Back to Blog
Insights11 min read

How to Prepare for a SOC 2 Audit in Australia

A

Alexander Sverdlov

Security Analyst

7/20/2026
How to Prepare for a SOC 2 Audit in Australia

Most Australian companies I meet do not chase SOC 2 because they want it. They chase it because a prospect in the United States, or an enterprise buyer anywhere, put it in the procurement questionnaire and will not sign without it. That is a perfectly good reason. It also shapes how you should prepare, because a SOC 2 examination is not a checkbox you tick in a week. It is an independent attestation by a licensed CPA firm about whether your controls are designed well and, for a Type 2, whether they actually operated over a period of time. Having guided companies through this on both sides of the assessment, here is how to prepare properly from Australia and avoid the expensive detours.

What SOC 2 Is, and What It Is Not

SOC 2 is a reporting framework governed by the American Institute of Certified Public Accountants (AICPA). An independent auditor examines your control environment against the Trust Services Criteria and issues a report with their opinion. It is not a certificate you frame on the wall, and there is no such thing as being "SOC 2 certified" in the strict sense. You receive a report. That distinction matters, because your buyers' security teams read the report, not a logo.

What this guide covers: What SOC 2 Is, and What It Is Not, Type 1 Versus Type 2: Choose Deliberately, The Australian Wrinkle: Who Perf

The Trust Services Criteria are five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security, often called the common criteria, is mandatory in every SOC 2. The other four are optional and you include them only where they are relevant to the service you provide and to what your customers actually care about. Adding all five because it looks thorough is a classic way to inflate cost and effort for no commercial return.

Type 1 Versus Type 2: Choose Deliberately

This is the first real decision, and it drives your whole timeline.

AspectSOC 2 Type 1SOC 2 Type 2
What it assessesDesign of controls at a single point in timeDesign and operating effectiveness over a period
Observation windowA specific dateTypically 3 to 12 months
What buyers preferAccepted as a first stepWhat most enterprises ultimately want
Best used whenYou need something credible quicklyYou want the report that closes deals long term

My usual advice: if a deal is on the line right now, a Type 1 gets you a defensible report faster and demonstrates intent. But plan for Type 2 from day one, because that is the report enterprise buyers keep asking to renew annually. Designing controls twice because you treated Type 1 as the destination is wasted money. There is more detail on this decision in SOC 2 Type 1 vs Type 2.

The Australian Wrinkle: Who Performs the Audit

The formal SOC 2 opinion must be issued by a licensed CPA firm, and in practice these are US-based or US-affiliated firms operating under AICPA standards. That does not stop an Australian company from getting a clean SOC 2 at all. It simply means the attestation itself comes from a CPA firm, while the heavy lifting of readiness, control design, remediation and evidence collection happens inside your organisation, usually with a consultant who has done it before. Keep those two roles separate in your head. The auditor tests and opines; they do not build your controls for you, and a good auditor should stay independent of that work.

Checklist: Type 1 Versus Type 2: Choose Deliberately

The other Australian reality is timezone and evidence. If your systems, your people and your data live in Australia while your auditor sits in a US timezone, tight, well-organised evidence matters even more, because you cannot rely on quick back-and-forth calls to paper over gaps.

The Preparation Journey, Step by Step

Step 1: Scope the Report

Decide which service or product the report covers, which of the five criteria apply, and where your system boundary sits. This is the single highest-leverage decision in the whole exercise. A scope that is too broad drags in systems and teams that your customers never asked about; a scope that is too narrow produces a report that does not actually cover the service the buyer cares about. Map your data flows, your production environment, your subservice organisations such as your cloud provider, and the people with access. Everything follows from this.

Checklist: The Australian Wrinkle: Who Performs the Audit

Step 2: Run a Readiness Assessment

Before you spend a dollar on the formal examination, do a readiness assessment against the criteria you selected. This is where you find the gaps between the controls you claim and the controls you can evidence. In every engagement I have run, the readiness assessment surfaces the same categories of problem: access reviews that were never performed, change management that lives in people's heads, no formal risk assessment, backups that are configured but never tested, and vendor management that amounts to a folder of PDFs. Better you find these than the auditor. A structured SOC 2 readiness assessment is the cheapest insurance you can buy against a qualified opinion.

Step 3: Remediate and Implement Controls

Close the gaps. At the core, a SOC 2 environment needs to demonstrate:

  • Access control with multi-factor authentication, least privilege, and periodic access reviews that are actually documented.
  • Change management, so that code and infrastructure changes are reviewed, approved and traceable.
  • A formal, documented risk assessment that is revisited, not written once and buried.
  • Logging and monitoring that can detect and support investigation of security events.
  • Vendor and subservice management, because your cloud provider and key suppliers are part of your control story.
  • Incident response and business continuity plans that are written down and tested, not aspirational.
  • Security awareness training and clean onboarding and offboarding of staff.

These map naturally onto frameworks you may already be pursuing. If you hold or want ISO 27001, much of this overlaps; I unpack that in ISO 27001 vs SOC 2. Getting the controls genuinely working, not just documented, is where an IT security audit and independent penetration testing earn their place, because they show the controls hold under real conditions.

Step 4: Operate the Controls Through the Observation Window

For a Type 2, this is the part companies underestimate. The auditor does not just check that a control exists on the final day; they sample evidence across the entire observation period. That means your access reviews have to have actually happened each quarter, your change tickets have to exist for the whole window, and your monitoring alerts have to have been triaged. If you switch a control on the week before the window opens and it lapses in month two, the auditor will see it. Discipline over the window is what separates a clean report from a qualified one.

Step 5: Collect Evidence and Undergo the Examination

Evidence collection is the grind. Screenshots, exports, tickets, policy documents, logs and reports, all organised and mapped to the criteria. The companies that suffer here are the ones that leave it to the end; the companies that breeze through are the ones that instrumented evidence collection from the start of the window. During the examination the auditor requests samples, asks questions, and tests. Answer precisely, provide exactly what is asked, and do not volunteer scope you did not commit to.

A Realistic Timeline

PhaseFocusTypical duration
ScopingBoundary, criteria, subservice organisations1 to 3 weeks
Readiness assessmentGap analysis against selected criteria2 to 6 weeks
RemediationImplement and document missing controls1 to 4 months
Type 1 examinationPoint-in-time design opinionWeeks after readiness
Type 2 observation windowControls operate and are evidenced3 to 12 months
Type 2 examinationFieldwork, testing, report4 to 8 weeks

Do not anchor on the fastest number you have heard. The honest range depends on how mature your controls are before you start. A company with no formal security programme should expect the better part of a year to a solid Type 2; one with an existing ISO 27001 posture can move considerably faster.

The Mistakes That Cost Australian Companies Time

  • Over-scoping the criteria. Adding Privacy or Processing Integrity when no customer asked inflates the whole project.
  • Skipping the readiness assessment. Walking straight into the examination means the auditor finds your gaps, which is the most expensive way to find them.
  • Treating controls as documents. A policy nobody follows is worse than no policy, because it creates an evidence gap the auditor will flag.
  • Leaving evidence to the end. For a Type 2 you cannot retroactively create six months of access reviews.
  • Confusing the auditor with the consultant. The CPA firm attests; they should not also be the ones building your controls.

Where a vCISO Fits

Most Australian scale-ups do not have a full-time security leader when the first SOC 2 request lands. That is exactly the moment a virtual CISO earns their keep: owning the scope decision, running the readiness assessment, driving remediation on a sensible sequence, and managing the relationship with the CPA firm so you are not learning the process at the same time you are being examined. For fintechs and regulated SaaS, this often runs alongside other obligations, which is why a specialised fintech virtual CISO engagement tends to fold SOC 2 into a broader compliance roadmap rather than treating it in isolation.

The Preparation Journey, Step by Step - key points What SOC 2 Is, and What It Is Not - key points

Frequently Asked Questions

Can an Australian company get SOC 2 without a US entity?

Yes. SOC 2 is about your controls and your service, not your place of incorporation. The formal opinion is issued by a licensed CPA firm working to AICPA standards, but your organisation can be entirely Australian. What matters is that the controls in scope are yours and that you can evidence them.

How long does SOC 2 preparation take in Australia?

It depends on your starting maturity. A Type 1 can follow a readiness assessment within weeks once gaps are closed. A Type 2 additionally requires an observation window, commonly three to twelve months, during which controls must operate and be evidenced. Companies with an existing ISO 27001 posture move fastest.

Which Trust Services Criteria should I include?

Security is always required. Add Availability, Confidentiality, Processing Integrity or Privacy only where they are relevant to your service and to what your customers ask for. Including criteria you do not need adds cost and effort without commercial benefit.

Do I need a Type 1 before a Type 2?

No, it is not mandatory. Many companies go straight to Type 2. A Type 1 is useful when you need a credible report quickly to unblock a deal, but design your controls for Type 2 from the start so you are not doing the work twice.

Can the same firm do my readiness work and my audit?

The CPA firm that issues the opinion should remain independent of the work of designing and implementing your controls. In practice, a consultant or vCISO handles readiness and remediation, and a separate CPA firm performs the examination and attests.

Is SOC 2 the same as ISO 27001?

No, but they overlap heavily. ISO 27001 is a certifiable management system standard; SOC 2 is an attestation report against the Trust Services Criteria. If you already hold ISO 27001, much of the control work carries over and SOC 2 becomes considerably faster.

Getting Started

SOC 2 preparation is a discipline, not a scramble. Scope it tightly, run a real readiness assessment, remediate honestly, then operate and evidence your controls through the window before the auditor arrives. Do it in that order and the examination confirms what you already know rather than exposing what you missed. If you want an experienced partner to run the readiness assessment and steer the whole engagement, get in touch.

A Realistic Timeline - key points
Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.