The RSI security blog site breaks down the steps in certain element, but the procedure in essence goes similar to this: Includes a new illustrative report Which may be utilized when executing and reporting on the SOC 2+ examination. PCI DSS fines can differ from payment processor to payment processor, https://www.nathanlabsadvisory.com/application-security-testing.html