
Short answer: SOC 2 is not an Australian legal requirement, but Australian SaaS and HealthTech companies pursue it because US customers ask for it in security reviews. A SOC 2 report is issued by a CPA firm under AICPA standards. It complements, and does not replace, your Privacy Act, Essential Eight and APRA CPS 234 obligations.
Related guides:
- SOC 2 Type 2: what it is and how to prepare
- How to choose SOC 2 auditors
- Australian Privacy Principles for small business
Key takeaways
- SOC 2 is a US attestation framework from the AICPA. No Australian law requires it, but US buyers and many global enterprise buyers expect it.
- AICPA SOC 2 examinations are performed by CPAs under AICPA attestation standards. Australian firms may also deliver SOC 2 style reports under Australian assurance standards such as ASAE 3000, so confirm which standard your customer will accept before you engage an auditor.
- SOC 2 overlaps heavily with APP 11 of the Privacy Act, the Essential Eight, ISO 27001 and APRA CPS 234, but does not close every gap.
- The usual path is readiness, a Type 1 report to unblock early deals, then a Type 2 report over an observation period.
Why do Australian companies need SOC 2?
Australian companies need SOC 2 mainly because their US customers require it before they will share data with a vendor. SOC 2 is a report US buyers commonly ask for, often early in the security review.
Without one, deals stall: buyers send long questionnaires instead, procurement needs a signed security exception, or the vendor can drop out of consideration. Australian enterprises with US parents and investors running technical due diligence ask for SOC 2 too.
SOC 2 is not a certification, and it is not an Australian compliance obligation. It is an independent auditor's opinion on whether your controls meet the AICPA Trust Services Criteria for security, and optionally availability, processing integrity, confidentiality and privacy. Your legal obligations in Australia still come from the Privacy Act 1988 and, for some customers, regulators such as APRA.
Who can issue a SOC 2 report for an Australian company?
AICPA SOC 2 examinations are performed by CPAs under the AICPA's attestation standards (AT-C 105 and AT-C 205). The AICPA describes its SOC suite as services that "CPAs may provide", and its information for CPAs states that "A CPA may be engaged to examine and report on controls at a service organization." Before you engage a firm, ask who will sign the report, what credential they hold and which standard the report will be issued under.
In Australia you will see two routes:
| Route | Standard used | What you receive | When it works best |
|---|---|---|---|
| AICPA SOC 2 examination | AICPA attestation standards (AT-C 105 and AT-C 205) with the Trust Services Criteria | A SOC 2 report issued by a CPA under AICPA standards | Selling to US buyers who expect an AICPA report |
| Australian assurance engagement | ASAE 3000 or ASAE 3150, using the Trust Services Criteria as the criteria | An Australian assurance report on the same criteria | Buyers who confirm in advance that they accept it; US buyers may not treat it as a SOC 2 |
BDO Australia states that in Australia it uses ASAE 3000, the equivalent of ISAE 3000, as the primary vehicle to deliver SOC 2 assurance reports.
The Australian standards themselves are set by the Auditing and Assurance Standards Board (AUASB):
- ASAE 3150 Assurance Engagements on Controls covers assurance engagements on controls at an entity, outside financial reporting. The current version was approved on 6 September 2022.
- ASAE 3402 Assurance Reports on Controls at a Service Organisation covers controls relevant to customers' financial reporting. It is the Australian counterpart to SOC 1, not SOC 2.
- GS 007 is AUASB guidance on the audit implications of using service organisations for investment management services, and it is not a SOC 2 substitute.
Before signing an engagement letter, ask which standard the report will be issued under, who will sign the opinion and what licence they hold. Our guide to SOC 2 auditors covers the rest of the selection criteria.
How does SOC 2 fit with Australian obligations?
SOC 2 sits alongside Australian obligations as evidence of a working security program, but it does not demonstrate compliance with any of them on its own. The controls overlap heavily, so one control set can serve several purposes if you map it deliberately.
| Australian obligation or framework | What it requires | Overlap with SOC 2 | Gaps SOC 2 does not address directly |
|---|---|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles (APPs) | APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access | High for APP 11 through SOC 2 security controls; partial through the optional Privacy criteria | Collection notices, APP 8 cross-border disclosure steps, access and correction requests, and Australian-specific privacy policy content |
| Notifiable Data Breaches (NDB) scheme | Assess suspected eligible data breaches within 30 days and notify affected individuals and the OAIC as soon as practicable | Medium: SOC 2 tests incident response | The serious harm assessment and the OAIC notification process |
| Essential Eight (ASD) | Eight mitigation strategies assessed against Maturity Levels Zero to Three | Medium: SOC 2 controls for patching, MFA, admin privileges and backups often support Essential Eight strategies | SOC 2 is principles-based, so it does not require specific Essential Eight controls such as application control or macro settings, and it does not map to maturity levels |
| ISO/IEC 27001 | A certified information security management system (ISMS) | High: many SOC 2 controls can be mapped to Annex A controls | ISMS clauses such as the Statement of Applicability and management review |
| APRA CPS 234 (for regulated customers) | Regulated entities must assess the security capability of third parties and notify APRA of material incidents within 72 hours | Medium: a SOC 2 report is common evidence in third-party assessments | Contractual notification timelines, board reporting and customer-specific testing |
Three points stand out.
The Privacy Act may apply to you even if you are small. According to the OAIC, the small business exemption currently covers businesses with annual turnover of $3 million or less (reform to narrow or remove it has been proposed), but health service providers are always covered, regardless of turnover. Our Australian Privacy Principles guide explains the exceptions in detail.
Essential Eight questions come from Australian buyers. Australian government and enterprise customers often ask for your Essential Eight maturity level, which a SOC 2 report does not answer. See our comparison of Cyber Essentials and the Essential Eight for how the maturity levels work.
APRA-regulated customers push CPS 234 down the supply chain. CPS 234 has applied since 1 July 2019. If you sell to banks, insurers or super funds, expect your SOC 2 report to be reviewed alongside contract clauses on incident notification. Our APRA CPS 234 checklist covers what vendors typically need to show.
SOC 2 or ISO 27001: which should an Australian company get first?
Choose SOC 2 first if your pipeline is mostly US buyers, and ISO 27001 first if your pipeline is mostly Australian, European or Asian buyers. Both frameworks rely on similar security controls, so much of the work for the first can be reused for the second.
A quick way to decide:
- US customers are blocking deals: SOC 2 first.
- Australian enterprise or government buyers are asking for "certification": ISO 27001 first. Look for a certification body accredited for ISO/IEC 27001, for example by JAS-ANZ in Australia and New Zealand.
- Both markets matter equally: design one control set mapped to both and sequence the audits within the same year.
What is the step-by-step path to a SOC 2 audit in Australia?
The path is scope, readiness, remediation, a Type 1 report, then a Type 2 report over an observation period. The steps are the same as anywhere else, but a few decisions are specific to Australian companies.
- Define your scope. Pick the product, infrastructure, people and processes your US customers rely on. Decide which Trust Services Criteria to include. Security is always in scope. Availability and confidentiality are common additions for SaaS, and privacy is worth considering if you handle health or other sensitive data.
- Choose your reporting standard and auditor early. Decide between an AICPA SOC 2 examination and an Australian standard such as ASAE 3000 or ASAE 3150, based on what your target customers accept. Factor in time zone overlap for walkthroughs.
- Run a readiness assessment. Compare your current controls against the criteria and list every gap. If you already work towards the Essential Eight or ISO 27001, map those controls first so you do not build them twice.
- Remediate. Common gaps include formal policies, access reviews, change management approvals, vendor risk reviews, security awareness training and documented incident response. Our SOC 2 compliance checklist lists the controls auditors expect.
- Get a Type 1 report. A Type 1 report gives the auditor's opinion on the design of your controls at a single point in time. It helps unblock early deals.
- Run the observation period and get a Type 2 report. A Type 2 report covers the operating effectiveness of controls over a period. The period length is agreed with your auditor; first reports often use a shorter period than later ones. Many US buyers will ask for Type 2, so plan for it from the start.
- Keep it current. Buyers usually expect a recent report, so treat evidence collection as an ongoing process rather than a once-a-year project.
What should Australian HealthTech companies plan for?
Australian HealthTech companies should plan for SOC 2, HIPAA and Australian health privacy obligations at the same time, because their buyers on both sides of the Pacific will ask about all three. Health information is sensitive information under the Privacy Act, and health service providers are covered regardless of turnover.
If you handle protected health information (PHI) for US healthcare organisations, expect to sign business associate agreements and show HIPAA safeguards. SOC 2 covers much of the technical groundwork.
Watch data location too. US customers may want US hosting, while APP 8 requires care with overseas disclosure. Decide early whether you run separate regional environments, and make sure your SOC 2 scope reflects that.
How SecureSlate helps
SecureSlate helps Australian SMBs and HealthTech teams prepare for SOC 2 without a large compliance team. A control library maps SOC 2 criteria to ISO 27001 and HIPAA, and you can track the Essential Eight as a framework and Australian requirements such as the APPs as a custom framework. During a Type 2 observation period, automated evidence collection gathers and stores evidence from your cloud and SaaS stack. Policy templates, a risk register and vendor risk workflows support readiness work, and audit-ready exports help you share evidence with your auditor.
Start your free SecureSlate trial
FAQ
Is SOC 2 mandatory in Australia?
No. No Australian law or regulator requires SOC 2. Companies get it because customers, especially in the US, require it. Your legal obligations come from the Privacy Act 1988 and, where relevant, rules such as APRA CPS 234 that regulated customers pass on to you.
Can an Australian accounting firm issue a SOC 2 report?
An AICPA SOC 2 examination is performed by a CPA under AICPA attestation standards, so ask any firm who will sign the report and under which standard. Australian firms can also issue reports against the Trust Services Criteria under Australian standards such as ASAE 3000. Check which format your customers accept before you engage a firm.
What is the difference between ASAE 3150 and SOC 2?
ASAE 3150 is an Australian assurance standard for reports on controls at an entity, issued by the AUASB. SOC 2 is an AICPA reporting framework that uses the Trust Services Criteria. An ASAE 3150 engagement can use similar criteria, but it is not an AICPA SOC 2 examination, and some US buyers specifically ask for the AICPA report.
Does a SOC 2 report satisfy the Essential Eight?
Not on its own. SOC 2 is principles-based: your controls for areas such as patching, multi-factor authentication, admin privileges and backups can support Essential Eight strategies, but SOC 2 does not require specific Essential Eight controls such as application control or Microsoft Office macro settings, and it does not map to Essential Eight maturity levels.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds