Straight answers for Melbourne companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Melbourne?
+
No. Melbourne is part of our Australia service area. We are headquartered in Gurugram, India, and serve Melbourne from there in AEST-friendly hours, with on-site days for kick-off, control walkthroughs and audit days when scope requires. Most of a SOC 2 or ISO 27001 engagement runs over video and shared evidence trackers regardless of where the consultant sits, and we say so plainly before you sign.
Will Australian enterprise buyers accept a SOC 2 prepared by an India-based consultancy?
+
Yes, because the opinion is not ours. A SOC 2 report is signed by an independent licensed audit firm — a CPA firm under AICPA standards, or an Australian CA/CPA firm reporting under ASAE 3150. TCSA prepares your controls and evidence and coordinates that firm; the buyer’s security team reviews the auditor’s opinion and the control tests, not the readiness consultant’s address. Our Australian customers include NIAD and InDepthIT, and we arrange reference calls before you commit.
Our product is an AI system. Is ISO 42001 worth doing before ISO 27001?
+
Usually alongside, not before. ISO 42001 shares its management-system structure with ISO 27001 — context, leadership, risk, support, operation, performance evaluation — so building the two together costs far less than sequencing them. If enterprise buyers are already asking for SOC 2 or ISO 27001, do that first and add the ISO 42001 AI controls, impact assessments and lifecycle records on top. Certification is by an accredited certification body; we prepare and coordinate.
We hold Victorian health data. Does ISO 27701 cover the Health Records Act as well as the Privacy Act?
+
ISO 27701 is a privacy management framework, not a certificate of legal compliance with either Act. What it does is give you one documented system — roles, data inventory, purposes, retention, breach handling — that you map to the Australian Privacy Principles and Victoria’s Health Privacy Principles in a single crosswalk. That is what hospital and enterprise customers ask to see; legal interpretation of either Act stays with your privacy counsel.
Type I or Type II — what should a Melbourne startup ask the auditor for?
+
Type I reports on control design at a point in time and unblocks a deal quickly once readiness is done. Type II reports on operating effectiveness over an observation window, commonly 3 to 12 months, and is what US enterprise buyers increasingly require before a large contract. Readiness typically takes 8–12 weeks for a team with a reasonable baseline. Anyone promising a Type II in weeks is describing readiness, not the attestation.
We sell to universities. Do we need anything beyond ISO 27001?
+
Usually ISO 27001 is the certificate university procurement accepts, plus a current penetration-test report and a completed institutional questionnaire. Because higher education sits within the SOCI Act’s critical-infrastructure sectors, some universities also ask vendors about continuity and incident-reporting arrangements; we cover those in the ISMS or, where the contract demands it, with ISO 22301.
Can you work with our existing compliance-automation platform?
+
Yes. Many Melbourne SaaS teams already run Vanta, Drata or a similar platform. We design the controls, write the policies and prepare the audit while the platform collects evidence; you do not need to buy software to work with us, and we do not resell any.
How is pricing structured for Melbourne engagements?
+
Fixed fee, agreed in writing after a scoping call, invoiced in AUD or INR as you prefer. Typical bands are USD 2,500–6,000 equivalent for SOC 2 readiness consulting, USD 3,000–8,000 equivalent for ISO 27001 implementation and from about USD 1,000 equivalent for a web-application VAPT. Audit-firm and certification-body fees are quoted separately by those firms, and we help you scope them.