Governance, Risk & Compliance

Build trust.
Manage risk.
Stay ready.

Practical support for SOC 2, ISO 27001 and your evolving compliance requirements.

ReadinessImplementationAudit support

Frameworks we support

Clarity across every requirement.

SOC 2 Type 1

Readiness for a point-in-time examination.

Explore

SOC 2 Type 2

Evidence of controls operating over time.

Explore

ISO 27001

ISMS implementation and audit preparation.

Explore

DPDP

Privacy readiness and data governance.

Explore
Additional support PCI DSSGDPRHIPAACERT-In
FrameworkWhy you would need itWho asksTypical
SOC 2 Type 1Proves your controls are properly built. Fastest route to unblocking a stalled contract.US enterprise buyers2–4 months
SOC 2 Type 2The one enterprises actually want. Proves controls have been working for months, not just that they exist.US enterprise, investors6–12 months
ISO 27001A certificate rather than a report. Asked for more often than SOC 2 outside the US.EU, UK, Middle East, Asia6–9 months
DPDP Act 2023Indian law, not a customer request. You do not get to opt out of this one.Regulator2–4 months
PCI DSSCard data touches your systems. Most of the cost is scope — we cut it before you pay for it.Acquirers, card brands3–6 months
CERT-In directionsSix-hour incident reporting and 180-day log retention. Binding in India; most firms have neither.Regulator4–8 weeks
GDPRYou hold data on people in the EU, wherever you are based.EU customers, regulatorVaries
HIPAAYou handle US health information.US healthcare buyersVaries
Security questionnairesYou answer the same 200-question spreadsheet every quarter. A framework costs less than the questionnaires do.Every prospectOngoing

Timelines assume a standing start. If controls are already in place these compress considerably — the readiness assessment tells you which case you are in before you commit to a date.

Our approach

A clear path to audit readiness.

  1. 01

    Assess

    Define scope and identify gaps.

  2. 02

    Implement

    Build controls and practical policies.

  3. 03

    Evidence

    Prepare and organize supporting evidence.

  4. 04

    Support

    Coordinate independent audit requests.

See what happens at each step, and what you receive

In detail

How an engagement runs.

The four steps above, with what actually happens and what you receive at each one.

  1. Scoping

    Which systems, which criteria, which report, what deadline. We push back when the scope is wider than the requirement — unnecessary scope is the most common reason these projects overrun.

    You get: scope statement, framework recommendation, a realistic date.

  2. Readiness assessment

    Every criterion tested against what exists today. Not a questionnaire — we look at the systems.

    You get: a gap register with severity, fix, effort and owner per finding. Useful on its own even if you stop here.

  3. Remediation

    The long part, and the part we are built for: identity and access management, logging and retention, monitoring and alerting, network segmentation, encryption in transit and at rest, backup and tested recovery, change management, vendor risk.

    You get: the controls actually running, plus policies that describe what runs rather than an aspiration.

  4. Evidence engineering

    A Type 2 window needs proof for every instance of every control. Retrofitting that at the end is where projects fail, so we automate collection at the start.

    You get: evidence accumulating on its own, mapped to the criteria it satisfies.

  5. Observation window Type 2 only

    Three to twelve months in which the controls must keep working. We monitor and correct drift; the window itself cannot be compressed.

    You get: monthly control-health reporting, and nothing to discover in month eleven.

  6. Audit support

    The auditor requests, we respond, produce evidence and remediate findings. Your engineers stay on their own work.

    You get: the report — and no month lost to answering an auditor.

  7. Keeping it

    A report expires. Type 2 is an annual rhythm and the controls have to keep running in between, which is usually where our managed security work continues.

    You get: next year's audit as a renewal, not a rebuild.

SOC 2 scope

Scope is what you pay for.

SOC 2 rests on five Trust Services Criteria. Only Security is mandatory. Every criterion added lengthens the audit and raises the fee, so scoping is the biggest lever on cost — and the one most often got wrong.

Required

Security

Protection against unauthorised access. The common criteria every report contains.

Add if

Availability

You have committed to uptime in a contract or SLA.

Add if

Confidentiality

You hold customer information that is commercially sensitive.

Add if

Processing integrity

You process transactions or calculations where being wrong is the risk.

Add if

Privacy

You handle personal information directly. Overlaps with DPDP and GDPR but replaces neither.

SOC 2

Type 1 or Type 2.

The question that decides your deadline and your budget. Type 1 is a photograph of a clean kitchen; Type 2 is the inspector's record of that kitchen over six months. One proves you can be clean, the other proves you are.

Type 1

Proves
Controls are designed properly, on one date
Auditor sees
A snapshot
Window
None
From a standing start
2–4 months
Choose it when
A deal is waiting and you need to move now

Type 2

Proves
Controls were designed properly and operated over a period
Auditor sees
Every instance across the window
Window
3 months minimum; 6–12 expected by enterprises
From a standing start
6–12 months
Choose it when
The customer asked for it by name, or controls already run

Most companies do Type 1 first and Type 2 the following year. The control work is identical, so nothing is wasted. Ask whoever requested it which they need, in writing, before you spend anything.

Strong controls.
Clear accountability.

Security engineering and compliance support, grounded in your actual environment.

NexusSec

Readiness, remediation, evidence preparation and audit support.

Independent assurance

SOC 2 reports from independent CPA firms. ISO certification from accredited certification bodies.

The split

Who does what.

A SOC 2 examination is an attestation engagement under AICPA standards. Only an independent licensed CPA firm may perform it and sign the report — and the firm that builds your controls is never allowed to audit them. Independence is the entire value of the report, so the work splits cleanly.

NexusSecThe CPA firm
Readiness assessment and gap registerPlans and performs the examination
Designs and builds the controlsTests those controls independently
Writes policies that match what runsSamples evidence across the window
Engineers automated evidence collectionForms and signs the opinion
Remediates findings, manages the projectIssues the report your customer reads

No auditor yet? We introduce you to CPA firms we have worked alongside and you choose. We take no commission on that introduction — a financial link between the consultant and the auditor is exactly what undermines the independence the report depends on. The same applies to ISO 27001: the certificate comes from an accredited certification body, never from us.

The difference

Before and after.

BeforeAfter
A deal is stuck behind a compliance requestThe report is in the buyer's hands and the deal moves
Nobody can say who has access to whatAccess is controlled, reviewed and evidenced
Logs are missing, or kept for a weekRetention that satisfies the standard and the law
Policies describe a company you no longer arePolicies match what actually runs
Evidence is screenshots gathered in a panicEvidence collects itself, all year
Every questionnaire costs a week of someone's lifeYou send the report and move on
Nobody knows whether the audit would passYou know, because we tested it first

Why us

Engineering, wearing compliance vocabulary.

Most of a compliance project is not paperwork. It is access control, logging, segmentation, backups, monitoring and change management — work we do every day as an infrastructure and offensive-security team.

The failure mode we kept being called in to fix: a client takes infrastructure we built into a compliance project run by people who have never configured any of it. Policies describing a network nobody looked at. Screenshots proving a setting exists but not that it works. A scramble in the final month. One team that both builds the control and can prove it removes that entire class of problem.

We are not accountants and will not pretend to be. We are the engineers who make the evidence real before someone independent comes to check it.

An honest position on cost

Two things decide it: how far your controls are from the criteria, and how much scope you agreed to. Readiness and remediation is where the time goes; the audit fee is usually the smaller line. Anyone quoting a fixed SOC 2 price before seeing your environment is quoting a template.

We would rather tell you that you are six months away than sell you an audit you will fail. A failed examination is not neutral — you pay for it, and you may have to disclose it.

Questions

Before you commit.

Can NexusSec issue our SOC 2 report?

No, and nor can any other cybersecurity firm. A SOC 2 examination may only be performed and signed by an independent licensed CPA firm. We handle readiness, control engineering, evidence and audit coordination. We will introduce you to CPA firms we have worked alongside and take no commission on that introduction — a financial link between consultant and auditor is exactly what undermines the independence the report depends on.

How long does a Type 2 really take?

Six to twelve months from a standing start: readiness and remediation, then an observation window of at least three months, then the examination. The window is the point of the exercise and cannot be compressed.

We already have ISO 27001. Do we still need SOC 2?

If a customer asked for SOC 2 by name, usually yes — they are different instruments and one is not accepted in place of the other. Most of the underlying control work overlaps, so the second framework costs considerably less than the first.

Do we need a penetration test?

It is not a named line-item requirement, but auditors expect evidence of vulnerability management and independent testing, and most reports include it. Our VAPT work is scoped to produce evidence an auditor accepts rather than a scanner export.

Can you audit the controls you built for us?

No — and that restriction is the point. Independence is what gives the report its value. Any firm offering to do both is offering a report a serious buyer will discount.

Can an Indian CA issue a SOC 2 report?

Not on ICAI registration alone. SOC 2 is an AICPA attestation requiring a US-licensed CPA firm; Indian firms that offer it work through a US-licensed entity or affiliate. Ask any prospective auditor for their licence and their peer-review report — both are normal requests.

Let’s plan your next step.

Tell us your framework, business scope and target date.

Book a consultation