If you rely on SOC2 compliance then you are indirectly requiring a pen test.
If you rely on SOC2 compliance then you are indirectly requiring a pen test.
Just so we're clear "you" is not Dropbox, and I'm not talking about what Dropbox does or doesn't do. I'm saying that, in general, most companies don't pentest other companies, they ask those companies instead to prove that they do their own pentests, which usually amounts to asking for their SOC2.
> we work with requires us to go through a pen test, or requires that we provide a recent and independent pen test report.
I am stating exactly this. Most companies require proof via SOC2, and that is it. Very few will actually hire a pentest firm directly for a 3rd party vendor.
> If you rely on SOC2 compliance then you are indirectly requiring a pen test.
To quote myself: "This is something you rely on a SOC2 for."