Best Penetration Testing for SOC 2
The best penetration testing for UK companies preparing SOC 2 evidence in 2026 comes from CREST-accredited providers who scope testing against the security Trust Services Criteria, cover both web application and API surface, include a retest for verified-fix evidence, and produce a report or summary that satisfies auditors and customer security questionnaires. This guide compares 7 providers: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof.
Seven penetration testing companies compared for UK companies preparing SOC 2 evidence, on the criteria that actually matter: coverage of the security Trust Services Criteria, verifiable CREST accreditation, a retest for verified-fix evidence, and reporting that stands up with an auditor and enterprise customers.
We are Precursor Security, and we have ranked ourselves first on this list.
Rather than pretend otherwise, we publish the selection criteria in full and describe every provider fairly, including where a rival is the better fit. One thing worth stating plainly: none of the firms below, including us, are your SOC 2 auditor. SOC 2 is an attestation performed by a licensed CPA firm; a penetration test is technical evidence that feeds it. Confirm any CREST claim in the independent CREST member directory.
Seven firms, side by side
| Provider | CREST status | Pricing published | From |
|---|---|---|---|
| 1. Precursor Security | Pen Test + VA + SOC | Yes | From £2,500 |
| 2. NCC Group | Member firm | No | On application |
| 3. Pen Test Partners | Member firm | No | On application |
| 4. Redscan (Kroll) | Member firm | No | On application |
| 5. JUMPSEC | Member firm + NCSC CHECK | No | On application |
| 6. OnSecurity | Member firm | No | Instant quote via platform |
| 7. Bulletproof | Member firm | No | On application |
Verified against each provider's public website, August 2026. "No" under pricing means a rate was not published at the time of writing, not that a provider is more expensive. Redscan is part of Kroll (US-headquartered).
The 7 best penetration testing
companies for SOC 2 in 2026
1. Precursor Security
Precursor holds triple CREST accreditation across Penetration Testing, Vulnerability Assessment, and Security Operations Centre. Testing is scoped against the security Trust Services Criteria SOC 2 auditors expect to see evidence of, covering web application and API surface together. Pricing starts from £2,500 at approximately £1,200 per consultant day, published on the website, with a retest included in every engagement so an auditor sees verified-fix evidence rather than a list of open findings. Ask about the report or summary format for your specific auditor and prospects before scoping starts, since that varies by provider.
Trade-off: A UK mid-market specialist rather than a global enterprise brand, and it delivers the penetration testing, not the SOC 2 audit itself: Precursor is not a CPA firm or a SOC 2 auditor and does not perform the attestation.
2. NCC Group
NCC Group is one of the largest security consultancies in the world, headquartered in Manchester, with a deep research pedigree and the capacity to staff very large assessment programmes across multiple products and regions. For a well-funded SaaS company running SOC 2 evidence collection across a global security programme, few firms match its bench depth.
Trade-off: Engagement model and pricing are built for enterprise procurement. Costs are on application.
3. Pen Test Partners
Pen Test Partners are the UK's best-known specialists in embedded and operational technology, and their public research is consistently cited. For a company whose product touches connected devices or unusual infrastructure rather than a standard web and API stack, they belong on the shortlist for that specific scope.
Trade-off: A specialist focus; standard web application and API testing is not their distinctive strength. Pricing on application.
4. Redscan (Kroll)
Redscan, now part of Kroll, pairs a large practitioner organisation with the backing of a global incident response and forensics business. For a company that wants its tester, its IR retainer, and its forensics provider under one roof at enterprise scale, the Kroll relationship is the draw.
Trade-off: Kroll is US-headquartered, and the engagement model leans enterprise. Pricing on application.
5. JUMPSEC
JUMPSEC holds NCSC CHECK status alongside CREST membership, with a strong red teaming and adversary-simulation practice. For a company whose customer base spans both enterprise SOC 2 buyers and public-sector or PSN-connected customers who mandate CHECK delivery, that combination is the differentiator.
Trade-off: Pricing on application.
6. OnSecurity
OnSecurity runs a platform-first, pentest-as-a-service model with instant online quoting and quick scheduling. For a company with a SOC 2 audit window closing and a test that needs booking this week, the platform model works well.
Trade-off: Quotes are generated through the platform rather than published as a rate card, and the model suits smaller, repeatable scopes.
7. Bulletproof
Bulletproof combines penetration testing with a broad compliance practice, including Cyber Essentials and PCI DSS support, which suits a smaller company building its first SOC 2 evidence trail alongside other certifications and wanting one supplier to handle both.
Trade-off: A generalist breadth play rather than a testing specialist. Pricing on application.
How we ranked them for SOC 2
Six criteria that matter specifically when a penetration test needs to feed a SOC 2 audit, each something you can verify without taking anyone's word for it. Weighting is ours; the facts are checkable.
Whether the provider scopes and reports against the security criterion SOC 2 auditors assess, rather than running a generic scan and hoping it fits. Ask how the testing methodology ties back to the controls your auditor will review.
What each provider actually issues at the end of the engagement varies. Ask up front whether that is a full technical report, a summary suitable for an auditor, or both, and whether it is included in the price.
Company and individual CREST accreditation, checkable in the public directory. It is the accreditation most auditors and enterprise customers look for on a penetration testing supplier.
Whether verification of your fixes is included or sold back as a second engagement. An auditor reviewing evidence for the audit window wants to see findings closed and confirmed, not just listed and open.
Whether the scope covers both the web application and the API layer together, since most SaaS attack surface, and most of what an auditor will ask about, sits across both.
Whether the provider can support an annual testing cycle plus a retest after significant changes, matching the period-in-time or period-of-time your SOC 2 audit actually covers.
Red flags for a
SOC 2 buyer
Whichever firm you choose, including us, walk away if you see these.
A scan passed off as the penetration test an auditor expects
Engagements priced under £500 a day are automated scans with a human cover sheet. Ask how many days of manual testing, by whom, with what certifications, and whether that maps to what your auditor will ask to see evidence of.
A provider that conflates the penetration test with the SOC 2 audit itself
A penetration test is technical evidence; the SOC 2 audit is a separate attestation performed by a licensed CPA firm. If a provider implies its report is the audit, or that it can issue SOC 2 compliance, that is a misrepresentation worth walking away from.
No shareable report or summary for your auditor and customers
Ask for a sample before you commit. If the deliverable is raw scanner output with no executive summary, your auditor and enterprise customers reviewing your security questionnaire will likely reject it.
No retest, so no verified-fix evidence
A test without verification of your fixes is half a service. Auditors reviewing evidence for the period increasingly want to see that findings were remediated and confirmed, not just listed in a report.
POA pricing that stalls the audit timeline
A firm that cannot indicate a day rate before a discovery call adds procurement drag when an audit deadline is fixed. UK CREST day rates run £1,000 to £1,500.
A generalist with no web, API, or SaaS depth
Ask for a sample report or a summary of past SaaS-specific engagements. If the provider cannot describe API testing methodology specifically, standard infrastructure testing is probably what you will get, and it will not cover where your real risk sits.
SOC 2 penetration testing prices
CREST-accredited testing runs £1,000 to £1,500 per consultant day. At Precursor's published rate of approximately £1,200 per day: web application from £3,750, API security testing from £2,500, internal network from £6,250, and combined multi-scope assessments from £10,000. A worked breakdown with examples is on the cost guide.
Full cost guide with worked examplesMore on penetration testing evidence for SOC 2 and the services referenced above.
Compare us against anyone on this list.
Testing mapped to the security Trust Services Criteria. Fixed pricing published before you call. A written quote within 24 hours of scoping. Retest included.
Penetration testing for SOC 2
The questions SOC 2 buyers ask most when comparing UK providers.
UK penetration testing runs from £2,500 for a small web application test to £25,000+ for a full multi-scope assessment, at roughly £1,000 to £1,500 per consultant day from a CREST-accredited provider. For a SOC 2 audit specifically, most companies budget for web application testing as a baseline, with API security testing added where the product exposes an API, and run it annually to match the audit period. Most firms price on application; Precursor publishes its rates. A worked breakdown is on our penetration testing cost page.
Not strictly. SOC 2 is a Trust Services Criteria attestation performed by a CPA firm, and the criteria do not name a mandatory penetration test as a control. In practice, auditors routinely expect annual penetration testing as evidence that the security criterion works in reality rather than on paper, and it is one of the most common items enterprise customers ask about in security questionnaires during procurement. Most companies pursuing SOC 2 commission a test for exactly that reason, even though the framework itself does not mandate it.
No. The SOC 2 audit is an attestation carried out by a licensed CPA firm, who reviews your controls against the Trust Services Criteria and issues the SOC 2 report. A penetration test is a separate, technical engagement carried out by a security testing firm, and its report becomes one piece of evidence your auditor reviews. Precursor delivers the penetration testing; it does not perform the SOC 2 attestation itself, and your CPA auditor remains a separate relationship.
Most providers issue a full technical report at the end of testing, and some will also provide a shareable executive summary suitable for an auditor or a customer security questionnaire, but the exact format varies by provider. Ask each firm on your shortlist what they issue, whether a redacted or summary version is available for your auditor and prospects, and whether that is included in the price or billed separately. Get this in writing before the engagement starts, since it usually cannot be produced retroactively in a different format.
UK companies preparing SOC 2 evidence commonly shortlist a mix of specialists and larger consultancies. This guide compares seven: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof. The right choice depends on whether the testing maps to the security Trust Services Criteria, whether pricing is published, whether a retest is included for verified-fix evidence, and whether the report format satisfies your auditor and enterprise customer questionnaires. Confirm any CREST accreditation in the public directory at crest-approved.org.



