Straight answers for Brisbane companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Brisbane?
+
No. Brisbane is part of our Australia service area. We are headquartered in Gurugram, India, and serve Brisbane from there in AEST-friendly hours, with on-site days for kick-off, control walkthroughs and audit days when scope requires. Most of a SOC 2 or ISO 27001 engagement runs over video and shared evidence trackers regardless of where the consultant sits, and we say so plainly before you sign.
Will Australian enterprise buyers accept a SOC 2 prepared by an India-based consultancy?
+
Yes, because the opinion is not ours. A SOC 2 report is signed by an independent licensed audit firm — a CPA firm under AICPA standards, or an Australian CA/CPA firm reporting under ASAE 3150. TCSA prepares your controls and evidence and coordinates that firm; the buyer’s security team reviews the auditor’s opinion and the control tests, not the readiness consultant’s address. Our Australian customers include NIAD and InDepthIT, and we arrange reference calls before you commit.
We want to host Queensland Government data. Do we need IRAP, and can you do it?
+
Possibly, and no. Cloud services hosting government data at certain classification levels commonly require an IRAP assessment by an Australian-endorsed assessor, and TCSA does not perform IRAP assessments. What we can do is build the ISO 27001 ISMS that most of the same questionnaire draws on — asset inventory, access control, logging, incident response, supplier management — so that when you engage an IRAP assessor the evidence already exists. Confirm the classification and assessment requirement with the agency before scoping either.
A mining major has sent us a supplier security assessment. Which framework answers it?
+
Almost always ISO 27001, backed by a current penetration-test report and, for systems the customer treats as operationally critical, tested continuity arrangements. The majors’ supplier-assurance programmes are built around recognised standards rather than bespoke checklists; an ISO 27001 certificate from a JAS-ANZ-accredited body, plus ISO 22301 where remote-site continuity matters, answers most of the questionnaire in one pass.
We are an aged-care software vendor with a small team. Does the Privacy Act still apply to us?
+
Very likely. Organisations that provide a health service and hold health information are APP entities regardless of turnover, and aged-care software commonly handles exactly that information on a provider’s behalf. You will also inherit obligations by contract from the providers you serve. ISO 27001 sized for a small team, with the privacy pieces mapped to the APPs, is the proportionate way to evidence it; confirm your specific status with privacy counsel.
How long does SOC 2 take for a Brisbane SaaS company?
+
Readiness typically takes 8–12 weeks for a company with a reasonable security baseline. A Type I report can follow within weeks of readiness. Type II needs an observation window, commonly 3 to 12 months, plus the audit firm’s examination. Anyone promising a Type II in weeks is describing readiness, not the attestation.
Is a penetration test from an India-based team acceptable to Australian customers?
+
Yes — what a customer or auditor reviews is the methodology, the scope, the findings and the retest, not the tester’s location. Our reports are written for the person reading them in a vendor review: executive summary, risk-rated findings, reproduction steps and a retest letter once remediation is done. Where a contract names a specific accreditation or an Australian-endorsed assessor, we tell you before scoping so you are not paying for a test that will not be accepted.
How is pricing structured for Brisbane engagements?
+
Fixed fee, agreed in writing after a scoping call, invoiced in AUD or INR as you prefer. Typical bands are USD 2,500–6,000 equivalent for SOC 2 readiness consulting, USD 3,000–8,000 equivalent for ISO 27001 implementation and from about USD 1,000 equivalent for a web-application VAPT. Audit-firm and certification-body fees are quoted separately by those firms, and we help you scope them.