The honest framework fact
SOC 2 does not strictly mandate penetration testing. The Trust Services Criteria are control criteria your auditor evaluates your system against — how you demonstrate them is between you and your auditor, and a pentest is the demonstration auditors most often ask to see when the topic is vulnerability identification.