If a US customer has asked whether you’re “SOC 2 compliant,” here’s what they mean. SOC 2 (System and Organization Controls 2) is a US framework for reporting on how well a service organisation protects customer data. It’s widely requested of SaaS and technology companies selling into the United States, and Australian businesses increasingly need it to close enterprise deals there.

What is SOC 2, exactly?
SOC 2 is an attestation report, not a certificate. It’s produced by an independent US CPA (accounting) firm, which examines your controls against the AICPA’s Trust Services Criteria and issues a report on how well they’re designed and operating. Because it’s a report rather than a pass/fail certification, customers read the actual report to satisfy their own due diligence.
The five Trust Services Criteria
- Security: the mandatory criterion, protecting systems against unauthorised access.
- Availability: systems are available for operation and use as agreed.
- Processing integrity: processing is complete, accurate and timely.
- Confidentiality: information designated as confidential is protected.
- Privacy: personal information is handled in line with commitments.
Security is always included; you add the others based on what you do and what customers expect.
Type I vs Type II
Type I assesses whether your controls are suitably designed at a single point in time. Type II goes further, testing whether those controls operated effectively over a period, usually three to twelve months. Type II carries far more weight with customers, so most organisations aim for a Type I first, then a Type II covering the following period.
SOC 2 vs ISO 27001
The two overlap heavily. ISO 27001 is an internationally certifiable management-system standard; SOC 2 is a US attestation report. Australian and international buyers generally recognise ISO 27001, while SOC 2 is more US-centric. The good news: a single, well-built information security management system can support both, so you don’t have to build twice. See ISO 27001 vs SOC 2 for a full comparison.
How to get SOC 2 from Australia
The report itself must be issued by a licensed CPA firm, but the bulk of the work is getting your control environment ready, which is where Streamline helps. The path is: define your scope and which Trust Services Criteria apply, build and document the controls (ideally on an ISO 27001 foundation), run a readiness assessment to close gaps, then engage a CPA firm for the Type I, followed by the Type II observation period.
How Streamline helps
We provide SOC 2 readiness and advisory: building and documenting your controls, running the readiness assessment, and getting you audit-ready, typically on an ISO 27001 base so the same work earns both. We’re independent of the attesting CPA firm, so we prepare you properly rather than marking our own homework.
Frequently asked questions
Is SOC 2 a certification?
No. It’s an attestation report issued by a CPA firm, not a certificate. Customers read the report itself. ISO 27001, by contrast, results in a certificate.
Do Australian companies need SOC 2 or ISO 27001?
It depends on your customers. US buyers often ask for SOC 2; Australian, European and international buyers usually recognise ISO 27001. Many companies build one system that supports both.
Speak with an experienced ISO auditor
Need SOC 2 to win a US customer? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











