Straight answers for Pune companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Pune?
+
No. Pune is part of our India service area. We are headquartered in Gurugram and serve Pune from there, with on-site visits for kick-off, control walkthroughs and audit days. Most of a SOC 2 or ISO 27001 engagement runs over video and shared trackers regardless of where the consultant sits.
Our engineering-services clients are European OEMs. Is ISO 27001 enough, or do we need something else?
+
ISO 27001 is usually the foundation OEMs expect, and many automotive supply-chain questionnaires are built around it. Some OEMs additionally ask for a TISAX assessment, which is run by TISAX-accredited providers rather than by TCSA; a well-built ISO 27001 ISMS gets you most of the way there and we can prepare the evidence for that assessment. Sequence ISO 27001 first.
Can we scope ISO 27001 to just our engineering environment and leave the plant out?
+
Yes, and it is common. The ISMS scope statement defines which sites, systems and business units are covered; plant OT can be excluded initially and brought in later. What matters is that the scope matches what customers are relying on — if an OEM is buying your connected-vehicle platform, that platform and the teams running it need to be inside the boundary.
Which should a Hinjawadi IT exporter do first — SOC 2 or ISO 27001?
+
It depends on who is asking. US enterprise buyers ask for a SOC 2 report, increasingly Type II. European OEMs, Indian banks and government buyers recognise ISO 27001. If both are on the horizon, we build one control set and sequence the two audits so evidence is collected once.
How does ISO 22301 relate to the continuity requirements our bank client keeps asking about?
+
RBI-regulated banks are expected to have tested continuity arrangements and to oversee their vendors’ arrangements too, so they push the requirement down to operations centres and fintech vendors in Pune. ISO 22301 gives you a structured business-impact analysis, recovery strategies and exercised plans, and a certificate the bank’s vendor-risk team recognises. It shares governance with ISO 27001, so the two are usually run together.
Does the DPDP Act treat edtech differently?
+
The Act itself applies to every data fiduciary, but processing children’s data brings extra duties: verifiable parental consent, a bar on tracking or behavioural monitoring of children, and no targeted advertising to them. Edtech platforms in Pune that serve school-age learners should design consent and product flows around these rules now.
Who issues the SOC 2 report or ISO 27001 certificate?
+
A SOC 2 report is issued by an independent licensed CPA firm operating under AICPA standards. An ISO 27001 or ISO 22301 certificate is issued by an accredited certification body. TCSA prepares you, runs the internal audit and coordinates the auditor; it does not issue either, and no consultant legitimately can.
How is pricing structured?
+
Fixed fee, agreed in writing after a scoping call. Typical Pune bands are ₹2–4 lakh for SOC 2 readiness consulting and ₹1–3 lakh for ISO 27001 implementation. CPA attestation and certification-body fees are quoted separately by those firms, and we help you scope them so there are no surprises.