SOC 2 compliance in India: one control set for US buyers and Indian law.
Indian SaaS companies need SOC 2 for US deals and must meet CERT-In and the DPDP Act regardless. Here is how to run the SOC 2 programme from India so the same controls satisfy all three.
Last updated Published by TryTrustableNot legal advice
SOC 2 is not required by Indian law, but Indian SaaS companies selling to US buyers usually need a Type 2 report. The report must be issued by a licensed US CPA firm, often working through an Indian team. Plan two to four months of readiness and a three to twelve month window. Build the controls once so they also meet the Indian rules that apply anyway: CERT-In's six-hour reporting and 180-day logs in India, and from 13 May 2027 the DPDP Act's safeguards and one-year logs.
What applies, and when
SOC 2 is an attestation, not a certificate: a licensed CPA firm's opinion on your controls against the AICPA Trust Services Criteria. Nothing in Indian law requires it. The SOC 2 guide covers the criteria, report types and how to check the signing firm; this page covers running the programme from India alongside the Indian rules that already bind you.
| Regime | Applies to an Indian SaaS company | Since |
|---|---|---|
| SOC 2 | When a customer asks for the report, usually US mid-market and enterprise | Commercial, no date |
| CERT-In Directions | Every body corporate: six-hour incident reporting, 180-day logs in India, clock sync, point of contact | 2022 |
| DPDP Act and Rules | Processing of digital personal data in India, as Fiduciary or through customer contracts as Processor | Substantive duties 13 May 2027 |
| ISO 27001 | When Indian or European customers ask for a certificate | Commercial, no date |
| Sector rules | Vendors to banks, securities firms and insurers, through their regulators' requirements | Varies |
See CERT-In Directions, the DPDP guide and the sector pages for RBI, SEBI CSCRF and IRDAI.
Decisions specific to an Indian company
- Who signs. The opinion must come from a US-licensed CPA firm under AICPA standards. An Indian affiliate doing the fieldwork is normal; confirm the signing firm on CPAverify. The AICPA has said it acts against reports issued without a licence or peer review
- Which entity. If you sell through a US parent and operate from an Indian subsidiary, the system description should name whoever runs the service, with its people and infrastructure
- Where data lives. SOC 2 does not prefer any region, but the description must say where the system runs. If you serve Indian users, CERT-In's log direction and the DPDP Rules shape that choice; the cloud provider's Indian region is usually carved out as a subservice organisation
- People across cities and contractors. Hiring, background screening where lawful, onboarding and offboarding are tested under CC1 and CC6. Contractors and agency staff with production access are in the sample too
- Which framework first. If most of your pipeline is Indian or European, ISO 27001 may win more deals; SOC 2 vs ISO 27001 sets out when each wins
One control, three regimes
The work that pays off is designing each control to meet the strictest requirement once, so the SOC 2 evidence also shows CERT-In and DPDP compliance.
| Control | SOC 2 (common reading) | CERT-In | DPDP Rules (from 13 May 2027) | Build it as |
|---|---|---|---|---|
| Incident response | CC7.3 to CC7.5 | Report listed incidents within 6 hours of noticing | Notify each person and the Board without delay; detailed report within 72 hours (Rule 7) | One runbook with both clocks |
| Logging | CC7.2 | 180 days of ICT logs in Indian jurisdiction | Logs and personal data kept at least one year (Rule 6(1)(e), 8(3)) | One year retained, with a copy in India |
| Clock sync | Supports CC7.2 | NIC or NPL NTP, or a traceable source | - | Cloud time service traceable to them |
| Access control | CC6.1 to CC6.3 | - | Access controlled and monitored (Rule 6(1)(b), (c)) | Reviews dated, leavers removed fast |
| Encryption | CC6.1, CC6.7 | - | Encryption, masking or tokens (Rule 6(1)(a)) | At rest and in transit, backups included |
| Vendor contracts | CC9.2 | Obligation cannot be passed to a vendor | Processors under contract with safeguards (s.8(2), Rule 6(1)(f)) | Standard DPA and vendor review |
CERT-In from the Directions of 28 April 2022 and its FAQs; DPDP from the Rules as notified. Not legal advice.
The gaps we see most often in Indian companies
- A system description naming the US entity while the people and infrastructure belong to the Indian subsidiary
- Incident response written for SOC 2 with no six-hour CERT-In step
- Log retention of 30 or 90 days, short of both CERT-In and the DPDP floor
- Offboarding of contractors and agency staff handled by email, with access removed days late
- Laptops bought locally with no record of encryption or screen lock
- A fixed-price bundle of software, policies and "the audit" from a provider who is not independent of the controls
- Treating the SOC 2 report as DPDP compliance
A realistic timeline
| Stage | What happens | Typical length |
|---|---|---|
| Scope | Entity, system, categories, subservice organisations, CPA firm engaged | Two to four weeks |
| Readiness | Gap assessment, policies, controls built to the strictest of SOC 2, CERT-In and DPDP | Two to four months |
| Type 1 (optional) | Design tested as of a date | A few weeks of fieldwork |
| Type 2 window | Controls operate; evidence accumulates | Three to twelve months |
| Fieldwork and report | Samples, exceptions, management responses; usually remote | Several weeks |
Common ranges, consistent with the SOC 2 guide. A first Type 2 commonly lands six to twelve months after work starts.
What drives the cost
There is no published price list, and figures quoted online vary widely, so we do not give one. The drivers are the categories in scope, the number of systems, locations and subservice organisations, the window length, how much evidence is system-generated, and whether you buy readiness help. Ask two or three licensed firms to quote on the same written scope.
SOC 2 checklist for an Indian SaaS company
| # | Task | Done when |
|---|---|---|
| 1 | Decide the entity that operates the system | Named in the engagement letter and description |
| 2 | Confirm the signing CPA firm's licence and peer review | CPAverify result and peer review on file |
| 3 | Choose categories: Security, plus Availability or Confidentiality if you commit to them | Scope agreed |
| 4 | Carve out the cloud provider as a subservice organisation | Complementary controls listed |
| 5 | Write one incident runbook with CERT-In's six hours and the DPDP 72 hours | Drill completed |
| 6 | Retain logs for a year, with a copy in India | Retention configured and tested |
| 7 | Sync clocks to a source traceable to NIC or NPL | Documented |
| 8 | Run quarterly access reviews and fast offboarding, contractors included | Dated reviews; removal times recorded |
| 9 | Record encryption and screen lock for every laptop | Per-device evidence |
| 10 | Put every vendor handling personal data under contract | DPA signed; vendor reviewed |
| 11 | Decide whether Indian buyers also need ISO 27001 | Decision recorded |
How TryTrustable helps, and what it does not do
- SOC 2, ISO 27001, DPDP and CERT-In on one control set. The compliance programme maps them together and derives readiness from control results; see coverage
- Evidence from code and cloud. SDK and CI checks plus GitHub, AWS and Google Cloud checks
- For the auditor and buyers. A scoped auditor portal, sealed reports a reader can verify, and a public trust page
- Built and hosted in India. Customer data is hosted in Mumbai
The platform does not issue SOC 2 reports, store your logs or report to CERT-In. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.
Sources
- AICPA: 2017 Trust Services Criteria, revised points of focus (2022)
- AICPA: SOC suite of services
- CPAverify: CPA licence lookup
- CERT-In: Directions under section 70B(6), 28 April 2022
- CERT-In: FAQs on the Directions, May 2022
- MeitY: Digital Personal Data Protection Rules, 2025
- MeitY: Digital Personal Data Protection Act, 2023
Checked against these sources in October 2026. Laws, standards and dates change: check the source before you rely on a figure. Not legal, audit or certification advice.
Related audience guides: SOC 2 for AI start-ups · ISO 42001 for AI start-ups · EU AI Act for SaaS · GDPR for SaaS · DPDP for SaaS
The things people ask us
Is SOC 2 mandatory for companies in India?
No. No Indian law requires SOC 2. It becomes necessary when customers, mostly in the US, ask for a SOC 2 Type 2 report in their security review. Indian legal duties such as CERT-In's Directions and the DPDP Act apply separately and are not satisfied by a SOC 2 report.
Can an Indian audit firm issue a SOC 2 report?
Only a CPA firm licensed in the US can issue the SOC 2 opinion, because it is an examination under AICPA attestation standards. Indian teams and affiliates often do the fieldwork. Check which licensed firm signs the report, look it up on CPAverify and ask for its peer review.
Which entity should be in an Indian company's SOC 2 report?
The entity that operates the system customers rely on. Many groups sell through a US parent and build in an Indian subsidiary. The system description must name the entity, people and infrastructure that actually run the service, so decide this before the engagement letter is signed.
Does SOC 2 cover CERT-In and DPDP requirements?
No, but the controls overlap. Incident response, logging and access control are tested in SOC 2 and required by CERT-In and the DPDP Rules. The specifics differ: CERT-In wants reports within six hours and 180 days of logs in India, the DPDP Rules a year of logs. Design one control that meets the strictest requirement.
Do Indian enterprise customers ask for SOC 2?
Some do, but Indian and European buyers more often ask for ISO 27001, and regulated buyers in banking, securities and insurance apply their regulators' own vendor requirements. If your pipeline is mainly Indian, check what your buyers ask for before choosing.
One control set for US buyers and Indian law.
We enable SOC 2 alongside CERT-In and DPDP for one entity, connect a repository and a cloud account, and show which requirements have evidence behind them. Thirty minutes.