Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

SOC 2 is an opinion on your controls, not a certificate.

A SOC 2 compliance consultant in India is usually hired because a customer asked for the report and the deal is waiting. Worth knowing before you start: SOC 2 is not a certification. It is an attestation report in which a licensed CPA firm gives an opinion on whether your controls are suitably designed and, in a Type II, whether they operated effectively over a period.

That distinction shapes everything. There is no fixed control list. You define your own controls against the Trust Services Criteria you select, and the auditor tests what you claimed. Choosing which criteria apply, and writing controls you can actually evidence every day for a year, is where the programme is won or lost.

We scope it honestly, close the gaps, and get the evidence collection running before the observation window opens, because a Type II is only as good as the records from the period it covers. Where you also need ISO 27001:2022, the control sets overlap heavily and should be built once.

Why you need it

01 / 06

Why SOC 2 is worth doing properly.

01

It is the price of entry to enterprise sales.

For a SaaS or service business selling into North American enterprises, the report is requested early and often decides whether a procurement process continues. It routinely removes weeks of bespoke security review.

02

A weak report is worse than none.

Auditors qualify opinions and list exceptions, and customers read them. A report with material exceptions in the areas the customer cares about invites more scrutiny than having no report at all.

03

The controls have to run continuously.

A Type II covers a period, typically three to twelve months. Access reviews that were skipped in month four and change tickets that were opened retrospectively both show up in testing. The system has to work every week, not before the audit.

04

It maps onto what you probably already need.

The Security criterion overlaps substantially with ISO 27001:2022 Annex A and with most customer questionnaires, so one control programme can serve several obligations.

Instrument

02 / 06

The criteria, in plain English.

Each criterion with the question it actually asks and the evidence that answers it, plus where it overlaps what you are already doing.

What we deliver

03 / 06

What we deliver.

01

Scoping and criteria selection

Which of the five Trust Services Criteria you actually need. Security is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are each added only where a customer requires it or your service genuinely depends on it. Adding criteria you do not need is the most common way to make a SOC 2 twice as expensive as it should be.

02

Readiness assessment

Your current controls tested the way the auditor will test them, with the gaps documented and an honest view of whether you are ready for a Type I now, a Type II later, or neither yet.

03

Control design and implementation

Writing controls you can evidence: access provisioning and review, change management, vulnerability management, monitoring and alerting, incident response, vendor management, and the human resource controls auditors always sample.

04

Policy and procedure documentation

The policy set the auditor expects, written to describe what you actually do. A policy that promises quarterly reviews you do not perform creates the exception; a policy that describes your real cadence does not.

05

Evidence automation

Getting evidence collected automatically from the systems that generate it, before the observation window opens. Manual evidence assembly for a twelve-month Type II is where most teams lose a month of engineering time.

06

Auditor selection and audit support

Introductions to licensed CPA firms and help comparing them properly, then management of the audit itself: evidence requests, sampling, auditor questions, and remediation of anything found before the opinion is issued.

How we run it

04 / 06

Six stages to a report.

  1. 01

    Determine scope and criteria

    Which systems and services the report covers and which Trust Services Criteria apply. We push back on scope creep here, because every additional criterion adds controls, evidence and audit cost for the life of the programme.

    Weeks 1-2
  2. 02

    Readiness assessment

    Testing current controls against the selected criteria the way an auditor will, producing a gap register with owners, effort and a realistic date for the observation window to open.

    Weeks 2-5
  3. 03

    Design and implement controls

    Closing the gaps: access control, monitoring, change management, incident response, vendor management and data protection, implemented so that operating them generates the evidence automatically.

    Months 2-5
  4. 04

    Document policies and procedures

    The documentation set, aligned to what the controls actually do. Auditors test the gap between the policy and the practice, so the documentation is written last, from reality.

    Months 3-5
  5. 05

    Internal testing

    Running the auditor's tests ourselves before they do, sampling evidence from the observation window as it accumulates, and fixing failures while they are still cheap.

    Month 5, then monthly
  6. 06

    Engage the auditor

    A licensed CPA firm conducts the examination: a point-in-time Type I, or a Type II covering the observation period. We manage the evidence requests and drive any findings to closure before the opinion is issued.

    Months 6-12

Key benefits

05 / 06

What changes after.

Deals stop stalling at security review

A clean report covering the service your customer is buying answers most of an enterprise assessment, and it answers it the same way for every customer.

The controls actually run

Because they were designed to generate evidence automatically, access reviews, change approvals and monitoring keep happening after the audit rather than resuming a month before the next one.

The next framework is cheaper

The Security criterion overlaps heavily with ISO 27001:2022 Annex A, so a mapped control set makes the second certification largely an exercise in re-presenting evidence you already collect.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Framework

  • AICPA Trust Services Criteria
  • COSO Internal Control framework

Evidence automation

  • AphelioNYX Compliance Hub
  • Cloud configuration evidence collection
  • Ticketing and change-record integration

Technical controls

  • Wazuh
  • Microsoft Sentinel
  • Nessus
  • Prowler

Access and change

  • Access review workflows
  • Change approval records
  • Onboarding and offboarding checklists

Mapping

  • ISO 27001:2022 Annex A
  • CIS Critical Security Controls v8

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about SOC 2.

Type I or Type II: which do we need?
Ask the customer who requested it, because they usually have a specific answer. A Type I attests that controls are suitably designed at a point in time and can be produced in a few months, which makes it a reasonable bridge when a deal is waiting. A Type II attests that they operated effectively across a period and is what most enterprises actually want. The common path is Type I first, then a Type II covering the following period.
How long should our observation window be?
Three months is the shortest that is generally accepted and is a reasonable first Type II. Six to twelve months is stronger and is what mature buyers expect. The window has to be continuous and the controls have to have operated throughout it, so the practical constraint is not the calendar but whether your access reviews, change approvals and monitoring were genuinely running from day one.
Which Trust Services Criteria should we include?
Security is mandatory. Add Availability if you commit to uptime service levels, Confidentiality if you handle customer data under confidentiality obligations, Processing Integrity if you process transactions where accuracy is the product, and Privacy if you handle personal data and a customer specifically asks for it. Each added criterion means more controls, more evidence and more audit cost every year, so include what is required, not what looks thorough.
Can you audit us as well as prepare us?
No, and no one legitimate can do both. The examination must be performed by an independent licensed CPA firm, and a firm that helped design your controls cannot then opine on them. We prepare you, run the readiness assessment, introduce you to audit firms and manage the examination on your side. That separation is a feature. It is what makes the resulting opinion worth anything.
What does the whole thing cost?
Two costs, quoted separately. The CPA firm charges for the examination, driven by scope, criteria count and system complexity. Preparation cost depends on how much needs building and how much you do internally. There is also a recurring cost that people forget: a SOC 2 is annual, and the evidence has to be collected continuously, which is precisely why we automate collection during the first cycle rather than after it.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.