SOC 2 vulnerability scanning
requirements
Meet AICPA Trust Services Criteria for vulnerability identification, monitoring, and remediation with continuous hosted network and application scanning - auditor-ready reports from $25/month.
AICPA Trust Services Criteria (CC7)
SOC 2 vulnerability management maps to AICPA Trust Services Criteria around how you identify weaknesses, monitor systems, and remediate findings.
| Criterion | Auditor expectation | Panoptic Scans evidence |
|---|---|---|
| CC7.1 | Identify vulnerabilities on systems in scope | External/internal OpenVAS, ZAP DAST, Nuclei, Nmap with asset scope and timestamps |
| CC7.2 | Detect and monitor security events and anomalies | Scheduled continuous scans and historical scan logs |
| CC7.3 | Evaluate and remediate identified vulnerabilities | Findings with severity, remediation guidance, and tracking in the dashboard |
Industry Recognized Scanner
OpenVAS Vulnerability Scanner
Produce detailed findings reports that show what systems are online, what ports are exposed, and whether services are vulnerable. Run external scans from the cloud, or scan internal networks on the Pro plan using our self-hosted OpenVAS script with results uploaded to Panoptic Scans for centralized reporting.
Continuous Vulnerability Management
Schedule, Track, Prove
SOC 2 Type 2 programs need operating evidence over time - not a one-off PDF. Schedule recurring scans, retain historical results, track remediation, and optionally auto-upload evidence to Vanta.
Scanning vs Penetration Testing
Complementary Controls
Automated vulnerability scanning provides continuous or periodic evidence for CC7. Penetration testing is a human-led, point-in-time assessment. Use Panoptic Scans for ongoing identification and monitoring; keep periodic pentests where your policy or customers require them.
Scanning AWS and SaaS environments
For internet-facing AWS assets (public EC2 IPs, load balancers, domains), Panoptic Scans provides perimeter vulnerability and DAST coverage with SOC 2-ready exports. AWS Inspector focuses on AWS-account and agent-centric workloads. Many teams use both: Inspector inside the account, Panoptic Scans for external attack surface and application scanning. See our AWS Inspector alternative comparison.
Frequently asked questions
What are SOC 2 vulnerability scanning requirements?
Under the AICPA Trust Services Criteria, SOC 2 programs expect organizations to identify, monitor, and remediate vulnerabilities (CC7.1–CC7.3). Auditors typically want timestamped scan reports with clear asset scope, severity ratings, and evidence that findings are tracked over time.
Is vulnerability scanning the same as penetration testing for SOC 2?
No. Vulnerability scanning is automated, repeatable evidence for ongoing identification and monitoring. Penetration testing is a point-in-time human assessment. Panoptic Scans supports continuous scanning evidence and complements - but does not replace - periodic penetration tests.
How often should we scan for SOC 2 Type 1 vs Type 2?
Type 1 focuses on design at a point in time; Type 2 evaluates operating effectiveness over a period. Many Type 2 programs run quarterly external scans, and some teams scan monthly. Panoptic Scans supports scheduled and on-demand scans with a historical evidence trail.
Do we need internal and external vulnerability scans for SOC 2?
Auditors often expect coverage of internet-facing systems and, where in scope, internal infrastructure. External scans are available on all plans. Internal OpenVAS scanning is available on the Pro plan via a self-hosted script with results uploaded to Panoptic.
How much does SOC 2 vulnerability scanning cost?
A free trial is available for one-off scans. Paid plans range from $25 to $200 per month depending on white-labeled reports and how many hosts you need to scan. Internal network scanning is available on the Pro plan.
Scan a URL, IP, or hostname
Enter a target and an email address. We'll send a findings report.