What is not included: the audit firm's fee. You engage the CPA firm directly, because the firm that prepares you cannot issue your report. Australian audit firms typically charge between $5,000 and $35,000 for a SOC 2 audit. The fee tracks audit effort, which tracks how many Trust Services Criteria are in scope and how complex your environment is. A SaaS business with Security criteria only and a single production environment sits at the lower end. We will give you a specific figure on the first call.
Most SaaS companies come to us because an enterprise prospect asked for SOC 2 and the deal has stopped. Type 1 answers that question at month four. It confirms your controls are designed correctly and in place at a point in time, and it is usually enough to get procurement moving again.
Type 2 is the one that proves the controls actually operated over a period. It follows on the same subscription, with the report landing at month nine. You are not paying for a second engagement to get there.
| Month | What Siege Cyber does | What you end the month with |
|---|---|---|
| 1 | Kickoff, pick the Trust Services Criteria, gap analysis, agree the system description | Scope, a gap report and a decision on which criteria are in |
| 2 | Write policies, design controls, set up evidence collection | A control set matched to the criteria, and a way to evidence it |
| 3 | Implement controls, security awareness training, external penetration test, dry run the auditor's requests | Controls in place, a test report, a rehearsed evidence process |
| 4 | Auditor walkthrough and point-in-time testing | SOC 2 Type 1 report issued |
| 5 to 7 | Three month observation period. Monthly access reviews, incident and change records, evidence checks | A continuous evidence trail the auditor can sample |
| 8 | Auditor fieldwork across the observation period | Testing complete, exceptions understood |
| 9 | Report drafting, management response, issuance | SOC 2 Type 2 report issued |
| 10 to 12 | Operate, remediate exceptions, prepare for the next cycle | Ready to move to a longer observation window at renewal |
Three months is the shortest period most auditors will sign, and for a small SaaS business it is usually the right choice. But not for the reason people assume.
The window length is set by evidence sufficiency, not headcount. What makes three months defensible for a small SaaS is that the control set is narrow, the systems are few and the evidence is clean. A complex environment with the same headcount would still need longer.
The practical consequence is that anything running quarterly has to land inside those three months. Access reviews, vendor reviews, the risk assessment refresh. We schedule those deliberately rather than letting them drift into month four.
The trade-off, said plainly. A three month window produces a thinner report than a six or twelve month one. Some enterprise buyers will ask for a longer period next cycle. That is why months 10 to 12 exist in the table above, and why MAINTAIN is the natural follow-on. We would rather you heard this from us than from your prospect's security reviewer.
| Month | Your time | What only you can do |
|---|---|---|
| 1 | Half a day a week | Name an internal owner, confirm scope, give access to systems |
| 2 | Half a day a week | Approve the control set and the system description |
| 3 | One day a week | Implement technical controls in your own systems, staff complete training |
| 4 | Two days in the audit week | Be available for the auditor's walkthrough |
| 5 onward | Two hours a month | Approve access reviews, keep the evidence trail current |
What we do not do: implement controls inside your systems, and issue your report. The second is not a choice, it is the rule that makes the report worth anything.
A mining services company, 80 staff. A prime contractor required independent assurance over their field data platform. We delivered a SOC 2 Type 1 report in nine weeks. They have since committed to a six month observation period to pursue Type 2.
On that timeframe. Nine weeks was a tightly scoped Type 1 with a client who moved fast on their side. Four months is what we commit to. It is also worth noting that this client chose a six month observation window rather than three, because their prime contractor wanted the longer period. Both are valid, and which one suits you is a scoping conversation, not a default.
Through CERTIFY, a Type 1 report at month four and a Type 2 report at month nine on a three month observation window. Longer observation periods push the Type 2 report out accordingly.
CERTIFY is $3,750 a month on a 12 month subscription, $45,000 for the year, including an external penetration test. The CPA firm's audit fee is separate and paid by you directly, typically $5,000 to $35,000 depending on how many criteria are in scope.
Type 1 says your controls were designed properly and in place on a given date. Type 2 says they actually operated over a period. Type 1 unblocks most deals. Type 2 is what mature enterprise buyers eventually want.
Not formally mandated, but widely expected, particularly for Type 2 where the auditor wants evidence that controls operated. A well-scoped test with documented remediation and a retest gives the auditor what they need. We include one.
No. A SOC 2 report is issued by an independent CPA firm, and a firm that prepared you cannot issue it. We prepare you and work alongside the auditor. You engage them directly.
Those platforms automate evidence collection well. They do not scope your criteria, write your system description, make judgement calls about what is in and out, or sit in the room with the auditor. We work with both, and we will make sure your penetration testing evidence is mapped correctly inside the tool.
Commissioning a penetration test that does not align with the systems inside the SOC 2 boundary. The report then does not satisfy the auditor and the test has to be redone. Scoping it right at the start saves both time and money.
These are about our penetration testing work rather than about compliance programmes. We have included them here because the external penetration test is part of CERTIFY, and because they are real, named and checkable. When we have compliance clients willing to be quoted, we will add those too.
Overall our experience with Peter and the Siege Cyber team was excellent. He was very professional in understanding our needs and delivered a thorough and comprehensive security report. We wouldn’t hesitate in recommending Siege Cyber to our customers.
Stefan Alpert, General Manager, FriendlyWare Partners, NSW
We have partnered with Peter and the team at Siege Cyber as a trusted advisor to perform penetration testing and vulnerability assessments to deliver our clients visibility and a clear understanding of their security footprint. Leveraging the results Siege Cyber provide has enabled our SME and enterprise clients to have peace of mind that security baselines, actionable security plans and roadmaps are in place and helping to protect their ICT systems and data.
Sam Gilchrist, GM Sales, eNerds, NSW
Siege Cyber are thorough and professional in their approach to penetration testing and the outcome report is well structured and delivered. Peter and the team are very knowledgeable and are a pleasure to work with, I’d recommend them to anyone.
Sasha Hajenko, Director, Blue Phoenix Systems, ACT
We engaged Peter of Siege Cyber to perform a penetration test on one of our largest clients that has critical logistics systems running 24/7. Peter was the utmost professional and worked directly with Intellica and the client’s senior leadership team throughout the process to ensure confidentiality of information and avoidance of impact on operational activities. I highly recommend Peter and Siege Cyber and look forward to utilising them for future engagements.
Oliver Caldwell, Managing Director, Intellica, QLD