SOC 2

SOC 2 testing evidence that covers the whole audit period

Hadrian tests your internet-facing systems continuously and runs agentic pentests on demand. Your team gets validated findings, fix history and pentest reports to support CC4.1, CC7.1 and related criteria.

Customer story

A once-a-year pentest report no longer met partner expectations, so Aroma360 now shows continuous, validated testing, with automatic retests after fixes.

Aroma360
Read the story →
Requirements

SOC 2 requirements Hadrian supports

SOC 2 is an attestation report from an independent CPA firm on a service organization's controls, assessed against the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022). A Type 2 report covers how those controls operated over a period of time.

0
1
CC3.2

Identify and analyze risks

Identify risks to your objectives across the organization and analyze them to decide how to manage them. This includes threats and vulnerabilities from vendors, business partners and others with access to your systems.

How Hadrian helps

Hadrian gives your risk assessment an attacker's view of your internet-facing assets, with validated exposures ranked by likelihood of exploitation and business impact.

Evidence you can show

An exported asset inventory and validated risk list used as input to your risk assessment.

0
2
CC4.1

Evaluate whether controls are working

Run ongoing and separate evaluations to check that controls are present and functioning. A point of focus lists penetration testing among the evaluations management may use.

How Hadrian helps

Atlas acts as an ongoing evaluation of your external controls by testing whenever your attack surface changes. Nova provides separate pentests on demand.

Evidence you can show

Nova pentest reports and dated continuous test results across the audit period.

0
3
CC6.6

Protect against threats from outside your boundary

Put logical access security measures in place to protect against threats from sources outside your system boundaries.

How Hadrian helps

Hadrian tests your boundary from the internet and flags exposed services and misconfigurations. With the infostealer add-on, it also shows leaked credentials and session cookies tied to your domains.

Evidence you can show

Validated findings on boundary systems with remediation and retest status, plus leaked-credential records.

0
4
CC7.1

Detect configuration changes and new vulnerabilities

Use detection and monitoring procedures to find configuration changes that introduce new vulnerabilities, and susceptibility to newly discovered vulnerabilities.

How Hadrian helps

Atlas starts new tests when an asset or its configuration changes, and Hadrian's hackers add coverage for new threats. Hadrian maps the Nova report to CC7.1.

Evidence you can show

Findings tied to the asset change that triggered them, with remediation and retest history.

0
5
CC9.2

Manage vendor and business partner risk

Assess and manage the risks that come from vendors and business partners.

How Hadrian helps

Atlas shows the third-party technologies and services on your external attack surface and validates the exposures they introduce. Secure Share lets you send a risk to a vendor without giving them platform access.

Evidence you can show

A record of vendor-related exposures, who they were shared with and when they were closed.

Hadrian supports these criteria for your external attack surface. It does not certify or attest to SOC 2 compliance; your CPA firm does that.

How Hadrian helps

Pentests on your schedule

Nova runs scoped pentests of web apps and APIs on demand, ahead of an audit window or after a release. Most tests finish within 24 to 48 hours. Hadrian's offensive security team validates every finding, and Hadrian maps the report to SOC 2 CC7.1.

See agentic penetration testing
01

Monitoring for new vulnerabilities between audits

CC7.1 looks for procedures that catch configuration changes and newly discovered vulnerabilities. Atlas runs new tests when your external attack surface changes, runs passive scans every hour, and only alerts on exposures it has validated.

See adversarial exposure validation
02

A clear record of what you fixed

Each finding has reproduction steps, an owner and a risk timeline showing when it was found, shared, assigned and resolved. Hadrian retests after a fix, so the record shows the issue was closed.

See threat exposure management
03
Case studies

More from customers

All case studies
Case study

WeatherTech

WeatherTech had done compliance reporting by hand; it now exports an external risk report for partners in one click.

Read the story →
Case study

Breeze Airways

Breeze's lean security team gets findings already confirmed as exploitable, including API and Content Security Policy coverage.

Read the story →
FAQ

Frequently asked questions

Does SOC 2 require a penetration test?
+

No criterion requires one by name. Penetration testing appears in a point of focus under CC4.1 as one type of evaluation management may use, and points of focus are guidance. Agree the approach with your auditor early.

Will our auditor accept a Nova report?
+

Nova reports are built to share with auditors. They include an executive summary, methodology, risk ratings, reproduction steps and remediation guidance, and Hadrian's offensive security team validates every finding. Hadrian maps the report to CC7.1. Your auditor decides what evidence is enough, so confirm their expectations on scope and tester independence. Where a framework or customer requires a named, certified tester, Hadrian recommends a traditional engagement alongside Nova.

How does continuous testing help with a Type 2 report?
+

A Type 2 report looks at how controls operated over a period. Atlas tests your external attack surface whenever it changes and keeps a dated record of what it found, who fixed it and when the retest passed. That gives you evidence across the whole period.

Has Hadrian completed its own SOC 2 audit?
+

Yes. Hadrian completed a SOC 2 Type II audit, announced in February 2025. Hadrian is delivered as a cloud service with no agents or sensors to install in your environment.

Does Hadrian test internal systems?
+

No. Atlas and Nova test your external attack surface: internet-facing assets, web apps and APIs. Nova covers the OWASP Top 10 from an external perspective. Tests that need source code access or internal infrastructure fall outside the scope of an external pentest.

Get a 15 minute demo

Go into your next SOC 2 audit with current test results

Book a demo to see how Atlas monitors your external attack surface, how a Nova pentest runs, and what the reports look like.