Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Prove Your Controls Work

SOC 2 Compliance and Audit Readiness in India

SOC 2 is the attestation report customers ask for before they trust you with their data. We help you get ready for both Type 1 and Type 2, then support you through the audit.

Certified ISO/IEC 27001:2022 (certificate IN60432E)

See the engagement path, 6 phasesSee the full Compliance service index

Overview

SOC 2 is an attestation, produced by a licensed auditor, that reports on how well your controls meet the Trust Services Criteria for security and, if you choose, availability, confidentiality, processing integrity, and privacy. A Type 1 report judges your controls at a single point in time. A Type 2 report tests that they operated effectively across a period, usually three to twelve months. It matters because buyers use it to vet vendors quickly. We help Indian SaaS and IT services companies design controls, pick the right criteria, and collect the evidence an auditor needs, working remotely across India from our Greater Noida and Kanpur offices.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the SOC 2 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Criteria Selection. We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2. Activities: Select the Trust Services Criteria in scope; Decide the Type 1 or Type 2 path and timing; Define system boundaries for the report; Shortlist audit firms and align on timeline. Hands over Scope Memo and Audit Roadmap. Phase 2, Gap Assessment. We measure your controls against the criteria and give you a clear list of what to fix before the audit. Activities: Map existing controls to each criterion; Interview engineering, HR, and IT control owners; Test key controls for design and evidence; Rank gaps by audit impact and effort. Hands over Readiness Assessment Report. Phase 3, Control Design and Remediation. We help you design and implement the controls, from access reviews to change management and monitoring. Activities: Draft policies for access, change, and incidents; Implement quarterly access reviews; Stand up change management and monitoring controls; Assign owners for every control in the matrix. Hands over Control Matrix and Remediated Control Set. Phase 4, Evidence Automation. We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2. Activities: Connect cloud, HR, and code repositories to the platform; Map automated tests to each control; Set alerts for failing evidence checks; Close manual evidence gaps with owners. Hands over Automated Evidence Collection Setup. Phase 5, Observation Period Support. For Type 2, we help you run the controls consistently across the audit window and watch for drift. Activities: Monitor control performance across the window; Review platform alerts and fix drift early; Document exceptions and remediation; Run monthly check-ins with control owners. Hands over Clean Observation Period Evidence Trail. Phase 6, Audit Support. We work alongside your auditor through fieldwork so the report lands without surprises. Activities: Manage auditor evidence requests; Prepare control owners for walkthroughs; Respond to exceptions before they become findings; Review the draft report and management assertion. Hands over SOC 2 Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Criteria Selection

We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.

What Happens In This Phase

  • Select the Trust Services Criteria in scope
  • Decide the Type 1 or Type 2 path and timing
  • Define system boundaries for the report
  • Shortlist audit firms and align on timeline

The Handover

Scope Memo and Audit Roadmap

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Criteria Selection

    We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.

    OutputScope Memo and Audit Roadmap

    Activities

    • Select the Trust Services Criteria in scope
    • Decide the Type 1 or Type 2 path and timing
    • Define system boundaries for the report
    • Shortlist audit firms and align on timeline
  2. 02

    Gap Assessment

    We measure your controls against the criteria and give you a clear list of what to fix before the audit.

    OutputReadiness Assessment Report

    Activities

    • Map existing controls to each criterion
    • Interview engineering, HR, and IT control owners
    • Test key controls for design and evidence
    • Rank gaps by audit impact and effort
  3. 03

    Control Design and Remediation

    We help you design and implement the controls, from access reviews to change management and monitoring.

    OutputControl Matrix and Remediated Control Set

    Activities

    • Draft policies for access, change, and incidents
    • Implement quarterly access reviews
    • Stand up change management and monitoring controls
    • Assign owners for every control in the matrix
  4. 04

    Evidence Automation

    We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2.

    OutputAutomated Evidence Collection Setup

    Activities

    • Connect cloud, HR, and code repositories to the platform
    • Map automated tests to each control
    • Set alerts for failing evidence checks
    • Close manual evidence gaps with owners
  5. 05

    Observation Period Support

    For Type 2, we help you run the controls consistently across the audit window and watch for drift.

    OutputClean Observation Period Evidence Trail

    Activities

    • Monitor control performance across the window
    • Review platform alerts and fix drift early
    • Document exceptions and remediation
    • Run monthly check-ins with control owners
  6. 06

    Audit Support

    We work alongside your auditor through fieldwork so the report lands without surprises.

    OutputSOC 2 Report

    Activities

    • Manage auditor evidence requests
    • Prepare control owners for walkthroughs
    • Respond to exceptions before they become findings
    • Review the draft report and management assertion

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the SOC 2 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Secureframe, AWS Config, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: AICPA Trust Services Criteria, SOC 2 Type 1, SOC 2 Type 2, AICPA SSAE 18, COSO Framework.

What We Run

8 tools

  • Vanta
  • Drata
  • Sprinto
  • Scrut
  • Secureframe
  • AWS Config
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • SOC2AICPATrust Services Criteria
  • SOC2AICPAType 1
  • SOC2AICPAType 2
  • AICPASSAE 18
  • COSOFramework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Readiness assessment report
  • Control matrix mapped to criteria
  • Remediation plan
  • Evidence collection setup
  • Audit support through fieldwork

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

What It Costs

Indicative Ranges, Before You Ask

Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.

  • Indicative rangeDepends on scope

    SOC 2 Type 1

    ₹1.5 lakh to ₹4.5 lakh

    What sets the figure

    • Readiness and audit support for a report on control design at a point in time
    • Security is always in scope; each optional Trust Services Criterion you add moves you up the range
    • How much of the control set and evidence trail already exists sets where you start
  • Indicative rangeDepends on scope

    SOC 2 Type 2

    ₹1.5 lakh to ₹4.5 lakh

    What sets the figure

    • Readiness and audit support for a report on controls operating over an observation period
    • The observation window, usually three to twelve months, and the criteria in scope set where you land in the range
    • Evidence collection through the period, then support through fieldwork

Indicative ranges in INR as of 2 September 2026; the final quote depends on scope.

Get a Fixed Price for Your Scope

Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.

Request an Assessment

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Should we start with SOC 2 Type 1 or Type 2?

Type 1 judges whether your controls are designed correctly at a single point in time, so it is faster and it unblocks a deal that is waiting on paperwork. Type 2 tests whether those controls actually operated across a period, usually three to twelve months, and buyers weigh it far more heavily because design without operation proves very little. The common path is Type 1 first, then a Type 2 covering the months that follow, which lets you show progress while the observation window runs. Going straight to Type 2 makes sense when no deal is blocked and your control set is already mature, because you skip the cost of two audits. What decides it is usually commercial rather than technical: how soon a customer needs the report, and whether they have said which type they will accept. We help you make that call during scoping.

How long is the Type 2 observation period?

Usually three to twelve months. A first report commonly uses a three to six month window, and annual reports that follow cover a full twelve months so there is no gap between reports for a customer to ask about. The window is a real constraint rather than a formality: your controls have to run consistently across it, and evidence has to accumulate as you go, because an auditor sampling month two cannot be satisfied with evidence produced in month six. That is why we connect a compliance platform during the evidence automation phase, so collection happens without somebody remembering to do it. A shorter first window gets you a report sooner but gives the auditor a smaller sample. We help you pick a window that balances the deal you are chasing against the maturity you can actually sustain.

Which Trust Services Criteria do we need?

Security, the common criteria, is always required and is the whole of the scope for most first reports. Availability, confidentiality, processing integrity and privacy are optional, and you add them when you have made a promise that needs evidencing. Availability suits a platform selling on an uptime commitment. Confidentiality suits one handling customer data under contractual restrictions. Processing integrity matters where the correctness of a transaction is the product, as in payments or payroll. Privacy overlaps heavily with the DPDP Act and GDPR work you may already be doing. Each criterion you add brings more controls, more evidence and a longer audit, so the discipline is to include what your customers actually ask about rather than everything that sounds reassuring. We check your contracts and security questionnaires during scoping and recommend the smallest set that answers them.

What does a SOC 2 engagement cost?

Indicative range: ₹1.5 lakh to ₹4.5 lakh for Type 1 readiness and audit support, and ₹1.5 lakh to ₹4.5 lakh for Type 2. The final quote depends on scope, mainly the Trust Services Criteria you include, how much of the control set already exists, and for Type 2 the length of the observation period. Two costs sit outside that figure and catch people out. The auditor's fee is separate, because the report has to come from a licensed CPA firm that stays independent of whoever built the controls, and you contract with them directly. The second is your own team's time across the observation window, running access reviews and producing evidence month after month, which is why we automate collection early rather than leaving it to a scramble before fieldwork. We confirm a fixed price once scoping is done, never before.

How long does SOC 2 take in India?

Most Indian companies reach a Type 1 report in eight to twelve weeks and a first Type 2 report in six to nine months, and our phases add up to that. Scoping and criteria selection takes one to two weeks, the gap assessment two to three, control design and remediation four to eight, and evidence automation two to three. Type 1 fieldwork can start as soon as the controls are designed and evidenced once. Type 2 then needs the observation period, usually three months for a first report, followed by four to six weeks of fieldwork. Location changes none of this: our team works from Greater Noida and Kanpur and runs engagements remotely across India, so a Bengaluru or Hyderabad SaaS company follows the same calendar as one in Delhi NCR. What moves the date is how many controls already operate and how fast your owners produce evidence, which is why we commit to a timeline only after the gap assessment.

Does an Indian company need SOC 2?

No Indian law requires it. The DPDP Act, the RBI and SEBI directions and the CERT-In rules set their own obligations, and none of them names SOC 2. The need is commercial. If you sell software or services to customers in the United States, and increasingly in the United Kingdom, the Gulf and Australia, their procurement and security teams ask for a SOC 2 report before they sign, and a security questionnaire answered without one tends to stall in legal review. Indian enterprise buyers ask far less often and usually accept ISO 27001 instead. So the test is your pipeline, not your geography: an Indian SaaS company with US customers needs SOC 2 as much as a Californian one does, while a services firm selling only to Indian banks may never be asked. We look at your active deals and customer contracts during scoping and tell you plainly whether SOC 2, ISO 27001 or both is the right first spend.

Who issues the SOC 2 report, and can SecureRoot issue it?

Only a licensed CPA firm, working under the AICPA attestation standards, can issue a SOC 2 report, and it has to stay independent of whoever designed and implemented the controls. SecureRoot is not a CPA firm and does not issue the report, and no readiness consultant honestly can: a firm offering to build your controls and then attest to them is proposing an audit of its own work. What we do is everything on either side of the audit. We scope the criteria, close the gaps, set up evidence collection, and then represent you through fieldwork, handling the auditor's requests and preparing your control owners for walkthroughs. We also shortlist audit firms with you, including India-based CPA practices and international firms that audit Indian SaaS companies remotely, so the auditor's fee and timeline are known before you commit. The report carries the auditor's name. The clean result is the work we do with you beforehand.

Should we do SOC 2 or ISO 27001 first?

Follow the customer who is asking. American buyers ask for SOC 2 and rarely accept ISO 27001 in its place; Indian, European and Middle Eastern buyers more often ask for ISO 27001 and accept it instead of SOC 2. If both appear in your pipeline, run them on one control set rather than as two projects. The Trust Services Criteria for security and Annex A of ISO 27001 overlap heavily on access control, change management, logging, incident response and vendor management, so a single access review or a single incident record serves as evidence for both. We map every control to both frameworks in the control matrix and run one evidence trail through a compliance platform, which is how a first SOC 2 Type 2 report and an ISO 27001 certificate can land within a few months of each other. Our ISO 27001 vs SOC 2 guide, linked below, sets out the differences in detail if you want the longer version.

Keep Moving Through Compliance

Service 8 of 13 in this practice area