Straight answers for Kolkata companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Kolkata?
+
No. Kolkata is part of our India service area. We are headquartered in Gurugram and serve Kolkata from there, with on-site visits for kick-off, control walkthroughs and audit days. Most of a SOC 1, SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.
Our BPO runs accounts-payable and payroll for a US client. Do we need SOC 1 or SOC 2?
+
SOC 1. When your process affects the client’s financial statements — payables, payroll, claims, reconciliations — the client’s financial-statement auditors need a SOC 1 report on your controls over financial reporting. SOC 2 covers security and availability and is what the client’s security team asks for. Many Kolkata outsourcers end up needing both; we design one control set and the CPA firm can examine both in one fieldwork window.
What is the difference between SOC 1 Type I and Type II?
+
Type I describes your controls and tests whether they were suitably designed at a point in time. Type II also tests whether they operated effectively over a period, usually six to twelve months, and is what client auditors normally want. First-time engagements often start with a Type I to fix the description, then move to a Type II covering the next period.
Which should a Sector V IT exporter do first — SOC 2 or ISO 27001?
+
It depends on who is asking. US and Australian enterprise buyers ask for a SOC 2 report, increasingly Type II. Indian banks, insurers, PSUs and some EU customers recognise ISO 27001. If both are on the horizon, we build one control set and sequence the two audits so evidence is collected once.
Our client is an Indian bank. What will their vendor-risk team ask for?
+
Typically an ISO 27001 certificate, a recent VAPT report, evidence of business-continuity testing and answers to a questionnaire drawn from RBI’s outsourcing and cyber-security directions. Where the bank needs a report it can rely on for its own auditors, a SOC 1 or SOC 2 Type II is often requested as well. We prepare all of that as one evidence pack.
Who issues the SOC report or ISO 27001 certificate?
+
SOC 1 and SOC 2 reports are issued by independent licensed CPA firms operating under AICPA standards. An ISO 27001 certificate is issued by an accredited certification body. TCSA prepares you, runs the internal audit and coordinates the auditor; it does not issue either, and no consultant legitimately can.
Does the DPDP Act apply to a Kolkata hospital or insurer?
+
Yes. Any organisation that decides the purpose and means of processing digital personal data in India is a data fiduciary under the DPDP Act 2023. Hospitals, diagnostics chains, insurers and lenders in Kolkata all qualify; large-volume or sensitive processors may be designated Significant Data Fiduciaries with additional duties such as a resident Data Protection Officer and periodic audits.
How is pricing structured?
+
Fixed fee, agreed in writing after a scoping call. Typical Kolkata bands are ₹2–4 lakh for SOC 2 readiness consulting and ₹1–3 lakh for ISO 27001 implementation; SOC 1 readiness is scoped to the number of control objectives. CPA attestation and certification-body fees are quoted separately by those firms, and we help you scope them so there are no surprises.