Overview
SOC 2 is not a certification in the way ISO 27001 or CMMI are. It is an attestation report defined by the American Institute of Certified Public Accountants (AICPA) and issued only by an independent, licensed CPA firm enrolled in the AICPA peer-review programme. There is no government body, standards council or accreditation scheme that hands out a “SOC 2 certificate” — anyone selling one by that name is describing something that does not exist. What a company actually receives is a report, addressed to its customers, carrying that CPA firm’s opinion.
There are two report types. A Type I report attests to whether your controls are suitably designed at a single point in time. A Type II report goes further: it tests whether those controls actually operated effectively over an observation window, typically three to twelve months. Type II is what most US and global enterprise buyers ask for, because it demonstrates sustained practice rather than a one-day snapshot.
The report is scoped against the AICPA’s five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy. Security is the common baseline almost every engagement includes; the other four are added depending on what your product actually does and what your customers are asking about. Choosing scope correctly at the start avoids paying to test criteria nobody asked for.
Demand for SOC 2 among Indian SaaS and IT-services companies comes almost entirely from one place: US and global enterprise buyers who use it as a vendor-risk gate before they will send you customer data. There is no India-specific equivalent, and no Indian regulator requires it — it shows up in procurement checklists, not in law. CapEasy runs the readiness side of this: gap assessment against the criteria you scope in, building and documenting the controls, collecting the evidence an auditor will ask for, and coordinating with the CPA firm through the engagement. The attestation opinion itself is the CPA firm’s to give, not ours; auditor independence requires that separation, and we say so plainly rather than blur it.
Who it’s for
- Indian SaaS and IT-services companies being asked for SOC 2 in a US or global enterprise sales cycle
- Companies that have never been through an attestation and need controls, evidence and documentation built from a clean starting point
- Teams that already hold ISO 27001 and want to understand where the two overlap before duplicating work
- Founders who have been quoted a “SOC 2 certification” by a vendor and want to know what is actually being sold
- Companies deciding between a Type I report now and a Type II observation window later in the sales cycle
Eligibility & requirements
- A defined system boundary — which product, environment or service the report will cover, since SOC 2 is scoped to a system, not the whole company
- Security in scope at minimum; availability, processing integrity, confidentiality and privacy added only where your product and customer commitments call for them
- Documented policies and operating controls across access management, change management, monitoring and incident response, consistent enough to produce evidence on demand
- For a Type II report, the controls need to actually run for the full observation window (commonly three to twelve months) before the CPA firm can test them
- An independent, licensed CPA firm engaged separately to perform the examination and issue the report — this cannot be the same party that built your controls
- A named internal owner who can pull evidence — access logs, change tickets, monitoring records, when the auditor asks for it
How CapEasy handles it
- Scoping — define the system boundary and which Trust Services Criteria the engagement covers, based on what your customers are actually asking for
- Gap assessment — map your current controls against the chosen criteria and flag what is missing, undocumented or inconsistently applied
- Controls build — design and implement the policies and technical controls the gaps call for: access control, change management, monitoring, vendor management, incident response
- Documentation — write the policies and procedures an auditor expects to see, not just the controls themselves
- Evidence collection — set up the logging, ticketing and record-keeping that will produce auditable evidence rather than reconstructing it under deadline pressure
- Internal readiness review — a dry run against the criteria before the real engagement starts, to catch gaps while they are still cheap to fix
- Auditor coordination — help select and brief the independent CPA firm, and support the fieldwork as evidence requests come in
- Type I now, Type II later (where relevant) — many companies start with a Type I report to satisfy an immediate ask, then run the observation window toward a Type II
Documents you’ll typically need
- A description of the system, product or environment the report should cover
- Existing information-security policies, if any already exist
- Access-control lists and identity/access-management configuration for the relevant systems
- Vendor and sub-processor list for anything that touches the in-scope data
- Incident-response and change-management records or templates currently in use
- Prior audit or certification reports, including ISO 27001, if one is already held
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



