Point in time
Type I
Type I — design of controls at a point in time; fastest path to a first report
SOC 2 · Trust Services Criteria
SOC 2 is the report your US enterprise buyers ask for before they sign. We take Australian SaaS companies and managed-service providers from first gap assessment to a CPA-issued Type I or Type II report — Trust Services Criteria scoped to your platform, controls built in your cloud stack, evidence collected live through Aeges, and the audit brokered with a licensed CPA firm. We prepare; a CPA firm attests.
Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Commercial decision
SOC 2 is an attestation report issued under the AICPA's attestation standards against the Trust Services Criteria — not a certificate. A licensed CPA firm examines the controls behind your service and publishes an opinion your customers' security and vendor-risk teams read line by line. That is the critical difference from ISO 27001: there is no certificate to frame, there is a detailed report, typically restricted to your customers and prospects under NDA. It is also not SOX — SOX is a US financial-reporting law for listed companies; SOC 2 is a voluntary, market-driven attestation about the security of a service. US and increasingly global enterprise buyers treat a current SOC 2 report as the entry ticket for SaaS and managed services: no report, no deal — or a security questionnaire so long it stalls the sale.
Report choice
A Type I report describes your system and tests whether controls are suitably designed at a single point in time. A Type II report covers an observation window — commonly three, six, or twelve months — and tests whether those controls operated effectively across the whole period. Buyers know the difference: a Type I proves you built the machine, a Type II proves the machine runs. The pragmatic path for most Australian providers is a Type I to unblock the deal that is on the table now, rolling straight into the Type II window so the stronger report lands within the year. We design the programme so evidence collected from day one of the observation window counts, and so the same controls serve both reports without rework.
Point in time
Type I — design of controls at a point in time; fastest path to a first report
Observation period
Type II — operating effectiveness over a 3–12 month observation window; what mature buyers ask for
Trust Services Criteria
Every SOC 2 includes the Security criteria — the Common Criteria — as its mandatory backbone. The other four categories are optional and should be scoped commercially, not aspirationally: Availability if you sell an SLA, Confidentiality if you hold sensitive customer data (most SaaS should), Processing Integrity if your platform's output is the product — billing, payroll, calculations — and Privacy only when you make specific privacy commitments to individuals. Over-scoping inflates both the audit fee and the ways an auditor can find exceptions; under-scoping triggers buyer pushback. We scope the system description around the service your customers actually buy — the platform, its infrastructure, the people and processes behind it, and the subservice organisations underneath (your cloud provider is usually carved out, with complementary controls documented).
Mandatory in every SOC 2
Required
When you contractually commit to uptime
When you hold sensitive customer data
When customers rely on the correctness of output
For direct privacy commitments to individuals
Evidence path
Readiness is where SOC 2 engagements are won or lost. We start with a gap assessment of your current state against the scoped criteria, then design and implement the controls in the stack you already run — identity and access in your cloud tenant, change management in your development pipeline, vendor management, incident response, logging and monitoring. Policies are written to match how you actually operate, not templates the auditor will see through. Then evidence: the Aeges risk engine collects control evidence live from your environment across the observation window, so when the CPA firm issues its request list, the population and samples are already sitting there — timestamped, complete, and mapped to the criteria. That is the difference between a two-week fieldwork and a three-month evidence chase.
Choose the criteria and define the service boundary.
Implement controls in the cloud stack you already operate.
Run the controls across the agreed reporting period.
Collect timestamped evidence and map it to each criterion.
A licensed CPA firm examines the controls and issues its opinion.
Delivery model
Choose the delivery model around the capacity you actually have. A software-only compliance platform can organise controls and evidence requests, but your team still owns scoping, control design, remediation and the CPA relationship. An advisory-only consultancy can interpret the criteria and write the programme, while your engineers implement it. Aegentra combines practitioner-led readiness with hands-on control implementation, live evidence collection through Aeges and CPA-auditor liaison. That integrated model is designed for SaaS teams that need the work delivered without turning engineering into a full-time compliance function; teams with a mature internal GRC owner may reasonably prefer software or advisory support alone.
Model 01
useful for workflow and evidence organisation; internal owners still design and operate the programme
Model 02
criteria interpretation and documents; your engineering team implements and evidences the controls
Model 03
readiness, cloud control implementation, live evidence and CPA liaison in one scope
CPA examination remains independent under every model
/ Delivery team
The readiness scope identifies the accountable lead, the systems and controls inside scope and any technical contribution required to prepare evidence for the independent examination.
Responsibility
Assigned role
How it is confirmed
Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.
Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.
The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.
Readiness support does not guarantee an examination result. The assigned roles and evidence responsibilities are confirmed for the agreed scope.
Independence boundary
Only a licensed CPA firm can issue a SOC 2 report, and the same independence principle we apply to ISO 27001 applies here: the firm that attests cannot be the team that built your controls. That separation is a feature — it means Aegentra sits entirely on your side. We shortlist CPA firms that fit your size and timeline, brief them on the system description, negotiate the scope so you are not paying for criteria you don't need, manage the request list during fieldwork, and handle exceptions before they become qualified opinions. If you already have an audit firm, we work with them. Your engineers keep shipping; we speak auditor.
Combined programme
The Trust Services Criteria and ISO 27001's Annex A cover many of the same operational areas: access control, change management, operations security, incident management, vendor management and monitoring. Where existing controls and evidence are valid for both programmes, Aegentra maps them once, closes the SOC 2-specific gaps and sequences the ISO audit cycle with the SOC 2 observation window. The result is one coordinated control environment serving Australian, UK, European and US buyer requirements.
At a glance
The report type, criteria, observation period, delivery responsibilities and separate CPA fee are made explicit in the agreed scope.
Questions buyers ask
Report, scope, timeline, cost and ownership — without treating an attestation like a certification.
No — SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a detailed report with an opinion; there is no certificate and no accredited certification body involved. That's why buyers ask to read the report itself. Aegentra's role is readiness and audit preparation — we design and implement the controls, collect the evidence, and liaise with the CPA firm that issues the report.
Start with scope
A practitioner reviews the buyer requirement, service boundary and delivery responsibilities, then provides a written plan and fixed price for the agreed work. The CPA audit fee remains separate.
Book a SOC 2 scoping call