Home >

,

Achievable Completes Its First SOC 2 Type II Security Examination

By

4 min read

A

“Achievable can prove how it operated for six months — most companies can only tell you.” — Justin Pincar, Managing Director, Achievable

Achievable, an exam preparation platform grounded in evidence-based outcomes, has announced the successful completion of its inaugural SOC 2 Type II examination. This independent audit assessed whether the company’s security controls functioned as described over a six-month period. The report, issued on July 29, 2026, by Prescient Assurance LLC, a licensed CPA firm, covered the timeframe from December 31, 2025, through June 30, 2026.

The auditor determined that Achievable’s controls were suitably designed and operated effectively in all material respects, though exceptions were noted in four control areas, leading to a qualified opinion. Achievable has since addressed and resolved all four issues. Its next examination period is scheduled to commence in the fourth quarter of 2026.

SOC 2 audits come in two varieties, with Type II being the more rigorous. A Type I assessment verifies that controls are properly designed on a single day. A Type II, in contrast, tests whether those controls actually operated consistently month after month, using samples drawn from real-world operations. Achievable’s examination covered the Security (Common Criteria) category and applied the carve-out method for its cloud hosting provider.

“Achievable can prove how it operated for six months — most companies can only tell you,” said Justin Pincar, Managing Director at Achievable. “We handed an independent firm the real record of how we work, published exactly what it returned, and closed every item it raised. The next examination covers a full period with all four operating, and we expect it to show them resolved.”

The controls behind the report

Achievable maintains a written vulnerability management program with severity-based remediation service levels and a monthly review cycle that addresses every tracked advisory. Production changes are managed through pull requests with branch protection and independent peer review prior to deployment. Background screening requires a documented determination before any new employee or contractor begins work. A documented incident response plan is exercised on an annual basis.

Four of these areas were still developing during the examination period, and the auditor’s exceptions identify them. All four have now been resolved. Achievable’s Background Check Policy took effect on July 15, 2026, and was reinforced the following month. Its Vulnerability Management Policy became effective on June 17, 2026, with the review cycle running every month since then. The incident response plan was tested via a tabletop exercise on July 22, 2026, establishing the annual cadence. Independent peer review now governs production changes, completing the remediation that was underway when the report was issued.

The part that cannot be manufactured

Generative tools have made it easy to create the appearance of an established company: a polished website, a confident security page, a badge in the footer. None of this constitutes evidence, and none of it has been examined by anyone.

A SOC 2 Type II cannot be produced in this manner. It requires a defined observation period, a genuine operating history within that period, and an independent CPA firm scrutinizing how the company actually behaved over those months. There is no expedited version and nothing to purchase. A company that did not exist a year ago cannot obtain one.

“Security is not something a company announces once,” Pincar said. “We are back in front of an auditor for the next period, and every period after that. That is the difference between a company that was examined once and a company that stays examined.”

For teams managing licensing and training programs

Achievable works with organizations that move entire teams through regulated licensing and continuing-education requirements — most commonly securities registration under FINRA and NASAA rules, and insurance licensing. Administrators receive a manager dashboard featuring real-time cohort progress, individual learner drill-down, and clear on-track, at-risk, and falling-behind indicators. Co-branded enrollment is configurable by branch, region, or business unit, with role-based access, SSO, LTI, and CSV and Excel exports. A new organization is typically onboarded within one business day.

Teams evaluating Achievable for a licensing or training program can reach the sales team at sales@achievable.me to see the platform and to request the SOC 2 Type II report, which Achievable provides under NDA to customers, prospective customers, and business partners.

About Achievable

Achievable is an exam preparation platform built on evidence-based outcomes. Its courses combine a complete online textbook, adaptive review questions, and full-length practice exams to help learners pass high-stakes exams across finance (including the SIE and FINRA Series 6, 7, 9, 10, 63, 65, and 66), healthcare (including the MCAT, USMLE, NCLEX, and PTCE), and college and graduate admissions (including the ACT, SAT, CLT, GRE, and AP subjects). Achievable pairs subject-matter expertise with modern measurement science — including Item Response Theory and its FACTS™ framework — to deliver personalized, measurable, and durable learning outcomes. Learn more at achievable.me.

Tyler York
Achievable, Inc.
email us here
Visit us on social media:
LinkedIn


David Hall

David Hall

David is the senior editor at BusinessInsightNews. He has a background in journalism and has worked with various media outlets, covering topics ranging from markets and investing to business strategy and economic policy. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.