rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/soc-2-vs-iso-27001-australian-assurance-reports
Printed 28 August 2026
SOC 2 or ISO 27001: which security assurance artefact your customers actually want
SOC 2 is an attestation report; ISO 27001 is a certificate. How they differ in scope, evidence and renewal, and which Australian buyers ask for which.
Australian businesses selling software, data processing or managed services are routinely asked for "your SOC 2" or "your ISO cert" in a procurement questionnaire, usually with no explanation of which one the buyer needs or why. The two are not interchangeable. They are produced by different professions, under different rule sets, and they answer different questions.
This article is about the assurance artefact itself — what it proves, what an assessor tests, what you hand a customer, and what happens each year to keep it alive. It is not an implementation guide for an information security management system.
The difference in one line: a certificate versus a report
ISO/IEC 27001 produces a certificate; SOC 2 produces a report. That single distinction drives almost every other difference.
An ISO/IEC 27001 certificate is issued by a certification body after it audits your information security management system (ISMS) against the standard. The certificate is short, public-facing, and states the standard, the certificate number, the validity period and — critically — the scope statement. It says a conforming ISMS exists. It does not tell the reader which controls you selected or how well any of them worked.
A SOC 2 report is issued by an accounting firm under the American Institute of Certified Public Accountants (AICPA) attestation standards, using the Trust Services Criteria. It typically runs to 60–120 pages and contains the practitioner's opinion, management's description of the system, the list of controls tested, the tests performed, and — the part buyers read first — any exceptions the practitioner found. It is normally released under a non-disclosure agreement, not published.
So: a certificate is a badge, a report is evidence. A buyer who wants to run their own vendor risk assessment wants the report. A buyer who wants a box ticked wants the certificate.
What each one actually covers
ISO/IEC 27001 covers the management system: context, leadership, risk assessment and treatment, competence, internal audit, management review, and corrective action, together with the Annex A controls you selected. The set of controls you excluded, and why, is recorded in your Statement of Applicability. The certificate is only as meaningful as its scope statement, which is why a sophisticated buyer reads the scope before anything else — a certificate scoped to "the corporate head office" tells them nothing about the production platform.
SOC 2 covers whichever Trust Services Criteria categories you nominate. The security category (the common criteria) is mandatory. Availability, processing integrity, confidentiality and privacy are optional add-ons. A report scoped to security only says nothing about uptime, and a buyer relying on it for availability commitments is misreading it.
| ISO/IEC 27001 | SOC 2 | |
|---|---|---|
| Output | Certificate plus audit report to you | Attestation report for customers |
| Issued by | Accredited certification body | Public accounting firm |
| Rule set | The standard, plus accreditation rules | AICPA attestation standards and Trust Services Criteria |
| Scope control | Scope statement and Statement of Applicability | Nominated criteria categories and system description |
| Failures visible to buyer | No | Yes, as exceptions in the report |
| Typical shelf life | Three-year cycle | The report period, usually 12 months |
| Usually public | Yes | No, released under NDA |
Type 1 and Type 2, stage 1 and stage 2
The two regimes both split the assessment in two, but they mean different things by it, and this is the most common source of confusion in Australian procurement.
SOC 2 Type 1 tests whether controls were suitably designed at a single point in time. SOC 2 Type 2 tests whether those controls operated effectively over a period — a minimum of three months, most commonly six or twelve. A Type 1 is a snapshot; a Type 2 is a film. Buyers who know the difference will accept a Type 1 once, from a first-time vendor, on the condition that a Type 2 follows.
ISO/IEC 27001 stage 1 is a readiness and documentation review. Stage 2 is the certification audit proper, where the auditor samples records and tests whether the ISMS operates as documented. Both stages happen before the certificate issues; neither is an alternative to the other, and there is no ISO equivalent of the "design only" Type 1 report.
The practical consequence is timing. A Type 2 cannot be produced faster than its observation window, so a vendor that has just switched on its controls is structurally incapable of handing a customer a twelve-month Type 2 this quarter. Certification is faster to a first artefact but slower to useful detail.
The Australian equivalents nobody asks for by name
Australia has its own controls assurance standards, issued by the Auditing and Assurance Standards Board. They are used constantly and named rarely.
- ASAE 3402 covers assurance reports on controls at a service organisation that are relevant to user entities' financial reporting. It is the local analogue of a SOC 1.
- ASAE 3150 covers assurance engagements on controls more generally, including operational and compliance controls. It was formulated for Australian purposes and has no international equivalent, and it expressly excludes the financial-reporting controls dealt with in ASAE 3402.
An Australian practitioner can issue a controls report under ASAE 3150 that does substantively what a SOC 2 does. Buyers rarely ask for it by name because the term "SOC 2" has become the market shorthand. If your customer base is entirely domestic and your auditor is Australian, an ASAE 3150 report is a legitimate answer to a SOC 2 request — but expect to explain it, and expect a US-headquartered buyer to push back.
Which artefact each Australian buyer asks for
| Buyer | Usually asks for | Why |
|---|---|---|
| ASX-listed enterprise procurement | ISO/IEC 27001 certificate | Simple to verify, fits a supplier register |
| APRA-regulated entity | Either, plus your control detail | It must meet CPS 234 obligations over material service providers |
| US or global SaaS buyer | SOC 2 Type 2 | Their own vendor risk process is built around it |
| Commonwealth agency | Neither — an IRAP assessment | Government systems are assessed against the Information Security Manual |
| Federal supply chain (services) | Essential Eight maturity | Assessed under Right Fit For Risk, not ISO |
| Mid-market Australian business | ISO/IEC 27001 certificate | Cheapest signal to check |
The government columns matter. An ISO/IEC 27001 certificate does not satisfy a Commonwealth agency assessing a system against the Information Security Manual — that is a separate exercise, covered in IRAP assessments and hosting Australian government data. Nor does it substitute for a maturity rating under the Essential Eight; see ISO 27001 vs the Essential Eight and Essential Eight maturity levels explained.
Evidence the assessor will ask you to produce
The evidence sets overlap heavily. The difference is that a SOC 2 Type 2 practitioner samples across the whole observation window and will record a failed sample as an exception in a document your customers read.
| Control area | ISO/IEC 27001 auditor asks for | SOC 2 Type 2 practitioner asks for |
|---|---|---|
| Risk management | Risk assessment methodology, risk register, treatment plan, Statement of Applicability | Risk assessment performed during the period |
| Access control | Access policy, sample of approvals | Joiner, mover and leaver samples across the period, plus periodic access reviews |
| Change management | Documented process, sample changes | Change tickets sampled across the period with approval and testing evidence |
| Monitoring | Logging policy, evidence of review | Alert and incident records for the period, with response times |
| Governance | Internal audit programme, management review minutes | Board or management oversight evidence for the period |
| Suppliers | Supplier security requirements, evaluations | Vendor reviews performed during the period |
| Incidents | Incident procedure, corrective actions | Every in-scope incident in the period and its handling |
If you hold personal information, the same evidence largely answers your obligations under APP 11, which is worth designing for once rather than assembling three times.
Renewal mechanics and what drives cost
ISO/IEC 27001 runs a three-year cycle: stage 1 and stage 2 in year zero, a surveillance audit in year one, another in year two, and a full recertification audit in year three. Surveillance audits sample a subset of the ISMS; recertification is a full re-assessment. Certificates lapse if the cycle is not maintained. The transition from the 2013 edition to the 2022 edition closed on 31 October 2025, after which certificates issued against the superseded edition were withdrawn (checked August 2026) — if a supplier hands you a certificate against the 2013 edition today, it is not current.
SOC 2 has no cycle in the same sense. Each report covers a stated period, and buyers expect continuous coverage: consecutive periods with no gap. A gap in coverage is treated as a red flag, because it is exactly where an incident could hide.
Cost varies too widely to quote a figure honestly, and anyone quoting one without seeing your scope is guessing. The drivers are consistent:
- Scope size — number of in-scope systems, products, entities and physical sites.
- Number of criteria or controls — adding availability and privacy to a SOC 2, or a large Annex A control set to an ISO scope.
- Observation window — a twelve-month Type 2 costs more to support than a three-month one, mostly in your own staff time.
- Evidence maturity — automated, system-generated evidence is cheaper to audit than screenshots assembled by hand.
- Remediation — findings from a readiness review are your cost, not the auditor's, and they are usually the largest line item in year one.
- Multi-site sampling — auditors sample sites, and more geographies means more sampling.
Two practical points. First, run a gap assessment before you engage an auditor; the ISO 27001 gap assessment tool is a reasonable starting inventory. Second, if you are also caught by Essential Eight maturity or CPS 234, map the evidence once. Most of what a SOC 2 practitioner samples is the same evidence an Essential Eight assessor tests, described in different vocabulary.
Frequently asked
Is SOC 2 a certification?
No. SOC 2 is an attestation report issued by a public accounting firm under the AICPA's attestation standards using the Trust Services Criteria. There is no certificate and no certification body. Vendors who advertise being 'SOC 2 certified' are using the term loosely — what they hold is a report, and you should ask to read it under NDA rather than accept the claim.
Do Australian businesses need SOC 2 or ISO 27001?
Neither is required by Australian law. Both are commercial requirements imposed by customers. Australian and ASX-listed buyers most often ask for an ISO/IEC 27001 certificate because it is quick to verify; US-headquartered and global SaaS buyers usually ask for a SOC 2 Type 2 because their vendor risk process is built around reading the report. Commonwealth agencies ask for neither and instead require assessment against the Information Security Manual.
What is the Australian equivalent of a SOC 2 report?
ASAE 3150 Assurance Engagements on Controls, issued by the Auditing and Assurance Standards Board, is the closest local analogue for operational and compliance controls. ASAE 3402 covers controls at a service organisation relevant to user entities' financial reporting and is the analogue of a SOC 1. ASAE 3150 was formulated for Australian purposes and has no international equivalent.
How long is an ISO 27001 certificate valid?
The certification cycle runs three years: stage 1 and stage 2 audits to obtain the certificate, a surveillance audit in each of the following two years, and a full recertification audit in year three. Missing a surveillance audit can suspend or withdraw the certificate. Certificates issued against the superseded 2013 edition ceased to be valid after the transition closed on 31 October 2025 (checked August 2026).
Can one audit produce both a SOC 2 report and an ISO 27001 certificate?
Not from a single engagement, because the two are issued by different professions under different rule sets. The underlying evidence, however, overlaps substantially, and many organisations run a combined evidence programme so that access reviews, change records, incident records and supplier reviews are collected once and used for both. Some firms offer coordinated scheduling to reduce duplicated fieldwork.
Does a SOC 2 report show whether the vendor failed anything?
Yes, and this is its main advantage over a certificate. A SOC 2 Type 2 report lists the controls tested, the tests performed and any exceptions found, together with management's response. A certificate discloses none of that. If you are assessing a vendor rather than collecting badges, read the exceptions section and the scope of the system description first.
Related
Related reading
ISO 27001 vs the Essential Eight: which framework for Australian business
ISO 27001 vs Essential Eight for Australian business: how the two frameworks differ, who each suits, certification vs maturity levels, and when to do both.
APRA CPS 234 Information Security: The Standalone Deep Dive
Plain-English guide to APRA Prudential Standard CPS 234 Information Security — in force since 1 July 2019, with 72-hour breach notification to APRA.
IRAP assessments and hosting Australian government data: the certification path
How an IRAP assessment works, what an IRAP assessor can and cannot give you, and how the Hosting Certification Framework sits alongside it (checked August 2026).
Essential Eight assessments: evidence quality, control ratings and what an assessor accepts
ASD grades evidence from excellent to poor and rates every control. How the ratings work and why one ineffective control sinks a whole maturity level.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/soc-2-vs-iso-27001-australian-assurance-reports