Sector · Software & SaaS
ISO 27001 first, SOC2 mapped from the same evidence.
Australian software businesses are pushed toward tools built for cloud-native stacks and priced by headcount. If you run on Google Workspace or a mixed estate, you want evidence that is deliberate and a rate that is flat.
What gets asked
The stack.
The standards this sector is asked for, and why.
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS).
SOC2
AICPA Trust Services Criteria for service organisations, run from the same evidence as your ISO 27001 controls.
ACSC Essential Eight
The Australian Signals Directorate's eight mitigation strategies, assessed at maturity levels 1–3.
- Enterprise procurement
- US customers asking for SOC2
- Government customers asking for E8
The first eight weeks
A worked plan.
What a typical programme looks like on ISO Assist. Scope and existing evidence move the dates; the shape holds.
- WEEK 1
Adopt 27001; SOC2 criteria mapped alongside. Owners across engineering and operations.
- WEEK 2–4
Evidence from your existing tooling linked or uploaded; vendor register for sub-processors.
- WEEK 5–7
Secure development, change and incident policies adapted; access reviews; internal audit.
- WEEK 8
27001 Stage 1 pack; SOC2 gap list to decide on a CPA engagement.
Registers that matter
What you will actually maintain.
Registers are data on a generic engine: pack-defined columns, CSV in and out, evidence links per row.
Example
Illustrative, a typical programme, not a named customer.
A B2B software team on Google Workspace keeping every 27001 control mapped, with SOC2 criteria credited from the same evidence and one flat annual rate.
Book the Software demo.
Bring your tender clause or client request. We adopt the standards it names, live.