Get to a SOC 2 report without becoming a compliance team.
The Common Criteria, the evidence behind every one of them, and the auditor relationship - all carried by us. You approve the work; you don't do it.
- Evidence collected and human-reviewed continuously, not reconstructed the week before fieldwork
- Type I in weeks, Type II across the observation window you actually need
- We run the auditor relationship and the questionnaire inbox















The report is the deliverable. The posture is the point.
SOC 2 is the report enterprise procurement asks for, but the criteria underneath it are ordinary security hygiene. We run the hygiene, and the report falls out of it.
We own the evidence, not the checklist
Most platforms flag a gap and hand it back. We collect the artifact, review it, approve it, and keep it current - so a control marked ready survives fieldwork.
The auditor is our conversation
We scope with the audit firm, field the evidence requests, and answer the follow-ups. You review and approve; we handle the back-and-forth.
Pentest findings support control evidence
Testing, monitoring, and remediation records support the applicable criteria. The auditor evaluates whether that evidence is sufficient for your scope.
Type II covers an observation period
The observation period is usually three to twelve months, agreed with your auditor. We monitor controls and collect evidence throughout that period.
What a SOC 2 actually covers.
Five Trust Services Criteria. Only one is mandatory - the rest you include when a customer contract or a real risk calls for it, not because a bundle said so.
Security (Common Criteria)
CC1-CC9 - requiredThe mandatory baseline: control environment, communication, risk assessment, monitoring, access, change management, and incident response.
Availability
optionalCapacity planning, backup and recovery, and the uptime commitments you put in front of customers.
Confidentiality
optionalHow confidential data is identified, restricted, retained, and disposed of across its life.
Processing Integrity
optionalThat system processing is complete, valid, accurate, and timely. Relevant when you process on a customer's behalf.
Privacy
optionalNotice, choice, collection, use, retention, and disclosure of personal information.
Type I vs Type II
scope decisionType I attests the design of controls on a date. Type II attests they operated effectively across a period - usually three to twelve months.
We scope to the AICPA Trust Services Criteria (2017, with the 2022 points of focus revision). Adding a criterion you do not need adds evidence you have to maintain forever - we will tell you when to leave one out.
From scoping call to signed report.
Two phases are gated - scoping and attestation. Those are the ones where we hold the line, so a control marked ready is one you can defend in fieldwork.
Pick the criteria - and drop the rest
We decide which Trust Services Criteria your contracts actually require, and whether Type I first or straight to Type II is faster to the deal you are trying to close.
Baseline and close the gaps
Integrations pull live configuration from cloud, identity, and code. We baseline every criterion, own the open gaps, and work them down with named owners.
Run the observation window
For a Type II the period is the product. Controls are monitored the whole way through, evidence is collected as it is generated, and drift surfaces the same day.
Fieldwork and report
We package the evidence, manage the audit firm, and walk the engagement to a signed report. Every artifact stays attestable in-platform afterward.
SOC 2: $23,000 a year total.
Startup base plus one framework.
$23,000/year for the Startup base plus one framework: $20,000 base + $3,000 per framework. For companies under $5M revenue or 50 staff. Independent audit and certification fees are separate. Enterprise pricing is custom.
The people who already handed it over.
"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Real engagements. Real outcomes.
The same programme, run for teams who had no security function when they started.
A four-person team with payment data, no security function, and a Series A closing.
Read the case studyechowinHIPAA attestation held and SOC 2 underway, with the whole department owned by us.
Read the case studyThe Academy of Charter SchoolsA penetration test their IT team rode along on, plus a roadmap of what to harden.
Read the case studySOC 2, honestly answered.
The questions that come up on every SOC 2 scoping call, answered before you have to ask them.
- How long does a SOC 2 take?
- A Type I is typically achievable in weeks once gaps are closed. A Type II requires an observation window - most companies run three months for a first report and twelve thereafter. The audit firm's fieldwork is a few weeks on top.
- Do you also do the audit?
- No, and no one legitimate does both. The report has to be issued by an independent CPA firm. We prepare the program, carry the evidence, and manage the audit relationship on your side of the table.
- Is the auditor's fee included in the $3,000?
- No. The $3,000/yr is the framework add-on to the required base plan ($23,000/year total for Startup plus SOC 2). It covers our work running the SOC 2 program - scoping, evidence, gap closure, and auditor management. The CPA firm bills you separately for the attestation itself. We will tell you the realistic range before you commit.
- We already started SOC 2 with another tool. Can you take it over?
- Yes. We baseline what exists, keep the evidence that stands up, and tell you plainly which controls were marked ready but would not survive fieldwork.
- Do we need a penetration test for SOC 2?
- The criteria do not explicitly mandate a penetration test. Testing can support control evidence, and auditors or customers may request it. Confirm the scope with your auditor; penetration testing is included in the base plan.
Walk into fieldwork with the evidence already done.
A 30-minute call. We will tell you which criteria you actually need, where you stand today, and what the path to a signed report looks like - whether or not you hire us.