IronSights

Compliance · SOC 2

SOC 2 ready, without the guesswork.

Your US customers are asking for a SOC 2 report and nobody internally has done one before. We scope it, find the gaps, fix them, and get your evidence into a state an auditor will accept.

One fixed-fee engagement, run by an Australian team that holds ISO 27001 itself. The audit stays with an independent CPA firm, which is exactly how it should be.

ISO 27001 certified ourselves
Fixed-fee engagements
Australian team

Scope, stated plainly

We get you ready. A CPA firm signs it.

A SOC 2 report is an attestation performed under AICPA standards, and only a licensed CPA firm can issue one. Any consultancy promising to certify you is selling something that does not exist.

Everything before that point is where the actual work sits, and it is the part most businesses underestimate. That is what we do.

Gap assessment

We map your current controls against the Trust Services Criteria in scope and tell you plainly what is missing. You get a findings register, not a slide deck.

Control remediation

We build and implement what is missing: access reviews, change management, logging and monitoring, vendor management, onboarding and offboarding.

Evidence and documentation

Policies, procedures and the evidence trail an auditor will ask for. Written so your team can maintain them after we leave.

Audit support

We help you select a CPA firm, prepare for fieldwork, and answer the auditor's requests alongside your team.

The five criteria

Scope only what you actually need.

Security is mandatory. The other four are optional, and adding them without a reason makes the engagement longer and the audit more expensive for no commercial gain. We scope to what your customers are asking for.

Security

Required

The only mandatory criterion. Protection against unauthorised access, covering access control, change management, monitoring and incident response.

Availability

Optional

Whether the system is available as committed. Relevant if you have uptime obligations written into customer contracts.

Confidentiality

Optional

Protection of information designated as confidential. Usually in scope when you hold customer data under a non-disclosure obligation.

Processing integrity

Optional

Whether processing is complete, valid and accurate. Most relevant to transaction and payment platforms.

Privacy

Optional

How personal information is collected, used and disposed of. Overlaps heavily with your Privacy Act obligations.

Why bother

What the report buys you.

US enterprise buyers expect it

For Australian software and services businesses selling into the United States, SOC 2 is often the first thing procurement asks for. No report, no deal.

It shortens security reviews

A current report answers most of a customer questionnaire before anyone fills one in. Sales cycles get shorter because security stops being the bottleneck.

The work is not wasted

The controls behind SOC 2 overlap heavily with ISO 27001 and the Essential Eight. Businesses doing both find most of the technical work counts twice.

It survives growth

A Type II report covers a period rather than a moment, so it demonstrates the controls actually operated. That is what enterprise buyers are checking for.

How it works

From first question to signed report.

  1. Scoping

    Which criteria apply, which systems are in scope, and whether Type I or Type II fits where you are now.

  2. Gap assessment

    Current state measured against the criteria. Findings rated so you fix what blocks the report first.

  3. Remediation

    We implement the missing controls with your team, rather than handing you a list and walking away.

  4. Evidence

    Policies, procedures and the operating evidence your auditor will sample. Set up to keep producing itself.

  5. Audit

    A licensed CPA firm performs the examination and issues the report. We support you through fieldwork.

Already doing something else

The work counts more than once.

Access control, change management, logging, vendor review and incident response appear in every framework worth holding. If you have already done Essential Eight work, or you are weighing SOC 2 against ISO 27001, most of the technical groundwork carries across. Our audit and assurance team runs them as one programme rather than three.

Common questions

SOC 2, answered straight.

Not answered here? Get in touch and we will tell you whether you need it yet.

  1. Can IronSights issue our SOC 2 report?

    No, and neither can any other consultancy. A SOC 2 report is an attestation performed under AICPA standards and it can only be issued by a licensed CPA firm. Anyone telling you they will certify you is describing something that does not exist. What we do is everything that comes before: scope it, find the gaps, fix them, build the evidence, and support you through the audit. The auditor stays independent, which is the point.

  2. Is SOC 2 a certification?

    Not technically, though almost everyone calls it one. ISO 27001 gives you a certificate. SOC 2 gives you a report, written by an auditor, describing your controls and whether they were operating. The distinction matters when a customer asks for your certificate and what you have is a report, which is normal and correct.

  3. Type I or Type II?

    Type I says your controls were designed properly at a point in time. Type II says they actually operated over a period, commonly somewhere between three and twelve months. Type II is what enterprise buyers usually want. Type I is a reasonable first step if you need something in front of a customer quickly, and it gets you most of the way to Type II.

  4. We already have ISO 27001. Do we need SOC 2 as well?

    It depends entirely on who is asking. ISO 27001 carries more weight in Australia, Europe and Asia. SOC 2 is what United States buyers ask for. If your customer base spans both, you will probably end up with both, and the good news is that the underlying controls overlap enough that the second one is much less work than the first.

  5. How long does it take?

    Scope drives it, so we give you a timeline at scoping rather than a number that suits nobody. The part people underestimate is the observation window for Type II: the auditor needs to see controls operating over a period, so there is a stretch where the work is done and you are simply running properly while evidence accumulates.

  6. What does it cost?

    Two separate costs. Ours is a fixed fee agreed at scoping, covering the gap assessment, remediation and evidence work. The auditor's fee is separate and paid to the CPA firm directly. We will tell you the realistic range for both before you commit to either.

First step

Find out how far away you really are.

Send us the customer request or the questionnaire that started this. We will tell you which criteria you actually need, what is missing, and whether Type I or Type II is the right first move.