Skip to main content
Since 2006 — Cybersecurity expertise in India

SOC 2 Compliance and Attestation for SaaS Companies

Accelerate US enterprise contracts and investor confidence with SOC 2 Type 2 attestation. Security Brigade delivers platform-driven compliance with continuous monitoring evidence, structured gap analysis, and end-to-end audit support.

Type I + II
Attestation Support
Trust Services
Criteria Coverage
6,700+
Assessments
Since 2008
CERT-In Empanelled

SOC 2 has become the de facto trust standard for SaaS companies selling to US enterprises. Whether you are a fintech raising from US investors, a B2B SaaS company pursuing enterprise deals, or a technology platform expanding into North America, SOC 2 readiness removes procurement friction and accelerates revenue. Security Brigade combines deep compliance expertise with proprietary platform capabilities to help you achieve and maintain SOC 2 readiness efficiently.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

What it is

SOC 2 produces an opinion about a period, not a pass mark

A SOC 2 engagement ends with a report written by an independent CPA firm, describing the controls you said you operate, what the auditor did to test them, and what the auditor found, including anything that did not work. That is a different object from a certificate, and the difference decides how the whole programme should be run. There is no pass mark, so a report can contain exceptions and still be entirely usable; what matters to the enterprise buyer reading it is which Trust Services Categories were in scope, what the system description covers, whether the exceptions touch anything they care about, and what the auditor concluded. The other decision that shapes everything is Type 1 against Type 2. A Type 1 opines on whether controls were suitably designed at a single date. A Type 2 opines on whether they operated effectively across an observation window, typically three to twelve months, and it is what enterprise procurement almost always means when it asks for SOC 2. The practical consequence is that a Type 2 cannot be bought in a hurry: the window has to elapse with the controls genuinely running and generating evidence. Organisations that start by choosing an auditor instead of starting the clock lose a quarter, so our readiness work is built around getting controls operating and evidenced early enough that the window is not wasted.

Choosing scope

Five categories, and only one of them is not a choice

Each category you add extends the control set, the evidence burden and the audit fee. Adding one to look thorough is the most common avoidable cost on a SOC 2 programme.

Five categories, and only one of them is not a choice
StateWhat it meansWhat follows
Security The common criteria, included in every SOC 2 engagement. Governance, access control, change management, risk assessment, vendor management, incident response, monitoring. Not optional, and the bulk of the work. For most organisations a Security-only Type 2 is exactly what their buyers are asking for.
Availability Commitments about uptime, resilience and recovery, tested against what you actually promise contractually. Worth including where you publish an SLA and customers hold you to it. It brings capacity planning, backup and recovery evidence into the audit.
Confidentiality How information designated as confidential is protected through its life, including disposal. Commonly added, and reasonable where customers entrust you with commercially sensitive material. The retention and deletion evidence is where it bites.
Processing Integrity That system processing is complete, valid, accurate, timely and authorised. Genuinely relevant to payments, billing and data pipelines; an expensive irrelevance for most other products. Include it because a buyer asked, not to look complete.
Privacy Collection, use, retention, disclosure and disposal of personal information against your stated notice. The heaviest to add, and it overlaps substantially with DPDP and GDPR work you may already be doing. Sequence it with that programme instead of running it twice.
Key
  • Always in scope
  • Include when a commitment exists
  • Heaviest; sequence with privacy work

Who does what

The engagement has three parties, and only one of them can issue the report

PartyWhat they doWhat sits elsewhere
You Define the system description and the commitments it makes, own the controls, and operate them through the observation window. The description is your assertion, and the auditor reports on it. Cannot be assured by a party that built the controls for you without independence being considered
Security Brigade Readiness: gap assessment against the criteria in scope, control design, policy and process build, technical testing, evidence collection through Lemon, and running the internal cadence so the observation window produces what the auditor needs. Does not issue the report and does not express the opinion
Security Brigade is not a CPA firm and does not issue SOC 2 reports. We are the readiness and technical testing partner; we coordinate with your auditor, respond to queries and keep the evidence base current between windows.
The CPA firm Performs the examination and issues the SOC 2 report with its opinion. Licensed to do so; independent of the control environment it is reporting on. Engaged by you, coordinated by us

You

What they do
Define the system description and the commitments it makes, own the controls, and operate them through the observation window. The description is your assertion, and the auditor reports on it.
What sits elsewhere
Cannot be assured by a party that built the controls for you without independence being considered

Security Brigade

What they do
Readiness: gap assessment against the criteria in scope, control design, policy and process build, technical testing, evidence collection through Lemon, and running the internal cadence so the observation window produces what the auditor needs.
What sits elsewhere
Does not issue the report and does not express the opinion

Security Brigade is not a CPA firm and does not issue SOC 2 reports. We are the readiness and technical testing partner; we coordinate with your auditor, respond to queries and keep the evidence base current between windows.

The CPA firm

What they do
Performs the examination and issues the SOC 2 report with its opinion. Licensed to do so; independent of the control environment it is reporting on.
What sits elsewhere
Engaged by you, coordinated by us

How we run it

Start the clock early, because the window is the long pole

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade does not simply hand you a checklist. We work as an extension of your compliance and engineering teams, using our Lemon audit management platform to track every control, evidence artefact, and remediation task. Our methodology is informed by experience across 6,700+ security assessments, ensuring nothing is missed and your audit proceeds smoothly.

Discovery
01

Scoping and Readiness Assessment

We define your SOC 2 system boundaries, identify applicable Trust Services Criteria, evaluate existing controls against SOC 2 requirements, and deliver a detailed gap analysis report highlighting what needs to change. Duration: 1 to 2 weeks.

02

Control Design and Policy Development

We help you design and document controls that satisfy each applicable criterion. This includes drafting information security policies, access control procedures, incident response plans, change management processes, and vendor risk management frameworks. Duration: 2 to 4 weeks.

Testing
03

Control Implementation and Evidence Collection

We work with your engineering and IT teams to implement technical controls, configure monitoring, establish logging and alerting, and set up continuous evidence collection mechanisms. Our B-52 platform capabilities satisfy CC7.1 and CC7.2 requirements for system monitoring, while Lemon manages CC5.3 and CC7.3 for control activities and change management. Duration: 3 to 6 weeks.

04

Penetration Testing from Customer Perspective

We conduct penetration testing of your SaaS application from the customer perspective, validating that security controls work as designed. This testing generates direct evidence for the SOC 2 audit and identifies any remaining vulnerabilities before the observation period begins. Duration: 2 to 3 weeks.

Delivery
05

Observation Period and Continuous Monitoring

For Type 2 attestation, controls must operate effectively over an observation period of three to twelve months. We help you maintain continuous monitoring, generate evidence artefacts automatically via our platform, and conduct periodic reviews to ensure controls remain effective throughout. Duration: 3 to 12 months.

06

Audit Coordination and Attestation

We prepare your complete evidence package, coordinate with the CPA firm conducting the SOC 2 attestation, respond to auditor queries on your behalf, and support you through the final audit process until the SOC 2 Type 2 report is issued. Duration: 2 to 4 weeks.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

SOC 2 is an attestation about controls operating over a period, so evidence that accumulates across the period is worth more than evidence gathered at the end of it. That is the argument for running the testing continuously.

See the B-52 platform Built and run by Security Brigade

FAQ

SOC 2, answered before you pick an auditor

Type, scope and timing decide the cost. Talk to our team about what your buyers are actually asking for.

Contact us
Does Security Brigade issue the SOC 2 report?+
No. A SOC 2 report is issued by an independent CPA firm, and independence is part of what gives the report its value. We are the readiness and technical testing partner: we assess the gap, design and build the controls, test them, assemble the evidence, and coordinate with your auditor through the examination. Keeping those roles separate is the arrangement the framework contemplates.
Type 1 or Type 2?+
Type 2 is what enterprise buyers almost always mean. A Type 1 opines on control design at a point in time and is useful as a milestone, and it can unblock a deal while the Type 2 window runs, but it is not a substitute. A Type 2 opines on operating effectiveness across a window, typically three to twelve months, which is why the window is the long pole in the programme and why starting it late costs a quarter that cannot be bought back.
Which Trust Services Categories should we include?+
Security always, because it is the common criteria. Beyond that, include a category when you make a commitment it covers: Availability where you publish an SLA, Confidentiality where customers entrust you with sensitive material, Processing Integrity where you handle payments, billing or data pipelines, Privacy where you process personal information and are ready for the weight it adds. Every additional category extends the control set, the evidence burden and the fee, so the honest scope is the narrow one your buyers actually ask about.
How does this relate to ISO 27001?+
They answer different markets with overlapping work. ISO 27001 certifies a management system against a standard and is the one European and Asian buyers recognise; SOC 2 produces a CPA firm’s report against criteria you scoped and is what North American enterprise procurement asks for. The overlap is in the control families where the same evidence answers both: access control, change management, risk assessment, vendor management, incident response, logging and human-resources security. Run as one programme the second framework costs a fraction of what it costs run cold.
Do we need penetration testing for SOC 2?+
Auditors expect to see evidence that you identify and address security vulnerabilities, and penetration testing is the most direct way to produce it. We run testing inside the readiness programme so the results feed the criteria they support, and so remediation is tracked to verified closure within the observation window, not left open when the auditor samples.
What if the report comes back with exceptions?+
That is a normal outcome and not a failure: there is no pass mark. What matters is whether the exceptions touch something your buyers care about and what the report says you did about them. Most exceptions are evidence problems, not control problems: the control ran and nothing recorded that it did. That is exactly what the readiness work exists to prevent, and it is why we wire evidence generation into each control instead of collecting it at the end.

Ready to Achieve SOC 2 readiness?

Start with a readiness assessment. Our compliance team will evaluate your current posture and provide a clear roadmap to attestation.

Typically responds within 1 business day · No commitment required

Request a Scoping Call