Friday, September 11, 2026

,

Achievable Completes Its First SOC 2 Type II Security Examination

written by

·

·

4 min read

Achievable can prove how it operated for six months — most companies can only tell you.”— Justin Pincar, Managing Director, Achievable

Achievable, a test-preparation platform rooted in evidence-based outcomes, disclosed today that it has finished its first SOC 2 Type II examination — an independent verification that its security controls functioned as specified over a six-month window. The report was issued on July 29, 2026, by Prescient Assurance LLC, a licensed CPA firm, and covers the span from December 31, 2025, through June 30, 2026.

The auditor concluded that Achievable's controls were suitably designed and worked effectively in all material respects, though exceptions in four control areas resulted in a qualified opinion. Achievable has since remediated all four of those areas. Its next examination period is set to begin in the fourth quarter of 2026.

SOC 2 exists in two forms, and Type II is the more demanding one. A Type I examines whether controls are correctly designed on a single day. A Type II verifies that they actually operated month after month, using samples drawn from real operations. Achievable's examination addresses the Security (Common Criteria) category and treats its cloud hosting provider under the carve-out method.

"Achievable can prove how it operated for six months — most companies can only tell you," said Justin Pincar, Managing Director at Achievable. "We handed an independent firm the real record of how we work, published exactly what it returned, and closed every item it raised. The next examination covers a full period with all four operating, and we expect it to show them resolved."

The controls behind the report

Achievable maintains a documented vulnerability management program with severity-based remediation service levels and a monthly review cycle that dispositions every tracked advisory. Production changes move through pull requests with branch protection and independent peer review before deployment. Background screening requires a documented determination before any new employee or contractor begins work. A documented incident response plan is exercised once per year.

Four of those areas were still maturing during the examination period, and the auditor's exceptions identify them. All four are now resolved. Achievable's Background Check Policy took effect July 15, 2026, and was strengthened the following month. Its Vulnerability Management Policy took effect June 17, 2026, and the review cycle has run every month since. The incident response plan was exercised via tabletop on July 22, 2026, establishing the annual cadence. Independent peer review now governs production changes, completing the remediation that was underway when the report was issued.

The part that cannot be manufactured

Generative tools have made it trivial to create a company that appears established: a polished website, a confident security page, a badge in the footer. None of it constitutes evidence, and none of it was examined by anyone.

A SOC 2 Type II cannot be produced that way. It requires a defined observation period, a real operating history within it, and an independent CPA firm examining how the company actually behaved across those months. There is no expedited version and nothing to purchase. A company that did not exist a year ago cannot have one.

"Security is not something a company announces once," Pincar said. "We are back in front of an auditor for the next period, and every period after that. That is the difference between a company that was examined once and a company that stays examined."

For teams managing licensing and training programs

Achievable partners with organizations that move entire teams through regulated licensing and continuing-education requirements — most commonly securities registration under FINRA and NASAA rules, and insurance licensing. Administrators receive a manager dashboard with real-time cohort progress, individual learner drill-down, and clear on-track, at-risk, and falling-behind indicators. Co-branded enrollment is configurable by branch, region, or business unit, with role-based access, SSO, LTI, and CSV and Excel exports. A new organization is typically onboarded within one business day.

Teams evaluating Achievable for a licensing or training program can contact the sales team at sales@achievable.me to view the platform and to request the SOC 2 Type II report, which Achievable provides under NDA to customers, prospective customers, and business partners.

About Achievable

Achievable is an exam preparation platform built on evidence-based outcomes. Its courses combine a complete online textbook, adaptive review questions, and full-length practice exams to help learners pass high-stakes exams across finance (including the SIE and FINRA Series 6, 7, 9, 10, 63, 65, and 66), healthcare (including the MCAT, USMLE, NCLEX, and PTCE), and college and graduate admissions (including the ACT, SAT, CLT, GRE, and AP subjects). Achievable pairs subject-matter expertise with modern measurement science — including Item Response Theory and its FACTS™ framework — to deliver personalized, measurable, and durable learning outcomes. Learn more at achievable.me.

Tyler York
Achievable, Inc.
email us here
Visit us on social media:
LinkedIn


David Hall

David Hall

David is the senior editor at NewsWatchInsight. He has a background in journalism and has worked with various media outlets, covering topics ranging from scientific research and policy analysis to global affairs and investigative features. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.


You May Also Like