Can the test report be used for SOC 2?
Yes, if it is scoped for it. SOC 2 auditors generally expect an independent penetration test of the in-scope system, usually annually, plus evidence the findings were fixed. The report needs the dates, the scope matching your system description, independent testers, and retest results. A QA review alone will not satisfy that; the penetration test portion will.
What an auditor or buyer looks for
- Independence: the testers did not build the app.
- Scope that covers the product the report describes.
- Dates inside the audit period.
- Severity and remediation status for each finding.
- A retest confirming fixes.
Across frameworks
SOC 2 has no explicit pentest rule but CC7.1 and CC4.1 are commonly evidenced by one. ISO 27001:2022 expects security testing under Annex A controls such as 8.29. PCI DSS requires testing explicitly. Details on GetPentest's SOC 2 penetration testing page.
Sharing with customers
Share an executive summary or a summary letter, not the full report. See reading a report.
Scoping the test for audit use
Tell the testing firm up front that the report will be used as audit evidence, and name the framework. Ask that the scope statement match the system boundary in your SOC 2 system description or ISO 27001 scope, that the report state the testing dates, the methodology and the testers' independence, and that the retest be documented with dates. Keep the tickets showing how each finding was fixed: auditors sample remediation evidence, not just the report.
Time the test inside the audit period. A test completed the month before a Type 2 observation window starts may not count for that period. If you are in your first year, a test early in the window with the retest before it closes gives the auditor both the test and evidence that you acted on it.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Do I need SOC 2 for my AI app?
Only if customers ask. See do I need SOC 2.
Does the report expire?
Buyers usually accept one from the last 12 months.