SOC 2 for Australian SaaS, Type 1 in Four Months

A prospect asked for your SOC 2 report and you do not have one. CERTIFY gets you a Type 1 report in four months and a Type 2 report at month nine, for $3,750 a month, with an Australian team doing the work. The external penetration test your auditor will expect is included, not sold separately.

Your Biggest Deal Is Stuck in Procurement

You have made it through discovery, demo and technical evaluation. Then security review asks for your SOC 2 report, and you do not have one. The deal does not die, it just stops, and stopped deals have a habit of not restarting.

The usual answer is a readiness consultant on day rates and a timeline nobody will put in writing. You end up paying for the uncertainty rather than the outcome, while the prospect waits.

CERTIFY is the opposite arrangement. One monthly fee, one agreed scope, a Type 1 report at month four to unblock the deal, and a Type 2 report at month nine on the same subscription.

What you get for $3,750 a month

  • Trust Services Criteria scoped to your business, not every criterion by default
  • A complete policy and control set, written for a SaaS operation
  • An Australia-based compliance team
  • An external penetration test, included. At our published rates that is $5,900 to $16,500 of testing inside the subscription
  • Evidence collection set up properly from month 2, so the observation period produces a usable trail
  • Auditor liaison, walkthrough preparation and fieldwork support
  • Security awareness training
  • A free compliance management platform, with no separate subscription

What is not included: the audit firm's fee. You engage the CPA firm directly, because the firm that prepares you cannot issue your report. Australian audit firms typically charge between $5,000 and $35,000 for a SOC 2 audit. The fee tracks audit effort, which tracks how many Trust Services Criteria are in scope and how complex your environment is. A SaaS business with Security criteria only and a single production environment sits at the lower end. We will give you a specific figure on the first call.

Type 1 is what unblocks the deal

Most SaaS companies come to us because an enterprise prospect asked for SOC 2 and the deal has stopped. Type 1 answers that question at month four. It confirms your controls are designed correctly and in place at a point in time, and it is usually enough to get procurement moving again.

Type 2 is the one that proves the controls actually operated over a period. It follows on the same subscription, with the report landing at month nine. You are not paying for a second engagement to get there.

The timeline, month by month

Month What Siege Cyber does What you end the month with
1 Kickoff, pick the Trust Services Criteria, gap analysis, agree the system description Scope, a gap report and a decision on which criteria are in
2 Write policies, design controls, set up evidence collection A control set matched to the criteria, and a way to evidence it
3 Implement controls, security awareness training, external penetration test, dry run the auditor's requests Controls in place, a test report, a rehearsed evidence process
4 Auditor walkthrough and point-in-time testing SOC 2 Type 1 report issued
5 to 7 Three month observation period. Monthly access reviews, incident and change records, evidence checks A continuous evidence trail the auditor can sample
8 Auditor fieldwork across the observation period Testing complete, exceptions understood
9 Report drafting, management response, issuance SOC 2 Type 2 report issued
10 to 12 Operate, remediate exceptions, prepare for the next cycle Ready to move to a longer observation window at renewal

Why a three month observation window

Three months is the shortest period most auditors will sign, and for a small SaaS business it is usually the right choice. But not for the reason people assume.

The window length is set by evidence sufficiency, not headcount. What makes three months defensible for a small SaaS is that the control set is narrow, the systems are few and the evidence is clean. A complex environment with the same headcount would still need longer.

The practical consequence is that anything running quarterly has to land inside those three months. Access reviews, vendor reviews, the risk assessment refresh. We schedule those deliberately rather than letting them drift into month four.

The trade-off, said plainly. A three month window produces a thinner report than a six or twelve month one. Some enterprise buyers will ask for a longer period next cycle. That is why months 10 to 12 exist in the table above, and why MAINTAIN is the natural follow-on. We would rather you heard this from us than from your prospect's security reviewer.

What you actually have to do

Month Your time What only you can do
1 Half a day a week Name an internal owner, confirm scope, give access to systems
2 Half a day a week Approve the control set and the system description
3 One day a week Implement technical controls in your own systems, staff complete training
4 Two days in the audit week Be available for the auditor's walkthrough
5 onward Two hours a month Approve access reviews, keep the evidence trail current

What we do not do: implement controls inside your systems, and issue your report. The second is not a choice, it is the rule that makes the report worth anything.

Work we have done

A mining services company, 80 staff. A prime contractor required independent assurance over their field data platform. We delivered a SOC 2 Type 1 report in nine weeks. They have since committed to a six month observation period to pursue Type 2.

On that timeframe. Nine weeks was a tightly scoped Type 1 with a client who moved fast on their side. Four months is what we commit to. It is also worth noting that this client chose a six month observation window rather than three, because their prime contractor wanted the longer period. Both are valid, and which one suits you is a scoping conversation, not a default.

Common questions

How long does SOC 2 take?

Through CERTIFY, a Type 1 report at month four and a Type 2 report at month nine on a three month observation window. Longer observation periods push the Type 2 report out accordingly.

How much does SOC 2 cost in Australia?

CERTIFY is $3,750 a month on a 12 month subscription, $45,000 for the year, including an external penetration test. The CPA firm's audit fee is separate and paid by you directly, typically $5,000 to $35,000 depending on how many criteria are in scope.

What is the difference between Type 1 and Type 2?

Type 1 says your controls were designed properly and in place on a given date. Type 2 says they actually operated over a period. Type 1 unblocks most deals. Type 2 is what mature enterprise buyers eventually want.

Is a penetration test required for SOC 2?

Not formally mandated, but widely expected, particularly for Type 2 where the auditor wants evidence that controls operated. A well-scoped test with documented remediation and a retest gives the auditor what they need. We include one.

Can you be our auditor?

No. A SOC 2 report is issued by an independent CPA firm, and a firm that prepared you cannot issue it. We prepare you and work alongside the auditor. You engage them directly.

We already use Vanta or Drata. Do we still need you?

Those platforms automate evidence collection well. They do not scope your criteria, write your system description, make judgement calls about what is in and out, or sit in the room with the auditor. We work with both, and we will make sure your penetration testing evidence is mapped correctly inside the tool.

What is the most common mistake?

Commissioning a penetration test that does not align with the systems inside the SOC 2 boundary. The report then does not satisfy the auditor and the test has to be redone. Scoping it right at the start saves both time and money.

What clients and partners say

These are about our penetration testing work rather than about compliance programmes. We have included them here because the external penetration test is part of CERTIFY, and because they are real, named and checkable. When we have compliance clients willing to be quoted, we will add those too.

Overall our experience with Peter and the Siege Cyber team was excellent. He was very professional in understanding our needs and delivered a thorough and comprehensive security report. We wouldn’t hesitate in recommending Siege Cyber to our customers.

Stefan Alpert, General Manager, FriendlyWare Partners, NSW

We have partnered with Peter and the team at Siege Cyber as a trusted advisor to perform penetration testing and vulnerability assessments to deliver our clients visibility and a clear understanding of their security footprint. Leveraging the results Siege Cyber provide has enabled our SME and enterprise clients to have peace of mind that security baselines, actionable security plans and roadmaps are in place and helping to protect their ICT systems and data.

Sam Gilchrist, GM Sales, eNerds, NSW

Siege Cyber are thorough and professional in their approach to penetration testing and the outcome report is well structured and delivered. Peter and the team are very knowledgeable and are a pleasure to work with, I’d recommend them to anyone.

Sasha Hajenko, Director, Blue Phoenix Systems, ACT

We engaged Peter of Siege Cyber to perform a penetration test on one of our largest clients that has critical logistics systems running 24/7. Peter was the utmost professional and worked directly with Intellica and the client’s senior leadership team throughout the process to ensure confidentiality of information and avoidance of impact on operational activities. I highly recommend Peter and Siege Cyber and look forward to utilising them for future engagements.

Oliver Caldwell, Managing Director, Intellica, QLD

Strengthen your organisation’s security and simplify your path to SOC 2 compliance Australia with Siege Cyber’s SOC 2 Compliance Assistance service. Whether you're in Brisbane, Sydney, or anywhere across Australia, our experts help identify gaps, provide actionable recommendations, and guide you through the process toward successful SOC2 certification Australia. To learn how our tailored support for SOC 2 Brisbane, SOC 2 Sydney, and beyond can elevate your cybersecurity strategy and meet compliance requirements, download our detailed datasheet today.

Not sure a packaged engagement is what you need yet? Our SOC 2 compliance and audit preparation page covers the standard itself, what an audit involves and how the Trust Services Criteria apply to your business.