Here is the mistake almost every Series A Indian SaaS founder makes with SOC 2. They discover the requirement in month zero when a US enterprise deal asks for it. They panic. They buy Vanta or Drata or Sprinto in month one because that is what LinkedIn told them to do. They spend three months configuring the platform. By month six they have a partial control inventory and no auditor engaged. By month nine they realise the auditor engagement itself takes 6 to 12 months of observation. By month twelve the enterprise deal is dead. By month eighteen they finally have their first Type II report.
SOC 2 is not a six-week project. It is a 15 to 18 month workstream for a first-time filer. Here is the calendar.
The overall shape
Total elapsed time for a first-time filer, Path B (skip Type I, direct to 12-month Type II): 15 to 18 months from decision to first report.
Total elapsed time for a first-time filer, Path A (Type I bridge, then 6-month Type II): 12 to 14 months from decision to first Type II report, plus a Type I report available around month 6 to unblock deals.
Months 1 to 3: Foundation
- Month 1: Scope the SOC 2 decision. Which TSCs (Security only or Security plus optional). Type I bridge or direct Type II. Six-month or twelve-month Type II period. Get founder sign-off on budget: total programme cost for a Series A Indian SaaS runs Rs 25 lakh to Rs 40 lakh in the first year (platform + advisory + auditor + internal FTE time).
- Month 2: Buy vs Build decision on the compliance platform. If Buy, evaluate Vanta, Drata, Sprinto, Secureframe, Comply.ai using the decision matrix in Module 6. If Build, stand up an internal evidence collection process on Notion, Confluence or SharePoint. Most Series A Indian SaaS buy Sprinto for the India entity and DPDP workflows.
- Month 3: Complete the Control Matrix mapping every applicable TSC criterion to a control, owner and evidence source (Module 5 Lesson 1). Draft the 10-Policy Pack (Module 5 Lesson 2). Get Board or founder approval on all ten policies.
Months 4 to 6: Readiness
- Month 4: Run the Risk Assessment (Module 5 Lesson 3). Stand up the Vendor Risk Register (Module 5 Lesson 4). Publish the Incident Response Plan and run a first tabletop exercise (Module 5 Lesson 5).
- Month 5: Auditor selection kickoff. Issue RFPs to three or four AICPA-licensed US CPA firms (Module 7 Lesson 2). Big 4, mid-tier, and SOC 2 boutique specialists (A-LIGN, Prescient Assurance, Insight Assurance, Barr Advisory, Schellman). Evaluation criteria: independence, sector experience, cost band, quality review track record.
- Month 6: Auditor selected. Engagement letter signed (Module 7 Lesson 3). Readiness Assessment conducted by the selected auditor firm as an informal, non-attestation review. Identify gaps. Fix everything the readiness assessment flags before the observation period begins. If pursuing Path A, run the Type I audit this month too.
Months 7 to 15: Observation period
The observation period is where the auditor watches your controls operate. For Path B with a 12-month Type II, the observation period is months 7 through 18. For Path B with a 6-month Type II, months 7 through 12. For Path A with a 6-month Type II following a month-6 Type I, months 7 through 12.
During the observation period:
- Monthly cadence: run the Evidence Collection Calendar (Module 6 Lesson 4). Every control has an owner. Every owner signs off monthly that the control operated. Every sign-off produces evidence in the system.
- Quarterly: internal review of evidence quality. Are the screenshots timestamped? Are the tickets properly linked to changes? Are the access reviews complete?
- Semi-annual: mid-observation checkpoint with the auditor. Not fieldwork, but a review of evidence pack maturity. Fix anything they flag before Type II fieldwork begins.
The single biggest thing that goes wrong in the observation period is inconsistent evidence collection. Month 7 goes well because everyone is engaged. Months 10, 11, 12 get sloppy because the observation period feels boring. Then the auditor arrives for Type II fieldwork and half the months have gaps. Do not let this happen. The Evidence Collection Calendar is the single most important artefact in the programme.
Months 13 to 17 (Path B, 12-month): Type II fieldwork and report
- Month 13 (or Month 16 for a 12-month Type II starting in month 5): Type II fieldwork begins. Auditor tests sampled controls across the observation period. Interviews with control owners. Walkthroughs. Evidence review.
- Month 14 or 17: Findings shared. If clean, report drafting begins. If findings exist, remediation and re-testing.
- Month 15 or 18: Type II report issued. Management assertion signed. Auditor opinion published.
Month 15+ (or 18+): Post-audit
- Publish the report on your customer trust portal (Module 8 Lesson 1). Freshworks-style Trust Portal is the current benchmark.
- Start responding to vendor security questionnaires (VSAQ, CAIQ, SIG) using the SOC 2 report as the primary artefact (Module 8 Lesson 2).
- Begin the observation period for the next annual Type II. The compliance treadmill starts.
- Consider adding TSCs (Module 8 Lesson 4). Most filers add Availability plus Confidentiality in the second annual audit.
Cost bands for a Series A Indian SaaS
| Item | Year 1 (first Type II) | Year 2 and onwards |
|---|---|---|
| Compliance platform (Vanta / Drata / Sprinto / Secureframe) | Rs 5 to 10 lakh | Rs 6 to 12 lakh (annual) |
| Advisory / readiness (optional) | Rs 3 to 8 lakh | Rs 1 to 3 lakh (if needed) |
| Auditor fee (Boutique) | Rs 8 to 18 lakh | Rs 8 to 15 lakh |
| Auditor fee (Mid-tier) | Rs 12 to 25 lakh | Rs 10 to 20 lakh |
| Auditor fee (Big 4) | Rs 20 to 50 lakh | Rs 18 to 40 lakh |
| Internal FTE time (1 to 2 FTE across CISO / DevOps / Sec Eng) | Rs 8 to 15 lakh notional | Rs 5 to 10 lakh notional |
Verified against 2026 platform pricing pages of Vanta, Drata, Sprinto and 2026 US CPA firm engagement patterns. Cost bands move around 15 to 25 percent year on year. Sprinto's 2026 write-up reports total first-year SOC 2 cost at 25,000 to 50,000 US dollars including audit, tooling and staff time; Indian CPA fees typically 30 to 50 percent lower than US equivalents.
End of the free-preview module
You now know what SOC 2 is, how it compares to SOC 1 and ISO 27001, the difference between Type I and Type II, the five Trust Services Criteria and how to scope your first examination, and the operating calendar from month zero to first Type II report. That is the framing that most first-time filers do not get from a Big 4 workshop or a Vanta onboarding session.
The rest of the course goes deep into the mechanics. Module 2 begins the Common Criteria CC1 through CC5 (governance and risk layer). Modules 5, 6 and 7 are template-heavy with the artefacts you will need in a live audit period. Enrol to continue.