Get to a SOC 2 report without becoming a compliance team.
The Common Criteria, the evidence behind every one of them, and the auditor relationship - all carried by us. You approve the work; you don't do it.
- Evidence collected and human-reviewed continuously, not reconstructed the week before fieldwork
- Type I in weeks, Type II across the observation window you actually need
- We run the auditor relationship and the questionnaire inbox















The report is the deliverable. The posture is the point.
SOC 2 is the report enterprise procurement asks for, but the criteria underneath it are ordinary security hygiene. We run the hygiene, and the report falls out of it.
We own the evidence, not the checklist
Most platforms flag a gap and hand it back. We collect the artifact, review it, approve it, and keep it current - so a control marked ready survives fieldwork.
The auditor is our conversation
We scope with the audit firm, field the evidence requests, and answer the follow-ups. You review and approve; we handle the back-and-forth.
Your pentest already satisfies CC4
The testing, monitoring, and vulnerability work we run for you flows straight into the criteria it evidences. No second system, no double entry.
Type II is a year, not a week
The observation window punishes point-in-time theatre. Controls are monitored the whole period, and drift raises a signal the day it happens.
What a SOC 2 actually covers.
Five Trust Services Criteria. Only one is mandatory - the rest you include when a customer contract or a real risk calls for it, not because a bundle said so.
Security (Common Criteria)
CC1-CC9 - requiredThe mandatory baseline: control environment, communication, risk assessment, monitoring, access, change management, and incident response.
Availability
optionalCapacity planning, backup and recovery, and the uptime commitments you put in front of customers.
Confidentiality
optionalHow confidential data is identified, restricted, retained, and disposed of across its life.
Processing Integrity
optionalThat system processing is complete, valid, accurate, and timely. Relevant when you process on a customer's behalf.
Privacy
optionalNotice, choice, collection, use, retention, and disclosure of personal information.
Type I vs Type II
scope decisionType I attests the design of controls on a date. Type II attests they operated effectively across a period - usually three to twelve months.
We scope to the AICPA Trust Services Criteria (2017, with the 2022 points of focus revision). Adding a criterion you do not need adds evidence you have to maintain forever - we will tell you when to leave one out.
From scoping call to signed report.
Two phases are gated - scoping and attestation. Those are the ones where we hold the line, so a control marked ready is one you can defend in fieldwork.
Pick the criteria - and drop the rest
We decide which Trust Services Criteria your contracts actually require, and whether Type I first or straight to Type II is faster to the deal you are trying to close.
Baseline and close the gaps
Integrations pull live configuration from cloud, identity, and code. We baseline every criterion, own the open gaps, and work them down with named owners.
Run the observation window
For a Type II the period is the product. Controls are monitored the whole way through, evidence is collected as it is generated, and drift surfaces the same day.
Fieldwork and report
We package the evidence, manage the audit firm, and walk the engagement to a signed report. Every artifact stays attestable in-platform afterward.
SOC 2 is $3,000 a year.
The security department is the rest.
Every other vendor in this category makes you book a demo to learn what SOC 2 costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.
The people who already handed it over.
"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Real engagements. Real outcomes.
The same programme, run for teams who had no security function when they started.
A four-person team with payment data, no security function, and a Series A closing.
Read the case studyechowinHIPAA attestation held and SOC 2 underway, with the whole department owned by us.
Read the case studyThe Academy of Charter SchoolsA penetration test their IT team rode along on, plus a roadmap of what to harden.
Read the case studySOC 2, honestly answered.
The questions that come up on every SOC 2 scoping call, answered before you have to ask them.
- How long does a SOC 2 take?
- A Type I is typically achievable in weeks once gaps are closed. A Type II requires an observation window - most companies run three months for a first report and twelve thereafter. The audit firm's fieldwork is a few weeks on top.
- Do you also do the audit?
- No, and no one legitimate does both. The report has to be issued by an independent CPA firm. We prepare the program, carry the evidence, and manage the audit relationship on your side of the table.
- Is the auditor's fee included in the $3,000?
- No. The $3,000/yr is our fee to run the SOC 2 program - scoping, evidence, gap closure, and auditor management. The CPA firm bills you separately for the attestation itself. We will tell you the realistic range before you commit.
- We already started SOC 2 with another tool. Can you take it over?
- Yes. We baseline what exists, keep the evidence that stands up, and tell you plainly which controls were marked ready but would not survive fieldwork.
- Do we need a penetration test for SOC 2?
- The criteria do not name one explicitly, but essentially every audit firm expects one, and customers reviewing your report will ask. It is included in the flat plan.
Walk into fieldwork with the evidence already done.
A 30-minute call. We will tell you which criteria you actually need, where you stand today, and what the path to a signed report looks like - whether or not you hire us.