Skip to main contentChat with us

Service area · Perth, Australia · Reviewed September 2026

Compliance Consultants Serving Perth
ISO 27001, ISO 22301 & SOC 2 for mining, energy and engineering vendors

Tranquility Cybersecurity serves Perth as part of its Australia service area from its Gurugram headquarters, in AWST-friendly hours, with on-site days in the CBD, West Perth, Subiaco or Osborne Park when an audit requires them. Perth companies come to us for ISO 27001 when their buyers are mining, oil-and-gas and engineering majors, ISO 22301 when those buyers — often SOCI responsible entities — ask for tested continuity arrangements, and SOC 2 when a Perth-built software product starts selling into the United States. Perth is only 2.5 hours ahead of India, so the whole working day overlaps.

500+Audits delivered
250+SOC 2 attestations
100+SOC 1 reports
India, USA, UK, Australia & UAEWhere our clients are

Quick facts

Compliance in Perth, in six lines

How we serve Perth
Service area, served from our Gurugram headquarters in AWST-friendly hours, with on-site days for kick-off, control walkthroughs and audit days as scope requires.
Frameworks Perth buyers ask for
ISO 27001:2022, ISO 22301 for resources-sector continuity clauses, SOC 2 (Type I and Type II) for US-bound software, VAPT for web, mobile and API, and vCISO for lean teams.
Who signs what
SOC 2 reports are signed by an independent licensed audit firm — a CPA firm under AICPA standards, or an Australian CA/CPA firm reporting under ASAE 3150; ISO certificates by JAS-ANZ-accredited certification bodies. TCSA prepares you and coordinates both — it never issues or certifies.
Typical readiness budget
ISO 27001 implementation USD 3,000–8,000 equivalent; SOC 2 readiness consulting USD 2,500–6,000 equivalent; VAPT web-app tests from about USD 1,000 equivalent; invoiced in AUD or INR.
Time zone
AWST is 2.5 hours ahead of IST and Western Australia has no daylight saving, so our full working day overlaps yours all year — the closest overlap of any Australian city.
Track record
500+ audits, 250+ SOC 2 attestations and 100+ SOC 1 reports across India, USA, UK, Australia and UAE.

The local picture

What Perth’s compliance demand actually looks like

Perth is the corporate capital of Australia’s resources industry. The CBD and West Perth hold the headquarters and regional offices of mining, oil-and-gas and engineering companies whose operations run in the Pilbara, the Goldfields and offshore — and the remote-operations centres that control them from the city. Around those anchors sits a dense layer of services vendors: mine-planning, fleet-management and geoscience software, engineering and asset-integrity consultancies, industrial-automation integrators and the data platforms that connect site to head office. Subiaco and West Perth host the professional-services and technology firms serving that cluster; Osborne Park is the light-industrial and business-park belt where many technology, engineering and telecommunications companies operate. The buyer here is usually a resources major with a supplier-assurance programme, or a SOCI responsible entity, which is why ISO 27001 and ISO 22301 arrive before SOC 2 in most Perth conversations.

Perth CBDWest PerthSubiacoOsborne Park

Mining and energy services software

Vendors supplying mine-planning, fleet, remote-operations and geoscience software to resources majors face structured supplier-assurance programmes that ask for ISO 27001, current penetration tests and tested continuity plans as a condition of the master services agreement.

OT-adjacent vendors under SOCI

Integrators and data platforms connecting operational technology to corporate networks serve energy, port, water and transport operators that are SOCI responsible entities. Those customers flow cyber-hazard and resilience expectations into contracts; ISO 27001 and ISO 22301 evidence answers them, with OT-specific testing scoped separately.

Engineering and professional services

Engineering, asset-integrity and advisory firms in the CBD, West Perth and Subiaco hold client drawings, site data and commercial information under NDA, and are increasingly sent security questionnaires by the majors; ISO 27001 is the certificate those questionnaires accept.

SaaS and product companies

Perth-built software products — many born in the resources sector — that begin selling into US enterprise procurement are asked for SOC 2 by name. We build it on the ISO 27001 control set most of them already have, so evidence is collected once.

What we deliver in Perth

The frameworks Perth buyers ask for, and why

ISO 27001:2022 certification

The certificate resources majors, engineering firms and SOCI responsible entities recognise in supplier assurance. ISMS scoping, risk assessment, the 93 Annex A controls, internal audit and coordination with a JAS-ANZ-accredited certification body — scoped so a lean Perth team can run it after we leave.

ISO 27001 guide

ISO 22301 business continuity

For Perth vendors whose mining, energy and port customers ask for tested continuity and recovery arrangements — including cyclone-season, remote-site connectivity and control-room failover scenarios: business impact analysis, continuity plans and exercised scenarios that a resources major’s vendor review will accept.

ISO 22301 guide

SOC 2 attestation

The report US enterprise buyers ask for when a Perth software product crosses the Pacific. We scope the Trust Services Criteria, design and implement controls, collect evidence and coordinate the independent licensed audit firm through to the signed Type I or Type II report. Confirm whether your buyers expect an AICPA-standard CPA firm or an Australian firm reporting under ASAE 3150.

SOC 2 guide

VAPT — web, mobile, API, cloud

Manual-first penetration testing that satisfies ISO 27001 control A.8.8, SOC 2 auditors and the independent-test clause in resources-sector contracts. IT-side scope — web, API, cloud and network — with reports written for the customer’s vendor reviewer; OT protocol testing is scoped separately with specialist partners where a contract requires it.

VAPT services

vCISO retainer

A named senior practitioner on retainer for Perth companies that need a security lead to own supplier-assurance questionnaires from the majors, SOCI-driven contract clauses, board reporting and audit cycles without a full-time hire.

vCISO services

Laws and regulators

What applies to a Perth company

Plain-English summary as of September 2026. Laws change; confirm current obligations with counsel before relying on any line here.

Laws, regulators and mandates relevant to companies in Perth
Law / regulatorWho it coversWhat it means in practice
Security of Critical Infrastructure Act 2018 (SOCI)Responsible entities in critical-infrastructure sectors — energy, ports, water, transport, data storage and processing, and others heavily represented in Western Australia — and, through contract, their key suppliers.Asset registration, critical-infrastructure risk-management programmes covering cyber, physical, personnel and supply-chain hazards, and mandatory cyber-incident reporting for responsible entities. Perth vendors are asked to evidence a recognised standard; ISO 27001 and ISO 22301 map well to the cyber and resilience hazard domains, and we write the supplier-facing crosswalk with you.
Privacy Act 1988, the Australian Privacy Principles and the Notifiable Data Breaches schemeAPP entities in Perth — organisations above the small-business turnover threshold, plus health service providers and others captured regardless of size. The Privacy and Other Legislation Amendment Act 2024 is the first tranche of reforms; check current commencement of each provision.Collection, use, cross-border disclosure (APP 8) and security (APP 11) obligations, plus notification to the OAIC and affected individuals for eligible data breaches. For most Perth B2B vendors the personal-data footprint is smaller than the operational one, but APP 11 and breach readiness still need to be evidenced — an ISO 27001 ISMS is the usual way.
Privacy and Responsible Information Sharing Act 2024 (Western Australia)Western Australian public-sector agencies and, through contract, their service providers — context for Perth vendors selling to the state. Commencement is staged; check the current position before relying on it.Western Australia is introducing state-level privacy principles and breach-notification duties for the public sector. Vendors to WA agencies should expect the obligations to arrive as contract clauses; an ISO 27001 ISMS with a documented incident process is the proportionate way to be ready. Where a cloud service needs an IRAP assessment, that is a separate assessment we do not perform.
APRA CPS 234 Information Security and CPS 230 Operational Risk ManagementAPRA-regulated banks, insurers and super funds (CPS 230 commenced 1 July 2025) and, through contract, their material service providers — context for Perth vendors to the state’s bank and insurer operations. The transition period for pre-existing supplier contracts ran to 1 July 2026 — confirm the current position with your counterparty.The regulated entity must assess your information-security capability and flow its continuity tolerances and exit arrangements into your contract. ISO 27001 plus ISO 22301 is the cleanest evidence pack a vendor-risk team can accept.

How we serve Perth

From our Gurugram team, on-site when it matters

Your time zone: AWST (UTC+8)Headquarters: Gurugram, IndiaService area: Perth, Western Australia
  • Our Gurugram team works a full shared day with Perth: AWST is 2.5 hours ahead of IST with no daylight saving, so a question asked at 9 am in Perth lands at the start of our morning and a 4 pm review still falls inside our afternoon.

  • On-site when it matters: kick-off, control walkthroughs at your CBD, West Perth, Subiaco or Osborne Park offices, and audit days with the audit firm or certification body.

  • Named lead auditors and CISA-certified practitioners run the engagement end to end — the people on the kick-off call write your risk assessment and sit in your audit.

  • One combined programme when you need ISO 27001, ISO 22301 and SOC 2 together: shared risk assessment, one policy set, one evidence library mapped to each framework and to your customers’ supplier-assurance questionnaires and SOCI-driven clauses.

  • We review controls and evidence only — we do not host or take custody of production, site or operational data. NDAs and data processing agreements are standard, and we help you document the APP 8 cross-border position for our access.

Pricing

Indicative bands for Perth engagements

Indicative bands for Perth engagements, quoted as USD equivalents and invoiced in AUD or INR. Scope, headcount, cloud footprint and starting maturity move the number; we give you a fixed figure in writing after a 30-minute scoping call. What you are paying for is senior auditor-led delivery at India-based cost — we are not the cheapest option, and we do not compete on that.

Indicative pricing bands for compliance engagements in Perth
EngagementIndicative bandNote
ISO 27001:2022 implementation and internal auditUSD 3,000 – 8,000 equivalentJAS-ANZ-accredited certification-body fees separate.
ISO 22301 business continuityScoped to critical operations and sitesOften bundled with ISO 27001 at a combined fee.
SOC 2 readiness consulting (Type I or Type II)USD 2,500 – 6,000 equivalentAudit-firm fee quoted separately by the independent licensed firm.
VAPT (web application, typical SaaS scope)From about USD 1,000 equivalent per testRetest included; API, cloud and network scoped separately; OT testing quoted with specialist partners.
vCISO retainerMonthly retainer, scoped to hoursNamed practitioner, customer- and board-facing.

Compliance in Perth: FAQs

Straight answers for Perth companies on SOC 2, ISO 27001, local regulation, timelines and cost.

Does Tranquility Cybersecurity have an office in Perth?

No. Perth is part of our Australia service area. We are headquartered in Gurugram, India, and serve Perth from there in AWST-friendly hours — the whole working day overlaps — with on-site days for kick-off, control walkthroughs and audit days when scope requires. Most of an ISO 27001 or SOC 2 engagement runs over video and shared evidence trackers regardless of where the consultant sits, and we say so plainly before you sign.

Will Australian enterprise buyers accept a SOC 2 prepared by an India-based consultancy?

Yes, because the opinion is not ours. A SOC 2 report is signed by an independent licensed audit firm — a CPA firm under AICPA standards, or an Australian CA/CPA firm reporting under ASAE 3150. TCSA prepares your controls and evidence and coordinates that firm; the buyer’s security team reviews the auditor’s opinion and the control tests, not the readiness consultant’s address. The same logic applies to ISO 27001, where a JAS-ANZ-accredited certification body issues the certificate. Our Australian customers include NIAD and InDepthIT, and we arrange reference calls before you commit.

Our customer is a SOCI responsible entity. Does the SOCI Act apply to us as a supplier?

Not directly, in most cases — the Act places obligations on the responsible entity for the asset. But that entity’s risk-management programme has to address supply-chain hazards, so it will push cyber, personnel and resilience expectations into your contract and ask for evidence. ISO 27001 for the cyber domain and ISO 22301 for resilience are the recognised standards those expectations usually reference. Whether you are yourself a responsible entity is a legal question for your counsel; we work from the contract clauses.

Do you test operational technology?

We scope honestly. Our VAPT covers the IT side — web applications, APIs, cloud configuration and corporate networks — which is what most vendor-assurance clauses test. Active testing of OT protocols and control networks needs specialist handling and site coordination; where a contract requires it, we scope it separately with specialist partners rather than pretending a web-app methodology covers a PLC. We tell you which is which before quoting.

ISO 27001 or SOC 2 first for a Perth mining-software vendor?

ISO 27001 first, in almost every Perth case. Resources majors, engineering firms and SOCI responsible entities run supplier-assurance programmes around ISO 27001, and it is the certificate their questionnaires accept. SOC 2 becomes relevant when the product starts selling into US enterprise procurement; when that happens we build it on the ISO 27001 control set you already have, so evidence is collected once.

How long does ISO 22301 take, and does it need its own certificate?

Implementation typically takes 2 to 4 months for a vendor with a defined set of critical services — business impact analysis, strategy, plans and at least one exercised scenario — followed by the certification body’s audit if you want the certificate. Many Perth customers accept an ISO 22301-aligned continuity pack inside an ISO 27001 certification rather than a separate certificate; we confirm which your contract actually requires before scoping.

How does the time zone work between Perth and India?

Better than anywhere else in Australia. AWST is 2.5 hours ahead of IST and Western Australia has no daylight saving, so the gap never moves. Your 9 am is our 6:30 am and your 5 pm is our 2:30 pm — effectively a full shared working day, with same-day turnaround on evidence reviews and questions as the norm.

How is pricing structured for Perth engagements?

Fixed fee, agreed in writing after a scoping call, invoiced in AUD or INR as you prefer. Typical bands are USD 3,000–8,000 equivalent for ISO 27001 implementation, USD 2,500–6,000 equivalent for SOC 2 readiness consulting and from about USD 1,000 equivalent for a web-application VAPT. Audit-firm and certification-body fees are quoted separately by those firms, and we help you scope them.

Also served

Other cities in Australia we serve

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: September 2026Content verified by certified lead auditors

Talk to a real auditor

Scoping compliance in Perth?

Book a free 30-minute call. We will tell you which framework your buyers or regulator actually need, what it will cost, and how long it takes — and whether we are the right fit.