Straight answers for Chicago companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Chicago?
+
No. Chicago is part of our US service area. We are headquartered in Gurugram, India and serve Chicago from there; engagements run over video in Central working hours, with on-site days available for audits when scope requires. Most of a SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.
Can an India-based consultancy prepare a US company for SOC 2?
+
Yes. A SOC 2 report is signed by an independent licensed US CPA firm operating under AICPA attestation standards; the location of the readiness consultant does not affect the report’s validity. TCSA prepares you — scoping, controls, policies, evidence — and coordinates the CPA firm through fieldwork to the signed report. We do not sign or issue the report, and no consultant legitimately can.
A trading firm’s auditors want a SOC 1. We already have SOC 2. Do we start over?
+
No. SOC 1 is a different report — control objectives around your clients’ financial reporting rather than the Trust Services Criteria — but most of the underlying evidence on access, change management and operations carries over. We define the control objectives, write the system description and coordinate the CPA firm; the observation period can run alongside your SOC 2 Type II window.
Our product uses facial recognition for identity checks. What does BIPA mean for us?
+
If any of those faces belong to Illinois residents, BIPA applies: written informed consent before collection, a published retention and destruction schedule, no selling of biometric data, and exposure to private lawsuits if any of that is missing. It is a product-design question as much as a compliance one; we build the consent, retention and vendor-contract controls into the ISMS or SOC 2 programme and evidence them.
Customers keep asking about business continuity. Is ISO 22301 worth it?
+
For logistics, market-infrastructure and fintech vendors whose customers depend on uptime, often yes. ISO 22301 turns continuity from a policy document into a tested, certifiable management system — business impact analysis, recovery strategies, exercised plans. It builds on ISO 27001 where you have it, and the Availability criteria of SOC 2 draw on the same evidence.
How long does SOC 2 take for a Chicago fintech?
+
Readiness typically takes 8–12 weeks for a company with a reasonable security baseline. A Type I report can follow within weeks of readiness. Type II needs an observation window, commonly 3 to 12 months, plus the CPA examination. Anyone promising a Type II in weeks is describing readiness, not the attestation.
Do you handle the PCI DSS assessment itself?
+
We prepare you for it. PCI DSS readiness — scoping, segmentation, gap remediation, evidence — is our work; the Report on Compliance is issued by a Qualified Security Assessor firm, and smaller merchants and service providers may self-assess using the applicable questionnaire. We help you decide which route applies and coordinate the QSA where one is needed.
How is pricing structured for a Chicago engagement?
+
Fixed fee, agreed in writing after a scoping call and invoiced in USD or INR. Typical bands are USD 2,500 – 6,000 for SOC 2 readiness consulting and USD 3,000 – 8,000 for ISO 27001 implementation; SOC 1 and ISO 22301 are scoped to the service. CPA attestation and certification-body fees are quoted separately by those firms, and we help you scope them so there are no surprises.