Most startups hit the same wall.
You're halfway through your SOC 2 audit, and the auditor asks for vulnerability scanning evidence. You've been heads-down on access controls, encryption, HR policies.
Scanning? You figured the pentest covered that.
It doesn't. Vulnerability scanning is its own control with its own evidence. I've watched three founders scramble to produce scan reports the week before their audit window closed. This post is what I wish I could have sent them.
The two controls
CC7.1 (shortened):
The entity conducts vulnerability scans designed to identify potential vulnerabilities or misconfigurations on a periodic basis and after any significant change in the environment and takes action to remediate identified deficiencies on a timely basis.
CC7.2:
The entity monitors system components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives.
CC7.1 = find problems before they get exploited. CC7.2 = notice when something goes wrong.
Most startups only need CC7.1 for the scanning requirement. CC7.2 matters if your scanner does continuous monitoring (DNS changes, expiring certificates, that kind of thing).
What your auditor wants
The standard doesn't prescribe tools, frequencies, or formats. But every founder I've talked to who's been through an audit says the same thing. Your auditor opens a shared doc. They want four things.
1. Regular scanning with a documented cadence
Quarterly is the floor. Most auditors push for monthly or continuous. Daily or continuous scans exceed the requirement and your auditor moves on fast.
2. Findings classified by severity
Critical, high, medium, low. CVSS scores are the gold standard, but any consistent system works. A raw JSON dump from Nuclei won't cut it. Auditors want something they can reference in their workpapers.
3. Evidence that findings were addressed
This is the one that trips people up. For each finding, three acceptable outcomes:
- Fixed, with a follow-up scan showing it's resolved
- Accepted, with a written justification
- Mitigated, with compensating controls documented
Findings sitting open with no response? That's a finding in the audit itself.
Some auditors also ask for remediation SLAs:
| Severity | Target fix time |
|---|---|
| Critical | 7 days |
| High | 30 days |
| Medium | 90 days |
| Low | Best effort |
They'll check whether your actual fix times match.
4. Scope documentation
Which apps and domains are being tested, and do they match your system description. They want to know you're scanning production, not a staging server.
What SOC 2 does NOT require
Worth knowing, because every scanner vendor will try to convince you otherwise.
- Internal vs. external scanning is not specified. Most startups pass with external scanning only.
- A penetration test is recommended but not required. It's a separate line item.
- A specific tool. Open-source is fine if you produce the evidence above. The trade-off is time.
- 24/7 monitoring. Regular automated scans with alerting satisfy CC7.2.
What this costs
For a Series A startup (10-50 people):
| Line item | Typical range |
|---|---|
| Compliance platform (Vanta, Drata, Secureframe) | $7.5K-15K/yr |
| Auditor fees | $10K-25K/yr |
| Annual penetration test | $5K-25K |
| Vulnerability scanner | $1K-6K/yr |
| Total Year 1 | $25K-70K |
The scanner line has the widest range. Open-source tools are free but produce raw output with no compliance mapping. Enterprise scanners (Qualys, Tenable) start at $5K+/year and include features a 20-person startup will never touch.
Mid-market tools (Intruder, Detectify, Probely, HostedScan, AttackerView) sit in between. The comparison table at the end breaks this down.
How AttackerView handles this
AttackerView is the scanner I built. Here's how it fills the requirement.
Watchtower scans continuously: DNS/TLS every 10 minutes, headers and cookies every hour, full crawls daily. Starter runs daily. Either way, past the quarterly bar.
Compliance reports group findings by control ID (CC6.1, CC6.6, CC7.1, etc.) across SOC 2, ISO 27001, PCI DSS, and HIPAA. Finding lifecycle with timestamps. When your auditor asks "what happened with this finding?", the answer is in the report. Compliance-formatted reports are Watchtower only. Starter gets findings and fixes, not the framework-mapped audit evidence.
Vanta and Drata sync is automatic. No CSV exports.
We do external web app scanning. That's it. Cloud config, internal network scanning, and SAST are separate tools. Watchtower covers up to 15 apps.
Scanner comparison (15 domains)
| Tool | Annual cost | Compliance reports | Vanta/Drata | Scanning |
|---|---|---|---|---|
| Open-source (Nuclei, ZAP) | $0 + eng time | No | No | Manual |
| HostedScan (Basic) | $588/yr (5 targets) | No | Vanta only | Scheduled |
| AttackerView Watchtower | $1,236/yr | Yes (4 frameworks) | Both | Continuous |
| Intruder (Essential) | Per-target, not published | Yes | Both | Monthly |
| Probely / Snyk DAST | ~€12.4K/yr | Yes | No | Continuous |
| Detectify | ~€13K/yr | Not specified | No | Continuous |
| Qualys / Tenable | $5K+/yr | Yes | Via API | Continuous |
Prices from vendor pages, March 2026.
Try AttackerView free for 14 days at attackerview.com. No credit card required.
