Skip to main content

SOC 2 · Trust Services Criteria

SOC 2 Readiness for Australian SaaS & Service Providers

SOC 2 is the report your US enterprise buyers ask for before they sign. We take Australian SaaS companies and managed-service providers from first gap assessment to a CPA-issued Type I or Type II report — Trust Services Criteria scoped to your platform, controls built in your cloud stack, evidence collected live through Aeges, and the audit brokered with a licensed CPA firm. We prepare; a CPA firm attests.

Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Modern office towers viewed from below
Prepared by Aegentra · Attested independently by a licensed CPA firm
Senior-led Australian delivery
Evidence collected live through Aeges
Audit brokered with a licensed CPA firm

Commercial decision

The report buyers read.

What SOC 2 is — and what it isn't

SOC 2 is an attestation report issued under the AICPA's attestation standards against the Trust Services Criteria — not a certificate. A licensed CPA firm examines the controls behind your service and publishes an opinion your customers' security and vendor-risk teams read line by line. That is the critical difference from ISO 27001: there is no certificate to frame, there is a detailed report, typically restricted to your customers and prospects under NDA. It is also not SOX — SOX is a US financial-reporting law for listed companies; SOC 2 is a voluntary, market-driven attestation about the security of a service. US and increasingly global enterprise buyers treat a current SOC 2 report as the entry ticket for SaaS and managed services: no report, no deal — or a security questionnaire so long it stalls the sale.

  • AICPA attestation against the Trust Services Criteria — an examined report, not a certificate
  • Issued only by a licensed CPA firm; Aegentra prepares you and brokers the audit
  • Restricted-use report your buyers read in vendor risk review; SOC 3 is the public summary
  • Market-driven, not legally mandated — the de-facto requirement for selling SaaS into the US
  • Not SOX: SOX is financial-reporting law for US-listed groups — a different engagement we also cover

Report choice

Type I vs Type II — which report you actually need

A Type I report describes your system and tests whether controls are suitably designed at a single point in time. A Type II report covers an observation window — commonly three, six, or twelve months — and tests whether those controls operated effectively across the whole period. Buyers know the difference: a Type I proves you built the machine, a Type II proves the machine runs. The pragmatic path for most Australian providers is a Type I to unblock the deal that is on the table now, rolling straight into the Type II window so the stronger report lands within the year. We design the programme so evidence collected from day one of the observation window counts, and so the same controls serve both reports without rework.

Point in time

Type I

Type I — design of controls at a point in time; fastest path to a first report

Observation period

Type II

Type II — operating effectiveness over a 3–12 month observation window; what mature buyers ask for

  • Common sequence: readiness → Type I → Type II window opens immediately after
  • Renewal is annual — Type II reports roll forward with a fresh observation period each year
  • Bridge letters cover the gap between report periods for procurement teams

Trust Services Criteria

Scope only what buyers need.

Scoping the Trust Services Criteria

Every SOC 2 includes the Security criteria — the Common Criteria — as its mandatory backbone. The other four categories are optional and should be scoped commercially, not aspirationally: Availability if you sell an SLA, Confidentiality if you hold sensitive customer data (most SaaS should), Processing Integrity if your platform's output is the product — billing, payroll, calculations — and Privacy only when you make specific privacy commitments to individuals. Over-scoping inflates both the audit fee and the ways an auditor can find exceptions; under-scoping triggers buyer pushback. We scope the system description around the service your customers actually buy — the platform, its infrastructure, the people and processes behind it, and the subservice organisations underneath (your cloud provider is usually carved out, with complementary controls documented).

Security

Mandatory in every SOC 2

Required

Availability

When you contractually commit to uptime

Confidentiality

When you hold sensitive customer data

Processing integrity

When customers rely on the correctness of output

Privacy

For direct privacy commitments to individuals

Evidence path

A continuous trace, not a document scramble.

Readiness: from gap assessment to evidence that holds

Readiness is where SOC 2 engagements are won or lost. We start with a gap assessment of your current state against the scoped criteria, then design and implement the controls in the stack you already run — identity and access in your cloud tenant, change management in your development pipeline, vendor management, incident response, logging and monitoring. Policies are written to match how you actually operate, not templates the auditor will see through. Then evidence: the Aeges risk engine collects control evidence live from your environment across the observation window, so when the CPA firm issues its request list, the population and samples are already sitting there — timestamped, complete, and mapped to the criteria. That is the difference between a two-week fieldwork and a three-month evidence chase.

  1. Scope

    Choose the criteria and define the service boundary.

  2. Build

    Implement controls in the cloud stack you already operate.

  3. Operate

    Run the controls across the agreed reporting period.

  4. Evidence

    Collect timestamped evidence and map it to each criterion.

  5. Attest

    A licensed CPA firm examines the controls and issues its opinion.

  • Gap assessment against your scoped Trust Services Criteria, with a costed remediation plan
  • Controls implemented in your real stack — identity, change, vendor, incident, monitoring
  • Policies drafted to match your operation, mapped criterion by criterion
  • Live evidence collection through Aeges across the whole observation window
  • Auditor request (PBC) list largely pre-answered before fieldwork opens

Delivery model

Choose for the capacity you have.

SOC 2 consultant, compliance platform or integrated delivery?

Choose the delivery model around the capacity you actually have. A software-only compliance platform can organise controls and evidence requests, but your team still owns scoping, control design, remediation and the CPA relationship. An advisory-only consultancy can interpret the criteria and write the programme, while your engineers implement it. Aegentra combines practitioner-led readiness with hands-on control implementation, live evidence collection through Aeges and CPA-auditor liaison. That integrated model is designed for SaaS teams that need the work delivered without turning engineering into a full-time compliance function; teams with a mature internal GRC owner may reasonably prefer software or advisory support alone.

Model 01

Software-only

useful for workflow and evidence organisation; internal owners still design and operate the programme

Model 02

Advisory-only

criteria interpretation and documents; your engineering team implements and evidences the controls

Model 03

Aegentra integrated delivery

readiness, cloud control implementation, live evidence and CPA liaison in one scope

/ Delivery team

Who will deliver your SOC 2 readiness engagement?

The readiness scope identifies the accountable lead, the systems and controls inside scope and any technical contribution required to prepare evidence for the independent examination.

ResponsibilityAccountable delivery
Assigned roleSOC 2 readiness lead
How it is confirmedThe named lead, scope, deliverables and client responsibilities are agreed in writing.
ResponsibilityTechnical contribution
Assigned roleControl or system specialist, where required
How it is confirmedThe specialist function and evidence responsibility are recorded in the scope.
ResponsibilityExamination boundary
Assigned roleIndependent CPA firm
How it is confirmedAegentra provides readiness support. The independent practitioner performs the examination and issues the SOC report.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

Readiness support does not guarantee an examination result. The assigned roles and evidence responsibilities are confirmed for the agreed scope.

Independence boundary

Aegentra prepares. A CPA firm attests.

Only a licensed CPA firm can issue a SOC 2 report, and the same independence principle we apply to ISO 27001 applies here: the firm that attests cannot be the team that built your controls. That separation is a feature — it means Aegentra sits entirely on your side. We shortlist CPA firms that fit your size and timeline, brief them on the system description, negotiate the scope so you are not paying for criteria you don't need, manage the request list during fieldwork, and handle exceptions before they become qualified opinions. If you already have an audit firm, we work with them. Your engineers keep shipping; we speak auditor.

The CPA-auditor liaison — we sit on your side of the table

  • Shortlisting and engagement of a licensed CPA firm sized to your business
  • System description (Section 3) drafted with you and defended in fieldwork
  • Request-list management — evidence delivered from Aeges, not from engineers' weekends
  • Exception handling and remediation before the opinion is drafted
  • Works equally with a CPA firm you already engage

Combined programme

Build SOC 2 on the ISO 27001 controls you already operate

The Trust Services Criteria and ISO 27001's Annex A cover many of the same operational areas: access control, change management, operations security, incident management, vendor management and monitoring. Where existing controls and evidence are valid for both programmes, Aegentra maps them once, closes the SOC 2-specific gaps and sequences the ISO audit cycle with the SOC 2 observation window. The result is one coordinated control environment serving Australian, UK, European and US buyer requirements.

  • Aeges evidence re-used across both programmes wherever valid
  • Combined programme: one control set feeding both the certificate and the report
  • ISO 27001 answers AU/UK/EU procurement; SOC 2 answers US enterprise buyers
  • Sequenced so the SOC 2 observation window and ISO audit cycle don't collide

At a glance

The scoping record, before work begins.

The report type, criteria, observation period, delivery responsibilities and separate CPA fee are made explicit in the agreed scope.

What SOC 2 is
AICPA attestation report against the Trust Services Criteria
Who issues the report
A licensed CPA firm — we prepare you; the CPA firm attests
Type I vs Type II
Control design at a point in time vs operating effectiveness over 3–12 months
Mandatory scope
Security (Common Criteria); Availability, Confidentiality, Processing Integrity, Privacy optional
Who asks for it
US enterprise buyers of SaaS and managed services
ISO 27001 overlap
60–80% shared controls — combined programme available
Typical readiness
8–12 weeks to audit-ready; Type II window 3–12 months
Where controls live
Your cloud stack, evidenced live through Aeges
Fee structure
Fixed fee, quoted after a scoping call; CPA audit fee separate
Delivery
Remote-first, Australia-wide and worldwide

Questions buyers ask

SOC 2, clearly answered.

Report, scope, timeline, cost and ownership — without treating an attestation like a certification.

No — SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a detailed report with an opinion; there is no certificate and no accredited certification body involved. That's why buyers ask to read the report itself. Aegentra's role is readiness and audit preparation — we design and implement the controls, collect the evidence, and liaise with the CPA firm that issues the report.

Start with scope

Know the report, criteria and evidence path before you commit.

A practitioner reviews the buyer requirement, service boundary and delivery responsibilities, then provides a written plan and fixed price for the agreed work. The CPA audit fee remains separate.

Book a SOC 2 scoping call