PECB Lead SOC 2 Manager — course at a glance
- Entity
- Aegentra Academy — official PECB authorised training partner, Australia
- Course
- PECB Certified Lead SOC 2 Manager
- Former name
- Lead SOC 2 Analyst — earlier course name
- Accreditation
- Accreditation is program- and scope-specific; verify the applicable credential before enrolment
- Price
- $849 + GST
- Format
- Self-Study using official digital materials; remotely proctored examination
- Effort
- 30–40 hours self-paced · 450+ pages of course material · 31 CPD credits
- Exam
- 80 multiple-choice questions, open book, 3 hours, 70% pass mark, 5 competency domains
- Included
- Two exam attempts — the initial sit plus one free retake within 12 months
- Target
- Individual professional certification
- Availability
- Australia (Melbourne & Sydney) and worldwide — enrol from anywhere
Lead SOC 2 Manager or Lead SOC 2 Analyst — which is it?
The current PECB course and candidate handbook use Lead SOC 2 Manager. Lead SOC 2 Analyst is retained as the former course name so existing links remain useful. Ask PECB about any conversion or upgrade of a previously awarded Analyst credential; this course does not promise an automatic conversion or exemption from examination.
Individual SOC 2 professional certification vs corporate readiness
Buying a SOC 2 course and engaging a SOC 2 consulting firm solve two different problems. The PECB Lead SOC 2 Manager course is an individual professional certification — you take it to build and prove your own expertise in preparing a service organisation for a SOC 2 audit, and to add a recognised credential to your CV and tender responses. Corporate readiness is a separate, organisation-level engagement where a firm gets your company audit-ready. If you are a compliance analyst, GRC practitioner, auditor, or consultant looking to certify your own skills and advance your career, this is the course you want: $849 + GST, 100% online and self-paced, with the official PECB exam voucher and two exam attempts included — enrol and sit the remotely-proctored exam from anywhere in Australia or worldwide.
What you learn: the five AICPA Trust Services Criteria
SOC 2 is built on the AICPA Trust Services Criteria (TSC). The course teaches you to scope, design, and evidence controls against all five, and to prepare a service organisation for both Type I and Type II reports.
- Security (the Common Criteria). Mandatory in every SOC 2 report — protecting systems and data against unauthorised access, disclosure, and damage. This is the baseline every engagement must cover.
- Availability. The system is available for operation and use as committed — capacity planning, monitoring, incident response, and disaster recovery.
- Processing integrity. System processing is complete, valid, accurate, timely, and authorised — the right data, processed the right way.
- Confidentiality. Information designated as confidential is protected across its lifecycle — access controls, encryption, and secure disposal.
- Privacy. Personal information is collected, used, retained, disclosed, and disposed of in line with the organisation’s privacy notice and the AICPA privacy criteria.
Security is always in scope; the other four are selected based on the commitments a service organisation makes to its customers. You will also learn the difference between a Type I report (control design at a single point in time) and a Type II report (operating effectiveness over a period, typically three to twelve months), and how to build a readiness program for each.
Lead SOC 2 Manager exam format and domain weighting
The exam is 80 multiple-choice questions over 3 hours, open book, with a 70% pass mark. Each question has three options and one correct answer, and the paper mixes stand-alone questions with scenario-based sets. Of the 80 questions, 45 test comprehension, application and analysis and 35 test evaluation. Check these examination details against the current PECB Lead SOC 2 Manager candidate handbook.
Planning and implementation together are 47 of the 80 questions — nearly 60% of the paper. That is where study time pays, and it is the part candidates most often under-prepare because it rewards applied judgement rather than recall.
The PECB SOC 2 credential ladder
Passing the exam makes you eligible to apply. PECB assesses professional and project experience before awarding the appropriate Manager tier.
| Tier | Professional experience | Project activity |
|---|
| Provisional Manager | No threshold | No threshold |
| Manager | 2 years, including 1 in information security | 200 hours |
| Lead Manager | 5 years, including 2 in information security | 300 hours |
| Senior Lead Manager | 10 years, including 7 in information security | 1,000 hours |
Each tier requires the PECB Code of Ethics. Provisional credentials are maintenance-exempt. Check the current maintenance requirements for other tiers and PECB’s assessment requirements before requesting an upgrade.
What’s included for $849 + GST