ISO 27001, SOC 2 and GDPR: what an Indian vendor actually needs
ISO 27001 certifies that you run an information security management system. SOC 2 reports on whether your controls actually operated over a period. GDPR is law, not a certificate. Most Indian vendors are asked for all three and need them in a specific order.
Every enterprise procurement questionnaire asks about certifications, and most Indian vendors answer badly — either overclaiming, or listing frameworks without understanding what the buyer is actually testing. The three that come up constantly are not the same kind of thing, and treating them as interchangeable is what makes a security questionnaire go wrong.
They are three different categories
ISO 27001 is a certification of a system. An accredited body audits whether you operate an Information Security Management System — documented policies, risk assessments, defined controls, management review, continual improvement. It certifies that the machinery exists and runs. It does not certify that any individual control worked on any given day.
SOC 2 is an attestation about evidence. A licensed accounting firm examines whether your controls were designed appropriately (Type I) and whether they actually operated over a period, usually six to twelve months (Type II). It produces a report, not a badge. Buyers who understand SOC 2 will ask for the report and read the exceptions section.
GDPR is law. There is no GDPR certificate. Any vendor selling you one is selling a readiness assessment with a misleading name. If you process the personal data of people in the EU, it applies whether or not anyone audited you. India's DPDP Act 2023 works the same way — obligation, not accreditation.
What buyers actually ask for, by market
For US enterprise buyers, SOC 2 Type II is the default request. Many will not proceed to contract without one, and their security team reads it properly.
For UK and EU buyers, ISO 27001 carries more weight, and a data processing agreement with GDPR-aligned terms is mandatory rather than negotiable.
For Indian enterprise and public sector, ISO 27001 is the recognised name, often written directly into tender eligibility criteria. DPDP compliance is increasingly specified.
For Gulf markets, ISO 27001 plus local data residency commitments tend to matter more than SOC 2.
The order that makes sense
Build the ISMS first, whether or not you certify. Almost everything SOC 2 tests is the same underlying control set — access management, change management, incident response, vendor risk, logging. Doing that work once serves both.
Then certify ISO 27001 if your market is UK, EU, India or the Gulf. Then add SOC 2 Type II if you are selling into US enterprise, and budget for a period of observation before the report means anything — a Type II covering three months is technically valid and commercially weak.
GDPR and DPDP obligations run alongside all of it, continuously, regardless of certification status.
What it costs
For a team of 20 to 60 people in India, ISO 27001 certification typically runs ₹6–15 lakh in the first year including gap assessment, implementation support, and the Stage 1 and Stage 2 audits, plus surveillance audits annually after that. SOC 2 Type II typically runs $15,000–40,000 per report cycle, and the readiness work beforehand often costs more than the audit itself.
The larger cost is neither of these. It is the engineering time to close the gaps — centralised logging, enforced access reviews, tested backups, an incident process people actually follow. That work is real and cannot be shortcut by choosing a cheaper auditor.
The trap worth naming
The most common failure we see is a vendor who holds a certificate and cannot answer a technical question behind it. Procurement teams increasingly ask second-order questions: how do you revoke access when someone leaves, what is your mean time to patch a critical CVE, show us a penetration test with the retest.
A certificate opens the door. Evidence wins the deal. If you have to choose which to build first, build the evidence — the certificate then becomes a formality rather than a performance.
What we tell clients
Do not claim a certification you do not hold, including by implication. "Designed against ISO 27001" and "ISO 27001 certified" are different sentences, and a buyer who catches the elision will assume everything else you said needs checking too.
We design and document against these frameworks, support clients through their own certification, and provide the penetration test evidence procurement teams ask for. See our security posture, our cybersecurity services, or ask us to scope a readiness assessment.
- iso-27001
- soc-2
- gdpr
- dpdp
- compliance
- procurement