Straight answers for Kochi companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Kochi?
+
No. Kochi is part of our India service area. We are headquartered in Gurugram and serve Kochi from there, with on-site visits for kick-off, control walkthroughs and audit days. Most of a SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.
Which should an Infopark IT exporter do first — SOC 2 or ISO 27001?
+
It depends on who is asking. US and many European enterprise buyers ask for a SOC 2 report, increasingly Type II. Indian banks, government buyers and some EU customers recognise ISO 27001. If both are on the horizon, we build one control set and sequence the two audits so evidence is collected once.
How long does SOC 2 take for a Kochi SaaS company?
+
Readiness typically takes 8–12 weeks for a company with a reasonable security baseline. A Type I report can follow within weeks of readiness. Type II needs an observation window, commonly 3 to 12 months, plus the CPA examination. Anyone promising a Type II in weeks is describing readiness, not the attestation.
Who issues the SOC 2 report or ISO 27001 certificate?
+
A SOC 2 report is issued by an independent licensed CPA firm operating under AICPA standards. An ISO 27001 certificate is issued by an accredited certification body. TCSA prepares you, runs the internal audit and coordinates the auditor; it does not issue either, and no consultant legitimately can.
Does the DPDP Act apply to a Kochi hospital or NBFC?
+
Yes. Any organisation that decides the purpose and means of processing digital personal data in India is a data fiduciary under the DPDP Act 2023. Hospitals, diagnostics chains, banks, NBFCs and consumer platforms in Kochi all qualify; large-volume or sensitive processors may be designated Significant Data Fiduciaries with additional duties such as a resident Data Protection Officer and periodic audits.
Do we need a CERT-In empanelled VAPT report?
+
Only if a regulator or contract asks for it — RBI-regulated entities and government tenders commonly do. For a private SaaS exporter selling to enterprises, report quality and methodology matter more than empanelment. Where empanelment is required, TCSA delivers the engagement with CERT-In empanelled partners.
Can you work with our existing compliance-automation platform?
+
Yes. Many Kochi SaaS teams already run Sprinto, Scrut, Vanta or Drata. We design the controls, write the policies and prepare the audit while the platform collects evidence; you do not need to buy software to work with us, and we do not resell any.
How is pricing structured?
+
Fixed fee, agreed in writing after a scoping call. Typical Kochi bands are ₹2–4 lakh for SOC 2 readiness consulting and ₹1–3 lakh for ISO 27001 implementation. CPA attestation and certification-body fees are quoted separately by those firms, and we help you scope them so there are no surprises.