Learn · SOC Reports
Can You Get a SOC 2
from India?
Yes — and the question is doing two jobs at once. Where your engineering, readiness and evidence work happens is a capability question, and India answers it well. Who signs the opinion is a licensure question, with a narrow answer that is not a verdict on quality.
The structure buyers want: one organisation builds and evidences the control environment; a separate, independent, licensed CPA firm examines it and signs. Not a workaround for geography — it is the cleanest way to satisfy the independence rules, which apply to every service organisation on earth.
Plain-English explainer · AICPA attestation rules · Last reviewed August 2026
Yes. Indian companies obtain SOC 2 reports routinely, and Indian teams do the engineering, readiness and evidence work behind them to a standard nobody needs to apologise for. What cannot move is the signature: a SOC 2 under the AICPA attestation standards is signed by a licensed CPA firm, and US buyers expect that firm to hold a licence in a US jurisdiction. Nearly every argument about “offshore SOC 2” runs those two facts together. Licensure is jurisdictional — which regulator issues which permission — not a verdict on competence.
The conflation
Two questions wearing one coat
A reviewer asking whether your SOC 2 “came from India” is rarely asking about a country. They are compressing three separable questions.
Where the system is built and operated
Anywhere. Nothing in the 2017 Trust Services Criteria (TSP section 100, with revised points of focus, 2022) or in DC 200 asks where an engineer sits. The description discloses it; the criteria then apply identically.
Who prepares the controls and the evidence
Anyone independent of the signing firm. No licence attaches to this work, it is the bulk of the effort, and India-based teams are strong at it.
Who examines the controls and signs
A licensed CPA firm, independent of everyone above. The only jurisdictional constraint in the engagement.
Most hours in a first SOC 2 land in the middle row. So the honest framing is not “where is your audit from” but “who did which part, and was that part independent”.
The rule, precisely
Licensure is jurisdictional. Competence is not.
A SOC 2 is an examination under the AICPA’s attestation standards: AT-C section 105, the concepts common to all attestation engagements, and AT-C section 205, redrafted by SSAE No. 21 as Assertion-Based Examination Engagements, effective for reports dated on or after 15 June 2022. Attestation is regulated public accountancy, so the opinion comes from a CPA firm: licensed by a state board and independent under the AICPA Code. Firms performing attest work are additionally subject to peer review — enrolment is required of AICPA member firms and by essentially every state board as a condition of practice monitoring, and SOC engagements are a must-select category within it. Buyers ask for the most recent peer review as market practice, not because AT-C 205 tells them to.
The interesting part is what the AICPA’s own guide says about everyone else. Appendix G of the AICPA Guide, SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy — “the guide” from here on — states that a non-US CPA may perform a SOC 2 examination in accordance with ISAE 3000 (Revised) and report accordingly, and sets out how to report under both sets of standards. Local licensing law still governs what that firm may sign in its own jurisdiction. The traffic runs one way: a US CPA may not report only under ISAE 3000, because the Compliance With Standards Rule (ET 1.310.001) requires compliance with standards designated by AICPA Council.
So a professional accountancy firm outside the US — an ICAI-registered CA firm, for example — bound by the IESBA Code and by ISQM 1 can issue real assurance under ISAE 3000 (Revised). It simply is not an AT-C 205 SOC 2. Read that as a statement about accountancy firms and not about anyone with an opinion: ISAE 3000 (Revised) is written for professional accountants in public practice, so a consultancy or compliance platform holding no accountancy licence cannot use that route either. On what an ICAI firm can and cannot sign in its own name, see can an Indian CA sign a SOC 2 report — including how US-licensed affiliates issue the report.
Who signs
Standard the opinion is expressed under
What the deliverable is properly called
How a US vendor-risk team treats it
A CPA firm licensed by a US state board of accountancy, independent under the AICPA Code
AT-C section 205, against the Trust Services Criteria, with the description evaluated under DC 200.
A SOC 2 report containing the practitioner’s opinion. Never a certificate.
Accepted. This is what a questionnaire means by "SOC 2 Type 2".
A professional accountancy firm outside the US — an ICAI-registered CA firm, for example — bound by the IESBA Code and ISQM 1
ISAE 3000 (Revised): genuine assurance over the same criteria, under international standards rather than the AICPA ones.
An ISAE 3000 (Revised) assurance report. Describe it that way — it is not an AT-C 205 SOC 2.
Needs explaining. Many buyers still ask for an AT-C 205 report, because their process names one.
A firm able to report under both the AICPA attestation standards and the ISAEs
Both, expressed together — the dual-standard route set out in Appendix G of the AICPA guide.
A dual-standard report carrying the AICPA opinion alongside the ISAE one.
Accepted where the AICPA opinion is present and the firm may express it.
A consultancy, compliance platform, or self-styled "certification body" holding no accountancy licence
Neither. AT-C 205 requires a licensed CPA firm, and ISAE 3000 (Revised) is written for professional accountants in public practice — so that route is closed too.
A badge, a "certificate", or a readiness report. None of them is an attestation.
Rejected. There is no SOC 2 certificate and no SOC 2 certification body.
Keep two labels straight. The standard requires a licensed, independent CPA firm expressing an opinion under AT-C 205. Market practice adds that the firm be a US firm. See who can perform a SOC 2 audit for the licensure question in full.
The vendor-risk desk
What a US buyer’s reviewer actually checks
The person opening your report has twenty minutes, a checklist, and forty other vendors in the queue.
What they check
What passes
What fails
The signing firm
A named CPA firm on the opinion letter, with a city and US state.
An opinion signed by a consultancy, or a firm with no accountancy licence.
Licensure
A current firm licence on the state board of accountancy register named in the opinion letter — the authoritative source — or the NASBA-hosted CPAverify search, which covers participating boards only.
A licence absent from the board’s own register, or a membership logo offered in place of a licence number. Absence from CPAverify alone proves nothing.
Peer review
A recent peer review the firm will name on request. SOC engagements are a must-select category once a firm is enrolled — an AICPA membership and state-board requirement, not something AT-C 205 itself imposes.
"We are AICPA members", as though membership were a peer review.
The standard cited
An opinion under the AICPA attestation standards, referencing the Trust Services Criteria and DC 200.
A report citing ISO/IEC 27001 while calling itself a SOC 2 — or a certificate.
Independence
Nothing suggests the signing firm designed or operated the controls it tested.
The same firm’s name on the policies, the remediation plan, and the opinion.
The opinion
Unmodified, using the "in all material respects" formulation, over a stated period.
A modified opinion you did not raise first, or a report with it removed.
Restricted use
The restricted-use paragraph is present and the reviewer falls inside it.
A "SOC 2" published openly on a marketing site. SOC 3 is the general-use report.
Subservice organisations and CUECs
Carve-out or inclusive stated, subservice organisations named, CUECs listed.
Silence on both, which adds a week to the review.
Notice what is absent: nowhere does a reviewer ask where the engineers sit. Geography enters once, in the description, as a disclosure.
What should worry you
The failures that are structural
Every real red flag here is about how the engagement was constructed. Not one is about a passport.
A "SOC 2 certificate"
The deliverable is a report containing an opinion. Certificates belong to schemes such as ISO/IEC 27001, with accredited certification bodies and registers. SOC 2 has none of that machinery.
An opinion signed by a firm that is not a CPA firm
Engagement teams routinely blend CPAs with CISA- and CISSP-credentialled IT auditors; that is normal. The line is the signature — the opinion is rendered in the name of the licensed firm.
An auditor who also implemented the controls
This should end the conversation. A firm that wrote your policies cannot examine the same controls and call itself independent — that is a document about itself.
An examination completed impossibly fast
A Type 2 tests operating effectiveness across a period. A SOC 2 advertised in a fortnight is a Type 1, a readiness report, or nothing. Ask for the period covered.
No restricted-use paragraph — or a report handed out freely
SOC 2 reports are restricted-use: intended for the service organisation, its user entities and prospective user entities, its business partners, and regulators with sufficient knowledge.
Independence
The model buyers should really screen for
The AICPA Code of Professional Conduct treats consulting work for an attest client as a non-attest service, and it draws the line by scope rather than by label. Assessing the design and operating effectiveness of a client’s controls, and giving observations and recommendations, sit on the permitted side, provided the general requirements of ET 1.295.040 are met and management makes every decision. Independence is impaired the moment the firm accepts responsibility for designing, implementing or maintaining internal control — which ET 1.295.030 treats as a management responsibility — or decides which gaps to fix first, or takes over an ongoing function. Even for permitted services, the client must designate an individual with suitable skills, knowledge and experience to oversee the work and accept responsibility for it. The threat has a name: self-review.
“We designed your controls, we wrote your policies, we assembled your evidence — and we are pleased to report that they operated effectively.”
— the sentence no independence framework permits
Splitting readiness and signature between two organisations is not the only way to satisfy those rules — a firm can stay independent while assessing controls it did not design — but it is the cleanest. It removes the question instead of arguing it, and a buyer can verify it from two engagement letters rather than from an assurance that the scope was fine.
So the geography question is a proxy. What the reviewer is groping towards is not “were these people Indian?” but “did anyone independent actually look?” — a better question, applying equally everywhere, with a verifiable answer.
How the engagement is structured
Three parties, one report
Take the independence rules seriously and the shape of a well-run SOC 2 is forced.
Activity
You (the service organisation)
Readiness partner (TCSA)
Independent CPA firm
System boundary and TSC categories
Owns the decision
Advises, drafts the scoping paper
Assesses scope at acceptance
Policies and control descriptions
Reviews, approves, adopts
Drafts them against the criteria
Neither drafts nor approves
Remediating gaps — MFA, logging, change
Implements and operates
Designs the fix, runs the project
No involvement
The evidence repository
Operates the controls
Builds it, tests completeness
Requests from it in fieldwork
The system description under DC 200
Owns it
Drafts and maintains it
Evaluates it against DC 200
Management’s written assertion
Signs it
Cannot sign it
Required to complete the examination
Sample selection and control testing
Provides populations and artefacts
Prepares populations, chases evidence
Defines samples, performs the tests
Forming and signing the opinion
No role
No role
Sole responsibility
How TCSA works. We sit in the third column and never the fourth: we scope the system, draft the policies and the description, close gaps with your engineers, build the evidence repository, and sit with your team through fieldwork. The opinion is signed by an independent licensed US CPA firm. We coordinate that engagement; we do not certify, attest, audit, or sign. We work that way across the USA, UK, Canada, Australia, UAE & India.
A worked example
One company, two countries, one report
An illustrative composite. A 55-person B2B SaaS company: a Delaware corporation holding the contracts, a wholly-owned Bengaluru subsidiary employing all thirty engineers, production on AWS.
Illustrative timeline
12 Jan 2026
Scoping
Security and Confidentiality selected. The description names both entities and states that development and support are performed from India. AWS is carved out as a subservice organisation.
Jan – Apr 2026
Readiness
Thirty-four gaps, concentrated in change approval evidence, the quarterly access review (no defined population), and vendor risk under CC9.2.
1 May 2026
Period opens
A six-month first Type 2, closing 31 October 2026 — chosen over three months because the sales cycle would have read a short window as thin.
May – Oct 2026
Controls operate
A September checkpoint catches an access review recorded with no reviewer identity — six weeks before period end.
6 – 21 Nov 2026
CPA firm fieldwork
Populations delivered 6 November and reconciled against payroll records; samples selected 11 November. Two exceptions: a leaver disabled four days after their last working day against a one-business-day control, and an access review completed nine days after quarter close.
18 Dec 2026
Report issued
An unmodified opinion. Both exceptions appear in Section IV with management responses — easier to explain than a spotless first report.
The populations behind that fieldwork. Over the 1 May to 31 October window, four of the composite’s control populations looked like this. They are the arithmetic the sampling table further down describes in the abstract.
Control
Population
How completeness was established
Sampled
Access removal on termination
11 leavers
HR list reconciled to the payroll register and to the contractor invoice roster
5
Provisioning on hire
9 joiners
Same reconciliation, run in the other direction
5
Change management (CC8.1)
340 production deployments
CI pipeline export, not the ticket tracker
25
User access review (CC6.2, CC6.3)
2 review cycles due
The in-scope system inventory in the description
2
Both exceptions came out of the first two rows, which is where cross-border organisations usually find them: the leaver population only reconciled once the contractor invoice roster was added to it, and the timing test was read against a control written without a timezone. The sizes above came from the firm’s own sampling plan, not from a rule.
In the composite, the first enterprise buyer — a US healthcare payer — runs the report through the checks above. India comes up once, as “where is our data processed?”, answered from the infrastructure section rather than the opinion.
Cost and elapsed time
Two fees, and the clock between them
The single most common budgeting error is treating a SOC 2 as one invoice. It is two, from two organisations, and only one of them buys assurance. The bands below are market practice; the right-hand column is what each looked like in the composite above.
Stage
Typical band (market practice)
In the composite
Readiness and implementation (TCSA)
A fixed fee from $4,000 for early-stage startups, quoted after scoping. Driven by the size of the boundary, how many criteria categories you take, and how much control design already exists.
Agreed at scoping, before the January start.
The CPA firm’s examination fee
Billed separately by the CPA firm on its own engagement letter. Driven by scope, the criteria categories in the assertion, the length of the period, and the number of in-scope systems and subservice organisations.
Two categories, one production environment, one carved-out subservice organisation, six-month period.
Scoping to period start
About three to four months for a first Type 2, which is remediation time rather than paperwork time.
12 January to 1 May — roughly fifteen weeks.
Observation period
Three to twelve months. Three is the shortest a first Type 2 is usually run; six and twelve read better in an enterprise sales cycle.
Six months, chosen because a three-month window reads as thin to an enterprise reviewer.
Fieldwork
About two to three weeks once complete populations are delivered. Late or unreconciled populations are what stretches it.
6 to 21 November, populations delivered on day one.
Report issued
About four to six weeks after fieldwork closes, covering the firm’s internal review, your management responses to any exceptions, and report production.
18 December — four weeks after fieldwork closed.
Note what does not appear in that table: a discount for where the work was done. The examination fee is a function of scope — categories, period, systems, subservice organisations — and it is billed by the CPA firm on its own engagement letter regardless of who ran readiness. What varies with geography is the consulting cost of getting ready, and that cost buys none of the assurance. A buyer who reads a low total as a shallow audit is reading the wrong line: ask instead how many criteria categories were in the assertion and how long the period was, because those are the two numbers that actually bound what was tested.
Treat every figure here as market practice rather than as a rule. No standard sets a fee, a period length, or a turnaround, and a firm that quotes a fixed timetable before seeing your boundary is quoting a guess.
Evidence
What the CPA firm actually requests
The biggest surprise in a first SOC 2 is not the controls — it is the evidence discipline, and almost everything that goes wrong goes wrong here.
Populations come first
The firm tests a sample drawn from a population, and its first question is whether that population is complete. For a termination control it is every leaver in the period — and the firm will reconcile your HR list against something you do not maintain, such as a payroll register. For change management under CC8.1 it is every production deployment, taken from the pipeline rather than the ticket tracker, which holds only the changes somebody remembered to raise. For access reviews under CC6.2 and CC6.3 it is every review cycle due across every in-scope system.
Anything you generate is information produced by the entity
Every export and screenshot you hand over was produced by you, and the firm must satisfy itself it is complete and accurate before relying on it. Expect to be asked for the query parameters, the account that ran it, the run date and time, and the full unfiltered output. A screenshot cropped to the row you liked is the most commonly rejected artefact in a first examination — not because the control failed, but because it cannot be tied to a population.
Frequency
Typical control
Population
Sample
What the artefact looks like
Annual
Policy review, DR test
1
1
The approved document plus its approval record — approver, date, version.
Quarterly
User access review
4
2
The review export, the sign-off, and tickets closing each revocation.
Monthly
Vulnerability scan review
12
2–3
Scan output, triage record, remediation ticket with dates.
Weekly
Backup verification
~52
5–8
The verification log for that week, plus the alerting configuration.
Daily
Log review, alert triage
250+
20–25
The alert record: who handled it, when, and what they did.
Event-driven
Onboarding, termination, change
Whatever occurred
Scaled to population
The ticket, an approval predating the action, and the system record.
Read that table as market practice, not as a rule. Sample sizes follow the firm’s sampling plan, the population size, and the risk assigned to the control. Ask your CPA firm for its sizes at kick-off. For a concrete instance, the composite above ran 11 leavers, 9 joiners, 340 deployments and 2 access-review cycles through exactly this logic, and the firm drew 5, 5, 25 and 2.
What gets rejected
None of these means the control failed. All mean the evidence cannot carry the test — which, in a report, reads identically.
Undated screenshots — if it cannot be tied to a date inside the period, it is not evidence of operation.
Cropped exports that hide the filter. The reviewer needs the population it came from.
Approvals recorded after the fact. A change approved the day after deployment is an exception, not a pass.
Policies with no approval record. A version number in a footer is not an approval.
Access reviews completed after their due date. Late is an exception even when thorough.
Documents edited during fieldwork. Back-dating turns an exception into a conversation about the assertion itself.
A hand-assembled population with no reconciliation. Expect to be asked how you know it is complete.
Where cross-border operation changes the evidence
Nothing above is India-specific — populations, completeness and dated artefacts are the same in Kansas. Four things genuinely are, and all four are cheaper to settle before the period opens than to argue during fieldwork.
Timestamps, and the window they are read against
Logs, ticket systems and IAM exports commonly stamp IST, while the CPA firm states its testing window in US dates and reads a one-business-day control against them. A revocation completed at 23:40 IST on a Friday can land either side of a US business day on nothing but the offset — and it fails on arithmetic, not on the control. Two cheap fixes: state the timezone inside the control description, and export evidence in UTC with the offset visible on the artefact.
Contractor, EOR and agency populations
The most common completeness failure in India-operated organisations is that contractors, EOR or PEO staff and agency engineers never appear in the payroll register the firm reconciles your HR list against, so the leaver population is quietly short. Name the reconciling source before fieldwork — the contractor invoice roster, the VMS or MSP roster, the vendor’s monthly headcount statement — and expect the firm to ask how you know it is complete. Answering that in November is far more expensive than deciding it in April.
What a background check looks like as an artefact
In an Indian hiring market the accepted artefact is the screening vendor’s completed report for the named candidate, carrying the candidate identifier, the checks actually run, and the completion date relative to the start date. An HR attestation that checks "are performed", or an invoice showing the vendor was paid, is not evidence that this hire was screened. Where a check genuinely cannot be completed — a university that will not verify — the artefact is the documented exception and the approval to hire anyway.
Auditor access to production, agreed at kick-off
The firm’s testers may need to observe a control operating rather than read an export of it. Settle four things before fieldwork, not during: whether observation happens by screen-share with a named operator or through a read-only reviewer role scoped to the systems in the description; whether the firm’s staff may view records containing customer personal data, and what is masked if not; who signs the NDA; and how the access grant is itself logged, since it is a privileged grant your own access control will be tested against.
All of that is preparation, not attestation — none of it touches licensure. See also the SOC 2 controls list and the common pitfalls.
Where this gets contested
The twenty per cent that generates the real questions
These are the situations where cross-border structure genuinely complicates a SOC 2.
Which legal entity is the service organisation?
The assertion is made by the entity responsible for the system, and that entity is named on the report. Where a US parent holds the customer contracts and an Indian subsidiary runs the platform, the usual answer is one description naming both and stating which functions each performs. Decide it at scoping and put it in the engagement letter — revisiting it during fieldwork means rewriting the description, re-obtaining the assertion, and explaining the change to the firm.
The GCC or captive development centre
Where the Indian entity is a wholly-owned development centre inside the same reporting entity, it is normally in scope within the same description: its controls are your controls, tested directly. Where it is a separate contracted entity — a group company billing under an intercompany services agreement, or a third-party GCC operator — it becomes a subservice organisation, and you choose carve-out or inclusive at scoping. Carve out and its controls sit outside the opinion, appearing instead as CUECs the buyer must satisfy; include it and its controls are described and tested, which means it must give the firm access and sign up to the assertion.
Use of another practitioner for on-site work
The signing firm may involve an India-based practitioner or component team to perform procedures locally — walkthroughs on site, observation of a data centre, inspection of records that cannot leave the country. That is ordinary, and it does not split the opinion: the engagement partner at the signing firm remains responsible for the engagement and for the work of anyone the firm uses. Ask two separate questions at kick-off — who performs the fieldwork, and whose name goes on the opinion — and do not be alarmed when the answers differ.
An EOR-employed or contractor workforce
When engineers are employed by an employer-of-record, a PEO or a staffing agency rather than by the reporting entity, the onboarding, background-check and termination controls have a different operator, and often a different system of record. The description must say who performs each control and how the entity supervises it — otherwise the population never reconciles, because the leaver list comes from a payroll register those people were never in. This is the single most common completeness failure we see in India-operated organisations.
Your subservice organisations may be Indian too
Payroll and HRMS platforms, an MSP running your endpoints, a colocation provider, a BPO handling tier-one support — each is assessed the same way, and the carve-out or inclusive decision applies to each. Expect a US reviewer who has never heard of the vendor to ask what assurance you hold over it: its own SOC 2 or ISAE 3402 report where one exists, and where none does, the alternative procedures you run and evidence under the vendor-risk criterion (CC9.2).
Buyer requirements a SOC 2 cannot satisfy
Two arrive constantly: data must reside in a named country, and only US persons may access it. Neither is a criterion. The description states what infrastructure is inside the boundary and controls over transmission and disposal are tested, but no criterion mandates a location or a nationality, and offering a report as though it settled either costs you credibility. Answer them on their own terms — a contractual commitment plus a geo- or role-restricted access control the examination can then test — and say plainly which one you are doing.
Background-check controls written for the wrong hiring market
If the description says checks are performed on every new hire before start date, the examination tests that against India-based hires as written. Screening vendors, university verification and prior-employer confirmation run on different timelines here, and a control drafted around a US HR process is a reliable source of exceptions. Write the control to the process you actually run — including what happens when a check cannot be completed — rather than to the process you wish you had.
The second deserves particular care. Read subservice organisations and CUECs and CSOCs before you decide, not after.
Objection handling
What security teams push back on, and the answer
Each answer is a fact the buyer can verify independently — the only kind that closes a review.
"Your auditor is offshore."
They are not. The opinion is signed by a CPA firm licensed in a US jurisdiction, and we will give you the firm name, the city and state, and the board register on which you can confirm the licence yourself. What sits in India is the engineering, the readiness work and the evidence preparation — none of which carries a licence in any country, and all of which is disclosed in the description you are holding.
"How do we know an Indian consultancy did not write its own audit?"
Because the firm that designed the controls cannot then attest to them. In our model readiness and signature sit in two separate organisations, on two separate engagement letters, and you are welcome to see both. That is the test worth running on every vendor you assess, not just this one: ask who drafted the policies, who assembled the evidence, and whose name is on the opinion. If one answer covers all three, the report is a document about its own author.
"We need a SOC 2 certificate for our vendor file."
There is not one to give you. SOC 2 is an attestation under AT-C 205: the deliverable is a report containing an opinion, a system description, and the tests the firm performed with their results. No certificate, no certification body, no public register. If your file needs something you can hold without an NDA, the right artefact is a SOC 3 — general-use, same examination behind it, without the detailed test matrix.
"Can we speak to the auditor directly?"
Yes, and you should. Ask the signing firm three things: where its firm licence is registered and whether it is current, when it was last peer reviewed and what the report concluded, and whether it performed any non-attest work for us during the period. Those three answers tell you more about the reliability of the opinion than any question about where our engineers sit, and the firm will expect to be asked.
"Your data sits under a different legal regime."
True, and a SOC 2 does not opine on that — no criterion addresses which government can compel which disclosure. The answers here are contractual and architectural: where the data is actually hosted and in which region, whether it is encrypted at rest and in transit, who holds and can use the keys, and a clause obliging us to notify you of a lawful-access demand so far as the law allows notice. If your requirement is that data never leave the United States, the fix is a US region plus an access control the examination can test — not a report.
"Why is your audit so much cheaper than our other vendors’?"
Because you are comparing two different fees. The CPA firm’s examination fee is set by scope: how many Trust Services Criteria categories, how long the period, how many systems and subservice organisations sit inside the boundary, and how much testing that implies. It is billed by the firm on its own engagement letter and does not move because readiness happened in Bengaluru. What differs is the readiness and remediation cost, which is a consulting fee and buys none of the assurance.
"We need a US entity on the contract."
That is a commercial and legal question rather than a SOC 2 one, and it is usually answerable. What the report has to be clear about is which entity makes the assertion and is responsible for the system: if the US entity holds your contract while the Indian entity operates the platform, the description names both and states what each performs. Ask to see that paragraph before you sign — it should match the entity on your MSA.
"Our policy requires US-only support access."
Then the right instrument is an access control, not a report. Restricting production or support access to a named group, geo-fenced or role-scoped, is a control we can design, you can operate, and the CPA firm can test across the period — after which the report evidences the control rather than the policy. Say which systems and which data the restriction covers before the period opens, because retrofitting it mid-period leaves you with a control that has no history to test.
Frequently Asked Questions
Can an Indian company get a SOC 2 report?
Yes, and many do. Nothing in the AICPA attestation standards, the 2017 Trust Services Criteria, or the DC 200 description criteria restricts an examination by the location of the service organisation; the report simply discloses where the system is operated. The one jurisdictional constraint sits on the other side: the opinion must come from a licensed CPA firm, and US buyers expect one licensed in a US jurisdiction.
Can an Indian CA firm sign a SOC 2 report?
Not an AT-C 205 SOC 2 in its own name: the opinion must be signed by a firm licensed to practise public accountancy, and an ICAI firm registration is not that licence. Two routes remain — a US-licensed affiliate issues the report, or the firm reports under ISAE 3000 (Revised) as a non-US accountancy firm. Our full answer, including how those affiliate arrangements work in practice, is the guide "Can an Indian CA sign a SOC 2 report?" linked above.
Is a SOC 2 prepared from India trustworthy?
Trust in a SOC 2 rests on three things: an independent licensed CPA firm signed the opinion, that firm tested controls against defined criteria using evidence it could rely on, and the report states what was in scope. None depends on where the readiness work happened. What damages trust is structural — a firm that both implemented and attested, or a "certificate" with no examination behind it.
Do my US customers care that my engineering team is in India?
They care that it is disclosed and that the controls covering it were tested. The system description states where services are performed, and a reviewer reads that as a fact about your operating model, not a defect. Where a genuine concern surfaces it is almost always data residency, or a restriction on who may access data — both answerable, and both separate from the attestation.
What is the difference between a SOC 2 and an ISAE 3000 report?
They can examine the same subject matter — controls evaluated against the Trust Services Criteria — under different standards. A SOC 2 is performed under the AICPA attestation standards, principally AT-C sections 105 and 205, with the description evaluated against DC 200. ISAE 3000 (Revised) is the international assurance standard, written for professional accountants in public practice and requiring compliance with the IESBA Code and ISQM 1. Appendix G of the AICPA guide states that a non-US CPA may perform a SOC 2 examination under ISAE 3000 (Revised) and report accordingly, and sets out how to report under both. A consultancy or platform with no accountancy licence cannot use either standard.
Can the same firm do our readiness work and our SOC 2 audit?
Sometimes — scope decides it, not the label. The AICPA Code permits a firm to assess the design and operating effectiveness of your controls and to give observations and recommendations, provided the general requirements of ET 1.295.040 are met and management makes every decision. Independence is impaired the moment the firm designs, implements or maintains the controls, decides which gaps to fix first, or takes over an ongoing function, which ET 1.295.030 treats as a management responsibility. The two-organisation split is the model we run because it removes the question entirely rather than arguing it.
How do I verify the CPA firm that will sign our report?
Confirm the firm licence on the register of the state board of accountancy named in the opinion letter — that board is the authoritative source — and check it is current and in good standing. The NASBA-hosted CPAverify search is a useful shortcut, but it aggregates participating boards only, so a firm absent from it is not thereby unlicensed; go back to the board itself before concluding anything. Then ask when the firm was last peer reviewed, since SOC engagements are a must-select category within peer review. Finally, confirm the deliverable is a report with an opinion, not a certificate.
Does a SOC 2 report say where our data is stored?
Not as an assertion of location. The system description identifies the infrastructure, software, people, procedures and data inside the boundary, and controls over transmission and disposal are tested against the relevant criteria. But no criterion requires data to sit in a particular country, and the opinion attests to no location. If a customer needs residency, put it in the contract, host in the region you promised, and build a control the examination can test.
What does a SOC 2 cost if the readiness work is done from India?
Budget for two invoices, not one. TCSA quotes readiness and implementation as a fixed fee from $4,000 for early-stage startups, after scoping; the CPA firm bills its examination fee separately, on its own engagement letter. That second fee is set by the size of the boundary, how many Trust Services Criteria categories sit in the assertion, the length of the observation period, and the number of in-scope systems and subservice organisations — none of which moves because readiness happened in Bengaluru. Treat any figure as market practice: no standard sets a fee.
Does the CPA firm need to visit our India office?
Usually not. Most SOC 2 fieldwork is performed remotely from system-generated evidence, walkthrough calls and screen-shared observation. Where on-site procedures are needed, the signing firm may involve a local practitioner or component team to perform them, and it remains responsible for the engagement and the opinion either way. Settle the access question at kick-off rather than during fieldwork: who observes production and how, whether the firm’s staff may see records containing customer personal data, and what gets masked if not.
Related reading: who can perform a SOC 2 audit, can an Indian CA sign a SOC 2 report, how to read a SOC 2 report, opinions and exceptions, how long a report stays usable, attestation vs certification, SOC 2 consulting from India, and the SOC 2 hub.
Written By Expert Auditors
Keep Exploring
Related Reading
Can an Indian CA Sign a SOC 2 Report?
Firm licensure, AICPA peer review, and how readiness and attestation actually split.
Read moreWho Can Perform a SOC 2 Audit?
Only licensed CPA firms — independence, peer review, and where consultants fit.
Read moreSOC 2 Consulting in India
Auditor-led SOC 2 readiness and CPA coordination for Indian teams.
Read moreIs There a SOC 2 Certificate?
There is no SOC 2 certification — what you may legitimately claim, and the wording that costs you credibility.
Read moreHow to Read a SOC 2 Report
All five sections annotated, an 8-step reviewer checklist, and the red flags.
Read moreSOC 2 Knowledge Hub
Type 1 vs Type 2, criteria, timelines and audit prep — all guides.
Read moreGet in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours