SOC 2 Vendor Compare

Vendors · Security testing

Pen testing inside SOC 2 platforms: what Scytale and Thoropass describe

Short answer

Scytale and Thoropass both describe penetration testing as part of their platform. Scytale bundles a pen test into its Build DFY and Build Stronger plans; Thoropass lists pen testing, PCI ASV scans and vulnerability scanning. The other four vendors do not describe pen testing on the pages we reviewed.

By the SOC 2 Vendor Compare ledger desk · Published 2026-01-13 · Reviewed 2026-09-29 · Editorial assessment

Why does pen testing come up in a SOC 2 purchase?

SOC 2 does not prescribe a specific test, but many customers ask for a recent penetration test during security reviews, and many auditors look for evidence of vulnerability management. A company buying its first SOC 2 platform often needs a pen test in the same quarter, so buying both from one vendor is a real option.

What does Scytale describe?

Scytale's penetration testing page describes pen testing inside the platform: scoping with a pen test expert, reports, Jira tickets for findings and retests. Its homepage refers to AI-integrated offensive security. On its pricing page, the Build DFY bundle ('Done for you', labelled Most popular) combines the platform, LaunchReady Consulting and a web app black box pen test; Build Stronger combines the platform, StayReady Consulting and a gray box pen test. Prices are not published.

Source: Scytale penetration testing · read 2026-09-29

Source: Scytale pricing · read 2026-09-29

What does Thoropass describe?

Thoropass lists IT security audit, penetration testing, vulnerability scanning and compliance automation on its platform, and PCI DSS with certified ASV scans and pentesting among its frameworks. Because Thoropass also performs audits, a buyer can get the pen test, the automation and the audit from one company. Prices are not published.

Source: Thoropass homepage · read 2026-09-29

What about the other four vendors?

Vanta, Drata, Secureframe and Sprinto do not describe pen testing as part of their platform on the pages we reviewed. That does not mean their customers cannot get one; it means you should expect to buy it from a separate firm, and ask whether the platform can ingest the report and track findings.

What should you ask any pen test provider?

Ask what is in scope (web app, API, cloud, internal network), whether the test is black box or gray box, who performs it, how findings are tracked and whether a retest is included. Scytale's bundles name the test type, which makes that comparison easier. Ask for a sample report.

Does this change the scores?

Pen testing is not one of our seven criteria, so it does not change the totals. We mention it on the Scytale and Thoropass profiles because it affects what a buyer has to purchase elsewhere.

How do pen test findings feed the SOC 2 program?

Findings from a pen test become remediation tasks. When the test happens inside the compliance platform, as Scytale describes with Jira tickets and retests, the findings can sit next to the controls they relate to, and the retest result becomes evidence. When the test comes from a separate firm, you upload the report and track findings yourself or in your ticketing system. Either way, auditors and customers tend to ask what you did about the findings, not only whether a test happened.

Related

More posts