Blog

SOC 2 in Australia: Which Trust Services Criteria Apply?

A SOC 2 project usually starts with an email. A customer’s procurement team asks for your SOC 2 report, and it lands in your inbox with a note that says do we have this?

The question most businesses ask next is “how do we get SOC 2?” That is the wrong question, and it is an expensive one to ask first. The better question is what should our SOC 2 actually cover? That single decision drives your timeline, your audit fee and how much of your team’s year disappears into evidence collection.

That decision is the Trust Services Criteria. If you are an Australian business with somewhere between two and a hundred staff, getting this right is the difference between a manageable compliance project and one that quietly takes over.

At Siege Cyber we help Australian businesses scope, prepare for and pass SOC 2 without paying for controls nobody asked them to have.

What the Trust Services Criteria actually are

SOC 2 is not a standard you comply with in the way you comply with ISO 27001. There is no fixed list of requirements that every organisation must meet. Instead, an independent auditor reports on how well your controls meet a set of criteria that you help select.

Those criteria are the Trust Services Criteria, published by the American Institute of Certified Public Accountants. There are five categories, and this is the part most businesses do not realise until they are already committed: you choose which of them apply to you.

Diagram of the five SOC 2 Trust Services Criteria showing Security as mandatory and Availability, Confidentiality, Processing Integrity and Privacy as optional
The five Trust Services Criteria. Security is mandatory in every SOC 2 report. The other four are scoping decisions.

Security is the only category you must include

Security, often called the Common Criteria, is mandatory. Every SOC 2 report includes it, and for a large number of Australian SMBs it is the only category they ever need.

It covers protection against unauthorised access, disclosure and damage to your systems and the information in them. Underneath it sit nine Common Criteria:

  • CC1 Control environment – governance, organisational structure, accountability and how you hire and manage people
  • CC2 Information and communication – how security expectations are communicated internally and to customers
  • CC3 Risk assessment – how you identify, analyse and respond to risk, including fraud risk
  • CC4 Monitoring activities – how you check that your controls are actually working
  • CC5 Control activities – the policies and procedures that put your risk decisions into practice
  • CC6 Logical and physical access controls – who can get to what, and how you prove it
  • CC7 System operations – detecting, responding to and recovering from incidents and vulnerabilities
  • CC8 Change management – how changes to systems are requested, tested, approved and deployed
  • CC9 Risk mitigation – business disruption and how you manage risk from vendors and partners

A Security-only SOC 2 report is a complete, legitimate and widely accepted report. If a customer has asked you for “a SOC 2” without specifying anything further, this is almost certainly what will satisfy them.

The four optional categories, and when each earns its place

The remaining four categories are added only when your business genuinely makes commitments in those areas. Adding one because it sounds thorough is the most reliable way to make a SOC 2 project cost more and take longer than it needed to.

Availability

Covers whether your systems are available for operation and use as you have committed. Add it if you sell uptime. If your contracts contain a service level agreement, if customers pay you to be reachable, or if an outage on your side stops your customer trading, Availability belongs in your scope.

If you provide a service people use during business hours and no contract promises a specific uptime figure, you probably do not need it.

Confidentiality

Covers information that has been designated as confidential and how you protect it through its lifecycle, including disposal. Add it if your contracts or NDAs commit you to protecting customer material such as source code, commercial terms, unpublished financials or intellectual property.

This is the most commonly added second category for Australian SMBs, and usually for good reason.

Processing Integrity

Covers whether system processing is complete, valid, accurate, timely and authorised. Add it if you calculate, transact or process on a customer’s behalf and the accuracy of that processing is the thing they are buying. Payroll, payments, billing engines, claims processing and financial calculation tools are the obvious cases.

Most SaaS products do not need it. If your software stores and displays information rather than computing an answer your customer relies on, this is usually out of scope.

Privacy

Covers the collection, use, retention, disclosure and disposal of personal information. Add it if handling personal information is central to what you do, or if a customer has explicitly asked for it.

Be careful here, because Privacy is the category most often added by mistake. Australian businesses already have obligations under the Privacy Act 1988 and the Australian Privacy Principles. Those obligations exist whether or not Privacy is in your SOC 2 scope, and meeting them does not require you to add the category. Adding Privacy adds a substantial set of controls and a great deal of evidence.

Why every extra category costs you twice

Each criterion you add brings three things with it: controls you have to design, evidence you have to produce every month, and audit testing you have to pay for. The first is a project. The second and third never end.

Timeline showing the SOC 2 path for an Australian SMB from scoping through gap analysis, remediation, Type 1 report, observation window and Type 2 report
Scope is decided at the very start, and it shapes the cost and duration of every stage after it.

Adding Privacy or Processing Integrity when no customer has asked for them is the most common way an Australian SMB overspends on SOC 2.

It is worth understanding how scope interacts with report type. A Type 1 report assesses whether your controls are designed appropriately at a single point in time. A Type 2 report assesses whether they operated effectively across a period, typically three to twelve months. Every category in your scope has to be evidenced across that entire window, month after month. Two extra categories do not add twenty per cent to the workload. They can double it.

What most Australian SMBs actually need

Across the businesses we work with, the pattern is consistent:

  • Security only. Suitable for the majority of Australian SMBs being asked for SOC 2 for the first time, particularly where the request came from a single enterprise customer.
  • Security and Confidentiality. The usual choice where contracts or NDAs create explicit obligations over customer material.
  • Security, Confidentiality and Availability. Appropriate for SaaS businesses that sell against a service level agreement.
  • Anything more. Justified when a named customer has asked for it in writing, or when processing accuracy or personal information handling is the core of your product.

If you are weighing SOC 2 against other frameworks first, our comparison of ISO 27001 and SOC 2 for Australian companies is a better starting point than this article. It is also worth reading whether SOC 2 is mandatory in Australia before you commit budget to it.

Where penetration testing fits

The Trust Services Criteria do not name penetration testing as a requirement. What they do require, under CC4 and CC7, is that you monitor your controls and that you detect and respond to vulnerabilities in your systems.

In practice that means auditors expect to see a working vulnerability management process, and most expect independent security testing as part of the evidence that it works. A current penetration test report with tracked remediation is one of the cleanest ways to demonstrate both, and it is evidence your enterprise customers will ask for separately anyway.

If you are scoping SOC 2 and a pen test in the same year, sequence them so the test happens early enough for remediation to land inside your observation window rather than after it.

How to decide your scope this week

You do not need a consultant to make the first cut. Do this in an afternoon:

  • Read the actual request. Go back to the customer email or questionnaire. Most say “SOC 2 Type 2” and nothing about categories. That is a Security-only answer until proven otherwise.
  • Search your contracts for uptime commitments. If you find a service level agreement with a specific availability figure, Availability is in scope. If not, it probably is not.
  • Search your contracts for confidentiality obligations. Look for clauses covering customer data, source code or commercial information. This usually settles Confidentiality quickly.
  • Ask whether your software computes anything the customer relies on. If it calculates money, entitlements or obligations, consider Processing Integrity. If it stores and presents information, do not.
  • Ask the customer directly. A short email asking which Trust Services Criteria they require is normal, professional, and can save you tens of thousands of dollars.

Then write your answer down and make your auditor argue you out of it, rather than starting from a broad scope and trying to argue your way back.

Common questions

Do I have to include all five Trust Services Criteria?

No. Security is the only mandatory category. The other four are included only where your organisation makes commitments in those areas, and a Security-only SOC 2 report is complete and widely accepted.

Can I add a category later?

Yes. Many organisations start with Security and add a category at a later audit as customer requirements change. It is far easier to expand scope than to justify contracting it after your first report.

Does SOC 2 replace our obligations under the Privacy Act?

No. Australian privacy obligations apply independently of SOC 2. Including the Privacy category in your scope does not discharge them, and excluding it does not avoid them.

How long does a SOC 2 take for a small Australian business?

Scoping and gap analysis typically take four to six weeks. Remediation commonly runs two to four months. A Type 2 report then requires an observation window of three to twelve months. Timeframes vary considerably with your starting maturity and your auditor.

Getting the scope right the first time

Scope is the cheapest decision in a SOC 2 project to get right and the most expensive to get wrong. It is set in the first fortnight, and everything after it inherits the consequences.

Siege Cyber helps Australian businesses decide what their SOC 2 should cover, close the gaps and get through the audit without carrying controls their customers never asked for. If you have been sent a SOC 2 request and are not sure what it means for your business, get in touch and we will walk you through it.

You can also read more about our SOC 2 readiness and compliance services, or explore virtual CISO support if you need someone to own this alongside your team.