Compliance/01 - SOC 2

Get to a SOC 2 report without becoming a compliance team.

The Common Criteria, the evidence behind every one of them, and the auditor relationship - all carried by us. You approve the work; you don't do it.

  • Evidence collected and human-reviewed continuously, not reconstructed the week before fieldwork
  • Type I in weeks, Type II across the observation window you actually need
  • We run the auditor relationship and the questionnaire inbox
Trusted by teams shipping in regulated markets
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess

The report is the deliverable. The posture is the point.

SOC 2 is the report enterprise procurement asks for, but the criteria underneath it are ordinary security hygiene. We run the hygiene, and the report falls out of it.

We own the evidence, not the checklist

Most platforms flag a gap and hand it back. We collect the artifact, review it, approve it, and keep it current - so a control marked ready survives fieldwork.

- collected + reviewed + approved

The auditor is our conversation

We scope with the audit firm, field the evidence requests, and answer the follow-ups. You review and approve; we handle the back-and-forth.

- audit + questionnaires, handled

Your pentest already satisfies CC4

The testing, monitoring, and vulnerability work we run for you flows straight into the criteria it evidences. No second system, no double entry.

- findings to criteria, automatically

Type II is a year, not a week

The observation window punishes point-in-time theatre. Controls are monitored the whole period, and drift raises a signal the day it happens.

- monitored daily - drift = signal

What a SOC 2 actually covers.

Five Trust Services Criteria. Only one is mandatory - the rest you include when a customer contract or a real risk calls for it, not because a bundle said so.

Security (Common Criteria)

CC1-CC9 - required

The mandatory baseline: control environment, communication, risk assessment, monitoring, access, change management, and incident response.

Availability

optional

Capacity planning, backup and recovery, and the uptime commitments you put in front of customers.

Confidentiality

optional

How confidential data is identified, restricted, retained, and disposed of across its life.

Processing Integrity

optional

That system processing is complete, valid, accurate, and timely. Relevant when you process on a customer's behalf.

Privacy

optional

Notice, choice, collection, use, retention, and disclosure of personal information.

Type I vs Type II

scope decision

Type I attests the design of controls on a date. Type II attests they operated effectively across a period - usually three to twelve months.

We scope to the AICPA Trust Services Criteria (2017, with the 2022 points of focus revision). Adding a criterion you do not need adds evidence you have to maintain forever - we will tell you when to leave one out.

From scoping call to signed report.

Two phases are gated - scoping and attestation. Those are the ones where we hold the line, so a control marked ready is one you can defend in fieldwork.

Phase 01 - gated

Pick the criteria - and drop the rest

We decide which Trust Services Criteria your contracts actually require, and whether Type I first or straight to Type II is faster to the deal you are trying to close.

Criteria set - window chosen
Phase 02

Baseline and close the gaps

Integrations pull live configuration from cloud, identity, and code. We baseline every criterion, own the open gaps, and work them down with named owners.

Gaps owned - evidence flowing
Phase 03

Run the observation window

For a Type II the period is the product. Controls are monitored the whole way through, evidence is collected as it is generated, and drift surfaces the same day.

Period evidenced continuously
Phase 04 - gated

Fieldwork and report

We package the evidence, manage the audit firm, and walk the engagement to a signed report. Every artifact stays attestable in-platform afterward.

Signed report - attested in-platform
Pricing

SOC 2 is $3,000 a year.
The security department is the rest.

Every other vendor in this category makes you book a demo to learn what SOC 2 costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.

Startup plan + SOC 2
$20,000 / year

For companies under $5M revenue or 50 staff. The whole department, included.

  • Penetration testing
  • Vulnerability management
  • Monitoring & detection 24/7
  • Incident response
  • Compliance & GRC support
  • A named human on call
  • The Sythe Labs platform, run by us
+ $3,000 / yr for SOC 2 - scoping, evidence, gap closure, and the path to a signed Type II report. Add other frameworks at the same rate, only when you need them.
Book a call
Enterprise
Custom

Over $5M revenue or 50 staff. Negotiated to your scale and obligations.

  • Everything in Startup
  • Dedicated security lead
  • Custom SLAs & response times
  • Audit & board reporting
  • Scaled to your headcount
  • Procurement & MSA support
Talk to us
IncludedSOC 2 auditors expect a current penetration test. Yours is already in the flat plan - not a line item you discover in fieldwork.
Compliance billed per framework - no per-seat fees, ever. Auditor and certification-body fees are billed by them, not by us.

The people who already handed it over.

"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
EchoWin
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
Maru AI
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Naked Denver

SOC 2, honestly answered.

The questions that come up on every SOC 2 scoping call, answered before you have to ask them.

How long does a SOC 2 take?
A Type I is typically achievable in weeks once gaps are closed. A Type II requires an observation window - most companies run three months for a first report and twelve thereafter. The audit firm's fieldwork is a few weeks on top.
Do you also do the audit?
No, and no one legitimate does both. The report has to be issued by an independent CPA firm. We prepare the program, carry the evidence, and manage the audit relationship on your side of the table.
Is the auditor's fee included in the $3,000?
No. The $3,000/yr is our fee to run the SOC 2 program - scoping, evidence, gap closure, and auditor management. The CPA firm bills you separately for the attestation itself. We will tell you the realistic range before you commit.
We already started SOC 2 with another tool. Can you take it over?
Yes. We baseline what exists, keep the evidence that stands up, and tell you plainly which controls were marked ready but would not survive fieldwork.
Do we need a penetration test for SOC 2?
The criteria do not name one explicitly, but essentially every audit firm expects one, and customers reviewing your report will ask. It is included in the flat plan.

Walk into fieldwork with the evidence already done.

A 30-minute call. We will tell you which criteria you actually need, where you stand today, and what the path to a signed report looks like - whether or not you hire us.