orchestration, expert validation, reporting, and retesting. Unused credits expire at the end of the contract year.
Cobalt for Release-Driven Teams That Need Unlimited Retesting
Cobalt makes sense when several product releases require testing and remediation must move through existing engineering tools. A company seeking one narrow annual test should compare the annual credit commitment with a project-based provider.
7. Packetlabs: Mid-Market and Regulated Companies
Packetlabs is an independent penetration testing company founded in 2011 by Richard Rogerson and headquartered in Toronto. The company states that its penetration tests are 95% manual and that every tester holds OSCP at minimum, with advanced credentials across the team.
Packetlabs focuses on human-led evidence and business impact across applications, networks, cloud, identity, red team, and continuous testing programs.
| Attribute | Details |
|---|---|
| Headquarters | Toronto, Ontario, Canada |
| Founded | 2011 |
| Founder or CEO | Founder Richard Rogerson |
| Testing Coverage | Applications, infrastructure, cloud, identity, red team, social engineering, and continuous testing |
| Delivery Model | In-house, 95% manual testing with targeted automation |
| Methodology Standards | NIST SP 800-115, SANS guidance, MITRE ATT&CK, and OWASP testing guidance where applicable |
| Retesting | Included; timing and finding coverage are set in the engagement terms |
| Attestation Letter | Available after testing; buyers should request it as a named deliverable |
| Compliance Support | SOC 2, PCI DSS, ISO 27001, customer reviews, and regulated-sector programs |
| Accreditations | CREST-accredited and SOC 2 Type II attested; OSCP-minimum testers |
| Pricing | Custom quote |
| Website | packetlabs.net |
Best For
Packetlabs is best for mid-market and regulated organizations that value an in-house testing team, senior hands-on credentials, manual depth, and independent technical advice.
Penetration Testing Services
Packetlabs tests networks, applications, cloud systems, identities, and security controls with a manual-led approach. The company uses targeted automation for coverage, then develops exploit paths and business-impact findings through hands-on analysis.
Retesting is included in the service, while the exact timing and eligible findings are defined in the engagement. A letter of attestation can confirm the test, high-level scope, and outcome without exposing the technical report. The public site does not state a universal fieldwork-to-report timeline.

Key Features
- 95% manual testing across the core service portfolio.
- OSCP as the minimum stated tester credential.
- CREST accreditation and SOC 2 Type II company assurance.
- Included retesting and auditor-facing evidence.
- Independent consulting model without a testing software quota.
Pros
- Every tester holds OSCP at minimum, which is the clearest personnel standard in this ranking.
- Uses a 95% manual model for attack-path and business-impact analysis.
- Provides included retesting and supports letters of attestation.
- Operates independently from security product sales.
Limitations
- Pricing is not published before scoping.
- The retest window and eligible finding set depend on the signed engagement.
- The attestation letter is not described as an automatic deliverable for every package.
- A universal kickoff-to-report timeline is not published.
Pricing
Packetlabs provides custom quotes based on asset count, access level, application complexity, cloud or identity scope, objectives, and schedule. Published company guidance places many engagements in a wide market range, so buyers need a written scope to compare quotes fairly.
Packetlabs for Buyers Who Prioritize Manual Depth and Tester Credentials
Packetlabs is a strong choice when tester seniority and manual attack-path analysis outweigh fixed online pricing. The contract should name the retest period and letter of attestation so the final evidence package matches the SOC 2 audit plan.
8. NetSPI: Large Enterprises and Multi-Asset Programs
NetSPI is a Minneapolis offensive security company founded in 2001 and led by president and CEO Aaron Shilts. It provides more than 50 penetration testing services through a platform supported by more than 350 in-house security experts.
The service is built for organizations that need repeatable testing, centralized findings, workflow integrations, and program reporting across many applications, APIs, networks, cloud environments, hardware systems, or AI assets.
| Attribute | Details |
|---|---|
| Headquarters | Minneapolis, Minnesota |
| Founded | 2001 |
| Founder or CEO | President and CEO Aaron Shilts |
| Testing Coverage | Applications, APIs, networks, cloud, mobile, hardware, mainframes, AI, and red team services |
| Delivery Model | Human-led PTaaS with more than 350 in-house security experts |
| Methodology Standards | NIST SP 800-115, OSSTMM, OWASP testing guidance, and PTES |
| Retesting | Included as part of every current engagement |
| Attestation Letter | No public standard letter policy; customizable compliance deliverables are available |
| Compliance Support | SOC 2, PCI DSS, ISO 27001, HIPAA, DORA, and other enterprise programs |
| Accreditations | Tester credentials include OSCP, OSCE, GPEN, GXPN, GWAPT, CISSP, and CREST qualifications |
| Pricing | Custom quote |
| Website | netspi.com |
Best For
NetSPI is best for large SaaS companies, financial institutions, healthcare organizations, and enterprises that need recurring tests across many technologies and business units.
Penetration Testing Services
NetSPI performs application, API, mobile, network, cloud, hardware, mainframe, AI, and specialized system testing. Manual analysis validates business logic, privilege paths, exploitability, and connected weaknesses, while the platform records findings, evidence, remediation status, and trends.
The current service states that retesting is included with every engagement. Findings arrive during testing, which gives internal teams more time to begin remediation. NetSPI does not publish a standard kickoff-to-report range or a standard one-page attestation-letter policy.

Key Features
- More than 350 in-house security experts across more than 50 services.
- Included retesting under the current service model.
- Real-time findings, remediation tracking, and enterprise reporting.
- More than 1,000 workflow integrations across the broader platform ecosystem.
- Point-in-time and recurring testing programs.
Pros
- Combines the largest named in-house testing team in this ranking with more than 50 service types.
- Includes retesting in every current engagement.
- Handles uncommon targets such as mainframes, hardware, and AI systems.
- Centralizes evidence and trends for large multi-business programs.
Limitations
- Fixed pricing and a standard report timeline are not public.
- A standard letter of attestation is not listed as a default deliverable.
- The enterprise platform can create unnecessary procurement and operating overhead for one small test.
- Legacy contracts may use terms that differ from the current included-retest policy.
Pricing
NetSPI prices projects according to asset count, technology, authenticated roles, cloud accounts, depth, reporting needs, frequency, and program scale. The provider does not publish a fixed SOC 2 penetration testing package.
NetSPI for Enterprise Testing Across Many Applications and Environments
NetSPI is most useful when a security team needs one testing system across a broad portfolio. Smaller buyers should compare the platform and procurement overhead with a project-based provider that publishes a fixed starting price.
9. Bishop Fox: Complex Enterprise Environments
Bishop Fox is an offensive security firm founded in 2005 by Vincent Liu and Francis Brown. Vincent Liu remains CEO and co-founder, while Francis Brown is co-founder and a board member. The company has more than 225 security professionals and focuses on technically deep offensive assessments.
Its service range covers applications, APIs, networks, cloud systems, mobile apps, hardware, AI, red teams, and continuous exposure management.
| Attribute | Details |
|---|---|
| Headquarters | Tempe, Arizona |
| Founded | 2005 |
| Founder or CEO | CEO and co-founder Vincent Liu; co-founder and board member Francis Brown |
| Testing Coverage | Applications, APIs, networks, cloud, mobile, hardware, AI, and red team services |
| Delivery Model | Expert-led offensive security consulting supported by automation and original tooling |
| Methodology Standards | Pre-assessment, reconnaissance, manual validation, exploitation, analysis, reporting, OWASP guidance, and framework-specific standards |
| Retesting | Available as an optional service; not listed as an automatic included benefit |
| Attestation Letter | No public standard one-page letter policy |
| Compliance Support | SOC 2, PCI DSS, ISO 27001, NIST, CMMC, HIPAA, GDPR, and DORA |
| Accreditations | CREST-accredited service provider; ISO 27001 and SOC 2 Type II company assurance |
| Pricing | Custom quote |
| Website | bishopfox.com |
Best For
Bishop Fox is best for large SaaS companies, technology providers, financial institutions, and regulated enterprises that need deep application, cloud, hardware, or attack-path analysis.
Penetration Testing Services
Bishop Fox combines automated reconnaissance with manual validation and exploitation. Application testing covers implementation flaws, business logic, access control, privileged functions, sensitive data, and underlying infrastructure. Cloud testing can examine identities, trust relationships, service roles, workloads, Kubernetes, and cross-account paths.
A typical application engagement can require one to two weeks for scoping and preparation, one to three weeks for fieldwork, and one to two weeks for reporting and remediation support. Retesting is available, but public materials do not list it as an automatic included benefit. The firm publishes original cloud and offensive tools such as CloudFox and Sliver.

Key Features
- More than 20 years of offensive security work.
- Manual business-logic and attack-path exploitation.
- Application, cloud, network, hardware, mobile, and AI testing.
- Original offensive security tooling and research.
- Technical and executive reporting with remediation support.
Pros
- Develops original offensive tooling that its consultants use to study modern attack paths.
- Provides deep manual testing across uncommon enterprise technologies.
- Publishes clear methodology phases for application and network assessments.
- Supports complex cloud identity, Kubernetes, and cross-account objectives.
Limitations
- The full application testing cycle can span about three to seven weeks.
- Retesting is optional and should appear as a priced line item in the statement of work.
- A standard letter of attestation is not described in public service materials.
- The offensive-security focus does not replace full SOC 2 readiness or audit management.
Pricing
Bishop Fox provides custom quotes based on target count, technology, user roles, cloud architecture, testing objectives, fieldwork length, reporting, and remediation support. Baseline, Standard, and Advanced application service levels are described publicly, but prices are not.
Bishop Fox for Deep Enterprise Application and Cloud Testing
Bishop Fox suits an enterprise that wants technical depth beyond basic audit evidence. A buyer focused on SOC 2 should add retesting and a shareable completion letter to the contract when those deliverables are required.
10. Coalfire: Regulated Enterprise Programs
Coalfire is a Chicago cybersecurity, compliance, and assessment company founded in 2001. Brad Little became CEO on January 6, 2026. Its DivisionHex practice, launched in August 2025, provides threat-informed penetration testing, red teaming, social engineering, exposure management, and related offensive services.
Coalfire serves regulated enterprises that want technical testing connected to a wider program covering SOC 2, FedRAMP, PCI DSS, HIPAA, ISO, HITRUST, and other frameworks.
| Attribute | Details |
|---|---|
| Headquarters | Chicago, Illinois |
| Founded | 2001 |
| Founder or CEO | CEO Brad Little |
| Testing Coverage | Web, API, network, cloud, mobile, wireless, IoT, hardware, AI, red team, and social engineering |
| Delivery Model | Custom projects and recurring DivisionHex OnDemand programs |
| Methodology Standards | Threat-informed human testing using attacker tactics, recognized framework requirements, and manual exploit validation |
| Retesting | Defined per project or OnDemand program |
| Attestation Letter | Defined per project |
| Compliance Support | SOC 2, PCI DSS, HIPAA, FedRAMP, ISO, HITRUST, and government programs |
| Accreditations | FedRAMP 3PAO, PCI assessment credentials, HITRUST assessor capabilities, and a licensed CPA affiliate |
| Pricing | Custom quote |
| Website | coalfire.com |
Best For
Coalfire is best for large SaaS providers, cloud companies, government contractors, financial institutions, healthcare organizations, and other regulated enterprises that need offensive testing connected to several formal assessment programs.
Penetration Testing Services
DivisionHex combines automated reconnaissance with human exploitation to determine which weaknesses produce practical attack paths. Testing can cover applications, APIs, cloud systems, networks, wireless infrastructure, mobile apps, connected devices, AI systems, and human targets.
Coalfire reports research based on more than 11,000 penetration tests, nearly 500,000 testing hours, and about 20,000 findings. The corporate group can connect security testing with readiness and assessment services, but independence rules can restrict the advisory and audit work delivered to the same client.

Key Features
- DivisionHex threat-informed offensive security practice.
- Broad technical coverage across regulated and government environments.
- Custom projects and recurring OnDemand programs.
- Large internal research base from prior penetration tests.
- SOC 2 readiness and examination capabilities within the corporate group.
Pros
- Combines a dedicated offensive division with one of the broadest compliance assessment portfolios in the market.
- Supports FedRAMP, PCI DSS, HITRUST, SOC 2, and other regulated programs.
- Uses a large historical test dataset to inform priorities and reporting.
- Can coordinate several security and assurance workstreams under one corporate group.
Limitations
- Pricing, standard retest terms, attestation-letter terms, and turnaround are not published.
- Auditor independence can limit the advisory and examination services provided to one client.
- The enterprise service model can exceed the needs of a startup seeking one annual test.
- Buyers need a detailed statement of work to compare DivisionHex with a fixed-scope provider.
Pricing
Coalfire provides custom pricing based on targets, compliance requirements, testing objectives, reporting, frequency, and service mix. DivisionHex OnDemand can consolidate several offensive services under one contract for organizations with recurring needs.
Coalfire for Regulated Enterprises With Multi-Framework Assessment Needs
Coalfire is most useful when the penetration test forms one part of a large assurance program. The buyer must structure advisory and CPA examination work carefully and place retesting, attestation, and report timing in the written scope.
How We Evaluated These Providers
Each company was evaluated against the same seven purchasing criteria. The ranking gives greater weight to evidence that a SOC 2 auditor or enterprise customer can use, followed by fit for the stated company size.
1. Manual Testing Depth: The service must include human validation of exploitability, access control, business logic, and attack paths. Scanner output alone does not qualify.
2. Reporting Quality: The deliverable must serve technical teams and nontechnical reviewers through clear scope, evidence, risk ratings, business impact, and an executive summary.
3. Remediation Guidance: Findings must include practical corrective actions, affected assets, reproduction details, and enough context for engineering teams to act.
4. Retesting: The evaluation records the published number of retest rounds, the available window, and whether the work is included or billed separately.
5. Attestation Letters: The evaluation states whether the provider supplies a shareable letter that confirms the test scope, dates, provider, and high-level outcome.
6. Compliance Experience: The review considers SOC 2 reporting needs, recognized testing standards, company assurance, and experience with regulated environments.
7. Business Size Suitability: Pricing, procurement effort, platform overhead, scheduling, scope flexibility, and enterprise scale determine the most practical buyer profile.
How to Choose a SOC 2 Penetration Testing Company
Choose a SOC 2 penetration testing company based on auditor acceptance, technical scope, tester experience, report quality, remediation support, and retesting terms. The selected provider needs to test the systems inside the SOC 2 boundary and produce evidence that security teams, company leadership, and the independent CPA firm can use.
SOC 2 examines controls related to security, availability, processing integrity, confidentiality, and privacy. The AICPA Trust Services Criteria use an outcome-based structure, which gives companies flexibility in how they test and document their security controls. A penetration test can provide evidence that vulnerability management and technical security controls operate as described.
1. Confirm What the Auditor Expects From the Penetration Test
Confirm the auditor’s evidence expectations before requesting proposals from penetration testing companies. The audit firm may want a recent report, proof of remediation, defined testing dates, or evidence that critical findings were resolved.
Request the following details from the CPA firm:
- Acceptable report age
- Required systems and applications
- Expected testing period
- Required remediation evidence
- Treatment of open findings
- Retest expectations
- Report confidentiality requirements
A SOC 2 examination evaluates whether controls are suitably designed and, for a Type 2 report, whether they operated effectively during the review period. The penetration test needs to support the controls and system description used in that examination.
Share the auditor’s response with each provider. This step keeps proposals focused on the evidence required for the examination.
2. Match the Test Scope to the SOC 2 System Boundary
Map every in-scope application, API, network, cloud environment, and supporting system before selecting a provider. A penetration test provides limited audit value when important components inside the SOC 2 boundary remain outside the testing scope.
Start with the system description prepared for the SOC 2 examination. Review the infrastructure, software, people, procedures, and data that support the covered service. Translate those components into specific penetration testing targets.
The scope may include:
- Public web applications
- Customer and administrative portals
- External IP addresses
- Internal networks
- APIs and integration endpoints
- Cloud accounts and services
- Authentication systems
- Supporting databases
- Employee access paths
- Segmentation controls
An application-focused company may need web application and API testing. A managed service provider may require network penetration testing across external and internal systems, plus cloud and Active Directory coverage. A SaaS company with several production environments may need separate coverage for each environment.
Bright Defense tests web applications, APIs, and networks. Our scoping process defines endpoints, user roles, testing hours, and technical boundaries before the engagement begins.
3. Verify the Experience of the Assigned Testers
Verify the credentials and relevant experience of the testers assigned to the engagement. Company-level credentials do not reveal who will conduct the test or review the final report.
Request the lead tester’s name, role, certifications, and hands-on experience. The technical background needs to match the environment under review. Web applications, cloud services, APIs, internal networks, and mobile applications represent different types of penetration testing and require different testing knowledge.
Relevant credentials may include:
- OSCP or OSCP+
- GPEN
- GWAPT
- CREST penetration testing certifications
- Cloud security certifications
- Vendor-specific technical certifications
Practical project history carries equal weight. Request examples involving a similar technology stack, business model, and attack surface. A provider testing a multi-tenant SaaS application needs experience with tenant isolation, authorization controls, business logic, APIs, and cloud permissions.
Confirm who performs the final quality review. The reviewer needs enough experience to challenge severity ratings, reproduction steps, technical conclusions, and remediation guidance.
4. Examine the Manual Testing Method
Examine how the provider validates vulnerabilities through manual testing and controlled exploitation. Automated tools can locate known weaknesses and common configuration errors. Human testing determines exploitability, business impact, and the attack paths that connect several findings.
A suitable methodology may reference NIST SP 800-115, the OWASP Web Security Testing Guide, PTES, or another recognized technical framework. NIST SP 800-115 covers planning, test execution, findings analysis, and mitigation. The OWASP Web Security Testing Guide provides structured testing coverage for web applications and web services.
Review how the company tests areas such as:
- Authentication
- Authorization
- Session management
- Business logic
- Privilege escalation
- API access controls
- Cloud permissions
- Credential exposure
- Network segmentation
- Lateral movement
The methodology needs to account for authenticated and unauthenticated access. Testing several user roles can reveal authorization failures that remain hidden during a public-facing scan.
Bright Defense combines automated reconnaissance with human-led testing, controlled exploitation, authentication checks, API testing, and technology stack review.
5. Review the Rules of Engagement and Data Handling Terms
Review the rules of engagement before granting the testing company access to production systems. The document defines testing authority, permitted actions, operating limits, communication procedures, and stop conditions.
NIST defines rules of engagement as the detailed guidelines and constraints set before a security test. These rules give the testing team authority to perform specific activities within an approved boundary.
The agreement needs to cover:
- Approved targets
- Testing dates and hours
- Production restrictions
- Prohibited techniques
- Social engineering permissions
- Denial-of-service restrictions
- Emergency contacts
- Critical-finding notifications
- Data storage locations
- Report encryption
- Tester access controls
- Evidence retention and deletion
- Stop conditions
Review the provider’s handling of credentials, screenshots, source code, customer records, and vulnerability evidence. Confirm how long it retains sensitive data and how it deletes that data after the engagement.
SOC 2 penetration tests often involve systems that process confidential customer information. Data handling terms need to reflect the sensitivity of the environment.
6. Evaluate a Redacted Sample Report Before Selecting a Company
Evaluate a redacted sample report before selecting a SOC 2 penetration testing company. The sample reveals whether the provider can communicate technical risk and produce usable audit evidence.
The report needs to serve three audiences. Executives need a clear summary of business risk. Engineers need reproduction steps and correction guidance. Auditors need evidence showing the scope, test dates, methodology, findings, and remediation status.
Review the sample for:
- Executive summary
- Defined scope
- Testing dates
- Methodology
- Severity model
- Affected assets
- Technical evidence
- Reproduction steps
- Business impact
- Remediation instructions
- Retest status
- Testing limitations
Check whether the report separates confirmed vulnerabilities from informational observations. Severity ratings need to reflect exploitability, affected data, required access, and potential business impact.
Bright Defense provides prioritized, audit-ready reports with remediation guidance and retest support. Our penetration testing service is designed to support SOC 2, ISO 27001, PCI DSS, and CMMC review processes.
7. Compare the Full Scope, Timeline, and Cost
Compare total testing coverage before reviewing the final price. Provider quotes can differ in testing hours, targets, user roles, remediation assistance, and retest coverage, so penetration testing pricing varies widely for the same nominal scope.
Use the following table to compare proposals on the same terms:
| Comparison Criteria | Provider A | Provider B | Provider C |
| Total testing hours | |||
| Web applications covered | |||
| API endpoints covered | |||
| External and internal networks | |||
| Cloud environments | |||
| User roles and account types | |||
| Manual testing activities | |||
| Report delivery date | |||
| Remediation support | |||
| Included retests | |||
| Scope-change fees |
Confirm when testing can begin and when the final report will arrive. Leave enough time for remediation, retesting, internal review, and auditor submission. A report delivered near the end of fieldwork can leave little time to close findings.
Bright Defense publishes fixed-scope penetration testing plans with 48, 96, or 176 testing hours. The plans define coverage limits for web endpoints, API endpoints, pages, modules, and user roles. Remediation guidance and retest support are included.
The right SOC 2 penetration testing company will understand the audit context, cover the complete technical boundary, assign qualified testers, document confirmed findings, and verify corrective actions. Select the provider whose proposal gives the clearest connection between technical testing and the controls presented during the SOC 2 examination.
Frequently Asked Questions About SOC 2 Penetration Testing
Does SOC 2 Require a Penetration Test?
SOC 2 does not explicitly require a penetration test. The AICPA Trust Services Criteria define control outcomes and do not prescribe that specific test. Auditors and enterprise customers frequently request recent SOC 2 penetration testing as evidence for monitoring, vulnerability management, risk evaluation, and corrective-action controls.
How Much Does a SOC 2 Penetration Test Cost?
A focused SOC 2 penetration test can start near $2,750 to $6,000 for a limited application or perimeter scope. Authenticated applications, several user roles, APIs, cloud accounts, internal networks, or enterprise reporting can move the price into the five-figure range. A valid comparison must include retesting, remediation support, report formats, and attestation documentation.
How Often Is a SOC 2 Penetration Test Needed?
Most organizations perform penetration testing at least annually and after a major architectural, application, infrastructure, or access-control change. The cadence should match the risk assessment, audit period, customer contracts, release frequency, and the rate at which the in-scope environment changes.
What Is a Penetration Testing Attestation Letter?
A penetration testing attestation letter is a short provider-issued document that confirms the tester, client, scope, dates, test type, and high-level result. It lets an organization answer auditor, customer, or procurement requests without sharing the sensitive technical report. The letter does not replace the full report or a SOC 2 report issued by a CPA firm.
What Is the Difference Between a Vulnerability Scan and a Penetration Test?
A vulnerability scan uses automated tools to locate known weaknesses and configuration issues. A penetration test adds human analysis, manual exploit validation, business-logic testing, attack-path development, impact assessment, and a report based on confirmed risk. A scan supports a testing program at a shallower depth, and the difference between a pen test and a vulnerability scan determines which evidence an auditor accepts.
How Long Does SOC 2 Penetration Testing Take?
A small engagement can require several testing days, while an authenticated application, internal network, or multi-cloud scope can require several weeks. Scheduling and access preparation may add time before fieldwork. The final report commonly follows fieldwork within several business days, while remediation and retesting extend the full evidence cycle.
Can the Penetration Testing Vendor Perform the SOC 2 Audit?
The SOC 2 examination must be performed by a licensed CPA firm. A provider group can offer penetration testing and CPA audit services through separate legal entities, but the work must follow professional independence rules. The buyer should document which entity performs each service and how conflicts are controlled.
Plan a SOC 2 Penetration Test With Clear Deliverables
A SOC 2 penetration test should end with confirmed findings, practical remediation work, retest evidence, and a document that external reviewers can use. Bright Defense publishes fixed-scope plans and can connect the technical assessment to the surrounding compliance program.
| Start With a Defined Scope and Published PlanReview the applications, APIs, networks, cloud systems, roles, audit period, report formats, retest terms, and attestation needs before fieldwork begins.Penetration Testing Services |
|---|
Scope drives provider fit more than any other factor. Organizations whose SOC 2 boundary sits largely in AWS, Azure, or Google Cloud should compare cloud penetration testing providers alongside the firms above, since identity permissions, storage exposure, and privilege-escalation paths need testers who work in those environments daily.
Related Bright Defense Resources


