Which platforms include a penetration test with SOC 2 compliance?
Almost none of them do. Vanta, Drata and Secureframe automate the compliance program and refer the penetration test to a partner firm, so the standard SOC 2 purchase is three separate vendors: a platform, a testing firm, and the CPA who signs the report. Only the last of those three has to stay separate.
That last sentence is the whole subject of this page. One of those three splits is a rule. The other is a business decision, and you are paying for it.
On this page: the three vendors · what each platform includes · why the test gets referred out · the line that cannot be bundled · when to buy separately · what auditors accept · the cost either way · how to evaluate an offer
The three vendors in a standard SOC 2 purchase
Nobody sells “a SOC 2”. You assemble one, usually from three parties who each run their own sales process.
| Vendor | What they sell | 2026 range | Contract |
|---|---|---|---|
| Compliance platform | Controls, evidence collection, monitoring, policies | $10,000 to $20,000 a year | Annual, per seat or per framework |
| Penetration testing firm | The test itself, and the report | $4,000 to $12,000 a test | Per engagement, scoped each time |
| Independent CPA firm | The attestation opinion | $7,000 to $50,000 | Per examination |
Only one of the three separations is a rule
The CPA is separate because an attestation engagement requires it. The pentest firm is separate because the platform vendor decided not to build one. Those are very different reasons, and conflating them is how the market talks buyers into treating a two-vendor overhead as though it were a compliance requirement. Our SOC 2 cost breakdown prices each line item on its own.
What each platform actually includes
This is the answer to the question in the title, laid out plainly.
| Vendor | SOC 2 program | Pentest included | Published price |
|---|---|---|---|
| Vanta | Yes, category leader | No, partner referral | No, quote only |
| Drata | Yes | No, partner referral | No, quote only |
| Secureframe | Yes | No, partner referral | No, quote only |
| XBOW | No | Testing is the product | No, per test |
| Horizon3.ai | No | Testing is the product | No, quote only |
| HackZero | Yes | Yes, every month | $299 / $499 a month |
You can verify this yourself in ten minutes
None of this requires taking our word for it. Drata publishes a service partner directory listing the firms that do the testing, and its own SOC 2 explainer describes a customer doing exactly what the model implies:
So, they chose to partner with one of Drata’s service partners to conduct an external penetration test during their SOC 2 observation period.
Vanta’s structure is the same, with a partner finder and a help-centre article explaining how test results get into the platform rather than how the platform produces them. Neither company hides it. It is simply not the thing most buyers check before signing.
Why the test gets referred out
A services business does not fit inside a software business
Penetration testing is delivered by people with certifications, and its cost scales with tester-days. Compliance automation is software, where the second customer costs almost nothing to serve. Bolting a services business onto a software business drags gross margin down and makes the whole company harder to value, so the rational move for a venture-scale platform is to refer the work and keep the software margin.
The referral is a margin decision, not a trick
Worth being fair about this. A referral network is a legitimate structure, the partner firms are usually good, and some of them discount for platform customers. What the structure costs you is not integrity. It is a second procurement cycle, a second scoping conversation, a second renewal to negotiate, and a report that arrives as a PDF you then have to file against the right criteria by hand.
The line that genuinely cannot be bundled
The attestation. Every serious version of this argument ends at the same sentence in the AICPA’s attestation standards:
An attestation engagement requires the practitioner to be independent of the responsible party.
The firm signing the opinion cannot also sell you the software it is opining on or fix the controls it is testing. That is why the SOC suite of services is built around a report rather than a certificate, and why no honest vendor sells an end-to-end SOC 2 with the audit inside it.
What “included” must never mean
If a vendor quotes one number covering the platform, the test and the audit, run the arithmetic before you get excited. At a $150 hourly rate, a $2,500 bundle covering both an examination and a penetration test buys roughly sixteen hours for the pair, which is how that tier produces templated no-exception reports. The 2026 audit-mill scandal, 533 near-identical reports across 455 companies, is why enterprise reviewers now read the methodology page before the findings.
So the defensible package is platform plus testing on one line, with the CPA paid directly by you. That is the structure we sell, and the direct payment is the point rather than an inconvenience.
When buying them separately is the right call
Against our own interest, because it is true often enough to say plainly:
- Your auditor or your customer named a firm. Some enterprise reviewers and some regulated buyers want a specific brand on the report cover. Argue if you like, but you will usually lose, and the deal is worth more than the principle.
- You need more than SOC 2. If you are carrying ISO 27001, HIPAA, PCI, GDPR and FedRAMP at once, framework breadth is the thing to optimise for and the incumbents are genuinely better at it. See which frameworks require a third-party test.
- The scope is not a web application. Internal network, Active Directory, hardware, physical and social engineering are different disciplines. A combined subscription scoped to apps and APIs will not cover them.
- You want a human-led engagement specifically. Continuous automated testing with human validation is a different product from four named testers for two weeks. We sell that separately at $2,999 per engagement rather than pretending the subscription is the same thing.
What auditors accept from a continuous test
Auditors judge evidence, not vendors. A report earns its place when it carries a documented methodology, findings validated as actually exploitable, reproduction steps, and a retest confirming the fix. Whether a human or a machine produced it is not the test.
Where continuous testing genuinely wins is the observation window. A Type 2 asks whether your controls operated across months, not on one day, so twelve signed monthly reports speak to that question in a way a single annual PDF cannot. Drata says the quiet part out loud on its own site:
Penetration tests are technically not a requirement for SOC 2 compliance.
Which is correct, and matches what we wrote in does SOC 2 require a penetration test. The test is demanded by your customers and expected by your auditor, not mandated by the criteria. That makes the question “what evidence satisfies them”, and the answer is exploit-validated findings on a cadence, filed against the right criteria.
What each route costs
| Three vendors | One subscription plus a CPA | |
|---|---|---|
| Platform | $10,000 to $20,000 a year | $2,990 or $4,990 a year |
| Penetration testing | $4,000 to $12,000 a test, once | Included, every month |
| Attestation | $7,000 to $50,000 | From $2,500, paid direct |
| Contracts to manage | Three | Two |
| Price you can check before a call | None of it | All of it |
Vanta and Drata publish no price list, so the platform band above comes from third-party procurement data rather than either vendor: Vendr’s buyer guides put observed Vanta contracts between $7,500 and $57,000 a year, median near $20,000. Our own numbers are on the pricing page and in our SOC 2 compliance guide, and the head-to-head detail is on HackZero vs Vanta and HackZero vs Drata.
How to evaluate a combined offer
Four questions, in the order that kills bad offers fastest.
- Who signs the attestation? If the answer is anyone connected to the platform, stop. Nothing else on the list matters.
- Who runs the test, employees or a referred partner? Both are acceptable. Only one of them is what “included” implies.
- What does the report contain? Reproduction steps and a proof that the exploit fired, or a scanner export with severity labels. These are not the same document and your customer’s security reviewer knows it.
- Is the retest included? A finding is not closed until someone re-runs it. If the retest is a new engagement, the annual number you were quoted is not the annual number you will pay.
A vendor that answers all four without a discovery call is unusual in this market, which is the actual reason we publish ours. If your situation is odd enough that the price list does not settle it, a 20-minute call will.
Frequently asked questions
Which platforms include a penetration test with SOC 2 compliance?
Very few. Vanta, Drata and Secureframe automate the compliance program and route the penetration test to a partner firm, so the test arrives on a separate contract and a separate invoice. Offensive-security vendors like XBOW and Horizon3.ai run the test but carry no controls, no evidence library and no monitoring. HackZero is the one that carries both in a single subscription at 299 dollars a month under ten people. In every case the CPA attestation stays separate, and it should.
Does Vanta include penetration testing?
No. Vanta automates the compliance program and points you at its partner network to buy the test, which is why a Vanta budget is really two budgets. That is a reasonable structure and it is not hidden, but it does mean the pentest is scoped, negotiated and scheduled by you, and the price is whatever the partner quotes. Third-party procurement data puts Vanta contracts themselves between 7,500 and 57,000 dollars a year before any test.
Can one vendor sell me the platform, the pentest and the audit together?
The first two, yes. The third, no, and you should walk away from anyone offering it. Attestation standards require the CPA signing the opinion to be independent of the party being examined, so a firm cannot audit controls it also built, operates or profits from. Bundling the platform with the testing is a packaging decision. Bundling the opinion in with them is the pattern behind the 2026 audit-mill reports that enterprise reviewers now reject on sight.
Will an auditor accept a continuous automated pentest instead of an annual one?
Auditors judge the evidence, not the vendor. What they test for is a documented methodology, findings validated as genuinely exploitable, reproduction steps, and a retest showing the fix landed. A monthly signed report that carries all four satisfies the CC4.1 and CC7.1 evidence expectations better than a once-a-year PDF, because a Type 2 asks whether controls operated across the whole window. An unvalidated scanner dump fails either way.
How can one subscription hold the controls and the pentest at 299 dollars a month?
Stack ownership. The attack agents, the exploitation toolchain and the reporting are all built in-house, so the marginal cost of a run is compute plus senior review instead of tester-weeks, and the day-rate arithmetic the pentest market prices on stops applying. AI does the continuous coverage no human team could afford every month, and hackers stay in the loop to confirm findings actually exploit and to write the report a reviewer will read. Because the same product holds the controls and the monitoring, evidence reaches the auditor pre-mapped rather than costing them billable hours to chase. The prices are published rather than quoted: 299 a month under ten people, 499 at ten or more, 2,990 or 4,990 paid annually, with the CPA attestation from 2,500 paid straight to the independent firm. The honest catch is that the subscription is AI-led with human validation, and a named human-led engagement is 2,999 per engagement on top.
What should I ask a vendor that claims the pentest is included?
Four questions. Who runs the test, and are they employees or a referred partner? Do you get a report with reproduction steps and a proof of exploitation, or a scanner export? Is a retest after the fix included or billed again? And who signs the attestation, because if the answer is anyone connected to the platform, the report is worth less than the money you saved.