
How Often Do You Need a SOC 2 Audit in Australia?
Once a year. A SOC 2 report has no formal expiry date, but a Type 2 report covers a defined observation period, and enterprise buyers almost always ask for one whose period ended within the last twelve months. That convention, not the AICPA, is what sets the cadence. Plan on a twelve month cycle: an observation window, fieldwork, a report, then the next window opening as the last one closes.
Below is what the cycle looks like month by month, how long a report actually stays useful, and the one situation where an Australian business can reasonably skip a renewal.

How often are SOC 2 audits done?
SOC 2 audits are done annually by most service organisations. The AICPA SOC suite of services sets no renewal interval, so the annual rhythm comes from the market: procurement teams and security reviewers treat a report older than about twelve months as stale, and ask for a newer one.
A SOC 2 Type 1 report describes controls at a single point in time and is not renewed as such. Most Australian businesses use one once, as a stepping stone, then move to Type 2. A Type 2 report covers a period, and it is the Type 2 cycle that repeats every year. The difference is set out in SOC 2 Type 1 versus Type 2.
How long is a SOC 2 report valid?
A SOC 2 report does not expire, because it is a statement about a period that has already finished rather than a certificate with a validity date. In practice a report stops being commercially useful about twelve months after the end of its observation period, because that is the cut-off most customer security reviews apply.
| Time since period end | How customers usually treat it | What to do |
|---|---|---|
| 0 to 3 months | Current, accepted without question | Nothing |
| 3 to 9 months | Accepted, sometimes with a bridge letter request | Have a bridge letter ready |
| 9 to 12 months | Questioned. Buyers ask when the next one is due | Confirm the next observation window in writing |
| Over 12 months | Generally treated as out of date | Expect to be asked for a current report before contract |
The gap between the end of one report period and the start of the next is covered by a bridge letter, a short statement from management that nothing material changed. Bridge letters usually cover up to about three months, and auditors will not stretch them much further. See what a SOC 2 bridge letter is and when you need one for the format.
What does the annual SOC 2 cycle look like?
A first SOC 2 Type 2 examination takes nine to twelve months from readiness assessment to report, because the observation window has to run its full length before an auditor can test anything. Renewals then settle into a twelve month rhythm where the next window opens as the previous report is issued.

The observation window is the constraint that surprises people. Controls have to be running, and generating evidence, for the whole period before fieldwork begins. A compliance platform can make evidence collection easier, but it cannot make six months of history appear. Our guide to preparing for a SOC 2 audit covers what to do in each phase.
Should your first observation period be 3, 6 or 12 months?
Choose a three month window if a customer contract is waiting, six months as the standard first Type 2, and twelve months once you are renewing and want the report period to line up with your financial year. A shorter window gets you a report sooner but gives reviewers less to look at.
| Window | Best for | Trade-off |
|---|---|---|
| 3 months | A deal that is blocked now and needs a Type 2 quickly | Some enterprise reviewers ask why it was so short |
| 6 months | Most first Type 2 examinations | None significant. This is the common default |
| 12 months | Renewals, and businesses aligning to a financial year | Longer wait, more sample evidence to produce |
Whichever you choose, the window only counts if the controls were genuinely operating throughout it. A readiness assessment before the window opens is what stops you discovering a broken control in month five.
Do you have to renew if only one customer asked for it?
No. Renewing a SOC 2 report is a commercial decision, not a legal or regulatory obligation in Australia. If the customer who asked has since signed a multi-year contract and no one else has requested a report in twelve months, pausing the examination is a defensible choice, provided you keep the controls running.

The risk in pausing is not the missing report. It is that access reviews, vulnerability management and change control quietly stop happening once nobody is auditing them, so the next examination needs a fresh six month window and a remediation project. Keep the controls and the evidence, and a future report is a scheduling exercise rather than a rebuild.
Be honest with buyers about where you are. Saying the last report covered a period ending in March and the next window opens in July is a reasonable answer in a security review. Implying you hold a current report when you do not is the answer that ends deals.
What is the Australian equivalent of a SOC 2 audit?
There is no Australian SOC 2. SOC 2 is an AICPA framework and the examination is performed by a licensed CPA firm under United States attestation standards. Australian businesses obtain SOC 2 reports from CPA firms, many of which operate here through local offices or affiliates.
Australia does have its own service organisation assurance standard, ASAE 3402, issued by the Auditing and Assurance Standards Board, which covers controls at a service organisation relevant to customer financial reporting. It is the closer analogue to SOC 1 than to SOC 2. For a security-focused credential that Australian and international buyers recognise, the usual alternative is ISO 27001 certification.
Which one you need is a market question rather than a technical one. If your buyers are North American technology companies, they will ask for SOC 2. If they are Australian enterprises, government departments or European customers, ISO 27001 is often the better investment. Our comparison of SOC 2 versus ISO 27001 in Australia works through the decision, and which Trust Services Criteria apply covers scoping the report itself.
What else has to happen every year?
A SOC 2 cycle carries a handful of annual obligations beyond the examination itself. Most auditors will ask for evidence of each one, and missing them is a common cause of exceptions in a first Type 2 report.
- Risk assessment. Refreshed at least annually, with the results feeding the control set.
- Penetration testing. Not named in the Trust Services Criteria, but auditors and customers expect annual testing. See whether penetration testing is required for SOC 2.
- Security awareness training. Completed and recorded for every person in scope.
- Access reviews. Usually quarterly, with evidence of who reviewed what and what was removed.
- Vendor reviews. Your own suppliers assessed, including reading their SOC 2 reports properly.
- Incident response testing. A test or a real incident, documented either way.
Common questions
How often are SOC 2 reports required?
There is no rule requiring them at any interval. Customers set the cadence, and the market convention is a report covering a period that ended within the last twelve months. Most service organisations therefore run one Type 2 examination a year, with each observation window starting where the last one finished.
How long does a SOC 2 audit take?
A first Type 2 usually takes nine to twelve months end to end: one to three months of remediation, a three to twelve month observation window, then four to eight weeks of fieldwork and reporting. Renewals are faster because remediation is done and evidence collection is already in place, so the elapsed time is essentially the window plus fieldwork.
Does a SOC 2 report expire?
Not formally. A SOC 2 report is an opinion on a period that has already ended, so it has no expiry date printed on it. Commercially it stops carrying weight about twelve months after the period end, and a bridge letter can cover roughly three months of the gap between reports.
Who does SOC 2 audits in Australia?
Licensed CPA firms, working to AICPA attestation standards. Several international firms perform SOC 2 examinations for Australian clients from local offices, and some Australian practices partner with a United States firm that signs the report. An Australian consultancy can prepare you for the examination but cannot issue the report.
What is the difference between a SOC 2 audit and an ISO 27001 audit?
A SOC 2 examination produces a detailed report describing your controls and the auditor’s testing, which you share under NDA. ISO 27001 produces a certificate from an accredited certification body, which you can publish. SOC 2 repeats annually as a full examination. ISO 27001 runs on a three year cycle with lighter surveillance audits in years two and three.
Can you have continuous SOC 2 compliance instead of annual audits?
You can run controls continuously, and monitoring tools help with that, but the report is still produced by an examination covering a finished period. There is no mechanism in the AICPA standards for a permanently current SOC 2 report. Continuous monitoring makes each annual examination cheaper and less disruptive, which is a real benefit, just not a replacement.
Planning your next SOC 2 cycle
If your last report period ended more than six months ago, the useful question is not whether you are still compliant but when your next observation window opens. Work backwards from the date a customer will next ask, and start the window early enough that fieldwork is not a scramble.
Siege Cyber helps Australian businesses get ready for SOC 2 examinations and keep the controls running between them. Learn more about our SOC 2 readiness and support or get in touch to map out your cycle.