Live Founding Cohort open, limited seats remaining Back to main site →

The SOC 2 timeline for a first-time Indian SaaS

Zero to first Type II report in 15 to 18 months. This lesson walks the month-by-month operating calendar every Series A Indian SaaS founder and CISO should be running.

Free preview 11 min read Verified
Legal basis
SOC 2 primary-source stack current to 29 August 2026. Core: AICPA SSAE 18 as currently effective in the April 2026 codification (Statement on Standards for Attestation Engagements No. 18, Attestation Standards: Clarification and Recodification, issued April 2016). Applicable AT-C sections: AT-C 105 (Concepts Common to All Attestation Engagements), AT-C 205 (Examination Engagements), and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting, i.e. SOC 1; referenced in Module 1 Lesson 2 for the SOC 1 versus SOC 2 distinction). Frameworks: 2017 Trust Services Criteria with Revised Points of Focus (2022) covering the five TSC categories (Security as Common Criteria mandatory, plus Availability, Processing Integrity, Confidentiality, Privacy as optional); AICPA Description Criteria DC-100 for the management assertion; COSO Internal Control Integrated Framework 2013 (the framework underlying Common Criteria CC1 through CC5); COSO Generative AI Internal Control Guidance February 2026 (non-authoritative, referenced in Module 8 emerging-controls lesson only). Related standards for context (referenced but not primary): ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 (February 2024), HIPAA Security Rule (45 CFR Part 164), FedRAMP. Items requiring ongoing verification and flagged inside the relevant lessons: proposed SSAE revisions to AT-C 105, 205 and 210 per the AICPA Exposure Draft of 26 February 2026 (comment period closed 30 June 2026; no final revised standard issued as of course pin date); AICPA-issued authoritative AI-specific Trust Services Criteria if published after August 2026; any TSC refresh after the 2022 Revised Points of Focus; current pricing on Vanta, Drata, Sprinto, Secureframe and Comply.ai platforms; current AICPA-licensed CPA firm roster and India-facing engagement fees.

Here is the mistake almost every Series A Indian SaaS founder makes with SOC 2. They discover the requirement in month zero when a US enterprise deal asks for it. They panic. They buy Vanta or Drata or Sprinto in month one because that is what LinkedIn told them to do. They spend three months configuring the platform. By month six they have a partial control inventory and no auditor engaged. By month nine they realise the auditor engagement itself takes 6 to 12 months of observation. By month twelve the enterprise deal is dead. By month eighteen they finally have their first Type II report.

SOC 2 is not a six-week project. It is a 15 to 18 month workstream for a first-time filer. Here is the calendar.

The overall shape

Total elapsed time for a first-time filer, Path B (skip Type I, direct to 12-month Type II): 15 to 18 months from decision to first report.

Total elapsed time for a first-time filer, Path A (Type I bridge, then 6-month Type II): 12 to 14 months from decision to first Type II report, plus a Type I report available around month 6 to unblock deals.

Months 1 to 3: Foundation

  • Month 1: Scope the SOC 2 decision. Which TSCs (Security only or Security plus optional). Type I bridge or direct Type II. Six-month or twelve-month Type II period. Get founder sign-off on budget: total programme cost for a Series A Indian SaaS runs Rs 25 lakh to Rs 40 lakh in the first year (platform + advisory + auditor + internal FTE time).
  • Month 2: Buy vs Build decision on the compliance platform. If Buy, evaluate Vanta, Drata, Sprinto, Secureframe, Comply.ai using the decision matrix in Module 6. If Build, stand up an internal evidence collection process on Notion, Confluence or SharePoint. Most Series A Indian SaaS buy Sprinto for the India entity and DPDP workflows.
  • Month 3: Complete the Control Matrix mapping every applicable TSC criterion to a control, owner and evidence source (Module 5 Lesson 1). Draft the 10-Policy Pack (Module 5 Lesson 2). Get Board or founder approval on all ten policies.

Months 4 to 6: Readiness

  • Month 4: Run the Risk Assessment (Module 5 Lesson 3). Stand up the Vendor Risk Register (Module 5 Lesson 4). Publish the Incident Response Plan and run a first tabletop exercise (Module 5 Lesson 5).
  • Month 5: Auditor selection kickoff. Issue RFPs to three or four AICPA-licensed US CPA firms (Module 7 Lesson 2). Big 4, mid-tier, and SOC 2 boutique specialists (A-LIGN, Prescient Assurance, Insight Assurance, Barr Advisory, Schellman). Evaluation criteria: independence, sector experience, cost band, quality review track record.
  • Month 6: Auditor selected. Engagement letter signed (Module 7 Lesson 3). Readiness Assessment conducted by the selected auditor firm as an informal, non-attestation review. Identify gaps. Fix everything the readiness assessment flags before the observation period begins. If pursuing Path A, run the Type I audit this month too.

Months 7 to 15: Observation period

The observation period is where the auditor watches your controls operate. For Path B with a 12-month Type II, the observation period is months 7 through 18. For Path B with a 6-month Type II, months 7 through 12. For Path A with a 6-month Type II following a month-6 Type I, months 7 through 12.

During the observation period:

  • Monthly cadence: run the Evidence Collection Calendar (Module 6 Lesson 4). Every control has an owner. Every owner signs off monthly that the control operated. Every sign-off produces evidence in the system.
  • Quarterly: internal review of evidence quality. Are the screenshots timestamped? Are the tickets properly linked to changes? Are the access reviews complete?
  • Semi-annual: mid-observation checkpoint with the auditor. Not fieldwork, but a review of evidence pack maturity. Fix anything they flag before Type II fieldwork begins.

The single biggest thing that goes wrong in the observation period is inconsistent evidence collection. Month 7 goes well because everyone is engaged. Months 10, 11, 12 get sloppy because the observation period feels boring. Then the auditor arrives for Type II fieldwork and half the months have gaps. Do not let this happen. The Evidence Collection Calendar is the single most important artefact in the programme.

Months 13 to 17 (Path B, 12-month): Type II fieldwork and report

  • Month 13 (or Month 16 for a 12-month Type II starting in month 5): Type II fieldwork begins. Auditor tests sampled controls across the observation period. Interviews with control owners. Walkthroughs. Evidence review.
  • Month 14 or 17: Findings shared. If clean, report drafting begins. If findings exist, remediation and re-testing.
  • Month 15 or 18: Type II report issued. Management assertion signed. Auditor opinion published.

Month 15+ (or 18+): Post-audit

  • Publish the report on your customer trust portal (Module 8 Lesson 1). Freshworks-style Trust Portal is the current benchmark.
  • Start responding to vendor security questionnaires (VSAQ, CAIQ, SIG) using the SOC 2 report as the primary artefact (Module 8 Lesson 2).
  • Begin the observation period for the next annual Type II. The compliance treadmill starts.
  • Consider adding TSCs (Module 8 Lesson 4). Most filers add Availability plus Confidentiality in the second annual audit.

Cost bands for a Series A Indian SaaS

ItemYear 1 (first Type II)Year 2 and onwards
Compliance platform (Vanta / Drata / Sprinto / Secureframe)Rs 5 to 10 lakhRs 6 to 12 lakh (annual)
Advisory / readiness (optional)Rs 3 to 8 lakhRs 1 to 3 lakh (if needed)
Auditor fee (Boutique)Rs 8 to 18 lakhRs 8 to 15 lakh
Auditor fee (Mid-tier)Rs 12 to 25 lakhRs 10 to 20 lakh
Auditor fee (Big 4)Rs 20 to 50 lakhRs 18 to 40 lakh
Internal FTE time (1 to 2 FTE across CISO / DevOps / Sec Eng)Rs 8 to 15 lakh notionalRs 5 to 10 lakh notional

Verified against 2026 platform pricing pages of Vanta, Drata, Sprinto and 2026 US CPA firm engagement patterns. Cost bands move around 15 to 25 percent year on year. Sprinto's 2026 write-up reports total first-year SOC 2 cost at 25,000 to 50,000 US dollars including audit, tooling and staff time; Indian CPA fees typically 30 to 50 percent lower than US equivalents.

End of the free-preview module

You now know what SOC 2 is, how it compares to SOC 1 and ISO 27001, the difference between Type I and Type II, the five Trust Services Criteria and how to scope your first examination, and the operating calendar from month zero to first Type II report. That is the framing that most first-time filers do not get from a Big 4 workshop or a Vanta onboarding session.

The rest of the course goes deep into the mechanics. Module 2 begins the Common Criteria CC1 through CC5 (governance and risk layer). Modules 5, 6 and 7 are template-heavy with the artefacts you will need in a live audit period. Enrol to continue.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of SOC 2 Readiness Practitioner Certification?

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The story of SOC 2
Module 2: Common Criteria Part 1: CC1 to CC5, governance and risk
  • CC1 Control Environment: tone at the top, board oversight, org structure
  • CC2 Communication and Information: internal comms, external commitments, the Trust Portal
  • CC3 Risk Assessment: asset inventory, threat identification, likelihood, impact, residual risk
  • CC4 Monitoring Activities: continuous monitoring, deficiency reporting, remediation tracking
  • CC5 Control Activities: selection, technology-general controls, segregation of duties
Module 3: Common Criteria Part 2: CC6 to CC9, operations
  • CC6 Logical and Physical Access Controls: IAM, MFA, provisioning, remote access, keys
  • CC7 System Operations: detection tooling, incident response, backup and recovery
  • CC8 Change Management: dev lifecycle, code review, testing, approval, deployment, rollback
  • CC9 Risk Mitigation: vendor risk, third-party risk, business continuity, insurance
  • The 2022 Revised Points of Focus: what auditors now specifically look for
Module 4: The optional four Trust Services Criteria
  • Availability TSC — the uptime criterion
  • Processing Integrity TSC — the transaction criterion
  • Confidentiality TSC — the trade-secret criterion
  • Privacy TSC — and the GDPR / DPDP Act 2023 / CCPA overlap
  • TSC decision matrix — which to add and when, by industry
Module 5: The Control Framework and Policy Pack
  • The Control Matrix — mapping TSC clauses to controls, owners and evidence
  • The 10-Policy Pack — draft skeletons your auditor will ask to see
  • Risk Assessment Framework — asset, threat, likelihood, impact, residual risk
  • Vendor Risk Register — the working register your auditor tests against CC9.2
  • Incident Response Plan and Tabletop Runbook
Module 6: Evidence Collection Operating Model
  • Continuous vs point-in-time evidence, and how the auditor samples
  • Buy vs Build: Vanta, Drata, Sprinto, Secureframe, Comply.ai, or in-house
  • Evidence types: what makes evidence auditor-quality vs unusable
  • The Evidence Collection Calendar, a twelve-month template
  • Audit trail hygiene: organising the evidence pack for the first 48 hours of fieldwork
Module 7: Selecting the Auditor and the Audit Cycle
  • What makes a SOC 2 auditor: licensing, independence, sector experience
  • The Auditor RFP and Selection Matrix: running Big 4 against mid-tier against boutique
  • The SOC 2 Engagement Letter, full SSAE 18 template
  • The audit cycle week by week, kickoff to report issuance
  • Auditor opinion types: unqualified, qualified, adverse, disclaimer
Module 8: Post-Audit and Continuous Compliance
  • Publishing the SOC 2 report on your customer trust portal
  • Answering vendor security questionnaires (VSAQ, CAIQ, SIG) with the SOC 2 report
  • The annual re-audit cycle and the bridge letter
  • Adding TSCs beyond Security: Availability, then Confidentiality, then Privacy
  • SOC 2 to ISO 27001 upgrade path and emerging AI controls