1. ISO 27001 & SOC 2 readiness
Since 2026, Abilitix has run one structured readiness programme that supports both frameworks — the same engineering controls and periodic evidence packs:
- ISO 27001–aligned ISMS — policies, risk register, scope and Statement of Applicability (SoA) artefacts, and management review as part of evidence collection (primary framing for ANZ enterprise and BPO procurement)
- SOC 2–aligned controls — mapping to Trust Services Criteria (Security, Availability, Confidentiality) for buyers who use SOC language
- Internal control reviews — assessments of tenant isolation, audit logging, access control, and data-handling practices
- Engineering gates — tenant isolation enforced by design and verified by automated cross-tenant isolation tests in CI; security controls documented in our engineering baseline
- Gap closure — partial controls tracked and remediated before a formal certification or observation window
Formal certification and Type II attestation each require an external auditor and defined observation period — separate steps from readiness. We do not publish a target certification date. Procurement teams can request our current evidence summary under NDA: security@abilitix.com.au