Skip to main contentChat with us

Learn

Compliance & Security,
Explained

Plain-English guides to the concepts behind ISO 27001, SOC 2, and the DPDP Act — written by certified auditors, not marketers. Start with the fundamentals below, or browse the full glossary.

Plain Englishno jargon walls
Auditor-writtenreviewed by experts
500+audits behind the advice

A growing knowledge base · Last reviewed June 2026

Start with the fundamentals

What Is an ISMS?

Information Security Management System explained — the framework of policies, processes, and controls at the heart of ISO 27001.

Read the guide

What Is GRC?

Governance, Risk & Compliance — the three pillars, why they belong together, and how they map to ISO 27001, SOC 2, and DPDP.

Read the guide

Risk Management Frameworks

NIST RMF, ISO 31000, ISO 27005, COSO ERM, and FAIR — what each is for, and how to choose the right one.

Read the guide

Data Governance Frameworks

Managing data as an asset — DAMA-DMBOK, DCAM, and how data governance maps to the DPDP Act and GDPR.

Read the guide

Data Privacy Laws in India

The full landscape — the DPDP Act 2023, the DPDP Rules 2025, the legacy IT Act framework, and the RBI/SEBI/IRDAI overlays that sit on top.

Read the guide

What Is a Data Fiduciary?

The DPDP Act’s equivalent of a data controller — how it differs from a data processor and a data principal, and what obligations it carries.

Read the guide

DPDP Full Form & Meaning

DPDP = Digital Personal Data Protection. What the DPDP Act, 2023 is, who it applies to, and the key terms in plain English.

Read the guide

What Is Access Control?

Who can access what — the models (DAC, MAC, RBAC, ABAC), least privilege, and its role in ISO 27001 & SOC 2.

Read the guide

NIST Cybersecurity Framework

CSF 2.0 explained — the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Tiers, Profiles, and how it maps to ISO 27001.

Read the guide

Information Security Policy

The top-level security document — what it must cover, the policy hierarchy, and why ISO 27001 Clause 5.2 requires one.

Read the guide

CUECs & CSOCs Explained

The controls a SOC report assumes of you and of carved-out vendors — plus the carve-out vs inclusive method, in plain English.

Read the guide

What Is AT-C Section 320?

The AICPA attestation section behind SOC 1 — the AT-C 105/205/320 architecture, the system-description elements, and management-defined control objectives.

Read the guide

SSAE 18 vs SSAE 21

Which standard is current in 2026 — the SSAE 18→23 lineage with effective dates, and why SOC 1 still runs on AT-C 320.

Read the guide

SOC 1 Description Criteria

Why SOC 1 has no DC 200 — the AICPA description criteria apply to SOC 2 only; SOC 1’s requirements live inside AT-C 320.

Read the guide

SOC 1 Bridge Letters

Gap letters between report periods — who signs them, what they must contain, and what they can never replace.

Read the guide

Can an Indian CA Sign a SOC 2 Report?

Firm licensure, AICPA peer review, and why readiness and attestation must sit with different firms.

Read the guide

Can You Get a SOC 2 from India?

Where the engineering happens versus who signs the opinion — and what a US vendor-risk team actually checks on the report.

Read the guide

Is There a SOC 2 Certificate?

There is no SOC 2 certification body. What you may legitimately claim, and the wording that makes a reviewer discount you.

Read the guide

Our Cloud Provider Has SOC 2 — Why Do We Need One?

The shared-responsibility split control by control, and the CUECs your provider’s own report assigns to you.

Read the guide

Carve-Out vs Inclusive Method

How subservice organisations are described and tested — and what carving out does not let you avoid.

Read the guide

SOC 2 Scope and the System Boundary

What may legitimately be excluded from scope, and the DC 200 test that stops a boundary drawn to flatter the vendor.

Read the guide

Choosing Your Trust Services Criteria

Security is mandatory; the other four follow the commitments you actually made — and Privacy is far more work than teams expect.

Read the guide

SOC 2 Auditor Independence

Why the firm that designs your controls cannot attest to them, and exactly where the permitted line falls.

Read the guide

A Security Incident During Your Observation Period

An incident does not automatically qualify the opinion. What turns one into an exception, and what the auditor asks for.

Read the guide

SOC 2 and Penetration Testing

No criterion mandates a pen test — your own control description does. Timing, scope, and what evidence gets rejected.

Read the guide

Is a SOC 2 Report Confidential?

Restricted-use language, NDAs, trust portals and SOC 3 — plus what to send when a prospect refuses to sign.

Read the guide

Does SOC 2 Replace Security Questionnaires?

What the report answers, what it was never scoped to answer, and how to use it to compress a questionnaire.

Read the guide

DR and Backup Testing for SOC 2

Why a tabletop may not satisfy a control promising technical restoration, and the evidence package auditors request.

Read the guide

SOC 2 With a Small Team

Segregation of duties when the founder approves their own access — the compensating controls that actually pass.

Read the guide

Do All Your Vendors Need SOC 2?

Risk-based vendor tiering, and what to do when a critical vendor has neither SOC 2 nor ISO 27001.

Read the guide

Does a SOC 2 Report Mean You Are Secure?

Reasonable versus absolute assurance — why a clean opinion is not an absence of risk, and what the report legitimately evidences.

Read the guide

Does SOC 2 Make You GDPR, DPDP or HIPAA Compliant?

What SOC 2 genuinely supports in each regime, and the obligations — lawful basis, rights, BAAs, breach timelines — it never touches.

Read the guide

SOC 2 or ISO 27001 First?

A sequencing decision keyed to buyer geography and which deal is blocked, plus what control work genuinely transfers.

Read the guide

Confidentiality vs Privacy in SOC 2

Processing personal data does not automatically require the Privacy category. The contractual triggers that actually do.

Read the guide

SOC 2 Sampling, Populations and Deviations

How populations are defined, why completeness is tested first, and how a single deviation is evaluated.

Read the guide

Changes During Your Observation Period

New modules, IdP migrations and adding a category mid-window — what is absorbable and what is not.

Read the guide

Scoping One Product When You Have Five

When a scoped system is genuinely separable, and when shared infrastructure makes the boundary misleading.

Read the guide

SOC 2 Evidence: What Auditors Actually Accept

Why screenshots are weak evidence, what a defensible artefact contains, and the rejections that cost weeks.

Read the guide

Moving from SOC 2 Type 1 to Type 2

What changes when design testing becomes operating-effectiveness testing, and when the window should start.

Read the guide

The Management Assertion (Section 2)

Your statement, not the auditor’s — what signing it commits you to, clause by clause.

Read the guide

What SOC 2 Readiness Actually Involves

What it produces, what it is not, and why the readiness firm generally should not also sign the opinion.

Read the guide

Continuous Monitoring and Year-Round Evidence

Why SOC 2 fails in the last four weeks, and how to design controls that generate their own evidence.

Read the guide

Your Second SOC 2: What Changes in Year Two

Period sequencing, prior-year exceptions, changing auditor, and the year-two complacency failure.

Read the guide

Writing the SOC 2 System Description

The omit-or-distort standard, writing at the right altitude, and a CUEC section that is honest rather than a liability dump.

Read the guide

Who Actually Runs Each SOC 2 Control

The controls that fall between teams and get dropped — offboarding, vendor reviews, orphaned access reviews.

Read the guide

How Long Is a SOC 2 Report Valid?

No AICPA rule makes a SOC 2 report expire — buyers decide. The freshness ladder they apply, and why a short observation period ages faster.

Read the guide

SOC 2 Bridge Letters

Your management signs it, not the CPA firm. What it can credibly say, the three-month practical limit, and the phrasings that overstate assurance.

Read the guide

SOC 2 Observation Period

Three, six or twelve months? No AICPA minimum exists — why short windows leave quarterly and annual controls with no testable population.

Read the guide

What Is SOC 2?

The AICPA attestation for service organizations — the five Trust Services Categories, Type 1 vs Type 2, and what "SOC 2 compliant" really means.

Read the guide

How to Read a SOC 2 Report

The five sections explained — auditor’s opinion, management’s assertion, system description, test results — plus the red flags reviewers check first.

Read the guide

SOC 2 Opinions & Exceptions

Unmodified, qualified, adverse, disclaimer — what each auditor opinion means, how test exceptions differ, and how to respond to both.

Read the guide

Who Can Perform a SOC 2 Audit?

Only a licensed CPA firm can issue a SOC 2 report — what that means, how independence works, and where consultants and platforms fit.

Read the guide

Subservice Organizations

Carve-out vs inclusive method — how your vendors’ vendors appear in a SOC report, and the monitoring you inherit.

Read the guide

SOC 2 Controls List

There is no official list — illustrative controls by criteria series (CC1–CC9 and beyond), and how to design your own set.

Read the guide

SOC 2 Compliance Checklist

Six phases from first scoping call to annual maintenance — with the concrete checkpoints auditors expect at each.

Read the guide

Types of SOC Reports

SOC 1 vs SOC 2 vs SOC 3 — audiences, criteria, restricted vs general use, and which report your customers are actually asking for.

Read the guide

Your SOC 2 Is In Progress — What to Tell Customers

What you can honestly claim mid-journey — readiness letters, timeline language, and questionnaire answers that hold up.

Read the guide

SOC 2 for Enterprise Sales

How a report actually moves security reviews and procurement — and the deals it won’t close on its own.

Read the guide

Anatomy of a SOC 2 Report (Interactive)

A SOC 2 Type II report you can dissect — 18 clickable markers explain the opinion, assertion, description, and test matrix.

Read the guide

SOC 2 Common Pitfalls

The ten predictable mistakes that stall first examinations — scoping, operating-period, and fieldwork — and what to do instead.

Read the guide

AI Risk vs AI Impact Assessment

The most-confused distinction in ISO 42001 — clause 6.1.2 risk (inward) vs 6.1.4 impact (outward, per ISO/IEC 42005), and how both feed the SoA.

Read the guide

Which AI Role Are You?

Provider, deployer, producer, user — and the four scenarios: API wrappers, fine-tuners, self-hosters, and internal-only AI use.

Read the guide

ISO 42001 + ISO 27001 Integration

One integrated system, two certificates — what your ISMS already gives you, the genuinely new AIMS artifacts, and combined audits.

Read the guide

ISO 42001 Accreditation & ISO 42006

Not all certificates are equal — accredited vs unaccredited, ISO/IEC 42006:2025, and the 30-minute IAF CertSearch verification.

Read the guide

ISO 42001 vs the EU AI Act

Voluntary standard vs binding law — the post-omnibus timeline (Annex III from Dec 2027), what an AIMS evidences, and what it can’t.

Read the guide

ISO 42001 vs NIST AI RMF

GOVERN, MAP, MEASURE, MANAGE crosswalked to clauses and controls — and the certifiability difference that decides adoption.

Read the guide

Looking for a specific term? The compliance glossary defines the acronyms and concepts across ISO 27001, SOC 2, DPDP, HIPAA, and more — and more in-depth guides are on the way.

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations