SOC 2 · India

SOC 2 compliance in India: one control set for US buyers and Indian law.

Indian SaaS companies need SOC 2 for US deals and must meet CERT-In and the DPDP Act regardless. Here is how to run the SOC 2 programme from India so the same controls satisfy all three.

Last updated Published by TryTrustableNot legal advice

Short answer

SOC 2 is not required by Indian law, but Indian SaaS companies selling to US buyers usually need a Type 2 report. The report must be issued by a licensed US CPA firm, often working through an Indian team. Plan two to four months of readiness and a three to twelve month window. Build the controls once so they also meet the Indian rules that apply anyway: CERT-In's six-hour reporting and 180-day logs in India, and from 13 May 2027 the DPDP Act's safeguards and one-year logs.

01

What applies, and when

SOC 2 is an attestation, not a certificate: a licensed CPA firm's opinion on your controls against the AICPA Trust Services Criteria. Nothing in Indian law requires it. The SOC 2 guide covers the criteria, report types and how to check the signing firm; this page covers running the programme from India alongside the Indian rules that already bind you.

RegimeApplies to an Indian SaaS companySince
SOC 2When a customer asks for the report, usually US mid-market and enterpriseCommercial, no date
CERT-In DirectionsEvery body corporate: six-hour incident reporting, 180-day logs in India, clock sync, point of contact2022
DPDP Act and RulesProcessing of digital personal data in India, as Fiduciary or through customer contracts as ProcessorSubstantive duties 13 May 2027
ISO 27001When Indian or European customers ask for a certificateCommercial, no date
Sector rulesVendors to banks, securities firms and insurers, through their regulators' requirementsVaries

See CERT-In Directions, the DPDP guide and the sector pages for RBI, SEBI CSCRF and IRDAI.

02

Decisions specific to an Indian company

  • Who signs. The opinion must come from a US-licensed CPA firm under AICPA standards. An Indian affiliate doing the fieldwork is normal; confirm the signing firm on CPAverify. The AICPA has said it acts against reports issued without a licence or peer review
  • Which entity. If you sell through a US parent and operate from an Indian subsidiary, the system description should name whoever runs the service, with its people and infrastructure
  • Where data lives. SOC 2 does not prefer any region, but the description must say where the system runs. If you serve Indian users, CERT-In's log direction and the DPDP Rules shape that choice; the cloud provider's Indian region is usually carved out as a subservice organisation
  • People across cities and contractors. Hiring, background screening where lawful, onboarding and offboarding are tested under CC1 and CC6. Contractors and agency staff with production access are in the sample too
  • Which framework first. If most of your pipeline is Indian or European, ISO 27001 may win more deals; SOC 2 vs ISO 27001 sets out when each wins
03

One control, three regimes

The work that pays off is designing each control to meet the strictest requirement once, so the SOC 2 evidence also shows CERT-In and DPDP compliance.

ControlSOC 2 (common reading)CERT-InDPDP Rules (from 13 May 2027)Build it as
Incident responseCC7.3 to CC7.5Report listed incidents within 6 hours of noticingNotify each person and the Board without delay; detailed report within 72 hours (Rule 7)One runbook with both clocks
LoggingCC7.2180 days of ICT logs in Indian jurisdictionLogs and personal data kept at least one year (Rule 6(1)(e), 8(3))One year retained, with a copy in India
Clock syncSupports CC7.2NIC or NPL NTP, or a traceable source-Cloud time service traceable to them
Access controlCC6.1 to CC6.3-Access controlled and monitored (Rule 6(1)(b), (c))Reviews dated, leavers removed fast
EncryptionCC6.1, CC6.7-Encryption, masking or tokens (Rule 6(1)(a))At rest and in transit, backups included
Vendor contractsCC9.2Obligation cannot be passed to a vendorProcessors under contract with safeguards (s.8(2), Rule 6(1)(f))Standard DPA and vendor review

CERT-In from the Directions of 28 April 2022 and its FAQs; DPDP from the Rules as notified. Not legal advice.

04

The gaps we see most often in Indian companies

  • A system description naming the US entity while the people and infrastructure belong to the Indian subsidiary
  • Incident response written for SOC 2 with no six-hour CERT-In step
  • Log retention of 30 or 90 days, short of both CERT-In and the DPDP floor
  • Offboarding of contractors and agency staff handled by email, with access removed days late
  • Laptops bought locally with no record of encryption or screen lock
  • A fixed-price bundle of software, policies and "the audit" from a provider who is not independent of the controls
  • Treating the SOC 2 report as DPDP compliance
05

A realistic timeline

StageWhat happensTypical length
ScopeEntity, system, categories, subservice organisations, CPA firm engagedTwo to four weeks
ReadinessGap assessment, policies, controls built to the strictest of SOC 2, CERT-In and DPDPTwo to four months
Type 1 (optional)Design tested as of a dateA few weeks of fieldwork
Type 2 windowControls operate; evidence accumulatesThree to twelve months
Fieldwork and reportSamples, exceptions, management responses; usually remoteSeveral weeks

Common ranges, consistent with the SOC 2 guide. A first Type 2 commonly lands six to twelve months after work starts.

06

What drives the cost

There is no published price list, and figures quoted online vary widely, so we do not give one. The drivers are the categories in scope, the number of systems, locations and subservice organisations, the window length, how much evidence is system-generated, and whether you buy readiness help. Ask two or three licensed firms to quote on the same written scope.

07

SOC 2 checklist for an Indian SaaS company

#TaskDone when
1Decide the entity that operates the systemNamed in the engagement letter and description
2Confirm the signing CPA firm's licence and peer reviewCPAverify result and peer review on file
3Choose categories: Security, plus Availability or Confidentiality if you commit to themScope agreed
4Carve out the cloud provider as a subservice organisationComplementary controls listed
5Write one incident runbook with CERT-In's six hours and the DPDP 72 hoursDrill completed
6Retain logs for a year, with a copy in IndiaRetention configured and tested
7Sync clocks to a source traceable to NIC or NPLDocumented
8Run quarterly access reviews and fast offboarding, contractors includedDated reviews; removal times recorded
9Record encryption and screen lock for every laptopPer-device evidence
10Put every vendor handling personal data under contractDPA signed; vendor reviewed
11Decide whether Indian buyers also need ISO 27001Decision recorded
08

How TryTrustable helps, and what it does not do

The platform does not issue SOC 2 reports, store your logs or report to CERT-In. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.

09

Sources

Questions

The things people ask us

Is SOC 2 mandatory for companies in India?

No. No Indian law requires SOC 2. It becomes necessary when customers, mostly in the US, ask for a SOC 2 Type 2 report in their security review. Indian legal duties such as CERT-In's Directions and the DPDP Act apply separately and are not satisfied by a SOC 2 report.

Can an Indian audit firm issue a SOC 2 report?

Only a CPA firm licensed in the US can issue the SOC 2 opinion, because it is an examination under AICPA attestation standards. Indian teams and affiliates often do the fieldwork. Check which licensed firm signs the report, look it up on CPAverify and ask for its peer review.

Which entity should be in an Indian company's SOC 2 report?

The entity that operates the system customers rely on. Many groups sell through a US parent and build in an Indian subsidiary. The system description must name the entity, people and infrastructure that actually run the service, so decide this before the engagement letter is signed.

Does SOC 2 cover CERT-In and DPDP requirements?

No, but the controls overlap. Incident response, logging and access control are tested in SOC 2 and required by CERT-In and the DPDP Rules. The specifics differ: CERT-In wants reports within six hours and 180 days of logs in India, the DPDP Rules a year of logs. Design one control that meets the strictest requirement.

Do Indian enterprise customers ask for SOC 2?

Some do, but Indian and European buyers more often ask for ISO 27001, and regulated buyers in banking, securities and insurance apply their regulators' own vendor requirements. If your pipeline is mainly Indian, check what your buyers ask for before choosing.

Book a walkthrough

One control set for US buyers and Indian law.

We enable SOC 2 alongside CERT-In and DPDP for one entity, connect a repository and a cloud account, and show which requirements have evidence behind them. Thirty minutes.