Achievable logo
Achievable blue logo on white background
  • Company News
  • /Achievable completes its first SOC 2 Type II examination

Achievable completes its first SOC 2 Type II examination

Achievable, an exam preparation platform built on evidence-based outcomes, has completed its first SOC 2 Type II examination and published the opinion in full.
Justin Pincar's profile picture
Justin Pincar
17 Aug 2026, 3 min read
Achievable blue logo on white background
Digital illustration of a laptop open to a mock exam preparation platform on a desk; below the desk's top is a hidden network of connected symbols related to technology and security, symbolizing the protective and technological work being done behind the scenes
Achievable
Achievable blue logo on white background
  • Company News
  • /Achievable completes its first SOC 2 Type II examination

SAN FRANCISCO, CA, July 9, 2026 —

Achievable, an exam preparation platform built on evidence-based outcomes, has completed its first SOC 2 Type II examination — an independent audit of whether our security controls operated as described across a six-month period. Prescient Assurance LLC, a licensed CPA firm, issued the report on July 29, 2026, covering the period December 31, 2025 through June 30, 2026.

The auditor found our controls suitably designed and operating effectively in all material respects, with exceptions in four control areas that qualify the opinion. We have since closed all four. Our next examination period begins in Q4 2026.

“Achievable can prove how it operated for six months — most companies can only tell you.”

SOC 2 comes in two forms, and Type II is the harder one. A Type I asks whether controls are designed correctly on a single day. A Type II tests whether they actually operated, month after month, on samples drawn from actual operations. Ours covers the Security (Common Criteria) category and treats our cloud hosting provider under the carve-out method.

“Achievable can prove how it operated for six months — most companies can only tell you,” said Justin Pincar, Managing Director at Achievable. “We handed an independent firm the real record of how we work, published exactly what it returned, and closed every item it raised. The next examination covers a full period with all four operating, and we expect it to show them resolved.”


The controls behind the report

We run a written vulnerability management program with severity-based remediation service levels and a monthly review cycle that dispositions every tracked advisory. Production changes move through pull request with branch protection and independent peer review before deployment. Background screening requires a documented determination before any new employee or contractor begins work. Our incident response plan is exercised annually.

Four of those areas were still maturing during the examination period, and the auditor’s exceptions name them. All four are now closed. Our Background Check Policy took effect July 15, 2026 and was strengthened the following month. Our Vulnerability Management Policy took effect June 17, 2026, and the review cycle has run every month since. We exercised the incident response plan by tabletop on July 22, 2026, setting the annual cadence. Independent peer review now governs production changes, completing the remediation that was underway when the report was issued.


The part that cannot be manufactured

Generative tools have made it trivial to stand up a company that looks established: a polished site, a confident security page, a badge in the footer. None of it is evidence, and none of it was examined by anyone.

A SOC 2 Type II can’t be produced that way. It requires a defined observation period, a real operating history inside it, and an independent CPA firm examining how the company actually behaved across those months. There’s no expedited version and nothing to purchase. A company that didn’t exist a year ago can’t have one.

“Security is not something a company announces once,” Pincar said. “We are back in front of an auditor for the next period, and every period after that. That is the difference between a company that was examined once and a company that stays examined.”


For teams managing licensing and training programs

We work with organizations that move whole teams through regulated licensing and continuing-education requirements — most commonly securities registration under FINRA and NASAA rules, and insurance licensing. Administrators get a manager dashboard with real-time cohort progress, individual learner drill-down, and clear on-track, at-risk, and falling-behind indicators. Co-branded enrollment is configurable by branch, region, or business unit, with role-based access, SSO, LTI, and CSV and Excel exports. We can typically onboard a new organization within one business day.

If you’re evaluating Achievable for a licensing or training program, reach our sales team at sales@achievable.me to see the platform and to request the SOC 2 Type II report, which we provide under NDA to customers, prospective customers, and business partners.

Justin Pincar's profile picture
Justin Pincar
17 Aug 2026, 3 min read