NEW ZEALAND

SOC 2 Certification in New Zealand

SOC 2 Certification in New Zealand is a formal attestation report issued by a Licensed CPA Firm following an independent examination of an organisation’s controls against the AICPA Trust Services Criteria. Only Licensed CPA Firms authorised under AICPA attestation standards can issue SOC 2 reports. CertPro is a Licensed CPA Firm conducting SOC 2 examinations for New Zealand organisations across all sectors. No self-assessment or report issued by a non-CPA firm constitutes a valid SOC 2 attestation.

OUR CLIENTS

Hacker Rank
Drivetrain
Entytle
Giift
Flyt Base
Anaconda Inc
Murf Ai
NORLEE GROUP
Vlex
Carestack.C

What Is SOC 2 Certification?

SOC 2 Certification in New Zealand is a formal attestation issued following an independent examination conducted by a Licensed CPA Firm under the American Institute of Certified Public Accountants (AICPA) attestation standards. The examination evaluates whether a service organisation’s controls are suitably designed and, in the case of a Type 2 report, operating effectively over a defined observation period. The resulting SOC 2 report provides independently verified documentation confirming that an organisation’s control environment meets the requirements of the AICPA Trust Services Criteria (TSC) across one or more of five defined categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

SOC 2 attestation is governed by AT-C Section 205 (Examination Engagements) and AT-C Section 105 (Concepts Common to All Attestation Engagements) as issued by the AICPA. These standards define the practitioner’s responsibilities, the nature of evidence collection, the structure of testing procedures, and the form of the final attestation report. The SOC 2 examination is not a self-assessment or a certification issued by a standards body — it is an independent audit conclusion reached by a qualified CPA firm after rigorous evaluation of controls relative to the applicable Trust Services Criteria. Organisations pursuing SOC 2 Certification in New Zealand must engage a Licensed CPA Firm authorised to conduct attestation engagements under AICPA standards.

CertPro is a Licensed CPA Firm conducting independent SOC 2 examinations for organisations operating across New Zealand. SOC 2 Certification is relevant to any organisation that stores, processes, or transmits client data as part of its service delivery — including SaaS providers, cloud infrastructure companies, fintech platforms, financial institutions, health technology organisations, government technology vendors, cybersecurity firms, AI businesses, e-commerce operators, telecommunications providers, data centres, agritech companies, and enterprises managing sensitive information across Auckland, Wellington, Christchurch, Hamilton, and throughout New Zealand. The SOC 2 audit serves as the primary mechanism through which these organisations formally demonstrate control effectiveness to enterprise customers, institutional clients, and international procurement teams conducting third-party risk assessments.

SOC 2 Type 1 vs. Type 2 Reports

SOC 2 certification is issued in two report types, each serving a distinct audit purpose. A SOC 2 Type 1 report reflects an examination of the design and implementation of controls as at a specific point in time. The Licensed CPA Firm evaluates whether controls are suitably designed to meet the applicable Trust Services Criteria as of the report date. A Type 1 report does not assess operational effectiveness over time — it represents a snapshot of the control environment at the examination date. This report type is commonly pursued by organisations that are new to SOC 2 attestation and require initial verification of their control design before committing to a full observation period.

A SOC 2 Type 2 report is a more comprehensive attestation covering both the design and operating effectiveness of controls over an observation period — typically a minimum of six months, with twelve months being the standard for established programmes. During this period, the Licensed CPA Firm collects and evaluates evidence demonstrating that controls functioned consistently and as intended. SOC 2 Type 2 attestation is the standard most demanded by enterprise customers, government technology procurement teams, and international clients conducting vendor assurance reviews. Organisations that complete a SOC 2 Type 1 audit frequently proceed to a Type 2 examination in the subsequent audit cycle to build a longitudinal record of control effectiveness.

SOC 2 vs. Other Certification Frameworks

SOC 2 certification differs from ISO 27001 and other information security frameworks in its audit methodology, attestation mechanism, and scope definition. ISO 27001 is a management system standard certified by accredited certification bodies through conformity assessments. SOC 2 is an attestation engagement conducted by a Licensed CPA Firm under AICPA attestation standards, producing a formal audit report rather than a certificate. SOC 2 compliance testing is directly linked to an organisation’s specific service commitments and system boundaries, whereas ISO 27001 assesses the information security management system as a whole. SOC 2 is customer-centric by design — controls are evaluated against what the organisation has committed to deliver to its customers within its defined system.

SOC 2 attestation compared to ISO 27001 certification
Criterion SOC 2 Attestation ISO 27001 Certification
Issuing Body Licensed CPA Firm (AICPA) Accredited Certification Body
Output Audit Report (Attestation) Certificate of Conformity
Scope Service commitments and TSC Information Security Management System
Report Types Type 1 and Type 2 Surveillance and Recertification
Market Recognition US, NZ, AU enterprise procurement Global, government, multi-sector

ENQUIRE NOW



SOC 2 Certification in New Zealand — Local Context and Market Drivers

SOC 2 Certification in New Zealand has become a standard expectation across the technology, financial services, and healthcare sectors as enterprise procurement teams formalise vendor assurance programmes. New Zealand’s technology ecosystem — anchored in Auckland’s commercial district, Wellington’s government and financial services precinct, and Christchurch’s growing tech and engineering sector — includes a significant concentration of SaaS providers, cloud platforms, and data-intensive service organisations. For these organisations, SOC 2 attestation has transitioned from a competitive differentiator to a baseline requirement for accessing enterprise and institutional customers.

New Zealand Privacy and Information Security Context

The New Zealand Privacy Act 2020 establishes thirteen Information Privacy Principles governing how organisations collect, hold, use, and disclose personal information. The Health Information Privacy Code 2020 extends additional obligations to organisations handling health information. While SOC 2 attestation does not automatically establish compliance with the Privacy Act 2020 or the Health Information Privacy Code, the controls evaluated during a SOC 2 examination — particularly those mapped to the Privacy Trust Services Criterion — address many of the same operational safeguards these frameworks require. Organisations subject to New Zealand privacy obligations frequently reference their SOC 2 audit reports as evidence of control maturity during regulatory reviews, customer due diligence processes, and procurement evaluations.

New Zealand’s government technology sector has progressively adopted SOC 2 compliance expectations as part of procurement and vendor assurance frameworks. Central government agencies and Crown entities procuring cloud-hosted or SaaS-based solutions increasingly require suppliers to demonstrate current SOC 2 attestation as part of security assessment processes. This expectation is reinforced by the New Zealand Government’s cloud computing risk and assurance framework and the broader alignment of New Zealand cybersecurity standards with Five Eyes partner requirements. Organisations operating in Hamilton’s technology sector, Christchurch’s agritech and engineering ecosystem, and across New Zealand’s regional technology base encounter these requirements in both public sector and enterprise private sector procurement processes.

Cross-Border Demand for SOC 2 Audit New Zealand

New Zealand organisations serving customers in Australia, the United States, the United Kingdom, and other international markets face direct SOC 2 compliance requirements from enterprise clients and institutional buyers in those jurisdictions. Australian financial institutions regulated by APRA require third-party service providers to demonstrate control assurance, and SOC 2 audit reports are a recognised mechanism for satisfying that expectation. US-based enterprise customers routinely require SOC 2 Type 2 attestation as a condition of vendor onboarding. New Zealand SaaS companies, fintech platforms, and cloud service providers with international customer bases frequently cite SOC 2 Certification in New Zealand as essential to sustaining and growing cross-border commercial relationships. SOC 2 examination for New Zealand organisations is therefore both a domestic market expectation and an international trade enabler.

The Five Trust Services Criteria Explained

The AICPA Trust Services Criteria define the control categories evaluated during a SOC 2 examination. Every SOC 2 audit in New Zealand must include the Security criterion — also referred to as Common Criteria — as a mandatory baseline. Organisations then select additional criteria based on the nature of their services, their customer commitments, and the risk profile of the information they process. The selection of applicable criteria is a formal scoping decision made prior to the examination. It directly determines which controls are evaluated, which evidence is collected, and what the resulting SOC 2 attestation report covers.

The Security criterion — the mandatory foundation of every SOC 2 examination — evaluates controls protecting the system against unauthorised access, both logical and physical. This includes access management, encryption, network security, change management, and incident response. The Availability criterion assesses whether the system is available for operation and use as committed or agreed, addressing infrastructure monitoring, redundancy, disaster recovery, and capacity management. The Processing Integrity criterion evaluates whether system processing is complete, valid, accurate, timely, and authorised — particularly relevant to financial processing platforms, payment systems, and data transformation services where data integrity directly affects client outcomes.

New Zealand fintech companies and financial services technology providers frequently include both Availability and Processing Integrity criteria in their SOC 2 scope, reflecting the operational commitments made to banking clients and payment processing customers. SOC 2 Certification in New Zealand for fintech organisations commonly covers all three criteria — Security, Availability, and Processing Integrity — to satisfy due diligence requirements from institutional clients and regulatory expectations from the Financial Markets Authority (FMA) and Reserve Bank of New Zealand (RBNZ) supply chain oversight frameworks. The Licensed CPA Firm evaluates evidence specific to each criterion through structured testing procedures defined in the audit programme.

The Confidentiality criterion evaluates controls over information designated as confidential — covering identification, protection, retention, and disposal of confidential data throughout its lifecycle. This criterion is relevant to organisations managing commercially sensitive client information, intellectual property, or contractually designated confidential data. The Privacy criterion evaluates controls across the full personal information lifecycle: collection, use, retention, disclosure, and disposal. It is assessed against the AICPA Privacy Management Framework, which aligns with major privacy principles including those reflected in the New Zealand Privacy Act 2020. SOC 2 certification for New Zealand financial services organisations and health technology providers commonly includes both Confidentiality and Privacy criteria within the audit scope.

AICPA Trust Services Criteria and typical selection by New Zealand sector
Trust Services Criterion Primary Focus Commonly Selected By
Security (Mandatory) Logical and physical access controls All SOC 2 organisations
Availability System uptime and redundancy Cloud, SaaS, data centres
Processing Integrity Data accuracy and completeness Fintech, payment platforms
Confidentiality Protection of confidential information Financial services, legal tech
Privacy Personal information lifecycle Health tech, HR platforms, SaaS
SOC 2 Requirements
  • Security, Availability, and Processing Integrity
  • Confidentiality and Privacy Criteria

SOC 2 Certification Requirements for New Zealand Businesses

SOC 2 Certification in New Zealand requires organisations to establish, document, and operate a control environment aligned with the applicable AICPA Trust Services Criteria before an examination can be conducted. The requirements span organisational governance, technical control implementation, documentation completeness, and evidence availability. Understanding these requirements enables organisations to structure their control environments accurately prior to the SOC 2 examination — though the design and implementation of those controls remains the organisation’s own responsibility, not that of the examining CPA firm.

SOC 2 compliance requires organisations to maintain formal, current documentation of their control environment. This includes a system description — a management-prepared narrative covering the nature of services, system boundaries, infrastructure components, data flows, and the controls in place relative to the applicable Trust Services Criteria. The system description is included in the final SOC 2 report and is subject to evaluation by the Licensed CPA Firm for accuracy and completeness. Additional required documentation includes information security policies, access management procedures, change management records, risk assessment outputs, vendor management documentation, and incident response records. All documentation must reflect actual operational practice and remain current at the time of examination.

Governance requirements for SOC 2 attestation include defined management accountability for the control environment, a documented risk assessment process, and formal review mechanisms for security policies and control effectiveness. Organisations pursuing SOC 2 certification — including New Zealand SaaS companies and technology providers — must demonstrate that control ownership is assigned, that reviews occur at defined intervals, and that exceptions or deviations from control procedures are identified, escalated, and resolved. The Licensed CPA Firm evaluates governance documentation as part of the control environment assessment, examining board-level or executive-level oversight artefacts, risk register records, and policy approval evidence during the SOC 2 audit.

Technical controls evaluated during a SOC 2 examination span access management, encryption, network security, logging and monitoring, change management, and vulnerability management. Access controls must enforce least-privilege principles, with user provisioning, de-provisioning, and access review processes documented and evidenced. Encryption requirements address data at rest and data in transit, with key management procedures forming part of the control evaluation. Network security controls — including firewall configurations, intrusion detection, and network segmentation — are evaluated against the Security criterion. Logging and monitoring controls must demonstrate that security-relevant events are captured, retained, and reviewed at intervals consistent with the organisation’s stated commitments and the applicable Trust Services Criteria requirements.

  • Documented system description covering service scope, infrastructure, and data flows
  • Formal information security policy suite reviewed at defined intervals
  • Access management controls with provisioning, de-provisioning, and periodic review evidence
  • Encryption controls for data at rest and in transit with key management documentation
  • Change management procedures with documented approval and testing records
  • Vulnerability management programme with scanning, remediation tracking, and escalation evidence
  • Incident response plan with documented testing and activation records
  • Vendor and subservice organisation management documentation where applicable
  • Documentation and Governance Requirements
  • Technical Control Requirements

The SOC 2 Audit Process — Step-by-Step

The SOC 2 audit process follows a structured sequence of stages governed by AICPA attestation standards AT-C Section 205 and AT-C Section 105. Each stage produces defined outputs that collectively form the basis for the Licensed CPA Firm’s attestation opinion. The process applies consistently to SOC 2 audit engagements in New Zealand regardless of the organisation’s sector, size, or the number of Trust Services Criteria included in scope. Understanding this sequence enables organisations to structure their evidence collection, documentation review, and management responses appropriately throughout the examination period.

The SOC 2 examination begins with formal scope definition. The Licensed CPA Firm and the organisation establish the system boundaries, applicable Trust Services Criteria, report type (Type 1 or Type 2), and — for Type 2 engagements — the observation period start and end dates. System boundaries define the infrastructure components, software, people, procedures, and data included within the examination scope. The audit programme is then determined: the Licensed CPA Firm designs specific testing procedures for each control relative to the applicable criteria, identifying the nature, timing, and extent of evidence collection required. The audit programme reflects the risk profile of the system and the complexity of the control environment, and it governs all subsequent examination activities.

For SOC 2 compliance engagements in New Zealand involving subservice organisations — cloud infrastructure providers such as AWS, Azure, or Google Cloud — the audit programme must address how the organisation’s controls interact with those of its subservice providers. The Licensed CPA Firm applies either the carve-out method, which excludes subservice organisation controls from the examination scope and notes their exclusion in the report, or the inclusive method, which extends the examination to cover subservice organisation controls directly. Most New Zealand organisations utilise the carve-out method, relying on subservice providers’ own SOC 2 reports as complementary user entity controls documentation.

Evidence collection during a SOC 2 examination involves the Licensed CPA Firm gathering documentation, configuration records, system-generated logs, personnel records, and other artefacts supporting each control’s design and operation. For Type 2 engagements, evidence must span the full observation period, demonstrating that controls operated consistently and without material deviation throughout the period under review. Testing procedures include inquiry, observation, inspection of documentation, and re-performance of control procedures where applicable. Identified control deviations — instances where a control did not operate as designed — are documented as exceptions, evaluated for severity, and disclosed in the final report with management’s response and any remediation actions taken.

Following the completion of testing and nonconformity review, the Licensed CPA Firm issues the SOC 2 attestation report. The report comprises the service auditor’s opinion, management’s assertion, the system description, and detailed control testing results including any identified exceptions. The opinion is expressed as unqualified (controls are suitably designed and operating effectively), qualified (with specific exceptions noted), or adverse (controls do not meet the criteria). The SOC 2 attestation report is typically valid for twelve months from the period end date, after which organisations must complete a new SOC 2 examination to maintain current attestation status. New Zealand organisations distribute the report under non-disclosure agreements to customers, prospects, and auditors conducting third-party risk assessments.

  1. Scope Definition — System boundaries, applicable TSC, report type, and observation period established
  2. Audit Programme Determination — Testing procedures designed for each control relative to applicable criteria
  3. Preliminary Documentation Review — System description and policy documentation evaluated for completeness
  4. Stage 1 Assessment — Control design adequacy evaluated (Type 1 and Type 2)
  5. Observation Period — Controls operate under examination conditions; evidence collected continuously (Type 2)
  6. Control Testing — Evidence evaluated through inquiry, inspection, observation, and re-performance
  7. Nonconformity Review — Exceptions identified, documented, and evaluated for materiality
  8. Management Response — Organisation provides formal responses to identified exceptions
  9. Report Issuance — Licensed CPA Firm issues SOC 2 attestation report with formal opinion
  • Scope Definition and Audit Programme Determination
  • Evidence Collection, Control Testing, and Report Issuance

SOC 2 Certification Cost in New Zealand

SOC 2 examination investment in New Zealand is determined by a defined set of variables that collectively reflect the scope and complexity of each engagement. Unlike packaged software or subscription services, SOC 2 audit engagements are scoped individually based on the specific characteristics of each organisation’s control environment, system boundaries, and applicable Trust Services Criteria. Understanding the factors that influence examination scope enables organisations to structure their audit engagements accurately and anticipate the resources required throughout the SOC 2 examination process.

Factors Determining SOC 2 Examination Scope

The primary factors determining the scope — and therefore the complexity — of a SOC 2 audit engagement include the number of Trust Services Criteria in scope, the size and complexity of the system under examination, the number of locations and infrastructure components included, the volume of controls to be tested, and the length of the observation period for Type 2 engagements. Organisations with complex multi-region cloud architectures, large personnel populations with system access, or multiple integrated subservice organisations will require more extensive evidence collection and testing procedures than those with simpler system boundaries. The report type also materially affects examination scope: a Type 2 report requires evidence spanning the full observation period — typically six to twelve months — whereas a Type 1 report requires only point-in-time evaluation.

For New Zealand organisations in their first SOC 2 examination cycle, the internal resource commitment — including personnel time for evidence collection, documentation preparation, and management assertion drafting — represents a significant organisational investment alongside the external audit engagement. Organisations with mature control environments, complete documentation, and automated evidence collection processes typically complete the examination more efficiently than those with manual or fragmented control documentation. New Zealand organisations pursuing SOC 2 compliance that invest in structured evidence management prior to the observation period start tend to reduce elapsed time between audit programme initiation and final report issuance.

Ongoing Examination and Renewal Considerations

SOC 2 attestation is not a one-time certification — it requires annual renewal through a new examination cycle to maintain current report status. Organisations that complete SOC 2 audit engagements in New Zealand annually benefit from a progressively more efficient process as their control environments mature, documentation becomes more complete, and internal evidence collection workflows are established. Subsequent examination cycles typically involve shorter elapsed times and more focused testing procedures for controls that demonstrated consistent effectiveness in prior periods. Organisations that allow their SOC 2 report to lapse beyond the standard twelve-month validity period must complete a full new examination to restore current attestation status, which may affect customer relationships and procurement eligibility during the gap period.

Benefits of SOC 2 Certification for New Zealand-Based Organizations

SOC 2 Certification in New Zealand delivers measurable commercial, operational, and reputational outcomes for organisations across the technology, financial services, health technology, and enterprise data sectors. The independently verified nature of SOC 2 attestation — produced by a Licensed CPA Firm under AICPA standards — differentiates it from self-assessments and questionnaire-based security declarations that carry no external verification. This verification quality is the primary driver of SOC 2’s commercial value: it enables enterprise customers to rely on the audit report as authoritative evidence of control effectiveness without conducting their own full security assessments of each vendor.

New Zealand organisations use their SOC 2 attestation reports as primary documentation in enterprise vendor onboarding processes, reducing the volume and complexity of security questionnaires, due diligence requests, and third-party risk assessment activities required from prospective clients. Enterprise procurement teams at New Zealand banks, insurance companies, telecommunications providers, government agencies, and large corporate entities routinely accept a current SOC 2 Type 2 report as the primary control assurance artefact in vendor security reviews. For New Zealand SaaS providers pursuing customers in Australia or the United States, a current SOC 2 audit report significantly accelerates the vendor qualification process, as international enterprise buyers recognise the AICPA attestation standard as authoritative evidence of control maturity.

The commercial value of SOC 2 certification for New Zealand companies extends beyond individual customer onboarding to sustained competitive positioning. Organisations with current SOC 2 Type 2 attestation reports are eligible for procurement opportunities that exclude vendors without independently verified control assurance — including government technology tenders, financial services vendor panels, and enterprise software procurement programmes with mandatory security attestation requirements. A completed SOC 2 examination enables New Zealand organisations to participate in these markets without repeated point-in-time security assessments for each prospective customer, as the SOC 2 report satisfies the assurance requirement across multiple customer relationships simultaneously.

Beyond its external commercial applications, SOC 2 compliance drives measurable improvements in internal control maturity for New Zealand organisations. The SOC 2 examination process requires organisations to document, test, and continuously monitor controls that directly reduce operational risk — including access management failures, configuration drift, undetected security incidents, and vendor-introduced risks. Organisations that complete annual SOC 2 audit cycles develop progressively stronger control environments, as each examination cycle identifies residual gaps and exceptions that management is formally required to address. This cycle of examination, exception identification, and remediation produces a documented control improvement trajectory that demonstrates institutional commitment to security and operational integrity.

  • Independently verified control assurance accepted by enterprise and government procurement teams
  • Reduced vendor security questionnaire burden across multiple customer relationships
  • Access to US, Australian, and UK markets requiring SOC 2 attestation for vendor qualification
  • Documented control improvement trajectory through annual examination cycles
  • Formal evidence of control effectiveness for regulatory and contractual compliance contexts
  • Strengthened internal risk management through structured control testing and exception resolution
  • Enhanced board and executive-level visibility into control environment effectiveness
  • Competitive differentiation in markets where SOC 2 Type 2 attestation is a procurement prerequisite
SOC 2 Benefits
  • Enterprise Sales Enablement and Vendor Onboarding
  • Operational Risk Management and Internal Control Maturity

SOC 2 Compliance New Zealand — Maintaining Certification Status

SOC 2 compliance in New Zealand is not a static achievement — it requires continuous control operation, ongoing evidence management, and annual re-examination to maintain current attestation status. Organisations that treat SOC 2 as a point-in-time project rather than an ongoing operational programme frequently encounter gaps in control evidence, documentation staleness, and control deviations identified during subsequent examinations. Maintaining SOC 2 certification status requires embedding control monitoring and evidence collection into routine operational processes throughout the year — not only in the period immediately preceding each SOC 2 audit.

Continuous Control Monitoring and Evidence Management

Continuous control monitoring involves establishing automated and manual review processes that generate contemporaneous evidence of control operation throughout the observation period. For SOC 2 Type 2 purposes, evidence must demonstrate that controls operated consistently from the period start date to the period end date — not only in the weeks preceding audit fieldwork. Organisations maintaining SOC 2 compliance in New Zealand typically implement quarterly access reviews, monthly vulnerability scanning with documented remediation, continuous security monitoring with alert review records, and periodic policy reviews with documented approval. These activities generate the evidence artefacts that the Licensed CPA Firm evaluates during the SOC 2 examination.

Vendor and subservice organisation management is a continuous compliance requirement that is frequently underdeveloped in first-cycle SOC 2 engagements. Organisations must maintain documentation of their subservice organisations’ SOC 2 reports or equivalent assurance documentation, assess the risk of subservice organisation control failures on their own control environment, and implement complementary user entity controls where required. For New Zealand organisations operating on major cloud platforms, this involves annually collecting and reviewing the relevant sections of the cloud provider’s SOC 2 report, documenting that review, and mapping any identified subservice organisation control gaps to compensating controls within the organisation’s own environment.

Annual Re-Examination and Scope Evolution

Annual SOC 2 examination cycles provide organisations with a structured mechanism for evaluating and evolving their compliance scope as business operations change. Organisations that expand their service offerings, add new customer data categories, migrate infrastructure to new cloud regions, or introduce new personnel roles must evaluate whether these changes affect the system boundary definition, the applicable Trust Services Criteria, or the controls required to meet their service commitments. Material changes to the system during a Type 2 observation period are disclosed in the final attestation report and evaluated by the Licensed CPA Firm for their impact on control effectiveness. Proactive scope management — conducted in advance of the next observation period — reduces the likelihood of material scope changes requiring disclosure during the examination.

CertPro — Licensed CPA Firm Conducting SOC 2 Audits in New Zealand

CertPro is a Licensed CPA Firm authorised to conduct SOC 2 examinations under the AICPA attestation standards AT-C Section 205 and AT-C Section 105. CertPro conducts independent SOC 2 audit engagements across New Zealand for service organisations in all sectors, issuing formal attestation reports following rigorous examination of control design and operating effectiveness against the applicable Trust Services Criteria. CertPro’s examination methodology is governed strictly by AICPA attestation standards — CertPro does not provide consulting, advisory, implementation, or remediation services. All SOC 2 engagement activities are conducted as independent examination procedures, preserving the auditor independence required by AICPA professional standards.

Examination Methodology and Institutional Standards

CertPro’s SOC 2 examination methodology applies structured testing procedures across all applicable Trust Services Criteria, with audit programmes tailored to each organisation’s system boundaries, control environment complexity, and the nature of services provided. For each control under examination, CertPro applies testing procedures including inquiry of relevant personnel, inspection of policy and procedure documentation, observation of control operation, and re-performance of control activities where required by the audit programme. Evidence is evaluated for sufficiency, appropriateness, and consistency across the observation period. Identified deviations are documented formally, evaluated for materiality, and disclosed in the attestation report with precision consistent with AICPA reporting standards.

CertPro issues SOC 2 attestation reports that meet the requirements of AT-C Section 205, including the service auditor’s opinion, management’s assertion, the system description, and the results of testing procedures. For New Zealand organisations serving international customers, CertPro’s reports are structured to satisfy the documentation requirements of US, Australian, and UK enterprise procurement programmes. CertPro’s Licensed CPA Firm status ensures that issued SOC 2 reports carry the professional authority recognised by enterprise legal, risk, and procurement teams globally. Organisations across Auckland, Wellington, Christchurch, Hamilton, and throughout New Zealand engage CertPro for annual SOC 2 examination cycles covering Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria as applicable to their service scope.

Sectors Served Across New Zealand

CertPro conducts SOC 2 examinations for organisations across New Zealand’s technology and data-intensive sectors, including SaaS platform providers, cloud infrastructure operators, fintech and payments companies, financial services technology providers, health technology organisations, government technology vendors, AI and machine learning businesses, e-commerce platforms, telecommunications providers, data centre operators, cybersecurity firms, and agritech technology companies. New Zealand financial services organisations, in particular, engage CertPro for SOC 2 Type 2 examinations covering Security, Availability, and Processing Integrity criteria, satisfying due diligence requirements from regulated institutional clients. Each engagement is conducted as an independent examination with no advisory or implementation activities performed by CertPro personnel.

Achieving SOC 2 Certification in New Zealand with CertPro

Organisations initiating SOC 2 Certification in New Zealand for the first time — or transitioning from a Type 1 to a Type 2 report — begin by engaging CertPro to define the examination scope, applicable Trust Services Criteria, report type, and observation period. This initial scoping discussion establishes the parameters of the engagement and informs the audit programme that CertPro will apply during the examination. Organisations are responsible for establishing and operating their control environments; CertPro evaluates those controls independently against the applicable Trust Services Criteria and issues the resulting SOC 2 attestation report based on the evidence collected and testing procedures performed.

Initiating the SOC 2 Examination Engagement

The SOC 2 examination engagement begins with an engagement letter that formally documents the scope, applicable criteria, report type, observation period dates, and the respective responsibilities of CertPro and the organisation’s management. Management’s responsibilities under AT-C Section 205 include preparing the system description, making an assertion about the fairness of the description and the effectiveness of controls, providing access to personnel and systems required for examination purposes, and disclosing to CertPro any known actual or suspected fraud, noncompliance, or control failures. These responsibilities are material to the integrity of the SOC 2 examination and are formally documented in the engagement letter before examination activities commence.

Organisations that have not previously undergone a SOC 2 audit should expect the first examination cycle to involve more extensive documentation review and evidence collection than subsequent annual cycles. First-cycle SOC 2 engagements require the organisation to produce complete documentation of the control environment under examination conditions for the first time — a process that frequently surfaces documentation gaps, undocumented controls, or control activities that require formal evidencing. Addressing these documentation requirements accurately and completely prior to the observation period start produces a stronger evidence base for the examination and reduces the likelihood of control deviations being attributed to documentation failures rather than control operation failures.

Report Distribution and Post-Examination Activities

Following issuance, the SOC 2 attestation report is distributed by the organisation to specified users — typically enterprise customers, prospective clients, institutional counterparties, and auditors conducting third-party risk assessments. SOC 2 reports are not public documents; they are distributed under non-disclosure agreements to parties with a legitimate need to evaluate the organisation’s control environment. The report’s validity period of approximately twelve months from the observation period end date means that organisations must initiate the next examination cycle before the current report lapses, to avoid a gap in current attestation status. CertPro works with organisations across New Zealand on annual re-examination programmes to maintain continuous SOC 2 compliance and ensure that current reports are available for ongoing customer and procurement requirements.

FAQ

What is SOC 2 Certification in New Zealand?

SOC 2 Certification in New Zealand is a formal third-party attestation issued by a Licensed CPA Firm — such as CertPro — confirming that a service organization’s controls related to security, availability, processing integrity, confidentiality, and privacy have been independently audited and validated against the AICPA’s Trust Service Criteria. The certification applies to New Zealand-based technology companies, SaaS providers, fintech firms, managed service providers, and any organization that stores, processes, or transmits client data on behalf of its customers. SOC 2 attestation is recognized by US, Australian, and international enterprise procurement standards as a credible, auditor-validated security credential.

What is SOC 2 Certification and who can issue it in New Zealand?

SOC 2 Certification in New Zealand is a formal attestation report issued by a Licensed CPA Firm following an independent examination of an organisation’s controls against the AICPA Trust Services Criteria. Only Licensed CPA Firms authorised under AICPA attestation standards can issue SOC 2 reports. CertPro is a Licensed CPA Firm conducting SOC 2 examinations for New Zealand organisations across all sectors. No self-assessment or report issued by a non-CPA firm constitutes a valid SOC 2 attestation.

What is the difference between SOC 2 Type 1 and Type 2 for New Zealand organisations?

A SOC 2 Type 1 report evaluates the design of controls at a specific point in time, confirming that controls are suitably designed to meet the Trust Services Criteria as of the report date. A SOC 2 Type 2 report evaluates both the design and operating effectiveness of controls over an observation period — typically six to twelve months. SOC 2 Type 2 attestation is the standard required by enterprise and government customers in New Zealand and internationally for ongoing vendor assurance purposes.

How long does the SOC 2 audit process take in New Zealand?

The duration of the SOC 2 audit process depends on the report type and the observation period. A SOC 2 Type 1 examination — covering a single point in time — typically takes six to twelve weeks from engagement initiation to report issuance, depending on the complexity of the control environment and the completeness of documentation. A SOC 2 Type 2 examination requires a minimum six-month observation period, with fieldwork and report issuance typically adding a further eight to twelve weeks after the observation period closes. Total elapsed time from engagement start to Type 2 report issuance is typically nine to fifteen months for organisations with established control environments.

What Trust Services Criteria do New Zealand organisations typically include in SOC 2 scope?

The Security criterion is mandatory for all SOC 2 examinations. New Zealand SaaS providers and cloud organisations typically include Availability as well. Fintech and payment processing organisations frequently add Processing Integrity. Financial services and legal technology organisations commonly include Confidentiality. Health technology organisations and HR platforms typically include Privacy, reflecting obligations under the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020. The applicable criteria are determined by the organisation’s service commitments and the risk profile of the information processed.

Does SOC 2 attestation establish compliance with the New Zealand Privacy Act 2020?

SOC 2 attestation does not automatically establish compliance with the New Zealand Privacy Act 2020 or any other New Zealand law or regulation. The Privacy criterion in the SOC 2 examination evaluates controls against the AICPA Privacy Management Framework, which aligns with major privacy principles but is not a direct legal compliance assessment under New Zealand law. Organisations subject to the Privacy Act 2020 must address their legal obligations through their own compliance programmes. A SOC 2 audit report may serve as evidence of control maturity in regulatory or contractual contexts, but it does not substitute for legal compliance determinations.

How often must SOC 2 certification be renewed in New Zealand?

SOC 2 attestation reports are valid for approximately twelve months from the observation period end date. Organisations must complete a new SOC 2 examination annually to maintain current attestation status. Allowing the SOC 2 report to lapse beyond the standard validity period creates a gap in current attestation documentation that may affect customer relationships and procurement eligibility. Enterprise customers conducting annual vendor assurance reviews typically require a current — non-lapsed — SOC 2 Type 2 report as a condition of continued vendor status.

What is the difference between SOC 2 certified and SOC 2 compliant?

SOC 2 compliant refers to an organisation that has implemented controls aligned with the Trust Services Criteria but has not undergone independent third-party verification. SOC 2 certified — or more precisely, SOC 2 attested — refers to an organisation that has completed a formal SOC 2 examination conducted by a Licensed CPA Firm and received an attestation report expressing an opinion on its controls. Only independently examined organisations can provide customers with a SOC 2 report carrying the authority of an AICPA-governed attestation engagement. Self-declared compliance without a completed SOC 2 examination does not constitute attestation.

Get In Touch

have a question? let us get back to you.






Schedule A Meeting