Skip to main contentChat with us

Service area · Kolkata, India · Reviewed September 2026

Compliance Consultants Serving Kolkata
SOC 2, SOC 1 & ISO 27001 for Sector V and New Town exporters and back offices

Tranquility Cybersecurity serves Kolkata as part of its India service area from its Gurugram headquarters, with on-site visits to Salt Lake Sector V, New Town and the Bantala IT hub when an audit calls for it. Kolkata companies typically come to us for SOC 2 for IT services and SaaS exporters, SOC 1 for the BPO and finance-and-accounting back offices whose work feeds a client’s financial statements, ISO 27001 for the same firms and their banking and insurance customers, and DPDP Act readiness for the hospitals, edtech platforms and consumer businesses that process Indian personal data at scale.

500+Audits delivered
250+SOC 2 attestations
100+SOC 1 reports
India, USA, UK, Australia & UAEWhere our clients are

Quick facts

Compliance in Kolkata, in six lines

How we serve Kolkata
Service area, served from our Gurugram headquarters, with on-site visits for kick-off, evidence walkthroughs and audit days as scope requires.
Frameworks Kolkata buyers ask for
SOC 2 (Type I and Type II), SOC 1 for outsourced financial processes, ISO 27001:2022, DPDP Act readiness and VAPT for web, mobile and API.
Who signs what
SOC 1 and SOC 2 reports are issued by independent licensed CPA firms; ISO 27001 certificates by accredited certification bodies. TCSA prepares you and coordinates both — it never issues or certifies.
Typical readiness budget
SOC 2 consulting ₹2–4 lakh; ISO 27001 ₹1–3 lakh; CPA and certification-body fees quoted separately.
Time zone and travel
Same IST working day as your team; Kolkata is a direct flight from Delhi, and Sector V and New Town are close to the airport for on-site days.
Track record
500+ audits, 250+ SOC 2 attestations and 100+ SOC 1 reports across India, USA, UK, Australia and UAE.

The local picture

What Kolkata’s compliance demand actually looks like

Kolkata’s technology economy is concentrated in Salt Lake Sector V, one of eastern India’s oldest IT districts, and the newer New Town (Rajarhat) hub beside it, with the Bantala IT and leather complex to the south-east. The mix is distinctive: alongside IT services and SaaS exporters sits a large base of BPO, KPO and finance-and-accounting outsourcing operations, many of them running processes for banks, insurers and corporates whose auditors care about financial-reporting controls. Kolkata is also a long-standing banking and insurance city with large operations and back-office centres, a growing private-hospital and diagnostics sector, active edtech companies, and the port, rail and logistics operators that serve eastern India. Each group answers to a different buyer or regulator, and that decides which framework comes first.

Salt Lake Sector V (Bidhannagar)New Town (Rajarhat) IT hubBantala IT complexPark Street–Camac Street business districtKolkata Port and the Hooghly logistics belt

IT services and BPO/KPO

Sector V and New Town firms serving US, UK and Australian clients are asked for SOC 2 reports and ISO 27001 certificates in procurement; outsourcers running finance, payroll or claims processes are asked for SOC 1.

Banking and insurance back offices

Operations centres of banks, NBFCs and insurers inherit RBI and IRDAI expectations from their principals and process personal financial data at scale under the DPDP Act; ISO 27001, VAPT and privacy work are the usual scope.

Hospitals, diagnostics and healthtech

Private hospital groups and lab chains hold sensitive health data under the DPDP Act; those serving US providers through outsourcing are HIPAA business associates by contract.

Edtech and consumer platforms

Learning platforms and consumer apps collect student and user data at scale, including children’s data, which carries additional duties under the DPDP Act.

Ports, logistics and shipping tech

Port operators, freight forwarders and logistics platforms handle customer and cargo data and depend on OT-adjacent systems; ISO 27001 and continuity work fit here.

What we deliver in Kolkata

The frameworks Kolkata buyers ask for, and why

SOC 2 attestation

The report US and European buyers ask Sector V and New Town exporters for. We scope the Trust Services Criteria, design and implement controls, collect evidence and coordinate the licensed CPA firm through to the signed Type I or Type II report.

SOC 2 consulting

SOC 1 attestation

For Kolkata’s finance-and-accounting, payroll, claims and transaction-processing outsourcers whose work affects a client’s financial statements: control-objective design, description of the system, evidence collection and coordination of the licensed CPA firm through to the SOC 1 Type I or Type II report.

SOC 1 guide

ISO 27001:2022 certification

The certificate Indian banks, insurers, PSUs and European buyers recognise. ISMS scoping, risk assessment, the 93 Annex A controls, internal audit and certification-body coordination — scoped so an operations team can run it after we leave.

ISO 27001 consulting

DPDP Act readiness

For the hospitals, edtech platforms, insurers, lenders and consumer businesses in Kolkata that are data fiduciaries under the Digital Personal Data Protection Act 2023: data mapping, consent and notice flows, grievance handling and breach-notification readiness under the DPDP Rules.

DPDP compliance

VAPT — web, mobile, API

Manual-first penetration testing that satisfies SOC 2 auditors, ISO 27001 control A.8.8 and RBI or IRDAI expectations. Where a regulator or tender requires a CERT-In empanelled report, we deliver with CERT-In empanelled partners.

VAPT services

Laws and regulators

What applies to a Kolkata company

Plain-English summary as of September 2026. Laws change; confirm current obligations with counsel before relying on any line here.

Laws, regulators and mandates relevant to companies in Kolkata
Law / regulatorWho it coversWhat it means in practice
Digital Personal Data Protection Act 2023 and DPDP RulesEvery Kolkata company that processes digital personal data of individuals in India — hospitals, insurers, lenders, edtech, e-commerce, HR and payroll platforms, BPOs handling Indian customer data.Consent and notice obligations, data-principal rights, breach notification to the Data Protection Board and affected individuals, and heavier duties for Significant Data Fiduciaries. Outsourcers acting as processors take on contractual duties. Readiness work should start now rather than at the deadline.
RBI and IRDAI expectations flowing to operations centresBanks, NBFCs and insurers headquartered or with operations centres in Kolkata, and the outsourcers that run processes for them.RBI’s IT governance and cyber-security directions and IRDAI’s information and cyber-security guidelines require regulated entities to oversee their vendors, so outsourcers are asked for ISO 27001, periodic VAPT and often a SOC 1 or SOC 2 report as evidence.
CERT-In cyber-security directions (2022)All service providers, intermediaries and body corporates in India, including Sector V and New Town exporters.Six-hour incident reporting to CERT-In, log retention, and synchronised clocks. An incident-response playbook that meets both CERT-In and SOC 2 expectations avoids doing the work twice.
SEZ and STPI export obligationsUnits in Kolkata’s IT SEZs and STPI-registered exporters in Sector V, New Town and Bantala.No security mandate of its own, but export contracts with US, UK and Australian clients routinely require SOC 2, SOC 1 or ISO 27001 as a condition of the master services agreement.
Client-side laws that reach Kolkata outsourcersAny Kolkata company processing US health data, EU or UK personal data, or card data for its clients.HIPAA business-associate duties, GDPR processor obligations and PCI DSS scoping flow down through contracts. We map them onto one control set instead of running parallel programmes.

How we serve Kolkata

From our Gurugram team, on-site when it matters

Your time zone: IST (UTC+5:30)Headquarters: Gurugram, IndiaService area: Kolkata, West Bengal
  • Our Gurugram team works in the same IST working day as your Kolkata team; workshops and evidence reviews run over video with shared trackers.

  • On-site when it matters: kick-off, control walkthroughs at Sector V, New Town or Bantala offices, and audit days with the CPA firm or certification body.

  • Named lead auditors and CISA-certified practitioners run the engagement end to end — no hand-off to a junior team after the sale.

  • One combined programme when a BPO needs SOC 1, SOC 2 and ISO 27001 together: shared risk assessment, one policy set, one evidence library, one CPA fieldwork window.

  • Fixed fee agreed in writing after a short scoping call; CPA and certification-body fees are quoted separately and we help you scope both.

Pricing

Indicative bands for Kolkata engagements

Indicative bands for Kolkata engagements. Scope, headcount, cloud footprint and starting maturity move the number; we give you a fixed figure in writing after a 30-minute scoping call.

Indicative pricing bands for compliance engagements in Kolkata
EngagementIndicative bandNote
SOC 2 readiness consulting (Type I or Type II)₹2–4 lakhCPA attestation fee quoted separately by the licensed CPA firm.
ISO 27001:2022 implementation and internal audit₹1–3 lakhCertification-body fees separate.
DPDP Act readinessScoped to data volume and fiduciary statusIncludes data mapping, consent flows and breach playbook.
VAPT (web application, typical SaaS scope)₹40,000 – ₹1.5 lakh per testRetest included; CERT-In empanelled partner where required.
vCISO / vDPO retainerMonthly retainer, scoped to hoursNamed practitioner, board and customer-facing.

Compliance in Kolkata: FAQs

Straight answers for Kolkata companies on SOC 2, ISO 27001, local regulation, timelines and cost.

Does Tranquility Cybersecurity have an office in Kolkata?

No. Kolkata is part of our India service area. We are headquartered in Gurugram and serve Kolkata from there, with on-site visits for kick-off, control walkthroughs and audit days. Most of a SOC 1, SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.

Our BPO runs accounts-payable and payroll for a US client. Do we need SOC 1 or SOC 2?

SOC 1. When your process affects the client’s financial statements — payables, payroll, claims, reconciliations — the client’s financial-statement auditors need a SOC 1 report on your controls over financial reporting. SOC 2 covers security and availability and is what the client’s security team asks for. Many Kolkata outsourcers end up needing both; we design one control set and the CPA firm can examine both in one fieldwork window.

What is the difference between SOC 1 Type I and Type II?

Type I describes your controls and tests whether they were suitably designed at a point in time. Type II also tests whether they operated effectively over a period, usually six to twelve months, and is what client auditors normally want. First-time engagements often start with a Type I to fix the description, then move to a Type II covering the next period.

Which should a Sector V IT exporter do first — SOC 2 or ISO 27001?

It depends on who is asking. US and Australian enterprise buyers ask for a SOC 2 report, increasingly Type II. Indian banks, insurers, PSUs and some EU customers recognise ISO 27001. If both are on the horizon, we build one control set and sequence the two audits so evidence is collected once.

Our client is an Indian bank. What will their vendor-risk team ask for?

Typically an ISO 27001 certificate, a recent VAPT report, evidence of business-continuity testing and answers to a questionnaire drawn from RBI’s outsourcing and cyber-security directions. Where the bank needs a report it can rely on for its own auditors, a SOC 1 or SOC 2 Type II is often requested as well. We prepare all of that as one evidence pack.

Who issues the SOC report or ISO 27001 certificate?

SOC 1 and SOC 2 reports are issued by independent licensed CPA firms operating under AICPA standards. An ISO 27001 certificate is issued by an accredited certification body. TCSA prepares you, runs the internal audit and coordinates the auditor; it does not issue either, and no consultant legitimately can.

Does the DPDP Act apply to a Kolkata hospital or insurer?

Yes. Any organisation that decides the purpose and means of processing digital personal data in India is a data fiduciary under the DPDP Act 2023. Hospitals, diagnostics chains, insurers and lenders in Kolkata all qualify; large-volume or sensitive processors may be designated Significant Data Fiduciaries with additional duties such as a resident Data Protection Officer and periodic audits.

How is pricing structured?

Fixed fee, agreed in writing after a scoping call. Typical Kolkata bands are ₹2–4 lakh for SOC 2 readiness consulting and ₹1–3 lakh for ISO 27001 implementation; SOC 1 readiness is scoped to the number of control objectives. CPA attestation and certification-body fees are quoted separately by those firms, and we help you scope them so there are no surprises.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: September 2026Content verified by certified lead auditors

Talk to a real auditor

Scoping compliance in Kolkata?

Book a free 30-minute call. We will tell you which framework your buyers or regulator actually need, what it will cost, and how long it takes — and whether we are the right fit.