Straight answers for Ahmedabad companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Ahmedabad?
+
No. Ahmedabad and Gandhinagar are part of our India service area. We are headquartered in Gurugram and serve the city from there, with on-site visits for kick-off, control walkthroughs and audit days. Most of a SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.
We are setting up a unit in GIFT City. What does IFSCA expect on cyber-security?
+
IFSCA sets its own expectations for regulated entities, and they vary by licence type — a banking unit, a fund manager and a fintech sandbox participant do not carry identical obligations. In practice, most units are expected to show governance, a documented control framework, periodic testing, continuity arrangements and incident reporting. We read the circulars that apply to your licence, scope an ISO 27001 ISMS and, where needed, ISO 22301 to evidence them, and coordinate the certification body.
Is a GIFT City fintech also under RBI?
+
Within the IFSC, IFSCA is the unified regulator, so a GIFT City entity generally answers to IFSCA rather than to RBI, SEBI or IRDAI directly. A group that also runs a domestic entity outside GIFT City will have that entity under the domestic regulator. We build one control set that satisfies both where a group straddles the boundary, and we recommend confirming the precise regulatory position with your legal counsel.
Do we need full PCI DSS certification, or just scoping?
+
It depends on how much card data you touch and what your acquirer or card brands require. Many fintechs and e-commerce operators can reduce scope by tokenising and routing card data through a compliant payment aggregator, then complete a self-assessment questionnaire. Higher transaction volumes or direct card storage bring a QSA assessment. We scope first, shrink the environment where possible, and prepare the evidence for whichever route applies.
Which should an SG Highway IT exporter do first — SOC 2 or ISO 27001?
+
It depends on who is asking. US and many European enterprise buyers ask for a SOC 2 report, increasingly Type II. Indian banks, GIFT City counterparties and government buyers recognise ISO 27001. If both are on the horizon, we build one control set and sequence the two audits so evidence is collected once.
Who issues the SOC 2 report, ISO certificate or PCI DSS attestation?
+
A SOC 2 report is issued by an independent licensed CPA firm operating under AICPA standards. ISO 27001 and ISO 22301 certificates are issued by accredited certification bodies. A PCI DSS Report on Compliance is issued by a Qualified Security Assessor. TCSA prepares you, runs the internal audit and coordinates the assessor; it does not issue any of them, and no consultant legitimately can.
Can ISO 27001 be scoped to just our pharma plant’s quality and business systems?
+
Yes. The ISMS scope statement defines which sites, systems and business units are covered, and pharma manufacturers commonly start with laboratory, quality-management and ERP systems where data-integrity expectations are highest, then extend to plant OT later. What matters is that the scope matches what customers and auditors are relying on.
How is pricing structured?
+
Fixed fee, agreed in writing after a scoping call. Typical Ahmedabad bands are ₹2–4 lakh for SOC 2 readiness consulting and ₹1–3 lakh for ISO 27001 implementation. CPA attestation, certification-body and QSA fees are quoted separately by those firms, and we help you scope them so there are no surprises.