Vanta, Drata and Secureframe do not perform your penetration test — they automate evidence collection and flag the pentest as a required artifact for SOC 2 and ISO 27001. You engage a separate qualified provider, receive a dated third-party report covering your in-scope systems, and upload it so the platform maps it to the control. For a SOC 2 Type II audit the report must fall inside the observation window and critical/high findings should show remediation or a retest. Book the test 6–10 weeks before the window closes so there's time to fix and retest. The platform surfaces the gap; only a timely, real test closes it.
// 01 What these platforms do — and don't
Vanta, Drata and Secureframe are compliance-automation platforms. They connect to your cloud accounts, identity provider, code repos and HR tools, and continuously collect evidence that your controls are operating — MFA is on, access is reviewed, backups run. That automation is genuinely useful and it removes a huge amount of screenshot-gathering from audit prep. But there's one control category they cannot automate: the penetration test. A pentest is an active, human-led engagement against your systems. No agent or API integration performs it. What the platform does is recognise that the test is required, flag its absence as an evidence gap, and give you a slot to upload the report once you have it.
// 02 Why the pentest gap appears at all
Penetration testing isn't named as a single mandatory line item in SOC 2 — but in practice it's effectively required. It's the standard evidence for the risk-assessment and monitoring criteria, and auditors and enterprise customers ask for it by name. ISO 27001 drives technical vulnerability assessment through Annex A controls. So whichever platform you run, it encodes this expectation and shows the gap. If you've landed here because the dashboard went red, that's the platform doing its job — see do you need a pentest for SOC 2 for the fuller answer, but treat it as a yes.
// 03 What the platform needs from the report
Third-party & dated
A report from a qualified external provider, clearly dated so it maps to your audit period.
In-scope systems
Coverage of the applications and infrastructure inside your audit boundary, not a different asset.
Findings & status
Findings with severity and remediation status — criticals/highs closed or retested.
Within the window
For Type II, recent enough to sit inside the observation window.
You upload that report as an evidence artifact and link it to the control; the platform stores it and presents it to your auditor. What it can't do is judge whether the test was any good — a scan dressed up as a pentest uploads just as easily as a real engagement, and it's your auditor, not the tool, who may push back. Learning to read the report matters here.
// 04 Timing it to your audit window
This is where teams trip. A Type II audit observes controls over a window — commonly three to twelve months — and the pentest evidence should sit inside it. Worse, any critical or high finding that's still open at window-close is itself an audit problem. So the test can't be a last-week scramble. The practical rule: book six to ten weeks before the window closes, so there's room to remediate criticals and get a retest confirming closure. Map the sequence with how to prepare for a pentest. Uploading a report full of open criticals right at the deadline is the single most common avoidable finding.
// 05 Choosing the provider (marketplace or not)
Each platform has a partner marketplace of pentest vendors, which is convenient but not obligatory — you can bring your own provider. Choose on the same criteria you'd use anywhere: evidence of manual testing, a sample report your auditor will accept, relevant certifications, and clear data-handling terms. If you're a GCC organisation pursuing SOC 2 or ISO 27001 for enterprise customers, a provider who also understands your local obligations means one engagement can satisfy both the platform and your regional regulator. Use how to choose a provider as the checklist.
// 06 Frequently asked questions
Does Vanta, Drata or Secureframe run the pentest for me?
No. They automate evidence collection and control monitoring but do not perform the test. You engage a separate qualified provider, receive the report, and upload it as an evidence artifact that the platform maps to the SOC 2 or ISO 27001 control. Some have partner marketplaces, but the test is always a human-led third-party engagement.
Do you need a pentest for SOC 2?
SOC 2 doesn't name it as an explicit mandatory control, but almost every Type II audit expects one — it's the standard evidence for the risk and monitoring criteria, and auditors and customers ask for it. ISO 27001 similarly drives technical vulnerability assessment. Treat it as effectively required; the platform will flag the gap.
What does the platform need from the pentest?
A dated third-party report covering your in-scope systems, with findings and remediation status, recent enough to fall in the audit period. You upload it as an artifact linked to the control. For Type II the report must sit inside the observation window, and criticals/highs should show remediation or a retest.
When should I run it relative to my audit window?
Early enough to remediate and retest before the window closes — a practical rule is 6–10 weeks before window-end. Uploading a report full of open criticals right before the deadline is the most common avoidable finding.
// 07 Related reading
- Do you need a penetration test for SOC 2? — the requirement in full.
- We failed our SOC 2 audit — what next and how to prepare.
- Pentest requirements by framework and how to read the report.