How long does SOC 2 Type II actually take?
6 to 9 months end to end for most Indian SaaS teams. Readiness work (gap assessment, policy library, control implementation, evidence automation) is 8 to 12 weeks. Observation period is a minimum of 3 months, most teams pick 6. Auditor fieldwork is 3 to 5 weeks. If you have a hard sales deadline, we start with SOC 2 Type I (point-in-time attestation) which can ship in about 10 weeks, then convert to Type II at the end of the observation period.
Should we do SOC 2 or ISO 27001 first?
Depends on where the buyer is. US enterprise buyers ask for SOC 2 first, ISO 27001 second. EU buyers ask for ISO 27001 first, SOC 2 second. If you sell globally, the controls overlap 70 to 80 percent so doing both is not double the work. We usually run them in parallel with a single policy library and shared evidence pool. That way the SOC 2 auditor and the ISO 27001 stage-2 audit reuse the same artefacts.
What does VAPT look like for a SaaS deal-unblock?
Named-tester engagement, CVSS 3.1 scoring, PoC screenshots, remediation retest included, report signed on Decipher letterhead. The report format is what US and EU procurement teams accept in security questionnaires. We cover the web app, API, tenant isolation, SSO flows and any customer-facing integration surface. Turnaround is typically 2 to 3 weeks depending on scope. Critical findings get a same-day heads-up so your team can start fixing before the report lands.
How do you handle GDPR for a SaaS built in India?
Data Processing Agreement templates, sub-processor management, DPA schedule with the customer, Article 32 technical measures documented, DPIA where the processing warrants it, DPO advisory. Storage residency options in EU regions (Frankfurt, Dublin, Stockholm) for customers who require it. Cross-border transfer mechanism (Standard Contractual Clauses since Schrems II) documented. We do the DPDP + GDPR delta together so the compliance work compounds rather than duplicating.
What is cloud posture and why do enterprise buyers ask about it?
It is the health check on your AWS / GCP / Azure account. Public S3 buckets, over-permissive IAM roles, security groups open to 0.0.0.0/0, unused access keys, MFA not enforced on the root account, missing GuardDuty. Enterprise security questionnaires now ask specifically about CSPM (Cloud Security Posture Management). We set up AWS Security Hub, GCP SCC or Azure Defender for Cloud, tune the rules for your architecture, and give you a dashboard the buyer's security team accepts as evidence.
How often should we run a penetration test?
Baseline is annual for compliance (SOC 2, ISO 27001, PCI-DSS all require it). Practical cadence is quarterly if you ship major features frequently, or on trigger (new payment integration, major auth change, new customer-facing surface). Between full tests, we run continuous vulnerability scanning on the API surface and dependency SBOM checks on every deploy. That way findings show up early rather than in the annual audit.
How much does SaaS security readiness cost?
Product + API VAPT: Rs. 1.5 to 4 lakh depending on surface. SOC 2 Type II readiness sprint (readiness + observation + auditor coordination): Rs. 5 to 8 lakh, plus the auditor fee separately (usually USD 15-30k). ISO 27001 certification sprint: Rs. 4 to 7 lakh, plus cert body fee. Ongoing cloud posture + managed security retainer: Rs. 80,000 to 2.5 lakh per month. Fixed-price scoping in 48 hours.