Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Practice Area13 services in this area
Compliance

Compliance Certifications and Privacy Programmes

Get certified, stay certified, and prove it to the people who ask. We build compliance programmes that hold up to auditors, regulators, and your biggest customers.

How We Work

Compliance is where security meets evidence. You need controls that work, documents that match reality, and audits that pass without a scramble. We run the full journey for 13 frameworks: scoping, gap assessment, control design, implementation support, internal audit, and standing by you through certification or attestation. You get a clear plan, a tidy evidence trail, and a partner who speaks both the auditor's language and yours. No box-ticking for its own sake. Real controls that make your business safer and easier to trust.

Jump to the 13 Services

Services in Compliance

Certifications and Privacy Programmes Across 13 Frameworks

13 services in this practice area

Measured Against

ISO/IEC 27001:2022NIST Privacy FrameworkISO/IEC 27701:2019GDPRISO/IEC 27001 Annex ADigital Personal Data Protection Act 2023ISO/IEC 42001:2023ISO/IEC 23894

What We Run

JiraConfluenceVantaOneTrustScrutTrustArcBigIDCredo AI

What You Get Back, Every Framework On One Board

Every service on this page feeds the same control set, so the evidence you produce for one certification counts toward the next one.

Compliance

Worked example

A flat product screenshot of TrustGrid, a compliance automation platform, shown in its dark product interface. The left sidebar carries the TrustGrid mark, the line "Powered by SecureRoot Risk Advisory LLP", and grouped navigation: Overview holding Dashboard, Automation and Tasks with 23 outstanding; Compliance holding Frameworks, Controls, Applicability, Evidence, Policies and Audits; Risk holding Risk register, Third parties and Incidents; Privacy and AI holding Privacy and AI governance; Organisation holding People and access, Integrations, Trust centre, Reports and Settings. Header: compliance posture for SecureRoot Risk Advisory LLP, 7 frameworks in scope, 100 unified controls, with a button to run automated checks. Five headline figures: overall readiness 63 percent, being 63 of 100 controls implemented; 11 failing checks, from 22 passing and 7 warning out of 40; 23 open remediation and implementation tasks; 12 third parties, 2 of them overdue for reassessment; 4 rights requests, 1 past its statutory deadline. Posture trend, recorded once per day when the automated sweep runs, shown for the quarter with trust score selected: 74, 71, 69, 73, 75, 74, 72 on 06-04, 07-02, 07-30, 08-21, 08-25, 08-29, 08-30, so the trust score stands at 72 of 100 and has moved -2 points over the quarter. Trust score, a weighted blend shown broken down so it is never a black box: control readiness scores 66 at 45 percent weight, 63 of 100 controls implemented; automated checks scores 55 at 25 percent weight, 22 of 40 passing; operational hygiene scores 91 at 20 percent weight, 8 of 85 dated items overdue; risk exposure scores 100 at 10 percent weight, 0 of 11 open risks are critical. Those four weighted scores total 71.65, which rounds to the headline 72. Open findings by severity, covering failing checks, vendor findings and remediation tasks: 5 critical, 19 high, 34 medium, 15 low, which sum to the 73 open at the centre of the donut. Illustrative snapshot of a typical programme, not a named client.

Illustrative figures for a typical programme, not a named client. 100 unified controls across 7 frameworks, 63 implemented, 11 failing checks named. The trust score is shown broken into its four measures rather than as one number.

Every one of these is scoped, run and reported by the same team. See All Practice Areas

What It Costs

Indicative Ranges, Before You Ask

Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.

  • Indicative rangeDepends on scope

    SOC 2 Type 1

    ₹1.5 lakh to ₹4.5 lakh

    What sets the figure

    • Readiness and audit support for a report on control design at a point in time
    • Security is always in scope; each optional Trust Services Criterion you add moves you up the range
    • How much of the control set and evidence trail already exists sets where you start
  • Indicative rangeDepends on scope

    SOC 2 Type 2

    ₹1.5 lakh to ₹4.5 lakh

    What sets the figure

    • Readiness and audit support for a report on controls operating over an observation period
    • The observation window, usually three to twelve months, and the criteria in scope set where you land in the range
    • Evidence collection through the period, then support through fieldwork

Indicative ranges in INR as of 2 September 2026; the final quote depends on scope.

Get a Fixed Price for Your Scope

Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.

Request an Assessment

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Which compliance framework should we start with?

Start with the one a customer or a regulator is already asking for, because that is the one with a deadline attached. In practice that means SOC 2 if you sell to US buyers, ISO 27001 if you sell to European or enterprise Indian buyers, PCI DSS if you touch cardholder data, and the DPDP Act if you process the personal data of people in India, which is not optional and does not wait for a customer to ask. If nothing is blocking a deal, ISO 27001 is usually the better first move, because its management system is the thing later frameworks plug into rather than duplicate. What we advise against is picking whichever looks easiest. A certificate nobody asked for costs the same to maintain as one that closes revenue. We work out which is actually in front of you during scoping.

Can we run more than one framework at the same time?

Yes, and it usually costs less than running them in sequence, because the control sets overlap far more than the documents suggest. Access control, change management, logging, vendor management, incident response and business continuity all appear in ISO 27001, SOC 2 and the DPDP Act in different language but resting on the same evidence. We map your controls once, then show which framework each piece of evidence satisfies, so an access review you already run for SOC 2 is not rebuilt from scratch for ISO 27001. The saving is real without being total: each framework keeps its own mandatory artefacts, its own auditor and its own timeline. The pattern that works is one anchor framework built properly, then the second layered onto it within the same year. We tell you honestly how much of the second is already done.

Do you issue the certificate or the report?

No, and no consultancy can. ISO 27001 certificates are issued by an accredited certification body, and SOC 2 reports are issued by a licensed CPA firm. Those bodies have to stay independent of whoever built the programme, so the same firm cannot both implement your controls and attest to them. We do the readiness work: scope, gap assessment, risk treatment, control design, documentation, internal audit and evidence, then we sit alongside you through the audit itself, answer the auditor's questions and help you close findings. We will introduce you to registrars and audit firms we have worked with, and you contract with them directly. Treat anyone offering a certificate inside a bundled price with caution, because a certificate from a body that is not accredited is worth very little to the customer who asked you for one.

How do we start, and what happens on the scoping call?

One call, usually 30 to 45 minutes, with the people who will do the work. Bring whatever started this: the customer questionnaire, the auditor's email, the clause in a contract, or the regulator's deadline. Tell us what you run, where your data sits and who already owns security internally. We work out which framework answers the question actually in front of you, what the scope should cover and what can safely stay outside it, then send you a written scope, a phase by phase timeline and a fixed price. The price is fixed after scoping, never before, so it does not grow later the way an open ended estimate does. If your problem is smaller than a full programme, or you are further along than you thought, we say so on the call rather than selling you a phase you do not need.

What do we actually get at the end of a compliance engagement?

A working management system and the evidence that proves it runs, rather than a folder of templates. Depending on the framework that means a defined scope, a gap assessment you can act on, a risk assessment and treatment plan, the policy and procedure set the standard requires, a Statement of Applicability where ISO 27001 applies, internal audit and management review records, and the evidence trail an auditor samples from. For privacy work it also means a data inventory and flow map, a consent and notice framework, a data principal rights playbook and a breach response procedure. All of it is written to fit how your teams actually work, because a control nobody follows fails the audit that tests operation rather than design. You own the output, it lives in your own systems, and it stays usable after we leave.

What happens after we are certified?

The certificate starts a cycle rather than ending a project. ISO 27001 runs on a three year cycle, with surveillance audits in the intervening years and a full recertification at the end, and each one asks for evidence that the management system kept operating. SOC 2 reports cover a point in time or a period, so buyers expect a fresh one every year with no gap between windows for them to ask about. The DPDP Act has no certificate at all, which means the programme itself is your evidence and it has to hold up whenever a regulator or a customer asks. What keeps this alive is unglamorous: access reviews on schedule, the risk register genuinely reviewed, incidents logged and closed, management review actually held. We stay on through the surveillance and annual cycles, or hand over with a calendar of what falls due when.

Not Sure Which of These You Need?

Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.

Locations