Where does your SOC 2 / ISO 27001 readiness stand? Take the 2-min self-check
Knowledge Base

Frequently Asked Questions

Answers to the most common questions about SOC 2, ISO 27001, DPDP, HIPAA, PCI DSS, AI Risk and vCISO — and how Tasvika Ventures works. If your question is not here, get in touch.

Tasvika Ventures is an independent cyber risk, audit and compliance advisory firm based in Hyderabad. We help organisations strengthen security, achieve audit and certification readiness, and build genuine compliance capability across SOC 2, ISO 27001, HIPAA, PCI DSS, DPDP, AI Risk and vCISO services.

We are a preparation and readiness firm. We do not issue certifications or audit opinions — those are issued only by accredited CPA firms and certification bodies.

Our positioning in one sentence: We prepare you. Accredited bodies certify you.

Primarily B2B technology companies, SaaS platforms, fintech, BFSI, healthcare technology and professional services organisations — across India and internationally. We also work with enterprise teams that need a senior independent advisory voice and are not yet ready to build an internal security or compliance function.

Auditors assess what is already in place. They don't coach you through gaps before the audit begins. Coming to an auditor unprepared typically means costly delays, unexpected findings, and a longer path to your report.

We close the gap first — so that when the auditor arrives, you are ready. It is a cleaner, faster and less expensive path to the outcome you need.

No. The formal SOC 2 attestation report is issued by a licensed CPA firm; ISO 27001 certification is issued by an accredited certification body. We prepare you for that examination — closing gaps, building evidence, strengthening controls — and maintain structural independence from the auditor, which protects the integrity of both relationships.

We are based in Hyderabad, India. We work with Indian organisations and with international companies — particularly those serving the Indian market (DPDP), US enterprise customers (SOC 2, HIPAA), or operating across global regulated markets (ISO 27001, PCI DSS).

SOC 2 (System and Organization Controls 2) is an independent attestation report confirming whether a service organisation's controls meet the Trust Services Criteria (TSC) — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory; the others are included based on what is relevant to your services.

The report is issued by a licensed CPA firm under the AICPA's AT-C Section 205 standard. It is the standard most B2B SaaS, cloud and technology companies are asked for by enterprise customers.

SOC 2 Type ISOC 2 Type IISOC 3
AssessesDesign and suitability of controls at a point in timeDesign + operating effectiveness over a periodSame as Type II, summary only
PeriodA single dateMinimum 6 monthsMinimum 6 months
AudienceCustomers, prospects (under NDA)Enterprise procurement (under NDA)Public — can be posted on your website
Typical useFast market entry, first audit, fundraisingEnterprise deals, regulated markets, ongoing assuranceMarketing and public trust signal
Timeline from ready1–3 months6–12 monthsSame process as Type II
SOC 3 is always based on a Type II examination but omits detailed test procedures and results. It is suitable for public sharing but does not replace SOC 2 Type II in enterprise procurement.

Start with Type I if you need a report quickly — an enterprise deal is pending, you are fundraising, or you are implementing controls for the first time. It is a faster, lower-cost milestone that gets something in front of customers while you build toward Type II.

Go directly to Type II if your controls are already mature and enterprise customers are demanding it. You save the Type I cost and reach the stronger report sooner.

Either path requires the same readiness preparation. The difference is only in the examination period and the depth of assurance the auditor provides.

SOC 1 focuses on controls over financial reporting — relevant if your service processes or affects your customers' financial data (payroll, billing, transaction processing). It is primarily of interest to your customers' financial auditors.

SOC 2 focuses on data security and operational controls. Most technology companies need SOC 2. Some need both, depending on the nature of their services.

  • Readiness and gap closure: typically 2–4 months
  • Type I audit: 1–3 months once ready
  • Type II observation period: minimum 6 months of operating controls before the audit begins
  • End to end (first-time Type II): typically 9–15 months

The best way to compress the timeline is to start readiness preparation early and treat evidence collection as a continuous activity, not a pre-audit scramble.

Not exactly — and the distinction matters. A SOC 2 report describes what the auditor examined during a defined period or as of a specific date, both of which have already passed. It provides assurance over that examination period, not over what happens afterward.

The auditor's opinion states whether controls were suitably designed and — in a Type II — operated effectively to meet the Trust Services Criteria during the examination period. It does not guarantee the organisation is secure today, predict future security, or certify the overall security posture.

A report covering January through June does not provide assurance about July. Controls that operated effectively during the examination can change afterward due to new systems, configuration changes, staff turnover or other operational changes.

When reviewing a SOC 2 report: confirm whether it is Type I or Type II, note the examination period, and review any exceptions or modified opinion. Enterprise procurement teams typically require reports issued within the last 12 months.

An exception means a control was not suitably designed (Type I) or did not operate as expected during testing (Type II). An exception does not automatically mean the report failed — its significance depends on frequency, which controls were affected, and their importance to the Trust Services Criteria.

  • Qualified Opinion One or more significant exceptions were identified, but remaining controls met the criteria.
  • Adverse Opinion Control failures were significant enough that the criteria were not met.
  • Disclaimer of Opinion The auditor could not obtain sufficient evidence to express an opinion.

Whenever exceptions or a modified opinion appear, read beyond the opinion letter. Management's response often explains the cause, corrective actions, and remediation already underway.

When a vendor performs controls that support your service commitments, it becomes a subservice organization. There are two ways to handle this in your report:

  • Carve-out method (most common): the system description identifies the vendor and the controls it is assumed to perform, but those controls remain outside the examination. Readers who need assurance over the vendor's controls refer to the vendor's own SOC 2 report.
  • Inclusive method: the vendor's relevant controls are tested alongside yours. This requires the vendor's management to provide a written assertion and participate in the examination — generally limited to closely affiliated providers.
A carve-out is not a gap or a red flag — it defines the examination boundary. Your system description should document which Trust Services Criteria depend on the vendor and what controls it is expected to perform. These are called Complementary Subservice Organization Controls (CSOCs). Readers use them to compare your assumptions against the vendor's own SOC 2 report.

Most organisations undergo a SOC 2 examination annually. Enterprise customers typically consider a report current only if issued within the last 12 months — annual renewal maintains continuous assurance for your customer base.

For short periods between reports, a bridge letter issued by your own management (not the auditor) can cover gaps of up to 3–6 months. Beyond that window, only a fresh examination restores independent assurance. The bridge letter is a management representation — it is not audited and cannot substitute for a current report.

A readiness assessment is an independent review of where your organisation stands against a framework's requirements before the formal audit or certification begins. It identifies gaps, prioritises what needs to be fixed, and gives you a clear remediation roadmap.

Think of it as a rehearsal before the real exam — one where you find and fix the problems before they become findings in an auditor's report.

The terms are often used interchangeably. Strictly, a gap assessment identifies and documents the specific gaps between your current state and the target framework requirements. A readiness assessment goes further — it also evaluates whether those gaps are remediated and confirms whether you are genuinely ready to proceed to audit.

Tasvika's readiness engagements include both: a gap analysis and a readiness gate that gives you a clear go or not-yet-go decision before you commit to the formal examination.

Your auditor will find the gaps during the formal examination — typically resulting in findings, a qualified or adverse opinion, delays while you remediate, or the cost of a re-audit. Skipping readiness preparation is almost always more expensive and slower than doing it properly upfront.

Most experienced organisations invest in readiness before every audit cycle, not just the first. Controls drift, systems change and staff turn over — readiness should be treated as a continuous programme, not a one-time event.

We start with a scoping session to understand your systems, services and the frameworks in scope. We then conduct a structured assessment — mapping your existing controls, policies, procedures and evidence against the framework requirements.

We deliver a gap analysis, a risk-prioritised remediation roadmap, and a readiness gate review that tells you plainly whether you are ready to proceed. We work alongside you through remediation but do not issue the report or certificate — that comes from your auditor or certification body.

ISO 27001:2022 is the internationally recognised standard for Information Security Management Systems (ISMS). Unlike SOC 2, it results in a formal certification issued by an accredited certification body — publicly verifiable and globally recognised.

It is required or strongly preferred for large enterprise contracts, government work, EU and UK customers, and any organisation wanting to demonstrate a systematic, audited approach to managing information security risk. Particularly prevalent in BFSI, healthcare, manufacturing, and organisations with significant European or Middle Eastern customer bases.

ISO 27001SOC 2
OutputCertification (public, renewable every 3 years)Attestation report (confidential, annual)
Issued byAccredited certification bodyLicensed CPA firm
RecognitionGlobal — strong in Europe, Middle East, AsiaStrong in North America; growing globally
StructureFixed: Clauses 4–10 + Annex A controlsFlexible: you design controls to meet the TSC

Many organisations pursue both for different customer bases. There is meaningful overlap in controls, so readiness work for one often accelerates the other.

India's Digital Personal Data Protection Act 2023 (and Rules 2025) governs how organisations collect, process and protect digital personal data of individuals. It applies to any organisation that processes personal data in India, and also to foreign organisations that offer goods or services to individuals in India.

If you handle customer data, employee data, user accounts or any information that can identify a person — it very likely applies to you. Use our DPDP Obligation Wizard for a quick indicative map of which obligations apply to your specific business.

Core obligations for Data Fiduciaries include:

  • Privacy notice — clear, plain-language notice before collecting data, in English and the 22 Eighth Schedule languages
  • Lawful basis — valid consent or an enumerated legitimate use (employment, legal obligation, public interest)
  • Purpose limitation and data minimisation — collect only what is necessary for the stated purpose
  • Data accuracy — reasonable steps to keep data accurate and current
  • Storage limitation — erase data when consent is withdrawn or the purpose is fulfilled
  • Security safeguards (Rule 6) — encryption, access controls, breach detection, annual review. Penalty for failure: up to ₹250 crore
  • Breach notification (Rule 7) — notify the Data Protection Board and affected individuals within 72 hours. Penalty for failure: up to ₹200 crore
  • Data Principal rights — respond to access, correction, erasure and grievance requests within 90 days

An SDF is a Data Fiduciary formally designated by the Central Government — typically based on volume, sensitivity of data processed, national security considerations, or risk to individual rights. In addition to all standard obligations, SDFs must:

  • Appoint a Data Protection Officer (DPO) resident in India with direct board-level reporting
  • Conduct an annual Data Protection Impact Assessment (DPIA) and independent audit. Penalty for failure: up to ₹150 crore
  • Verify that algorithms used to process personal data do not pose a risk to Data Principal rights
  • Comply with any data localisation requirements for sensitive categories notified by the Government

HIPAA applies to US-based Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates — any vendor that creates, receives, maintains or transmits Protected Health Information (PHI) on their behalf.

If you are an Indian technology company providing services to US healthcare clients and you touch PHI — even based in India — HIPAA applies to you. Many Indian SaaS and services firms become Business Associates as they expand into US healthcare.

HIPAA readiness covers three rules:

  • Privacy Rule — how PHI may be used and disclosed
  • Security Rule — administrative, physical and technical safeguards for electronic PHI (ePHI)
  • Breach Notification Rule — what to do when PHI is compromised

Readiness involves a risk analysis, gap remediation, policy documentation, staff training, Business Associate Agreements (BAAs) with covered entity clients, and evidence that safeguards are working. There is meaningful overlap between HIPAA security requirements and SOC 2 — organisations often pursue both efficiently together.

PCI DSS applies to any organisation that stores, processes or transmits cardholder data — card numbers, CVVs, PINs or magnetic stripe data. It applies regardless of geography or company size.

If you handle card payments, provide payment processing services, or build platforms that touch card data, PCI DSS applies. The best way to reduce scope is to minimise how much cardholder data you actually handle — for example, by using a certified payment gateway and never storing raw card numbers.

Compliance levels are determined by transaction volume and how you engage with card data. Level 1 (highest) applies to merchants processing over 6 million card transactions per year and requires a Qualified Security Assessor (QSA). Lower levels have different Self-Assessment Questionnaire (SAQ) requirements.

The right level is determined by your payment brand relationships and acquiring bank. A readiness assessment helps you understand your actual cardholder data environment scope and what needs to be in place before your assessment.

AI risk advisory helps organisations govern, test and manage the risks of AI systems — including generative AI tools, machine learning models and embedded AI features in products. It is relevant to any organisation building, deploying or using AI that affects business decisions, handles personal data, or operates in regulated sectors.

As AI use expands, customers, regulators and enterprise procurement teams increasingly ask for evidence of AI governance — not just a description of what the AI does.

  • NIST AI RMF 1.0 — GOVERN, MAP, MEASURE, MANAGE. The primary operating model for AI risk management
  • ISO/IEC 42001:2023 — the certifiable AI Management System standard for organisations pursuing formal AI governance
  • NIST AI-600-1 (GenAI Profile) — applied as an overlay for organisations using large language models or generative AI tools, covering 12 GenAI-specific risk categories

Yes. The EU AI Act applies extra-territorially — if your AI system is placed on the EU market or its output is used by individuals in the EU, obligations apply regardless of where you are headquartered.

High-risk AI systems (including those used in credit scoring, hiring, or decisions affecting people's fundamental rights) face the strictest requirements. Tasvika flags EU AI Act exposure as part of AI risk assessments and includes it in the remediation roadmap where applicable.

Flagging regulatory exposure is advisory — not a legal opinion. We recommend involving qualified legal counsel for formal EU AI Act compliance decisions.

A virtual CISO is an experienced security leader who acts as your organisation's Chief Information Security Officer on a fractional basis — without the cost of a full-time hire. It makes sense when you need senior security leadership and board-level reporting but are not yet at the stage where a full-time CISO is justified.

Common triggers: a first major enterprise deal with security requirements, a security incident or near-miss, board or investor pressure on security posture, or a compliance requirement that needs executive ownership.

Onboarding: a security maturity assessment against NIST CSF 2.0, a cyber risk register, and a 90-day security roadmap — giving you a clear, evidence-based baseline and a prioritised plan from day one.

Ongoing monthly cadence: security KPI reporting, board and leadership reporting, risk register updates, and senior advisory on incidents, vendor decisions and programme direction.

The engagement scales to your organisation's needs — from strategic direction only to more hands-on involvement in specific areas.

A compliance consultant typically works on a defined project — getting you ready for a specific audit or certification. A vCISO is an ongoing leadership role: they own the security programme direction, sit in on leadership discussions, represent security at the board level, and provide continuity across multiple years.

Tasvika offers both. Many clients start with a readiness engagement for a specific framework, then move to a vCISO model as they need ongoing security leadership rather than project-based advisory.

Still have questions?

Talk to us directly — no sales pitch, just a straightforward conversation about your situation and whether we can help.

Get in touch →