Penetration testing for SaaS procurement

Turn a buyer’s testing request into an agreed scope. Know the deliverable and its limits before booking.

Last reviewed:

Sorami scopes SaaS procurement penetration testing around the buyer’s written requirement, not a promise of procurement approval. Agree assets, tenant boundaries and roles before testing. The published web scope starts at A$7,500 ex GST. Report acceptance, delivery dates and retest terms must be confirmed in writing for your engagement.

Confirm the acceptance criteria first

The buyer decides what evidence they accept. Ask for their required assets, report age and tester credentials. Confirm whether they need remediation evidence or a retest letter. Share their exact wording without customer records or credentials.

Testing is not universally required by SOC 2. AICPA’s Trust Services Criteria describe penetration testing as one example evaluation activity in the points of focus. A contract may separately request it. The SOC 2 vs ISO 27001 decision guide separates testing evidence from assurance formats.

Define the assets and boundaries

Use the penetration test scope builder to prepare a starting scope without sign-up. It does not test your systems. Confirm these items in the written authorisation:

  • Application URLs and API endpoints, with owned assets identified.
  • Tenant isolation and cross-account data access paths.
  • User roles and separate test accounts for permission checks.
  • Environment, deployment version and differences from production.
  • Third-party integrations, permitted techniques and testing windows.
  • Stop-test contacts and safe synthetic test data.

A staging test is not a production test. Record differences in configuration and integrations. Agree whether production checks are needed and permitted. Cloud accounts are not automatically included because the application runs in them.

What the published offer includes

The published penetration testing offer starts at A$7,500 ex GST for one web application, its API and two user roles. It includes five testing days, the report and a retest of critical and high findings. Expanded assets and other system types need written scope review.

Five testing days means testing effort, not elapsed delivery. Agree dates after reviewing scope and access readiness. The scope builder does not reserve dates. Remediation and retesting need their own agreed schedule.

Inspect the deliverable before you buy

Our illustrative penetration test report (PDF) contains synthetic findings, not a client engagement. It shows scope and limitations alongside reproducible evidence. Severity rationale and remediation priorities support engineering decisions.

The written engagement defines the report and retest record. Confirm covered findings and the retest window. Ask how resolved, partial and outstanding items are recorded. New features and new assets are not assumed to be part of a focused retest.

Delivery scope and exclusions

Testing follows written authorisation and agreed techniques. Destructive testing and denial of service are excluded by default. Unauthorised third-party systems and assets outside the written scope are excluded. This is not emergency incident response.

A penetration test is not SOC 2 reporting or ISO certification. It cannot establish that every vulnerability has been found. The buyer may need additional evidence. Individual tester credentials are separate from company accreditation. Sorami is not a CREST member company. See the credential boundaries.

Frequently asked questions

Will a penetration test report satisfy SaaS procurement?

Acceptance belongs to the buyer. Confirm their scope, credentials and report-age requirements before booking. The report is not a promise of procurement approval or audit success.

How long does procurement penetration testing take?

The published base web scope includes five testing days, not five days of elapsed delivery. Scope review, access readiness and remediation affect scheduling. Dates and retest terms are confirmed in writing.

What is included in the starting price?

The published offer starts at A$7,500 ex GST for one web application, its API and two user roles. It includes five testing days, the report and a retest of critical and high findings. Other assets and expanded scopes require written review.

Is penetration testing mandatory for SOC 2?

It is not universally required by SOC 2. A buyer may separately request it, or your selected controls may call for testing evidence. Share the exact requirement and confirm it with your CPA before commissioning work.

Discuss the buyer’s requirement

Use the penetration testing service for scope and estimates, then contact Sorami with the requirement and deadline. We confirm fee and dates in writing.

Related: scoping checklist and what a useful report contains.

Sources and offer basis

Offer details come from Sorami’s published penetration testing service and credential register, reviewed 2026-10-07. Framework context comes from AICPA’s revised Trust Services Criteria. No audit or procurement outcome is promised.