SOC 2 vulnerability scanning
requirements

Meet AICPA Trust Services Criteria for vulnerability identification, monitoring, and remediation with continuous hosted network and application scanning - auditor-ready reports from $25/month.

AICPA Trust Services Criteria (CC7)

SOC 2 vulnerability management maps to AICPA Trust Services Criteria around how you identify weaknesses, monitor systems, and remediate findings.

Criterion Auditor expectation Panoptic Scans evidence
CC7.1 Identify vulnerabilities on systems in scope External/internal OpenVAS, ZAP DAST, Nuclei, Nmap with asset scope and timestamps
CC7.2 Detect and monitor security events and anomalies Scheduled continuous scans and historical scan logs
CC7.3 Evaluate and remediate identified vulnerabilities Findings with severity, remediation guidance, and tracking in the dashboard
OpenVAS vulnerability scan report

Industry Recognized Scanner

OpenVAS Vulnerability Scanner

Produce detailed findings reports that show what systems are online, what ports are exposed, and whether services are vulnerable. Run external scans from the cloud, or scan internal networks on the Pro plan using our self-hosted OpenVAS script with results uploaded to Panoptic Scans for centralized reporting.

White labeled SOC 2 report

Continuous Vulnerability Management

Schedule, Track, Prove

SOC 2 Type 2 programs need operating evidence over time - not a one-off PDF. Schedule recurring scans, retain historical results, track remediation, and optionally auto-upload evidence to Vanta.

Attack narrative report

Scanning vs Penetration Testing

Complementary Controls

Automated vulnerability scanning provides continuous or periodic evidence for CC7. Penetration testing is a human-led, point-in-time assessment. Use Panoptic Scans for ongoing identification and monitoring; keep periodic pentests where your policy or customers require them.

Scanning AWS and SaaS environments

For internet-facing AWS assets (public EC2 IPs, load balancers, domains), Panoptic Scans provides perimeter vulnerability and DAST coverage with SOC 2-ready exports. AWS Inspector focuses on AWS-account and agent-centric workloads. Many teams use both: Inspector inside the account, Panoptic Scans for external attack surface and application scanning. See our AWS Inspector alternative comparison.

Vulnerability management remains a critical security operations activity that helps organizations identify assets, mitigate threats and meet compliance mandates.
Gartner Research

Frequently asked questions

What are SOC 2 vulnerability scanning requirements?

Under the AICPA Trust Services Criteria, SOC 2 programs expect organizations to identify, monitor, and remediate vulnerabilities (CC7.1–CC7.3). Auditors typically want timestamped scan reports with clear asset scope, severity ratings, and evidence that findings are tracked over time.

Is vulnerability scanning the same as penetration testing for SOC 2?

No. Vulnerability scanning is automated, repeatable evidence for ongoing identification and monitoring. Penetration testing is a point-in-time human assessment. Panoptic Scans supports continuous scanning evidence and complements - but does not replace - periodic penetration tests.

How often should we scan for SOC 2 Type 1 vs Type 2?

Type 1 focuses on design at a point in time; Type 2 evaluates operating effectiveness over a period. Many Type 2 programs run quarterly external scans, and some teams scan monthly. Panoptic Scans supports scheduled and on-demand scans with a historical evidence trail.

Do we need internal and external vulnerability scans for SOC 2?

Auditors often expect coverage of internet-facing systems and, where in scope, internal infrastructure. External scans are available on all plans. Internal OpenVAS scanning is available on the Pro plan via a self-hosted script with results uploaded to Panoptic.

How much does SOC 2 vulnerability scanning cost?

A free trial is available for one-off scans. Paid plans range from $25 to $200 per month depending on white-labeled reports and how many hosts you need to scan. Internal network scanning is available on the Pro plan.

Scan a URL, IP, or hostname

Enter a target and an email address. We'll send a findings report.