Skip to content

Trust · SOC 2 Type II

Our path to SOC 2 Type II.

Where Resolute Security stands on every Common-Criteria control today, what evidence backs each one, and when we expect the audited report.

See also: Policy library · Trust page

CC criteria total

33

Satisfied

2988%

Partial

3

Not yet

1

In-scope

Security (Common Criteria) only for the first audit cycle. Availability + Confidentiality folded in after the Type II report ships.

Security (Common Criteria) only. Availability and Confidentiality added after audit firm engaged. Observation period planned to start Jan 2027.

Timeline

  • Readiness: ongoing — policies, controls, evidence accumulating since project start
  • Observation period start: Jan 2027
  • Audit fieldwork: Q3 2027
  • Type II report: Q4 2027 (target)

Per-criterion status

Every AICPA Common Criterion with our current self-assessed status. Click a row to read the policy that proves it.

Want more detail?

Every policy is in the public repo. The risk register, the solo-founder memos, and the SECURITY.md disclosure policy are all linked from /security/policies. For an NDA-gated readiness pack, email security@resolute-security.com.