Learn
Compliance & Security,
Explained
Plain-English guides to the concepts behind ISO 27001, SOC 2, and the DPDP Act — written by certified auditors, not marketers. Start with the fundamentals below, or browse the full glossary.
A growing knowledge base · Last reviewed June 2026
Start with the fundamentals
What Is an ISMS?
Information Security Management System explained — the framework of policies, processes, and controls at the heart of ISO 27001.
Read the guideWhat Is GRC?
Governance, Risk & Compliance — the three pillars, why they belong together, and how they map to ISO 27001, SOC 2, and DPDP.
Read the guideRisk Management Frameworks
NIST RMF, ISO 31000, ISO 27005, COSO ERM, and FAIR — what each is for, and how to choose the right one.
Read the guideData Governance Frameworks
Managing data as an asset — DAMA-DMBOK, DCAM, and how data governance maps to the DPDP Act and GDPR.
Read the guideData Privacy Laws in India
The full landscape — the DPDP Act 2023, the DPDP Rules 2025, the legacy IT Act framework, and the RBI/SEBI/IRDAI overlays that sit on top.
Read the guideWhat Is a Data Fiduciary?
The DPDP Act’s equivalent of a data controller — how it differs from a data processor and a data principal, and what obligations it carries.
Read the guideDPDP Full Form & Meaning
DPDP = Digital Personal Data Protection. What the DPDP Act, 2023 is, who it applies to, and the key terms in plain English.
Read the guideWhat Is Access Control?
Who can access what — the models (DAC, MAC, RBAC, ABAC), least privilege, and its role in ISO 27001 & SOC 2.
Read the guideNIST Cybersecurity Framework
CSF 2.0 explained — the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Tiers, Profiles, and how it maps to ISO 27001.
Read the guideInformation Security Policy
The top-level security document — what it must cover, the policy hierarchy, and why ISO 27001 Clause 5.2 requires one.
Read the guideCUECs & CSOCs Explained
The controls a SOC report assumes of you and of carved-out vendors — plus the carve-out vs inclusive method, in plain English.
Read the guideWhat Is AT-C Section 320?
The AICPA attestation section behind SOC 1 — the AT-C 105/205/320 architecture, the system-description elements, and management-defined control objectives.
Read the guideSSAE 18 vs SSAE 21
Which standard is current in 2026 — the SSAE 18→23 lineage with effective dates, and why SOC 1 still runs on AT-C 320.
Read the guideSOC 1 Description Criteria
Why SOC 1 has no DC 200 — the AICPA description criteria apply to SOC 2 only; SOC 1’s requirements live inside AT-C 320.
Read the guideSOC 1 Bridge Letters
Gap letters between report periods — who signs them, what they must contain, and what they can never replace.
Read the guideCan an Indian CA Sign a SOC 2 Report?
Firm licensure, AICPA peer review, and why readiness and attestation must sit with different firms.
Read the guideCan You Get a SOC 2 from India?
Where the engineering happens versus who signs the opinion — and what a US vendor-risk team actually checks on the report.
Read the guideIs There a SOC 2 Certificate?
There is no SOC 2 certification body. What you may legitimately claim, and the wording that makes a reviewer discount you.
Read the guideOur Cloud Provider Has SOC 2 — Why Do We Need One?
The shared-responsibility split control by control, and the CUECs your provider’s own report assigns to you.
Read the guideCarve-Out vs Inclusive Method
How subservice organisations are described and tested — and what carving out does not let you avoid.
Read the guideSOC 2 Scope and the System Boundary
What may legitimately be excluded from scope, and the DC 200 test that stops a boundary drawn to flatter the vendor.
Read the guideChoosing Your Trust Services Criteria
Security is mandatory; the other four follow the commitments you actually made — and Privacy is far more work than teams expect.
Read the guideSOC 2 Auditor Independence
Why the firm that designs your controls cannot attest to them, and exactly where the permitted line falls.
Read the guideA Security Incident During Your Observation Period
An incident does not automatically qualify the opinion. What turns one into an exception, and what the auditor asks for.
Read the guideSOC 2 and Penetration Testing
No criterion mandates a pen test — your own control description does. Timing, scope, and what evidence gets rejected.
Read the guideIs a SOC 2 Report Confidential?
Restricted-use language, NDAs, trust portals and SOC 3 — plus what to send when a prospect refuses to sign.
Read the guideDoes SOC 2 Replace Security Questionnaires?
What the report answers, what it was never scoped to answer, and how to use it to compress a questionnaire.
Read the guideDR and Backup Testing for SOC 2
Why a tabletop may not satisfy a control promising technical restoration, and the evidence package auditors request.
Read the guideSOC 2 With a Small Team
Segregation of duties when the founder approves their own access — the compensating controls that actually pass.
Read the guideDo All Your Vendors Need SOC 2?
Risk-based vendor tiering, and what to do when a critical vendor has neither SOC 2 nor ISO 27001.
Read the guideDoes a SOC 2 Report Mean You Are Secure?
Reasonable versus absolute assurance — why a clean opinion is not an absence of risk, and what the report legitimately evidences.
Read the guideDoes SOC 2 Make You GDPR, DPDP or HIPAA Compliant?
What SOC 2 genuinely supports in each regime, and the obligations — lawful basis, rights, BAAs, breach timelines — it never touches.
Read the guideSOC 2 or ISO 27001 First?
A sequencing decision keyed to buyer geography and which deal is blocked, plus what control work genuinely transfers.
Read the guideConfidentiality vs Privacy in SOC 2
Processing personal data does not automatically require the Privacy category. The contractual triggers that actually do.
Read the guideSOC 2 Sampling, Populations and Deviations
How populations are defined, why completeness is tested first, and how a single deviation is evaluated.
Read the guideChanges During Your Observation Period
New modules, IdP migrations and adding a category mid-window — what is absorbable and what is not.
Read the guideScoping One Product When You Have Five
When a scoped system is genuinely separable, and when shared infrastructure makes the boundary misleading.
Read the guideSOC 2 Evidence: What Auditors Actually Accept
Why screenshots are weak evidence, what a defensible artefact contains, and the rejections that cost weeks.
Read the guideMoving from SOC 2 Type 1 to Type 2
What changes when design testing becomes operating-effectiveness testing, and when the window should start.
Read the guideThe Management Assertion (Section 2)
Your statement, not the auditor’s — what signing it commits you to, clause by clause.
Read the guideWhat SOC 2 Readiness Actually Involves
What it produces, what it is not, and why the readiness firm generally should not also sign the opinion.
Read the guideContinuous Monitoring and Year-Round Evidence
Why SOC 2 fails in the last four weeks, and how to design controls that generate their own evidence.
Read the guideYour Second SOC 2: What Changes in Year Two
Period sequencing, prior-year exceptions, changing auditor, and the year-two complacency failure.
Read the guideWriting the SOC 2 System Description
The omit-or-distort standard, writing at the right altitude, and a CUEC section that is honest rather than a liability dump.
Read the guideWho Actually Runs Each SOC 2 Control
The controls that fall between teams and get dropped — offboarding, vendor reviews, orphaned access reviews.
Read the guideHow Long Is a SOC 2 Report Valid?
No AICPA rule makes a SOC 2 report expire — buyers decide. The freshness ladder they apply, and why a short observation period ages faster.
Read the guideSOC 2 Bridge Letters
Your management signs it, not the CPA firm. What it can credibly say, the three-month practical limit, and the phrasings that overstate assurance.
Read the guideSOC 2 Observation Period
Three, six or twelve months? No AICPA minimum exists — why short windows leave quarterly and annual controls with no testable population.
Read the guideWhat Is SOC 2?
The AICPA attestation for service organizations — the five Trust Services Categories, Type 1 vs Type 2, and what "SOC 2 compliant" really means.
Read the guideHow to Read a SOC 2 Report
The five sections explained — auditor’s opinion, management’s assertion, system description, test results — plus the red flags reviewers check first.
Read the guideSOC 2 Opinions & Exceptions
Unmodified, qualified, adverse, disclaimer — what each auditor opinion means, how test exceptions differ, and how to respond to both.
Read the guideWho Can Perform a SOC 2 Audit?
Only a licensed CPA firm can issue a SOC 2 report — what that means, how independence works, and where consultants and platforms fit.
Read the guideSubservice Organizations
Carve-out vs inclusive method — how your vendors’ vendors appear in a SOC report, and the monitoring you inherit.
Read the guideSOC 2 Controls List
There is no official list — illustrative controls by criteria series (CC1–CC9 and beyond), and how to design your own set.
Read the guideSOC 2 Compliance Checklist
Six phases from first scoping call to annual maintenance — with the concrete checkpoints auditors expect at each.
Read the guideTypes of SOC Reports
SOC 1 vs SOC 2 vs SOC 3 — audiences, criteria, restricted vs general use, and which report your customers are actually asking for.
Read the guideYour SOC 2 Is In Progress — What to Tell Customers
What you can honestly claim mid-journey — readiness letters, timeline language, and questionnaire answers that hold up.
Read the guideSOC 2 for Enterprise Sales
How a report actually moves security reviews and procurement — and the deals it won’t close on its own.
Read the guideAnatomy of a SOC 2 Report (Interactive)
A SOC 2 Type II report you can dissect — 18 clickable markers explain the opinion, assertion, description, and test matrix.
Read the guideSOC 2 Common Pitfalls
The ten predictable mistakes that stall first examinations — scoping, operating-period, and fieldwork — and what to do instead.
Read the guideAI Risk vs AI Impact Assessment
The most-confused distinction in ISO 42001 — clause 6.1.2 risk (inward) vs 6.1.4 impact (outward, per ISO/IEC 42005), and how both feed the SoA.
Read the guideWhich AI Role Are You?
Provider, deployer, producer, user — and the four scenarios: API wrappers, fine-tuners, self-hosters, and internal-only AI use.
Read the guideISO 42001 + ISO 27001 Integration
One integrated system, two certificates — what your ISMS already gives you, the genuinely new AIMS artifacts, and combined audits.
Read the guideISO 42001 Accreditation & ISO 42006
Not all certificates are equal — accredited vs unaccredited, ISO/IEC 42006:2025, and the 30-minute IAF CertSearch verification.
Read the guideISO 42001 vs the EU AI Act
Voluntary standard vs binding law — the post-omnibus timeline (Annex III from Dec 2027), what an AIMS evidences, and what it can’t.
Read the guideISO 42001 vs NIST AI RMF
GOVERN, MAP, MEASURE, MANAGE crosswalked to clauses and controls — and the certifiability difference that decides adoption.
Read the guideLooking for a specific term? The compliance glossary defines the acronyms and concepts across ISO 27001, SOC 2, DPDP, HIPAA, and more — and more in-depth guides are on the way.
Get in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours