z3roday Day zero · before anyone asks

Certification & privacy law

A customer asked for your SOC 2 report. Now what?

Separate from the AI work, and usually driven by someone else's deadline — a tender, an enterprise customer, a regulator. We assess where you stand, do the work to close the gaps, and manage the auditor.

Readiness register — extract 6 of 114
A.5.15Access control policyIn place
A.8.16Monitoring activitiesPartial
A.5.30ICT readiness for continuityMissing
CC6.1Logical access — provisioningPartial
A.5.19Supplier securityMissing
APP 1.7Automated decision disclosureMissing
One assessment, mapped to every standard you need. Illustrative only.
days to APP 1.7

10 December 2026. New Australian Privacy Principle 1.7 commences. If a computer program uses personal information to make — or substantially help make — a decision that significantly affects someone, your privacy policy has to say so. It is a disclosure duty, not a ban. Most companies will find they are in scope and have nothing written.

What this means

The deadline nobody has budgeted for

You do not need AI to be caught by APP 1.7.

The rule says “computer program”, not AI. A system that declines an application, ranks job applicants, decides who gets a payment plan, flags a transaction as fraud, or sets a roster that affects pay — if personal information goes in and a decision that significantly affects someone comes out, you have to disclose it. It also covers decisions your suppliers make for you, which is where most companies get caught short.

  1. Find every system in scope, including bought onesYour own software, your SaaS platforms, and anything a supplier runs for you. Procurement contracts rarely say. Someone has to ask.
  2. Decide what counts, and write down whyThe judgement calls sit around “substantially and directly related” and “significantly affect”. Getting them right matters less than having a documented reason for each.
  3. Draft the privacy policy wordingThe kinds of personal information used, the kinds of decisions made by the program alone, and the kinds it substantially helps make. In plain English, because that is the point of the rule.
  4. Leave a register behindA forward-looking duty, not a one-off. Every new tool changes the answer, so it needs somewhere to live and someone who updates it.
Get this done before December Fixed fee AUD 2,500 · two weeks · delivered before 10 December or you don't pay

We are not lawyers and this is not legal advice. We do the inventory, the technical scoping and the draft; your counsel signs it off. Where you don't have counsel, we'll introduce a privacy lawyer and tell you who they are before they start.

Standards we work to

The same controls carry most of the way into the next standard.

Most companies end up needing more than one. Assessed together, the overlap does the work.

SOC 2 Type 1 & Type 2

What North American and enterprise buyers ask for by name. Scoping, control design, and evidence that survives the observation window.

ISO/IEC 27001:2022

What international and European customers recognise. Full build: scope, risk method, Statement of Applicability, internal audit and management review.

ISO/IEC 42001

The first certifiable AI management standard, adopted here as AS ISO/IEC 42001. Turns “we're careful with AI” into something a board can be shown. Certifications are still rare and auditors scarce, which is why being early is worth something in a tender.

Essential Eight

Still what insurers, tenders and assessors measure against. We assess against the current maturity model and build uplift that carries forward rather than becoming work you redo.

APRA CPS 234 & CPS 230

If you supply banks, insurers or super funds, these reach you through your contracts. Information security capability, incident notification, and operational risk for material service providers.

Privacy Act & NZ Privacy Act 2020

APP 1.7 disclosure, the Notifiable Data Breaches scheme, and the statutory tort of serious invasion of privacy live since June 2025. Plus NIST AI RMF and the EU AI Act if you sell into Europe.

How the work runs

Assess, fix, certify, sustain. Take one phase or all four.

Phase 01

Assess

Control-by-control gap assessment, prioritised roadmap, policy gap list, evidence guide, and a costed path to certification.

3–4 weeks · fixed fee

Phase 02

Remediate

Policies written to how you actually work, controls implemented, tooling configured, evidence trail started. Hands on the console.

Fixed-price sprint, quoted from the assessment

Phase 03

Certify

Auditor selection and briefing, evidence assembly, managing the request list through fieldwork, translating findings before they become surprises.

Through the audit cycle · monthly retainer

Phase 04

Sustain

Certification is annual. Access reviews, register upkeep, internal audit and surveillance prep, so year two isn't another scramble.

From AUD 900/month

Set expectations early

SOC 2 Type 2 takes about a year. Most people are told six weeks.

  1. Weeks 1–4 · Readiness assessmentWhere you find out what you are actually working with.
  2. Months 2–5 · RemediationPolicies written, controls implemented, and — the part teams underestimate — controls operated long enough to leave a trail.
  3. Month 5 · Auditor selection and Type 1A point-in-time report you can put in front of a customer while the clock runs on Type 2.
  4. Months 5–11 · Observation windowThree to six months in which your controls must demonstrably operate. It cannot be shortened, bought or backdated. The step nobody mentions.
  5. Months 11–12 · Fieldwork and reportThe auditor tests your evidence and issues the report your customer asked for.

If a deal depends on a date, you need this map before you promise one — usually the difference between a Type 1 that holds the customer and a commitment you can't meet.

The option most teams try first

Doing it in-house doesn't save money. It moves the cost onto your engineers.

01

Engineering time

A first certification absorbs a third to a half of a senior engineer for four to six months, plus a manager. That's a feature you didn't ship, at your most expensive internal rate.

02

Learning on the clock

The first attempt is also the training run. Scoping errors surface during fieldwork, which is the most expensive possible moment to find them.

03

Key-person risk

The knowledge ends up in one person's head. When they take leave — or another job — the evidence trail and the auditor relationship go with them.

04

It comes back every year

ISO 27001 brings annual surveillance audits and recertification every three years; SOC 2 needs a fresh report each year. Access reviews and register upkeep run indefinitely.

Before you ask

Common questions.

We already bought a compliance platform. Do we still need you?

Vanta, Drata and Sprinto watch controls you've already built. They don't decide what those controls should be, write policies that match your business, or configure the systems so the checks go green for real reasons. Most teams who stall sit at 60% with no idea which of the remaining 40% is an afternoon and which is three months. That gap is the job.

Can you work with the auditor we've already chosen?

Yes — the normal arrangement. We're not auditors and don't issue reports, so there's no independence question. We sit on your side and manage the relationship, the request list and the findings. If you haven't picked one, we'll shortlist firms that suit your size rather than price for enterprise.

Can you do an IRAP assessment?

No. IRAP assessments must be performed by an ASD-endorsed assessor and we don't hold that endorsement — anyone telling you otherwise is worth a second look. We can get you ready for one and help you close what the assessor finds.

What does the whole thing cost, end to end?

For 20 to 100 people on a modern cloud stack, budget AUD 50,000 to 90,000 across a first SOC 2 Type 2 or ISO 27001 cycle — including auditor fees and tooling, not just ours. The APP 1.7 work is far smaller at AUD 2,500. You get a specific number before you commit.

Talk to us Half an hour, and a straight answer either way.