AegentraNew Zealand

Govern / New Zealand

SOC 2 readiness

Aegentra helps New Zealand service organisations prepare for a SOC 2 examination by connecting the service boundary, relevant criteria, control owners and operating evidence. The independent CPA firm performs the examination and issues the report.

On this page

Start with the boundary

Define the work that is needed.

For SaaS and other service organisations responding to customer assurance requirements or preparing their first reporting cycle.

  • Service description and assurance objectives
  • Control gaps against agreed Trust Services Criteria
  • Evidence ownership and collection arrangements
  • Readiness review and remediation support

Keep the responsibilities distinct

SOC 2 is an assurance report, not an ISO certification. Aegentra’s readiness work does not issue a SOC 2 report, confer a CPA licence or guarantee the examination outcome.

What the engagement can produce

Useful outputs, agreed in advance.

  • A scoped readiness roadmap
  • A control and evidence responsibility map
  • Prioritised gaps and action owners
  • Preparation for discussions with the appointed CPA firm

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A customer requests a Type 2 report, but the supplier has only recently introduced its controls. The next step is to agree report expectations and evidence needs with the CPA firm, not to describe newly written policies as a completed reporting period.

Questions for the first discussion

  • What report and scope does the customer need?
  • Which services and subservice organisations are involved?
  • For how long have the relevant controls operated?

Before you begin

Your questions, answered.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 addresses the system and control design at a specified date. Type 2 also addresses operating effectiveness over a specified period. The scope and reporting period should be agreed with the independent CPA firm, not assumed from a generic readiness package.

What can be included in soc 2 readiness?

The agreed scope can include service description and assurance objectives; control gaps against agreed Trust Services Criteria; evidence ownership and collection arrangements; readiness review and remediation support. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: What report and scope does the customer need? Which services and subservice organisations are involved? For how long have the relevant controls operated? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.