Skip to content
soc2pentest

A plain-English reference on SOC 2 for European vendors: who may issue the report, and what the penetration test is actually for.

Run the gap finder→
  • 01Who issues what
  • 02The pentest question
  • 03Gap finder
  • 04In Europe
  • 05Guides
Home

About soc2pentest.org

Updated 13 September 2026

soc2pentest.org covers SOC 2 as a European software or service company actually meets it: through a customer contract, on somebody else's calendar, and around a report the company is not permitted to issue for itself. Readers making procurement decisions deserve to know where guidance like this comes from, so it is set out here.

Publisher

The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a penetration testing and security consulting company. Contact: support@offseq.com.

What we are not

OffSeq is not a CPA firm, an accredited certification body or a registered audit firm. It cannot issue a SOC 1, SOC 2 or SOC 3 report, an ISAE 3000 or ISAE 3402 assurance report, or an ISO/IEC 27001 certificate. This site is not affiliated with, endorsed by or accredited by the AICPA, the IAASB or ISO. SOC 1, SOC 2 and SOC 3 are registered trademarks of the AICPA.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.

How the guidance is sourced

  • Statements about SOC reports are sourced to AICPA material or to the Journal of Accountancy, the AICPA's own publication, and quoted where the wording is the point.
  • Statements about the international assurance standards are sourced to the IAASB pronouncement itself.
  • Statements about EU law cite the instrument on EUR-Lex, article by article.
  • The trust services criteria are not reproduced here. They are published by the AICPA behind an account, and paraphrasing copyrighted criteria into quotation marks would be worse than describing them, so this site describes them and links to the source.
  • The tender figures on the home page are our own measurement against the public TED search API, with the query, corpus and date stated so anyone can repeat it.
  • The "Updated" date moves only when the text changes. An automated content-hash ledger reverts unearned bumps.

Commercial interest

We sell readiness work and the penetration test this site describes. That is a direct interest in you concluding that you need them, and it should color how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
  • No CPA firm, certification body, compliance platform or tool vendor pays for a mention. There is no advertising and no affiliate revenue.
  • Where the honest answer is that you do not need a SOC 2, or that ISO/IEC 27001 would serve your buyers better, the site says so. That answer costs us work and it is still the right one.
  • We do not receive a commission for referring you to a CPA firm.

Not advice

Nothing here is legal advice, and it is not a substitute for the judgment of the CPA firm that will perform your examination or the counsel who reviews your customer contracts. Scope, criteria selection and evidence sufficiency are decisions for you and your service auditor.

Corrections

Send corrections to support@offseq.com, ideally with the source. Substantive changes are made and re-dated in the open.

soc2pentest

soc2pentest.org is a free reference on SOC 2 for European vendors: what the report is, who is allowed to issue it, where the expectation of a penetration test really comes from, and how SOC 2 sits alongside ISO/IEC 27001 and the ISAE assurance standards.

Guides

  • Does SOC 2 require a pentest?
  • Who can issue a SOC 2
  • SOC 2 or ISO 27001
  • Scope, timing and the report

Professional help

  • Readiness and gap assessment
  • Penetration testing
  • Scope an engagement
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies and browser storage

soc2pentest.org is a free reference maintained by the OffSeq security team. OffSeq is not a CPA firm and does not perform SOC examinations or issue SOC reports.

SOC 1, SOC 2 and SOC 3 are registered trademarks of the AICPA. This site is not affiliated with, endorsed by or accredited by the AICPA, the IAASB or ISO.

Operated by SEQ SIA · Riga, Latvia