Does SOC 2 require a penetration test?
The honest answer is no, and it does not help you much, because the reason people ask is usually a customer contract rather than the framework.
Research
Findings we can talk about publicly, the methodology behind them, and what each one means if you happen to run the software. Written by whoever did the work.
The honest answer is no, and it does not help you much, because the reason people ask is usually a customer contract rather than the framework.
Every vendor dodges this question. The reason is real, but you can still work out roughly what you should be paying, and spot a quote that is wrong.
In July we reported that the official fix for CVE-2026-41992 left the bug reachable. Upstream shipped a better one the same day. Here is what that says about trusting patches.
If nobody has confirmed the fix closes the path rather than the reproducer, that is worth an afternoon of somebody's time.