SOC 2 Readiness Practitioner Certification
For the Indian SaaS founder and CISO who has to pass SOC 2 to sell to US customers, not the Big 4 consultant selling readiness services
A citation-anchored, exam-backed practitioner course on SOC 2 as it actually runs for an Indian SaaS company preparing for a first Type II examination that gates enterprise US contracts. Not a Big 4 workshop flyover of the AICPA framework. This course teaches the working programme: reading a SOC 2 report end-to-end, mapping every one of the nine Common Criteria (CC1 through CC9) plus the four optional Trust Services Criteria to a control, a control owner and an evidence source, building the 10-policy pack the auditor will ask to see on day one, running the 12-month evidence collection cycle with or without a Vanta / Drata / Sprinto platform, selecting an AICPA-licensed US CPA firm through a proper RFP, drafting the SSAE 18 examination engagement letter, and publishing the final report on your customer trust portal. Includes a template pack the student can lift into a live audit period: Control Matrix, 10-Policy Pack, Risk Assessment Framework, Vendor Risk Register, Incident Response Plan and Tabletop Runbook, Evidence Collection Calendar, Auditor RFP and Selection Matrix, SOC 2 Engagement Letter, Bridge Letter, Customer Trust Portal Copy.
Written against primary sources current to 29 August 2026 including AICPA SSAE 18 as currently effective (April 2026 codification), AT-C section 105 Concepts Common to All Attestation Engagements, AT-C section 205 Examination Engagements, AT-C section 320 SOC 1 reporting (referenced for the SOC 1 versus SOC 2 distinction), the 2017 Trust Services Criteria with Revised Points of Focus published in 2022, AICPA Description Criteria DC-100 for the management assertion, COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5), and COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in the Module 8 emerging-controls lesson). Cross-check case material against publicly published SOC 2 postures at Freshworks Trust Portal, Zoho Trust page, Sprinto and Chargebee security pages. The course pairs naturally with DPDP Act 2023 for the Indian privacy overlay under the Privacy TSC, with CERT-In Directions for the Indian cyber-incident reporting overlay under the Security TSC, and with RBI Cybersecurity Framework Practitioner for Indian SaaS serving banks and NBFCs.
What you will learn
- Read a SOC 2 Type II report end-to-end and identify management assertion, description of the system, applicable Trust Services Criteria, tested controls, sample sizes, exceptions, and the auditor opinion (unqualified, qualified, adverse, disclaimer)
- Apply the 2017 Trust Services Criteria with the Revised Points of Focus (2022) to your entity: Security as the Common Criteria mandatory plus the four optional categories (Availability, Processing Integrity, Confidentiality, Privacy)
- Map every one of the nine Common Criteria (CC1 through CC9) to a specific control, control owner, and evidence source in your organisation
- Build the 10-policy pack the auditor will ask to see on day one: Access Control, Data Classification, Incident Response, Business Continuity, Vendor Risk, Change Management, Security Awareness, Password, Acceptable Use, Encryption
- Run a Risk Assessment methodology that starts with asset inventory, moves through threat likelihood and impact scoring, and produces the residual-risk register the auditor will test against Common Criteria CC3
- Design a vendor risk management programme that satisfies Common Criteria CC9 and gives you a working Vendor Risk Register
- Draft an Incident Response Plan aligned to Common Criteria CC7 with a tabletop exercise runbook the auditor will test against your last operating quarter
- Select between buy (Vanta, Drata, Sprinto, Secureframe, Comply.ai) and build for evidence collection using a decision matrix scored on integrations, policy library, cost, India presence, and DPDP Act workflow support
- Run the 12-month evidence collection cycle with a monthly cadence template and owner sign-offs
- Select an AICPA-licensed US CPA firm through a proper RFP process scoring Big 4, mid-tier and SOC 2 boutique specialists across independence, sector experience, cost band and quality review track record
- Draft the SSAE 18 examination engagement letter covering scope, criteria, period, deliverables and fee structure
- Publish the final SOC 2 report on your customer trust portal, answer VSAQ / CAIQ / SIG vendor security questionnaires with it, and prepare the bridge letters between annual audit periods
- Plan the SOC 2 to ISO 27001 upgrade path and anticipate emerging AI controls per COSO Generative AI Internal Control Guidance February 2026
Prerequisites
- Working exposure to a SaaS product engineering environment (AWS or Azure or GCP as primary cloud, CI/CD pipeline, ticketing system like Jira or Linear) — typical for a first-year CISO or a Series A CTO
- Comfort reading a technical policy document and mapping its clauses to specific controls
- Familiarity with the concept of an audit report (SOC 1, ISO 27001, PCI DSS, or similar assurance report background is helpful)
- Access to your own product security posture (identity provider, MFA policy, code repositories, deployment pipeline) is helpful for the practical exercises but not required
Who this is for
- Indian SaaS founders post Series A (Rs 20 crore to Rs 200 crore ARR bracket) preparing for a first SOC 2 Type II examination that gates enterprise US contracts
- CISOs and Heads of Security at Indian SaaS companies from Series A through IPO stage
- DevOps and Platform Engineers who own the technical controls (IAM, MFA, encryption, backup, change management, logging) the SOC 2 auditor tests
- Consultants at ESG or cyber advisory boutiques building a SOC 2 practice
- Assurance associates and managers at Indian branches of US CPA firms who want an operating view of the client side of a SOC 2 examination
- Product Security engineers at unicorn Indian SaaS companies maintaining continuous SOC 2 compliance year to year
- Internal Auditors at Indian SaaS reviewing SOC 2 evidence packs before external examination
- Sales and Customer Success teams responding to enterprise US customer vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
- Investor Relations staff at Indian SaaS explaining the SOC 2 posture to Series B, Series C and IPO investors
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 40 lessons. Click any module to expand.
SOC 2 is a US commercial gate, not a regulatory obligation. If you sell SaaS to enterprise US customers, a Type II report is a table-stakes contract requirement. This free-preview module walks through why SOC 2 exists, who demands it, the AICPA SSAE 18 standard that governs it, the five Trust Services Criteria, the Type I versus Type II distinction, and the operating timeline from zero to a first Type II report for an Indian SaaS post Series A.
Free preview.
Common Criteria CC1 through CC5 are the governance and risk layer of the Security Trust Services Criterion. They map directly to the five COSO 2013 Internal Control components. This module walks each in turn, explaining what the criterion requires, what the 2022 Revised Points of Focus add, and what evidence the auditor tests.
Common Criteria CC1 through CC5 typically absorb 30 to 40 percent of the total control set for a first-time filer.
- 1. CC1 Control Environment: tone at the top, board oversight, org structure 10 min
- 2. CC2 Communication and Information: internal comms, external commitments, the Trust Portal 10 min
- 3. CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk 11 min
- 4. CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking 10 min
- 5. CC5 Control Activities: selection, technology-general controls, segregation of duties 10 min
Common Criteria CC6 through CC9 are the technical operating layer where most audit findings sit. This module walks Logical and Physical Access controls (identity, MFA, provisioning, physical security), System Operations (detection, incident response, backup and recovery), Change Management (development lifecycle, testing, approval, deployment), and Risk Mitigation (vendor and third-party risk, business continuity). Closes with the 2022 Revised Points of Focus that specify what auditors now expect beyond the 2017 criteria.
- 1. CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys 12 min
- 2. CC7 System Operations: detection tooling, incident response, backup and recovery 11 min
- 3. CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback 11 min
- 4. CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance 10 min
- 5. The 2022 Revised Points of Focus: what auditors now specifically look for 10 min
Beyond Security (Common Criteria mandatory), the four optional Trust Services Criteria are Availability, Processing Integrity, Confidentiality, and Privacy. This module walks each: what it means, what customers most often demand, what controls it requires, and how it interacts with the Common Criteria. Closes with a decision matrix on which TSCs to add based on your industry, customer contract requirements, and business risk profile.
- 1. Availability TSC — the uptime criterion 10 min
- 2. Processing Integrity TSC — the transaction criterion 10 min
- 3. Confidentiality TSC — the trade-secret criterion 9 min
- 4. Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap 11 min
- 5. TSC decision matrix — which to add and when, by industry 10 min
SOC 2 fails on artefacts, not on intentions. This module builds the operating layer: a Control Matrix mapping every applicable TSC criterion to a control, owner and evidence source; the 10-policy pack the auditor will ask to see on day one; a Risk Assessment Framework that starts with asset inventory and produces a residual risk register; a Vendor Risk Register with onboarding and ongoing monitoring; an Incident Response Plan with a tabletop exercise runbook. Every template is embedded inline and can be lifted into a live audit period.
- 1. The Control Matrix — mapping TSC clauses to controls, owners and evidence 18 min
- 2. The 10-Policy Pack — draft skeletons your auditor will ask to see 22 min
- 3. Risk Assessment Framework — asset, threat, likelihood, impact, residual risk 16 min
- 4. Vendor Risk Register — the working register your auditor tests against CC9.2 14 min
- 5. Incident Response Plan and Tabletop Runbook 17 min
SOC 2 fails on evidence, not on framework understanding. This module builds the evidence operating layer: continuous versus point-in-time evidence, the Buy versus Build decision (Vanta, Drata, Sprinto, Secureframe, Comply.ai versus in-house), evidence types the auditor accepts, a monthly evidence collection calendar with owner sign-offs, and audit trail hygiene that keeps the evidence pack organised across a 12-month examination period.
- 1. Continuous vs point-in-time evidence, and how the auditor samples 9 min
- 2. Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house 12 min
- 3. Evidence types: what makes evidence auditor-quality vs unusable 10 min
- 4. The Evidence Collection Calendar, a twelve-month template 11 min
- 5. Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork 9 min
The audit quarter. This module walks the SOC 2 examination from the RFP process (Big 4 versus mid-tier versus SOC 2 boutique specialists) through engagement letter drafting under SSAE 18, kickoff and sample selection, interviews and walkthroughs, evidence review and testing, findings and remediation, and finally the auditor opinion (unqualified, qualified, adverse, disclaimer). Includes the Auditor RFP + Selection Matrix template and the SOC 2 Engagement Letter template.
- 1. What makes a SOC 2 auditor: licensing, independence, sector experience 9 min
- 2. The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique 11 min
- 3. The SOC 2 Engagement Letter, full SSAE 18 template 14 min
- 4. The audit cycle week by week, kickoff to report issuance 10 min
- 5. Auditor opinion types: unqualified, qualified, adverse, disclaimer 8 min
Life after the first SOC 2 report. This module walks publishing the report on the customer trust portal, using it to answer vendor security questionnaires (VSAQ, CAIQ, SIG), the annual re-audit cycle with bridge letters between audit periods, adding TSCs beyond Security (Availability then Confidentiality most commonly), the SOC 2 to ISO 27001 upgrade path, and the emerging AI controls per COSO Generative AI Internal Control Guidance February 2026.
- 1. Publishing the SOC 2 report on your customer trust portal 14 min
- 2. Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report 11 min
- 3. The annual re-audit cycle and the bridge letter 13 min
- 4. Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy 10 min
- 5. SOC 2 to ISO 27001 upgrade path and emerging AI controls 11 min
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme aimed at working Indian SaaS founders, CISOs and Heads of Security, DevOps and Platform Engineers, consultants at cyber advisory boutiques, and assurance associates at CPA firms. Every substantive claim is anchored to a primary source: AICPA Standard reference (SSAE 18 clause, AT-C section number, Trust Services Criteria clause code such as CC6.1 or A1.2), AICPA Description Criteria DC-100 clause, or COSO framework component reference. Items flagged as UNVERIFIED in the lesson prose are pending re-verification against the current primary source and must be checked before the student acts on them in a live audit engagement. The course maintains a 15-item verification checklist covering the proposed SSAE 18 revision status, Trust Services Criteria refresh status, AI-controls emerging guidance, and current platform pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai.
This is not legal, tax, audit, or accounting advice and does not create a professional-client relationship. For specific engagement decisions on a SOC 2 examination, consult an AICPA-licensed CPA firm authorised to perform attestation engagements under SSAE 18.
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only).
Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.