{"id":4783,"date":"2026-08-18T18:00:28","date_gmt":"2026-08-18T12:30:28","guid":{"rendered":"https:\/\/skillarbitra.ge\/blog\/?p=4783"},"modified":"2026-08-18T18:00:30","modified_gmt":"2026-08-18T12:30:30","slug":"soc-2-compliance-indian-service-providers","status":"publish","type":"post","link":"https:\/\/skillarbitra.ge\/blog\/soc-2-compliance-indian-service-providers\/","title":{"rendered":"SOC 2 Compliance For Indian Service Providers"},"content":{"rendered":"\n\n<p>SOC 2 compliance for Indian service providers is an attestation report on your own controls, examined against the <a href=\"https:\/\/www.aicpa-cima.com\/resources\/download\/2017-trust-services-criteria-with-revised-points-of-focus-2022\" target=\"_blank\" rel=\"noopener\">Trust Services Criteria<\/a> published by the American Institute of Certified Public Accountants and signed by a licensed CPA firm. It is not an Indian legal obligation and not a certificate you can put on a wall: your customer in the United States or Europe asks for it, sets the bar, and decides whether your report clears it. Security is the only category you have to include, and the other four are chosen rather than assigned. Two decisions drive almost everything that follows: which categories you scope, and how long your observation window runs.<\/p>\n\n<p>This article sets out how to scope, evidence and buy SOC 2 compliance for Indian service providers, and where the report stops being useful to you.<\/p>\n<p>Most Indian providers meet SOC 2 the same way. A security questionnaire arrives halfway through a procurement cycle, the buyer&#8217;s vendor risk team asks for your latest Type 2 report, and the deal parks at that line until you produce one. If you have never been through it, the instinct is to look for a certification body and get certified.<\/p>\n<p>There isn&#8217;t one. That is the first thing to unlearn, and it changes who you call, what you buy, and what you are allowed to claim in a proposal.<\/p>\n\n<hr>\n\n<nav class=\"ls-toc\" aria-label=\"Table of contents\">\n<h2>Table of Contents<\/h2>\n<ol class=\"ls-toc-list\">\n<li><a href=\"#h2-1\">Scoping SOC 2 compliance for Indian service providers<\/a>\n<ul>\n<li><a href=\"#h3-1a\">Choosing between Type 1 and Type 2<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#h2-2\">Controls and evidence your auditor will test<\/a>\n<ul>\n<li><a href=\"#h3-2a\">Subservice organisations and the carve out method<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#h2-3\">Choosing an auditor for SOC 2 compliance for Indian service providers<\/a>\n<\/li>\n<li><a href=\"#frequently-asked-questions\">Frequently asked questions<\/a>\n<\/li>\n<li><a href=\"#references\">References<\/a>\n<\/li>\n<\/ol>\n<\/nav>\n\n<hr>\n\n<a id=\"h2-1\"><\/a><\/p>\n<h2 id=\"scoping-soc-2-compliance-for-indian-service-providers\">Scoping SOC 2 compliance for Indian service providers<\/h2>\n<p>Scoping SOC 2 compliance for Indian service providers comes down to two decisions you make before any auditor is engaged: which Trust Services categories you include, and where you draw the system boundary. Get both right and the examination stays proportionate to the deal that triggered it. Get them wrong and you will spend a year producing evidence for controls no customer ever asked about.<\/p>\n<p>Start with the categories. The AICPA&#8217;s 2017 Trust Services Criteria, reissued with revised points of focus in 2022, set out five: security, availability, processing integrity, confidentiality and privacy. Only security is mandatory. It is delivered through the common criteria, numbered CC1 to CC9, and the first five of those map onto the COSO internal control framework, which is why your auditor asks about board oversight and risk assessment before anyone mentions a firewall.<\/p>\n<p>Choose the rest from your contracts and your data flows, not from what reads well in a proposal. Add availability if you carry an uptime commitment in a service level agreement. Add processing integrity if you compute something the customer relies on, such as payroll runs, billing calculations or account reconciliations. Add confidentiality if you hold customer data under classification or non-disclosure obligations.<\/p>\n<p>Privacy is the one to think hardest about. It reaches personal information across notice, choice, collection, use, retention and disposal, and it is the heaviest category to evidence over a full year. The mistake we see most often is a first-time provider scoping all five to look thorough, then failing to produce twelve months of clean evidence for four of them. Two categories done properly beat five done thinly, and no buyer has ever rejected a scope that matched the contract.<\/p>\n<p>Different customers will ask for different things, and that is the pressure that pushes scope outward. One buyer wants availability, another wants privacy, a third sends a questionnaire that mentions neither. Set the scope against the contracts you have signed and the ones sitting in your pipeline now, not against every request you might one day field. You can add a category at the next annual examination, and adding one later costs far less than carrying an unevidenced category through a full observation window.<\/p>\n<p>The system boundary is the second decision, and it is where Indian providers routinely under-specify. Name the service, the production environment, the cloud region, the delivery centre and the teams inside it. Everything you do not name sits outside, and that is the point: your corporate laptop fleet, your marketing website and your second product stay out of scope unless they touch the system.<\/p>\n<p>Here&#8217;s what that actually looks like. Adapt the paragraph below, put it in front of a prospective auditor, and your first call gets a great deal shorter.<\/p>\n<blockquote>\n<p>[Company] provides a cloud based accounts payable processing service to customers in the United States and the European Union. This examination covers the production environment of that service, hosted on Amazon Web Services in the [region] region, together with the supporting delivery operations at the [city] office in India. The examination covers the security and confidentiality categories. Amazon Web Services is treated as a subservice organisation under the carve out method. Corporate IT, the marketing website and [second product] are outside the scope of this examination.<\/p>\n<\/blockquote>\n<p>One thing scoping does not do is settle your Indian obligations. The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025, require reasonable security safeguards under Rule 6 whether or not a customer ever asks you for anything. Your SOC 2 security evidence will carry a good deal of that weight, but the report does not discharge the statute, and the two answer to different audiences (one is a buyer, the other is a regulator). If personal data of Indian users sits inside your system, work through the <a href=\"https:\/\/skillarbitra.ge\/blog\/dpdp-act-compliance-checklist\/\" target=\"_blank\" rel=\"noopener\">DPDP Act compliance checklist<\/a> in parallel rather than afterwards.<\/p>\n<a id=\"h3-1a\"><\/a>\n<h3 id=\"choosing-between-type-1-and-type-2\">Choosing between Type 1 and Type 2<\/h3>\n<p>A Type 1 report says your controls were suitably designed and implemented on a single date. A Type 2 report says they operated effectively across a period, which is what a vendor risk team actually wants to see. Nearly every buyer request you receive will either say Type 2 outright or say SOC 2 and mean Type 2.<\/p>\n<p>So when is a Type 1 worth buying? Only when a live deal is blocked and you cannot wait a quarter for the shortest credible observation window. Treat it as a bridge, start the Type 2 period the day after the Type 1 date, and tell the customer exactly that. If nothing is blocked, skip the Type 1 and put the money into readiness instead.<\/p>\n<p>Write your scope statement before you approach a single audit firm. The firms that quote fastest, and cheapest, are the ones you hand a boundary to rather than ask to discover one.<\/p>\n<a id=\"h2-2\"><\/a>\n<h2 id=\"controls-and-evidence-your-auditor-will-test\">Controls and evidence your auditor will test<\/h2>\n<p>The controls your auditor tests are the ones you wrote down, and the evidence is whatever proves they actually ran. That distinction is the entire difference between the two report types. A policy document describing a quarterly access review is design evidence. Four dated, signed access reviews sitting inside your observation window are operating evidence.<\/p>\n<p>In a Type 2, your auditor samples from that window. For a control that fires on every change, they will pull a set of changes and check each one carries the approval your policy claims it does. For a control that fires quarterly, they need at least one completed cycle inside the window before they can test anything at all.<\/p>\n<p>That is the real reason three months is the practical floor. The AICPA does not fix a minimum period, so in principle you could ask for something shorter, but a window that contains no full cycle of your periodic controls leaves the auditor with nothing to sample and leaves you with exceptions you cannot explain away. Six and twelve month windows read as more mature to enterprise buyers, and twelve becomes the norm once you settle into an annual cycle.<\/p>\n<p>Based on what we&#8217;ve seen, the gaps that bite Indian providers are rarely technical. Contractor onboarding and offboarding runs outside the HR system, so no ticket trail exists. Personal devices sit inside the delivery centre with no enrolment record. Production credentials get shared across a team because a single break-fix rota needed them at 2am, and the vendor inventory stops at the three tools finance happens to pay for.<\/p>\n<p>Security awareness training is the quiet one. Almost every provider runs it, and far fewer can produce a completion record per employee covering the whole window.<\/p>\n<p>Build an evidence index before your auditor sends a request list. It is a table, it takes an afternoon, and it turns a vague obligation into named owners with dates against them.<\/p>\n<table>\n<thead>\n<tr>\n<th>Control<\/th>\n<th>Evidence artefact<\/th>\n<th>Cadence<\/th>\n<th>Owner<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Logical access review, production systems<\/td>\n<td>Exported user list plus dated review sign-off<\/td>\n<td>Quarterly<\/td>\n<td>Head of engineering<\/td>\n<\/tr>\n<tr>\n<td>Joiner and leaver access changes<\/td>\n<td>HR record linked to the deprovisioning ticket<\/td>\n<td>Per event<\/td>\n<td>People operations<\/td>\n<\/tr>\n<tr>\n<td>Change approval before deployment<\/td>\n<td>Pull request showing reviewer approval before merge<\/td>\n<td>Per change<\/td>\n<td>Engineering lead<\/td>\n<\/tr>\n<tr>\n<td>Risk assessment<\/td>\n<td>Dated risk register with treatment decisions recorded<\/td>\n<td>Annual<\/td>\n<td>Security lead<\/td>\n<\/tr>\n<tr>\n<td>Backup restoration test<\/td>\n<td>Restore log showing a pass or fail result<\/td>\n<td>Half yearly<\/td>\n<td>Infrastructure lead<\/td>\n<\/tr>\n<tr>\n<td>Subservice organisation review<\/td>\n<td>Provider&#8217;s current SOC 2 report on file plus a dated review note<\/td>\n<td>Annual<\/td>\n<td>Security lead<\/td>\n<\/tr>\n<tr>\n<td>Security awareness training<\/td>\n<td>Per-employee completion record for the full period<\/td>\n<td>Annual<\/td>\n<td>People operations<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Keep every artefact where the index says it is. Fair warning: an auditor who asks for the second-quarter access review and receives a chat thread instead of a dated export will record that, and enough of those turn into a qualified opinion.<\/p>\n<p>Understand exceptions before you meet one. When the auditor tests a control and finds instances where it did not operate as described, that becomes an exception recorded in the testing results, and enough of them, or one serious enough, produces a qualified opinion rather than an unqualified one. A qualified SOC 2 report is neither a failure nor unusable. Buyers read the exception, read your management response, and form a view of both.<\/p>\n<p>So write the management response properly. State what happened, which part of the period it affected, what you changed and when the fix took effect. The practical reality is that a clean report resting on a thin system description convinces an experienced reviewer less than a qualified one showing an organisation that catches and closes its own problems.<\/p>\n<a id=\"h3-2a\"><\/a>\n<h3 id=\"subservice-organisations-and-the-carve-out-method\">Subservice organisations and the carve out method<\/h3>\n<p>Your cloud provider is a subservice organisation, and you have two ways to treat it. The carve out method describes what the provider does but excludes its controls from your examination, so your auditor tests only your side of the line. The inclusive method pulls the provider&#8217;s controls into your system description and into testing, which in practice needs that provider&#8217;s active cooperation.<\/p>\n<p>Carve out is what nearly everyone uses for the large cloud platforms, and no buyer will object to it. What you cannot do is read carve out as forget about it. You are expected to monitor the subservice organisation, which means collecting its own SOC 2 report each year, reading the exceptions in it, and keeping the review on file with a date attached.<\/p>\n<p>The other half of that arrangement is complementary user entity controls: the controls a report tells its readers they must operate themselves for the described controls to work. Your cloud provider&#8217;s report carries a list of these aimed squarely at you. Read it, map each item to something you genuinely do, then write your own list for your customers before your auditor writes it for you.<\/p>\n<p>Do the index and do the subservice review, and the request list stops being a scramble. Worth flagging that US financial clients may require offshore service providers to meet Safeguards Rule-related security requirements <a href=\"https:\/\/skillarbitra.ge\/blog\/ftc-safeguards-rule-wisp-offshore\/\" target=\"_blank\" rel=\"noopener\">FTC Safeguards Rule<\/a>, which draws on the same evidence but is not satisfied by a SOC 2 report.<\/p>\n<p>\n\n<figure class=\"ls-infographic-wrap\" style=\"margin:2rem 0;\">\n<div class=\"sa-ig-soc2-trail\" style=\"margin:2rem 0;max-width:800px;\">\n<style>\n.sa-ig-soc2-trail, .sa-ig-soc2-trail *, .sa-ig-soc2-trail *::before, .sa-ig-soc2-trail *::after { margin: 0; padding: 0; box-sizing: border-box; }\n.sa-ig-soc2-trail {\n  font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Arial, sans-serif;\n  color: #212121;\n}\n.sa-ig-soc2-trail .infographic {\n  max-width: 800px;\n  margin: 0 auto;\n  border: 1px solid #e0e0e0;\n  border-radius: 10px;\n  overflow: hidden;\n  background: #ffffff;\n}\n.sa-ig-soc2-trail .title-bar {\n  background: #2941ba;\n  color: #ffffff;\n  padding: 22px 24px 20px;\n  text-align: center;\n}\n.sa-ig-soc2-trail .ig-title {\n  font-size: 21px;\n  font-weight: 700;\n  line-height: 1.3;\n  letter-spacing: 0.1px;\n}\n.sa-ig-soc2-trail .stamp {\n  display: inline-block;\n  margin-top: 12px;\n  padding: 5px 14px;\n  border-radius: 999px;\n  background: #feae2d;\n  color: #21306f;\n  font-size: 13px;\n  font-weight: 700;\n  letter-spacing: 0.3px;\n}\n.sa-ig-soc2-trail .content { padding: 24px 24px 18px; }\n.sa-ig-soc2-trail .lead {\n  font-size: 13px;\n  color: #5a6472;\n  font-weight: 700;\n  text-transform: uppercase;\n  letter-spacing: 0.7px;\n  margin-bottom: 12px;\n}\n.sa-ig-soc2-trail .rail {\n  display: grid;\n  grid-template-columns: repeat(5, 1fr);\n  gap: 8px;\n  margin-bottom: 26px;\n}\n.sa-ig-soc2-trail .crit {\n  border: 1px solid #dfe3ea;\n  border-top: 4px solid #1b7f4d;\n  border-radius: 8px;\n  padding: 11px 10px 12px;\n  background: #f7f9fc;\n}\n.sa-ig-soc2-trail .crit.must {\n  border-top-color: #b3261e;\n  background: #fdf4f3;\n  border-color: #f0cfcc;\n}\n.sa-ig-soc2-trail .crit-name {\n  font-size: 13.5px;\n  font-weight: 700;\n  line-height: 1.25;\n  color: #21306f;\n  margin-bottom: 6px;\n}\n.sa-ig-soc2-trail .crit-tag {\n  display: inline-block;\n  font-size: 10px;\n  font-weight: 800;\n  letter-spacing: 0.6px;\n  text-transform: uppercase;\n  padding: 3px 7px;\n  border-radius: 4px;\n  background: #e3efe8;\n  color: #1b7f4d;\n  margin-bottom: 7px;\n}\n.sa-ig-soc2-trail .crit.must .crit-tag { background: #f6dedb; color: #b3261e; }\n.sa-ig-soc2-trail .crit-note {\n  font-size: 11.5px;\n  line-height: 1.4;\n  color: #5a6472;\n}\n.sa-ig-soc2-trail .stage {\n  display: flex;\n  gap: 14px;\n  align-items: flex-start;\n  padding: 13px 14px;\n  border: 1px solid #dfe3ea;\n  border-radius: 8px;\n  margin-bottom: 9px;\n  background: #ffffff;\n}\n.sa-ig-soc2-trail .stage.key {\n  border-color: #feae2d;\n  background: #fffaf0;\n}\n.sa-ig-soc2-trail .num {\n  flex: 0 0 30px;\n  height: 30px;\n  border-radius: 50%;\n  background: #2941ba;\n  color: #ffffff;\n  font-size: 14px;\n  font-weight: 800;\n  display: flex;\n  align-items: center;\n  justify-content: center;\n}\n.sa-ig-soc2-trail .stage.key .num { background: #feae2d; color: #21306f; }\n.sa-ig-soc2-trail .stage-body { flex: 1 1 auto; }\n.sa-ig-soc2-trail .stage-name {\n  font-size: 14.5px;\n  font-weight: 700;\n  color: #21306f;\n  margin-bottom: 3px;\n}\n.sa-ig-soc2-trail .stage-does {\n  font-size: 12.5px;\n  line-height: 1.5;\n  color: #3f4855;\n}\n.sa-ig-soc2-trail .facts {\n  margin-top: 22px;\n  border-top: 1px solid #e6e9ef;\n  padding-top: 16px;\n}\n.sa-ig-soc2-trail .facts-h {\n  font-size: 12px;\n  font-weight: 700;\n  text-transform: uppercase;\n  letter-spacing: 0.7px;\n  color: #5a6472;\n  margin-bottom: 11px;\n}\n.sa-ig-soc2-trail .fact-grid {\n  display: grid;\n  grid-template-columns: repeat(4, 1fr);\n  gap: 9px;\n}\n.sa-ig-soc2-trail .fact {\n  border-radius: 7px;\n  background: #f5f5f5;\n  padding: 10px 11px;\n}\n.sa-ig-soc2-trail .f-label {\n  font-size: 10.5px;\n  font-weight: 800;\n  text-transform: uppercase;\n  letter-spacing: 0.5px;\n  color: #2941ba;\n  margin-bottom: 5px;\n}\n.sa-ig-soc2-trail .f-value {\n  font-size: 11.5px;\n  line-height: 1.45;\n  color: #3f4855;\n}\n.sa-ig-soc2-trail .notes {\n  margin-top: 16px;\n  font-size: 11px;\n  line-height: 1.5;\n  color: #6b7480;\n}\n.sa-ig-soc2-trail .branding {\n  border-top: 1px solid #e6e9ef;\n  padding: 12px 24px;\n  display: flex;\n  align-items: center;\n  justify-content: space-between;\n  gap: 14px;\n  background: #fbfcfe;\n}\n.sa-ig-soc2-trail .stamp-foot {\n  font-size: 11.5px;\n  font-weight: 600;\n  color: #5a6472;\n}\n.sa-ig-soc2-trail .branding img {\n  height: 30px;\n  width: auto;\n  display: block;\n}\n@media (max-width: 640px) {\n  .sa-ig-soc2-trail .rail { grid-template-columns: repeat(2, 1fr); }\n  .sa-ig-soc2-trail .fact-grid { grid-template-columns: repeat(2, 1fr); }\n}\n<\/style>\n\n  <div class=\"infographic\">\n    <div class=\"title-bar\">\n      <div class=\"ig-title\">SOC 2 evidence trail, scope to signed report<\/div>\n      <div class=\"stamp\">Position as of 18 August 2026<\/div>\n    <\/div>\n\n    <div class=\"content\">\n\n      <div class=\"lead\">Trust Services categories: pick from five, one is not optional<\/div>\n      <div class=\"rail\">\n        <div class=\"crit must\">\n          <div class=\"crit-tag\">Mandatory<\/div>\n          <div class=\"crit-name\">Security<\/div>\n          <div class=\"crit-note\">Common criteria CC1 to CC9<\/div>\n        <\/div>\n        <div class=\"crit\">\n          <div class=\"crit-tag\">Optional<\/div>\n          <div class=\"crit-name\">Availability<\/div>\n          <div class=\"crit-note\">Add if you carry an uptime SLA<\/div>\n        <\/div>\n        <div class=\"crit\">\n          <div class=\"crit-tag\">Optional<\/div>\n          <div class=\"crit-name\">Processing integrity<\/div>\n          <div class=\"crit-note\">Add if you compute client figures<\/div>\n        <\/div>\n        <div class=\"crit\">\n          <div class=\"crit-tag\">Optional<\/div>\n          <div class=\"crit-name\">Confidentiality<\/div>\n          <div class=\"crit-note\">Add if data carries classification duties<\/div>\n        <\/div>\n        <div class=\"crit\">\n          <div class=\"crit-tag\">Optional<\/div>\n          <div class=\"crit-name\">Privacy<\/div>\n          <div class=\"crit-note\">Heaviest category to evidence<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"lead\">From scope to signed report<\/div>\n\n      <div class=\"stage\">\n        <div class=\"num\">1<\/div>\n        <div class=\"stage-body\">\n          <div class=\"stage-name\">Scope<\/div>\n          <div class=\"stage-does\">Pick your categories, draw the system boundary, name the delivery centre and the subservice organisations.<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"stage\">\n        <div class=\"num\">2<\/div>\n        <div class=\"stage-body\">\n          <div class=\"stage-name\">Design the controls<\/div>\n          <div class=\"stage-does\">Write down what each control is, who owns it, and how often it fires. This alone is what a Type 1 examines.<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"stage\">\n        <div class=\"num\">3<\/div>\n        <div class=\"stage-body\">\n          <div class=\"stage-name\">Run the cadence<\/div>\n          <div class=\"stage-does\">Quarterly access reviews, approval on every change, annual risk assessment. Keep dated artefacts, not intentions.<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"stage key\">\n        <div class=\"num\">4<\/div>\n        <div class=\"stage-body\">\n          <div class=\"stage-name\">Observation window<\/div>\n          <div class=\"stage-does\">Three to twelve months. No AICPA minimum, but it must contain one full cycle of every periodic control or the auditor has nothing to sample.<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"stage\">\n        <div class=\"num\">5<\/div>\n        <div class=\"stage-body\">\n          <div class=\"stage-name\">Examination and report<\/div>\n          <div class=\"stage-does\">A licensed CPA firm samples the window, tests the controls, records any exceptions and issues the opinion.<\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"facts\">\n        <div class=\"facts-h\">Four things buyers assume you already know<\/div>\n        <div class=\"fact-grid\">\n          <div class=\"fact\">\n            <div class=\"f-label\">Who signs<\/div>\n            <div class=\"f-value\">A licensed CPA firm only. The signer must be a CPA.<\/div>\n          <\/div>\n          <div class=\"fact\">\n            <div class=\"f-label\">What you get<\/div>\n            <div class=\"f-value\">An attestation report. There is no certificate.<\/div>\n          <\/div>\n          <div class=\"fact\">\n            <div class=\"f-label\">Type 1 or Type 2<\/div>\n            <div class=\"f-value\">Design on one date, versus operating effectiveness across a period.<\/div>\n          <\/div>\n          <div class=\"fact\">\n            <div class=\"f-label\">Distribution<\/div>\n            <div class=\"f-value\">Restricted use under NDA. SOC 3 is the public version.<\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n\n      <div class=\"notes\">\n        <p>Source: AICPA 2017 Trust Services Criteria (with revised points of focus, 2022) and the 2018 SOC 2 Description Criteria (with revised implementation guidance, 2022).<\/p>\n      <\/div>\n    <\/div>\n\n    <div class=\"branding\">\n      <div class=\"stamp-foot\">SOC 2 compliance for Indian service providers<\/div>\n      <img decoding=\"async\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAY4AAABeCAYAAAA0TfPnAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAFiUAABYlAUlSJPAAADYQSURBVHhe7Z13YBzF1cB\/s3t36r1astzkjjs2NmB6TSiGkAQI3UBCiXEAE3oJpiT0UAIJKRACBAidJPQawOAq28jdli1btiVZ\/SSd7m7n+2P3ZOlu93Qny0bwzQ8W49s2O+3NvPfmjRhzxLsShUKhUChiRAv\/QaFQKBSKaCjBoVAoFIq4UIJDoVAoFHGhBIdCoVAo4kIJDoVCoVDEhRIcCoVCoYgLJTgUCoVCERdKcCgUCoUiLpTgUCgUCkVcKMGhUCgUirhQgkOhUCgUcaEEh0KhUCjiQgkOhUKhUMSFEhwKhUKhiAslOBQKhUIRF0pwKBQKhSIulOBQKBQKRVwowaFQKBSKuFCCQ6FQKBRxoQSHQqFQKOJCCQ6FQqFQxIUSHAqFQqGICyU4FAqFQhEXSnAoFAqFIi72ueAQoX9E+Jn\/3+iawOPWSEzQSPBo6Fr\/ziNdE7hdvUuvru\/+Vo9bQxOx3\/t9JiJPdZUviv6JGHPEuzL8x75EIBA6pCQlkJGeTHpaEm63C58\/QF1dCw2NXvwdQSR7NRn9FiEgKVHn4Kk5nDlrIBPGZFLf2MEnC2r5yz8r2FHTjtxLWaPrgrQUF5npbgC8bUHq6jswpHR8pxCQ4NGZOiGTc388mP1GplFb5+OrpfU8\/\/pWtmxrJWjY3ywEZGV4OPqQfE4\/sZiBA5LZVOnljfe28+Z722lpDTi+9\/tOYoLOjClZ\/OyUEsaOSKfdF+SdT6p55pUtVNf4MPZyxghhttWkJJ2cLA+6JvB1BKne5SMYdK4Piv+f7FXBIRDoumDC+MGMG1NMSlIiQjOHUBJJwB+kobGVDz8tp66+ud9WzlCjEgIQ5t+xvk9KCdbfpQQkUTverggBmhDMPn0wl59fise9ewIYDErWV7Qwe95i6hv93e7bU4QwhcaRB+VxxezhnYKjrT3Iq29v468vbMHXEbT9Bl0TnHVqCb+6cDiJiXrn71LClm2tXHbjMjZVervdg\/VOl65xz43jOPqQfHSrHgD4\/QZfLN7F1fNX0NoW7HZfbwnlrfmX+MplX6MJwTmnDeKK2aUkdclTw5BsqWrjvCsXUbPL1+2evkbXBBP3y+CmOaPJzfagaQJ\/QLKwrI7fPraWhkb\/Xhdeiu8Oe1VwJCS4OXzmaIYNKYwy5Zb4OgJ8vWgDK1dV9suGrWuCUaVpTB6XwchhaZQMSCI320OCRwMEdQ0+mloCVNf6WL2hmfUVXpZ904Cvwwh\/VDc0IcjN9vD6X2aQke4JP43fb\/C3Fzfz0F\/Wh5\/aI3RdcOk5w\/jF2UO7deAAHR1BXnxrG\/f\/aV1E+jUhcLsF\/3zsAEYOS4so02BQ8vS\/NvPAn9ZHdDK6Lpg6PovH75rUTeCEaGsPcsUtZXy+aFf4qbgRAoaWpHDglGzychNwuzS2V7fx5eI6Nm7x9qs6JgQkJ7l47c\/TKSpIjsjTDr\/BXY+s4aV\/b91r6dY1weEH5nLnr\/cjLdXdLQ1SwvJVjfzqN8uprt17s1\/Fdws9b+g5t4X\/2Be4XDoHTx\/BiOEDdo\/8bBHoukZhfgbbdzTS4m0Pv+BbQVgqpGkTs7hp7mjmzh7OIQfkMmZEGgMLk8jOTCA9zU16mpv83AQGFSUzengaM6flcuJRhZx4zACamgNs3tZGIGjf2jRNcNTMPI4\/vBAtrAMP4W0N8N+PdvaZIk\/XBKkpOvfeNJ5Ejx7RUWmaxqjSNCq2trJuU0vYOUFudgJzLxpum14hBDlZbv75xlaMMJmp64LZpw9hwpgMRPhLLaG0bWc7i8oaev2tQoDHrXHJ2UO558bxHDo9lynjM5k4NoOZU3M58egBbKjwsmVbW6\/f0ddoQjBhTAZnnTIIXY\/MFwS0tgb48POavdZpJ3h07rhmLCVFkYJLCMjLSaDDH2RhWcNeS4Piu8VeM44XFmQwskehYSIQuN1uDp05hqSkyJH3vkbXBSVFyTxwy3geu2MyB+2fg9ttGit1TaBZhuDQoVm\/6ZqpmnO7NQYWJnHbVWN56Lbx5GYnhL\/CRGCec8oiAakpLkQflpLQ4IxZJaQmuyI6CayOwqWbI9CIshMwpCTZObkCsjMSSPBEzigE5uzKEQH5OQm2aYoVXRdccs5QLjxjKG7X7vIKlUtaiov514zl4Gk5e\/SevkQIyMlyzhcBZr7tpfQKAYOKkxgxJNUxT3TNnC267ASb4v8lfdgldad0SAG6K\/bHCyFIT00iJ9u5Au8LXC7BfiPTeeqB\/Tl0eh6JCZrt6LonNE2QmKBx4JQcbp472n40CWhRskhYnWFfIhAUFyTZjvpDCAFpKe5eCSxdFyQnRQqOWLBTYcWKrgnGDE\/jrFMHkeDRbOuQpgky0t3MvbDUUXD2RzzuyJlhX5Kfm4Crh7aamtJzfgnLduZ2abhcInLgofjeEL227AElA7MRMvaKIwRoumBAQSbEcV9foglBUUES9988jsK8xB4bSiy4XBozp+UwcWxG+KmY6OtRnkSysdJrGvUdkBKamv3I6CaaPkUAKUlar0fWLpfgzCgzqRC6JhgxJJUTj45tNvxtI4QgOWmvNVMANm1pjbBJhVPX4I9QP4YQwszXgrxE5v1iBH97YAqP3D6BQ6bn4HIpl+LvI3utRqamJMXdCQgEqSmJ4T\/vM7Iy3dx30ziKCpLCT\/Wa0Chs4pjeCQ6PjR1iTzCC8Mp\/q6ip8znqq\/0Bg3++WdljZ9Jf0IRgv1HpHDUzL6a80nXBBT8dTIblTfb\/GSlhV30HK1Y3hp\/qxDAk\/1tY6+hmrQnBMYfm89LjB3DuaYOZMi6Lw2bk88jtE7ll7mhc+l7rZhTfEnutRHuj3gEQ0XQ3exFNCA6dnsuIoWlR1ThYDamtPUhjs59mr9+xQYWQEtZVdDc0f1sYUuL1BvjD0xupb+yIEB7e1gB\/em4Ty8ubup\/ox7jdgp+eUExqcmyCQAjBgIJEjp7Z3S34\/ysdHQYP\/nk926vbMcLqst9v8Nb72\/nHK5UR57AGRvm5CVzzixFkZXi6CW5d1zjluGJmHpDznZjdKWLn2+ml+xkhN9OzTx3YbS1FV6Q03U03bG7h5vvKOe\/KRZx9xULOmbuIX960jJf+vY329mBE4woakopKL4uXN3T7\/dvEkJJX36li9rzFPPvqFlata2LLtlbe+WQnl96wlKdf2tyjMOwvCMvB4KCpsRu8hbXG46iZeX1uQ\/ouYkhJ2TeNnDN3IQ88uZ7FK+rZsq2VLxbt4pb7y7nj4TUEgkbEIANLSzBmRBp5OYkRA67QbHvG5Oxe2csU\/RdVnFYFHzIwmZHD0h07H8OQVG5v49IblvH6O9tZuaaJDZu9rN3Ywmdf7eLOh1cze95i3nhvO9ur2\/H7Ddp9Bms2NPPgn9fR7uubhW19gZQQCEjWbWrhnifWcuYvFzLrwi+55s4VLF7RQLvPQZndD9E0wQlHFpKV6eyZZIcQsP\/4TPYbma5Gw9YAp2pnO0+\/tJnZVy9h1oVfcukNy3jzvR1RV\/QLAemppiOFXTYKAVkZbpXH3zO+c4JDCIGw3F9Nt1gz9tUeIaB0SGpUm0wgKLn\/T+vYur0tQvdvSEmH36BsVSO33F\/OSRd8wblXLuLMy7\/iZ79cyGdf73JseH1JaCQdaxsNzaICAYnfL79zoSXMTsnDJWcP7VXHlJigc+OckXg8vW8GseR56JqerouHrs\/UNfPPvnh+0JAEggZ+v\/lneF3vFXEmKpb8Cl0T+nan68Lpel\/ITbur23Zv6lFPhL8zlN6eXhVL3YqVbmmw+eZ439H7FrOvESA0QVFhJgcfMIJjj5zAsUdO4PCZYxg+vIDEhNj02070lG9SQnNL9NAfoZF8a1uQsvJG1mxsocNvP8XvS0KVIivDw9SJmUwel0liQs9GdSHMznPqxEwOnZFLUUHSXmk4ewuB4Mc\/LMbttne\/BczOz0HtpmmC4gHJDB+SEn4qJjQhyM9JYNqkLMaOSCc9rfuq69A1pYNT+cGRBfzwqII9nuGEyjoz3c2U8Zn88KgCTjy6kBOPLuCAyZmdK79784rQs8cMT+eQ6TkMGZjimNbOd8T4rtD1XQ87hIDsTA\/Tp2QxZXwmedkJEWnQhGBQcTJHHpzLiUcXMm1SVsQ14YS+LSfLLK9TjhvAuT8exOXnDuPyc4dxzmklzDpuAONGp3e2nR4e2SPC8jYbkJ\/IIdNzrHIq5KhD8hhVmtbpNh7+HmEtZJ20n9kuS4qSe\/w+J7p+9\/QpWZx1aknnN5\/\/00GcdkIx06dkkZZqzgpjfc1eCzly2UXHhP\/UI4YhWbthBx998k23oIcCQWZmMjMPGsXAwmxkl8yW0oxD1Nzk5fOF69lcWYt06Cic0HXB8YcV8NsbxjkaSzv8Bn\/4+0b+9Oym8FO9RtfNOFVXzB5u+17DkKyr8PKTSxYQCNh\/k7AWzs0+YzBnnFSCpgmkhPUVzdx83yrK1zVFCC4hwO3SOOKgXK68eATFlheZYUj+8kIFTz5XQVt7pGpN1wUHTMriyd9NcXR+aG0L8oNzP4+IreR2aTxw63iOODDP9l7DkHyyoIYrbl1O0GGlfVeEFfvqmd9PZfzoDNsKHwhIXn17G4dMz6Ug1969OhiU\/P1lM0xKPHadxASNn50yiEvOGUpSgrn+pNnr58En1\/Pm+zvwdQRJ8Ohceu4wzvvxoM7ylRJe\/u9W7npkLf6Aga4Jjj4kn3tvHI\/LFZlAKWHNhiZOv2whEsn4URmc\/aMSjjgwD3fIHifMNgDg6wjy2jtVvPX+Dlasbor5m3RNMG50OndfO5aBA1IQwiyTN97fzu\/\/soFd9bu98HRNMHZkOiceVUBJUTKF+YmMsglBE6J6l4\/V65sxDImUksbmAK+9U8WSlQ3d6rXLJTh4ag63XjmGPGvRbGt7kOdfr+SvL2ymqdmPyyWYdWwR118+ygz5Y337e5\/t5Jb7VtHSGujyZrOeZKSZQvZns0qYNjHLrH8OaUVCfWMHf31xM+98vLNXQUaFtXB36vgsLjtvKKWD03C7urzTep63NcCr71Tx7ifVlJU3YkiJrgsmjM7gtqvGMLQkGSEE7b4gL\/+3isf\/vpHG5uiD164kJersNzKdU44v4rhD80lM0O2\/W5r5\/No723jxzW1UVDoHKg2x10KOTJtSGv5Tj0gJu+pbqNhc0\/mb0AR5uWmccOxkcrNTEZrWqZ4yAw+ahyfBzeCSPDQNduxsjKuwNU0wsCiZ4w8vcJbsAkYMSeXTr2tpbAr0ScgKTRNMHpfJ9MnZtu+V0vSff+mtyBAeWBU0LzuBB2+bwNGHFOBymYsVNc2cfUwcm85r72yP6Ih1TXDkzHzuvnYcOZkJnfdommDcqHSqdrazdkNLxDdqmqC4MImTjxkQYQgN4Q9Inn21MiJYoa4Jjju8gKElKbb3Sgmbt7by3493xlR2ui44dEYuZ59qH6pDSqip8zHvjhUkuDUmj8+0zWMhBKWDU\/jwi5qYg0kKASccWch1l48iMUHvzLsEj86MKdmsq2hhR42P264aw49+UITHvfsaTRMMH5zK6g3NbNnahhAwbHAKxx5aYCtQAeoaOvj3hzu4cc5IrrhgOGNGpOPuUtaa2P1sl0tjv1HpHHNIARNGp\/PF4jo6\/DaVpwuaEIwdmcaj8ycxID8JXd\/9vJFD0xgyMJn3PqvBMCSaEAwdlMwffzuZAyZlM2RgMrnZ0Vf8Jye5GFSUxOCByQwZmMLI0jSOOaSA2roO1m5s6SzvcaMyeOi2CWRnejrT4HFrpiu7hEXL67n0nCHMOX84iQlmZIDQtw8qTqalNcjyVbvbvtul8aMfFHHrlaP56YklDC5ORtetfLNUYRGHJkhKdDF9UhbHHFrAlm2tbK1q6\/Y90dCEYNigFB69YxKnnzSQwrzE3e2yyzs0TeDx6Iwfk8Exh+YzqCiJRcsbGFSczMO3T6CkaHda3S6NcSPT8bYGKCvvuW\/ThKAgP5H7bhrPBacPYfzo9N11MPx7rfR43BrjRmfwgyMKGT4khYVlDfj9zjHL+7WqShOCBLeLQw8aTUpKIiKKa4YmBB63i\/FjBzGgMCtqRY5AwqZKb9SZiq4JsrM8\/P7WCcw+YzDjRplTWi2uF\/UdmqWuuGJ2KRPGZETMWHRdMHRQKscfXtAtL4QwBcDJRw+IWGEtBCR4NC46cwgez7fzXbEgBKSluLjq4uG2QgNrBvPxl7U0Nvv520tbaPHaG3iFFZPsxKMKYyrLUP6dcFQhrrD9MoQAj0fj+MMKOOKgPI6ZmW+76tvj0Thz1sCYPY2Sk3Suu3wkJx9TRFqqGz3K3ifCUo9kprs54qB8nrh7MqNK06J+m9Dg+MMLyMkyo+J2\/m55RR06PZdxo9IRgKbDGSeXmKHXrc49yqOhS56FDl0TpCa7uPKi0k77kiYExxyST1qK2yENOYwalsYZJw+yjebgdmnMPn0wCQnm83RdcPn5w7j+l6MZPsRUC8WSVqx3ut0aRQWJ3HXtOA47MDfifXbomuDIg3N58p4pjCpNIynR7Kyd3hkqq\/RUN6ccV8zcC0vZf3wWuVnmYK7rdZoGxx1uDi6iPk8XzDpuAP98dBrTJ2eTluKKWl9ChNKSnenhxKMHcP\/N4ykuTHSsNzFW3W8HoQlGjyomP89eFRGOEJCY6OawA0ehxdoqLeP21qo2ytdFD+2ua4LSIanMvXA4f39oGi\/84QBO+2ER2ZlmpFwtDh3hnqAJgcejcd3lo5h1XFGE0AihCSgu7L6YUSDQNNOLzG7kr2mCwrxEhg9JDT\/Vb9CEYPTwNAYOSHZs0K3tQd76wJxteVsDfPRFjaOhV9cFxxxSQHpa9FXnITQhKBlgH7YllLZ5PzfDzttcghCC\/Jzuax6cEAIGDkjm5GOKcLmcbTl26Lqpfrr3xnFkZ3kcOwFdEwwuts9LIcyIDiOHpXaeL8hziL0WB0JAUuLuvWCEBiOH2Ycb0jRz3c2cC0rJyugu3EKYz9M73enHjkjj3NMGRwyO4kGzBPDtV49lUA92Bk0IigoSue2qseTnJDi2STuEMNV0p59cwg1zRtmGf9E0wZCByei62Ybt0HXBOT8aZKr6chLjSkNXdE1w4JRsfnP1GFJT7dtEZAr7EbquMXHcoPCfoyIQpKQmUVSYGX7KEWkZtZ\/+12b8gejTeqyMTUzQGDE0lduuGsubfzuIB2+dwBmzis2KbZfTfYQQkJJsegP98MjCqJXDkNiuHxECe12nhcAKvthPcbkEJx5VGHXNzaYtXlPdJkMrn3dhONhONE1QUpTEUTPzeyy7kOB1it0krJDu+bnOERAMKVmyojHmkC7CxoAaK7omGDIwhTnnD0NzCAUmBCRFiS8mMGeiWHn7zdomRxVGrBiGZNk3Deyq7wArDXbBMUNkpns4bEauYz5ICRWVXlpaAwgBRx6UFzEj7IqU3Q8nhOW5N+u4AY6zWyEgJ9vDo3dMIjO9+4wpHnRrNuaU5gSPTka6\/YBDCNh\/fBY\/P2soHgdnkdC3Gobsdth9v6YJ9h+fxdmnDrRtE\/Ytrx8gEKSmJpKUGJ9\/PtZH5+elh\/8cFUNKvlxcx7JvetYhdkUIyEx3c+j0XK7\/5Wje+OuBXHnxcIoLk2wLb09JStT55fnDOPX44qhCI2hIlq9qYMnKXoTCFsI05vVDNCEYVZrKyccUhZ\/qxDAkb7xX1WlnkRI+WWCqrZzyQtcFl54zZI8CLcbKuk0t\/PG5CscZUF+jaYJTjy9m5jT7FdzC8ryJBcOQvPyfKpas6Hm\/GSekhPJ1Tdz24KqYBmqx0NTi59d3rey0522PsmtiW3uQtRub+d\/CWj5ZUEPZqkaavd2N6l0RAs44eSBpTqNvTfCTE4opHZzSa6ERK4mWKi6c1BQXV8wuJT3VFX4KrDzfur2Nl\/69lTk3l3HyhV9yztxF\/OHvG9i2oxXDRk3vdmv84qxhTB4XaR+0T0U\/ITnRE21g7IgQ4HbbZ2A0mpoDXD1\/ua0nUjSEpcPVranteT8ezPOPTuPHPyx2HBX3hqREnat\/PoIzTja9p5wwDEl9Qwd3PmKu+P0+4fEITj9poGNUYSlh2442Xn17ezfPvPb2II8+tZGgnZcBIISgIDeJw2bkRBXI8SKttTK+DoNmr5\/Fy+u58jfLqd3lHCvMCSnB12GwYEkd19y5gguuWsxVty\/nkwU1Ud2+haX7PuGoAbaeW\/EgJeyq9\/HLm5fxk0u+Yt4dK3jmlc22HU+IsvJGrr17JfPuWMGVv1nOGZd\/zc+vXcr2nfF7LAFIKQka0lxk2x5k5Zom5t5axuZtrUhrVP3W+9up2tHW6R1kGGYZvPyfrZx68Zecd9Vi5txcxtxbl3Pxr5dw2s8XRB1kpSS5mDnN3onF7RL86AfFPbbJDr\/Ba+9Ucct95cy7YwXX3r2SV9+uot3nXHbdcHi8EPCTE4pNV2+bNAQNyVdL6zjrioXc+fAaPv2qlootrZSVN\/LHZyv42ZyFrFpv74Gn64KfnjQQTe8+63Vofv2Djo7eeS9JCR1+5xGEE4aUNDT5uXr+Cj76oib2Au2CpglcLtNv+rrLR3HlxcNJSY5fiIUwghKB6Vlx\/k8Gcerx5roFJ4KGueXspTcsZf2m\/rXb3Z4iBGRmeDhgUrZtA8Eqw7c\/2RnRkQYNySdf1VJbZ6pGwgkJ\/1nHFjmqJOJBWurPt96v4ub7yjn\/qkWcfMGXXHjNkqj7sjsRNCTLyhu46JrFXHL9Ut7+aCcLy+p579Nq5t66nDk3l7F1e5tjeQsBB07JJsnB7hIPUkJzS4ANm1t455OdrF4f6YHXlbrGDt77dCdvf7ST9z6tZuWaRhqaeo7xZkcwKFn6TSO3P7iKi369mB+e\/wXnzF3I4uXdXXvb2w3m3FLGn57dxPOvV3LvH9dy1pyF3P7QGrZWtdPU7KfDb+APGHhbA1TtaOf+P61zXASraeaGW+GmU00ITjp6APk5zpoRw5AsWdnAGZd\/za33r+LVt6t4+6Od\/OeDHdz2gPkdi5bX92qQJ6y1WMcdVmhbb6WEDRVefvPQKurqO\/AHDIKGxJDmEQxKdtV3cOfDa2ixmXUJITj0gBxSklzdhKZzD\/QtI5E0NrcRCEauJ+gJKSXNLb3bSTAYNA3l8+5Yzr1PrGVnbTvtPudFZE4Iy1h3xsklXH5e5BatsdLhN9B1wZmzBnLpOaWOU1VpjWw3bm7hF9cvY9W6Fsep+ncVTTMX\/BXm29sPQnnw3w932JZXQ2MHK1Y7zyaFgOmTsynIje5e2hNSmhGG\/\/zPTdx4Tzmvv1tFWXkjO2t9EQItFgxDsmmLl7m3LmfpykY6\/Lsbf9AayX6xeBe3PVgeNbRNRpqbU39Q5GhcjRcpgR5sBFjXSWvPd2MP9n03DMm7n+7komsW8\/J\/qlhY1sCO6nZ8HWZ+dLtWSjZs9vLoUxu48+E1PP3SFsrXNeEPmKvhRdhKaqHBqnVNbNvRarvlgBBQXJgcsc2By2V6MelRIgBv3OJl7q1lrN3Q0q3jDhoSf8Bg6coGfnVbGVur2mzrbU9kpLsZXGy\/eDcYlNz7xFq2bjddirVwV1xracOmylbbQZWw1qScenxRN6Hp\/LX9gGAgyOq1VeE\/R0VK8Lb62FZVH34qZgwpafcZ\/PONSn78i6+48jdlvPdZNcHgbmOSTd2yxePWOO0HA5k+OTv8VExommkIvmJ2qaOaQVoGr02VXi67sYzq2vbvndAQ1kLHn51S4iiEDSlZVFZPxVZTZRGO3y95+T\/bojZOly646YrRe6RiNKRkzYZmnnyugqCD8TEeAlbj31XvrLcPBiULy+p55pUtju8TAg6fkeNoJO\/PSAn1jX4efWojHR1mxxsLUpqD0E4hoZk7QY4blcFRM\/P46UnFXPCTQcy5oJTLzh2G22WuC7MjLdWFO8zjqcDaNtrhFvx+g3ueWEtTc8AxzVJCQ5Of59\/Y6rjNtBMCwdEz80lOsre\/tLQGyM32MGNyNgfu73xMGJMRIRRDCGF6WX0nZhxYI4zlK7fEtQ95MBhk2fLNtLVFSs94MStrB599tYt581dw9JmfMf\/3q\/nfwlp21samnxXC9MO\/ea610jUOhMDy3BpDcpKzusswJAuW7uKsKxZStdNZXfFdRiA44qBc0lKc88Hvl\/zpuU34\/fYZYEjJ18vq2VTpDT\/ViaYJJu2XyZjhaeGnYkYa8OWSOtp9wT0uC8OQlJU38uWSuh6fZQThPx\/uoKXV3glA0wSjS9NJ2gcOAF3p6Ih\/lhWOISUbt7SwparnTae6EhpwHDwth+suH8Xzj03j81cP57lHp\/HgrRO4cc5ofnXRCC46YwizTx\/CgAJnIZBkLfbsSlamx3GQISU0ewOsr\/D2mGYpzX1yGpvsy84JIeCg\/bMd05yZ7uaua8fxx99Ojno8ftckBhUnh9\/eyYgwV2n7L+4nGFLS4vXx9aINURfn0XXUXVHNmvVV3Qyje4K0pthBQ1K9y8e\/\/rONK24p49SLFnDL\/eUx2UGEgPzcRIYPMUM5xIoQpttveGUNp6nFz+0PrnZc5PZdRxOm3ejU44uj5p\/HLXj4NxP57JXD+J\/D8dGLh0RtIFgL7qaHjbDiwZCS1eujrwmKFQksK2\/EcNZAdSKRNDT6afE6X6zppgPHviQQ6LmN9IiEZeVNneE6ekIISEl2cc0lI3npiek8fPtEzpg1kLEj0nG5rOB+Nke0Ik\/wmKvVu5KUoEf8FkJKc9+euvrIfW\/saPcFWVbeYKsqi0ZJUaKj4RwrL8K\/0+6I9u1mGe5OV78WHABSGqzdsIMPPl5JY5P9aEMakkAgQNmKzXzyxepeGZliQXbxkGlq8fP6u1Ucd\/b\/eOqlzRFhPboihKlHLSpIjFu\/LGNQi6WluLnmkhER0+jvC0KDg6bmMLo0LaoQ1TRBepqbrAw32Zke2yMjze04QgyhaabnVmF+79aySEv10CdYwTVjHQh1+A38\/u6NvCvCUp\/uS1rbgzGnPxrh8c+cEAImjsngqQf256xTSsjJSjA7fauD7C12quKEBPO5TtQ3xuE9Z4UYivXyEEUF0QdCe4q0lirILlt679sa1AvMmYTBuk07efHVBSxZtpG6+haamtto8bZT3+hl05ZqXv\/PEhYsXE9HRyDmUcmeIC2vmdo6H7\/\/y3pefXtbhIEuhLAMcdHUTXZICZu3tVK+LvraEl0XHDYjj3mXjCA5ac+9ZvoTwgqD8svzhu6z7xICcjI9nHvaoF7POppbIj1UeouwVHWx4HKZo2InPb206tV3DSmJaUatCcHQkhR+d+N4Rg9Pc4ycLKUVQj5gOhe0tQdpaw9aQjf86q50P9nhD+LQ7BFCkJ2ZiB6rZtAKpWOT3Kg0NEVXy0vLISHewzBMr6st21p58vmKbrbBfi84Qkgp8fuDLFyykZde+5pX3lzIy28s5OXXv+ad91dQXdPYJ6OaUCdvV9nskNIc5b3y390LzvoKKSUdHQaX3lDGuk27g8GFI4TZYZxxUgm\/umj4Ho2q+huaEEwYk87wodFnG32NrgsOmppDSsq3K4iFgP1GpUe4gdohEGRnuklPdVZFScPUu38XabWJ2ByOpsP8a8ZSXGAfckNaWoMt27z845Ut3PpAORfOW8IFVy9m9rzFvPDmVsfZmh1t7UZUbUNSok5eTmRoeDt0TTBxbLqj0HeiaoezDTgQMKjZ5WNHdVvcx5KVDTz0l\/VccsMyqna0dxsYx1Ad+xdmwQdpbfXh9bZbaz2cCy4edM0crRw0LZvpk7PJjmNXuUBQ9miH6Q0SaGr2c9O937CjxtnwLaxFXmeeXMLpJxbbTqu\/i7hcgpOOLtrn6hXNCkNy4JTsmEf7ewNNMwVYtLDlITQdDpyS4xgORUqob+rocV+ZvibBo\/dJHmba7HfSFSFg7Ih0xo2073yllKyvaGbeHSuYdeEC7nl8rRXevZ4VqxtZuaYpanQBO+rqO\/B12As0Yc0gxo5Ii0nwzzp2gLUFb\/gZZ6SEVRuaHcPXtLQGuPjapRzzs8\/jPs67chF\/faGCShuHhBg+5\/uPOWIXnHZCMf96YjqPzZ\/EE3dP5v3nZvKjH\/TcCWtWaO4UB48fKSFoGDQ0xa6rDuF2WZVjXTM3\/Lac1jbn0aKwjGC\/uniEY3iJ7xKatVHSiUcVhp\/aJ7hdGjddMfpbV\/8lJer86qJhUQP2aUKQm53Az88aHH6qE0NKvli0y9HrbG9hRokN\/zU+hAC32+HjLTQrwKTmsI2tYcA9j6\/j\/f9V47cM9l0PgPGj06MamsOpqeugts7ZjuFyCa65ZAQZUYSesMIWnf2jQY4usdF4493tER17iLRUNycdPQBN372OJtoBZj57PKZdFgfV5h4W5\/cDTROcelwR1102ioQEHbdbw+PWSEjQuWnOKB66bSIzpmSZeyB0KX1NmCu6J47N4IrZwx07aiklwSBU7XSeUtohhMDtNhWkoZXDv\/\/resdNnbAqYXKizl3XjjPDMDuk6buAxyO47LxSR68VLHfV0P7u8R6hhXROCCHIzHBz3GE9Bz\/cm2hCMG1iDjfOGUVGmhlWvSu6bkaPvf\/m8WSk2QfBA+jwBXnhzW2OnczeYvjgFNuIr3uD\/JwENAcpZRiS9Zu9nWuxuiKsSNJTJ8TnTef3G\/zbYcFpiMK8JO6+bj8GFyfjcu1WgwtrwDpuVAZ\/vncKwwbFH+tKItm8rZUd1e22adCE4KxTBnKiFW7G6dN0zXTeufayEbz0xHRe\/4sZuHXE0FTb\/LDP4W+T8BLdywjL+Drr2KKIEZ0QkJioc9iMXB6\/awp\/vX8KF54xmKkTspg4Jp1pk7KYc0Epj8yfSGGe8xRTSqiubaeyylnVFAsdfoN\/\/Xsbz79eGbXD0zRBWqqLubNLGVi0d4It7m2EwFy4NMU5vIiUsLOmndMv\/5pZs7+I+zjpgi94\/7Nq2wZHqGHrGodMt9+1cF8RqqOnHF\/MUw9M5ZhD8xk9PJXSwSnsNzKdM2eV8MIfDmDimAzHdEpLpVFR2bdhaKTEjHDbZdQezqDiZA6bkcuA\/ERysxNMF\/NeVMpooXZChAvVrmiaYMSQyM5ZE4LEBJ0Lfmru9RFP0gxpBn2s3uU8KNQ0c2fDV\/98IPN+PoJDDshlyvhMjj20gOsvH8WT90xmdGla1AGSE1KC1xtk0fJ6x83eEhNdXHf5SH5x1lCGDEwhOUnH7dJwucwNnAbkJ\/LDowp5\/tED+Nmpgxg+JJWSoiSOODCPB28ZT0py5Iy755LoJe2+6JZ+eyTe1thc7voKgblrWl6us+ulrgkSPBr7j8\/iyotH8NQD+\/P3h6bx5D2TuejMIWRnOo\/ypDR3xbv27pVRw0HEgrSC3D32942UlTsHZMNKc3FhEn+9b\/+4vbn6AwLTUyw3y9nOJKXks4W7WF\/RQuX2triPrdvbePSpDXT0EOX1gEmZpDlEHd2X6Jq5L8Z9N43nmYem8Y+Hp\/H3B\/fn+stHkZ1pv09FCENKXn93e9TZam+QSCqrosfecrkEd\/56P559ZBrPPjKNP9w5ielTsqJ28rY4v6ITc2Gu\/YWaJrj5V2M4YJKpPXC5TI3BqOGpPHbHRE49PnqgQjuktcjvrfd3EIyyDECz+pBzfzyYx++axNMPTuXBWydw5qwS0lN7H4odq2z\/+sJmmlrs7TNCQHqqm8vOLeWZ30\/lHw9PY\/68Mdx97X785d4pPPvwNO68Zj\/ywvYR0TTBwAHJTJ2QFWGj2muCY\/v26C6kdhgG1NQ1g4jzxj1ASokRlDQ1xy7oNE3gdmu4osSnCWEYko+\/rOabNc3hpwCIFopLSklbW3cfeCmhpSXAZTeWsXJN9DzWNEFutofRpT0bVvuS3ghICTQ07Xal1nQ47jDn7VSlNOvLR1\/UxLQ4zg4pzf2w125qCT\/VjdRkN6NK7TcZ+jbQNEFKsouMNDdJDqEmumIYkvK1zbz90c6oHXxvkNJUwW6oiJ6HCR6NwrxESgYkMWNKDg\/cMsH0Fush7V3pKQS7ISUr1zRhGPazHyGgZEASf75nfz7450ze+ttBfPjCTF56fDozpuT02gHDMCT\/eLWS1RvMfdV7QljhT\/qSispWHnt6Y9RQ90JAdqbZH5x8bBEnHDWA\/SdkUZif6GjHFULYrovrXU7FwIZNO5BOpn4bDClp9\/mp3hl9JN3XSKC9I8jHX9bGVOjxEDQklVVe7nh4jb1e2Vrc5TSSkpghT8Kz0ZASrzfAjfeU422L7tsugPRUV8SIwemdYPYGtvtvW1FRnZASmls6aG+3L\/eoXmeSbt8iEORlO882DCmpqGzh80W77PM2RlrbgnyyoKbHDjU7w4NAIJEYBjR7ncOJSAneVud8igfDWmvQW8wy8XPD71bibbWXsNJyKXdCWvntRNDqOONpP2kpLubO3u06LqU5UHJCSqiudTZCY12zekMzC5bWRU2vEJCT5aGkKJnszO7btEbDfGTktVLCrroOfn3nN1Tv8sWVD10JWhsrORJFHWhIyatvb+PzhbV7VF+6IiVsqfLyzdrmCKeevSY4tmyro3ZXU8QL7ZCWb\/XK8i20ePetqgrMGD9\/f3kLz7yy2dG1Lh5C31NW3sAlN5RR32g\/m5ESVq5tcqws0jA3X7FrBIY0I6ZeeZvz8wEMaQrGUDlITEP9DocpvZQQCBqssxmFSwmbt7Y6LsSSUrJqvX1UXolkpcOsC6uD\/GbN7voikWyparNNI5jh5v\/4bEWvZxshDEPy4lvb2FrVGn6qE0NKNlZ6O9NmSHNRlF3apIRd9e3sqHHWeXdFdnaIkc\/CWrtw3x\/X0tgcW9iKrhiGpK7Bx\/W\/+4aKrZEulSGChqTKYW8MKc16uKHC2TZizqprWL3Bfk8HJ7p6SUkD1m50XqtkSEn5Ouf6E8IIwvyHVrFt++69OOwQ1lqt0IxHWgsC3\/3U2ebV0OTH7yBgDSnZvLWVq+cvZ32FN+rajnCkNI3sT71YQV1Dh2NdAKhvcK4Hvg6D63\/7DS++VUmHP\/6I3l2R1mz8Nw+upqExUgW21wSHz+fnnQ9XUlPTFDUjzAIzWLOuiqUrNoef3icYUtLiDfDY05t47KkNVFa1Ocblj0ao8nnbArzxXhVX3LKcyir7SK1YneP6TV4+WVATUciGIWnzBXn302rb+0Pv+npZA08+V0Fbe+QIOBg09c+r1+9ucNJaEfrh\/6ptjWmBgMFr72y3jc0vMaMGf7XMfkTX7jP478c7bbdoNYLw4ltbqa6NHJEZVhywZeW7VW9GEP7xSiXeVvvv+mZtEx8vqI1pYBINKaGx2c+Tz2\/GZxOMzzBMF9ZQxxnKv4++qLGtI4GAwTufVMfs8moK1CaWr26MyJegIdlQ4eW1d7czb\/6KTltC+DvtCAYlFZWt3HjPN3z21a6oHZkRhH9\/YB8cUUpJ+bpGVq2PHHWGkFaIlbseWWvuNWKTL+H4OgyefbWyczYtkXyyoBZfR2R5B4IGn31lBRZ1SEMIQ0q27mjj2rtXsnGzl0Cg57QYhqTZ6+fJ5zZx7xNrqa3viCyLoGT5qsaoqiBDSsq+aWLOzcv4+Msa6hvNPUec3i+tAebOmnYef2Yjf3x2kzVwjZzVYKnq\/FFmE9Katd\/92Frm\/341FZWt+OMUINISYktW1HPdXStZsrLBtq3reUPPuS38x74i4A9SWVVPeloSGenJZpF3kfBmxgVZsnQji5ZswrDryfYhfr9BWXkT\/\/5wB2XljZQUJZGdYapLpPWfULq7HoY0G18gKFm6soG5ty7ntXeqHFUDXZFSsmZjC4cfmEdyost8ngGt7QF+94d1fPC5fQcfwjDMgHo1u3wcNDUH0aVCbtziZfa8Jeb6kbCyX1\/hZUB+IqWDU6DLPeXrmpj\/+9V4HVbBS0uPfORBeSQn7U5vICh577Nq\/vbiZtvKLa3otVuqWjlqZoH1LPNeb2uAq+ev6NwjPHT9jup2WrwBZuxvhqQPpXHtxhau\/903VNf2zexUWnuUJyXqjBtlbjkcelfVzjbm3bGSpubum4pt3OIlI93dGUU3dP2ajU3c9ehaWuJQVUlpCs5jDykARGe+rF7fxKU3LKWp2c+2He389+Od5GR6dpeZ9Z9QHZTG7rJ48c2t3HhPOWs3xhCZFaip81G108fBU0131ND31NR1cNXtK9hZ43MMrRFiZ207H39ZS052AgMLEzufI638kVYag0HJWx9s5x+vVnazW+yo8bGz1sf0yVnoutaZD1u3t3LTveXUNdioTx2orvXx4Re1BA3J0JJk3C7zeXZpKV\/XzNXzV\/DuJ9U0NQdo9xnMmJKDELvr6AefV\/O7x9f2aL+TQFNLgPc\/q+GDL6rJz0mgIDcRrcuzgtb2DPWNHTz\/xlbufGQ1H39Zi5Rw2XmltlG0pTRnG8+8ssW04YRf0AUpYfX6Zv7z4Q5qdvmYMCazc31I6Pu71ZsuebF5m5e7H1vL489sNGepDoUuxhzxrv2ZPkTXNEqKsykuziE7KwWBoN3nZ1ddE5s211Jfv1sN0J8QAoYNSmHCmAyGlKSQk+UhPyeh237cjc0Btu1oY92mZpZ+02ipMLo9JibSUl0cPDWHQcXJ1OzysWJ1Exs399zoQ2hCMKQkmUn7ZZCV4Wbz1jYWr6i3t1VYuFyCyftlMqTE3KBm6\/Z2vl5WF3VUFSIpUeegqTkU5HgwJCxf1cSq9c6bJHUlPyeBAyZnkZPloaUlwFfL6tm2w95VWROCkuIk9h+fSVaGm8qqNr5cXLdXwmZoQjBjSjaDByYBUFvnY8GSelpa7VVzHrfGQVNzKMpPQAKbt7axZGU97b6e88+O7EyPmae5CVTtbOeLRbtobO5efkLAqNI0Jo7JYNigFDLT3SQk6DS3+Nm2o42NW7wsWFpvBka0SXM0dF0wYmgq40eZEWSra30sX90Uc3DBEMIKZT5+dAaDByZ3RmAIBCXVte0sWdnAGgeVpiYEI4amMHFsBinJLrZsa2XB0vpe24yEgKwMD5PHZVKUn0BOdgJul4avI8iO6nZWb2hh9frmbjYeIWDKuCyGD0lG0wQ7anx8ubiuR6HhRFqqiwH5iZ2hYHwdBrvqfdTsMnfkCzF6eBrPPTzNdt97KWF9RQs\/ueSrzsWLsZLg0RgxNJXRpakMLEomJ9NDaoo56PO2Bqje5aOi0svGLa2s3WhuNtUT+0RwIKwgbea\/YEk+IaMb3foDwopdFUp4uBdIV+ktcZ6W9oT5ClPv2ttndaY1NKrq4Rld34l1T6zlsSfpjffeeL9rT9C6xCnr6V12+Rft+p6INV868yNco9FP6iHhedO10VsqnWjP7OvyDi8nc1pu\/q9TWvoqH0KEngfmswj1HV3OX3jGEOacX2q7XsUwJB9\/WcuvflMWkyowHNvyCNFDXtgRmcK9gQQpzVhOhnVIa\/vE\/o60bAnBoHkEAt2PYNDcqyOeTLdDWp32njyrM60xPqPrO0P3xMqepDfee+P9rj0hPD+ivcsu\/6Jd3xOx5ktnflh1svPo4b5YiDUNPdEtb7qkLxhF5x+ir8s7vJxiSUu8+aAJQXKSzrGHFfDTE4uZvF8mni6ReUPPCz2r6\/OEsLb1Pd55v3sJrN\/cghHsfm+s2JZHnOXSlX0z41AoFIrvKZoQjB2Zxvx5Yxk6KAUBGBK+XlrH489sZPWGFtNIHSaAQjOrAQWJXHvpSA4\/MM9RcPj9BlfPX8EHn9s7y+xrlOBQKBSKPcDlEtxzw3iOO6xgtzrMGuX7OgwWr6jn6X9tZlFZg6ltsXpct1tw\/OGFXHrOEAbkJzmuJ5ESKre3csqFC2y9zr4NlOBQKBSKPSAxQePtZw4mPzcx\/FQnUkoamwPU7PLR1h7E5RIU5CaQlRE9VAyWm\/sdD6\/mtberMPqD1NhnNg6FQqH4HtNT9F8hzL3ehw9JZfzoDMYMT49p1bqUsGRlPe99trPfCA2U4FAoFIo9IxiEFatjc0UXovsRDSmhbFUjN91bjtfbO1fgvYUSHAqFQrEHBIOSP\/5jI1U7o0cJjhVpeZUtWVnPdXevpKbW169mGyjBoVAoFHuGISXLVzVx+mULWbuhBV+HuUFYvH19SGD4Ogxee6eKi3+9hK1V0WNufVso47hCoVD0EYkJOgdOyebQ6bkcNTOvc9W83R7oXZFS0tzi551Pq3nt7SpWrm3qsyi3ewMlOBQKhaIPCUUfSE7WGTM8jQMmZTN6eCoZaW48bt1ahGcQDMLO2jaqdrazYnUTC5bU4fOZ4UT6m2oqHCU4FAqFYi+hCYHQzD91XeB2CXM1ugEgCVjhQ6Sx52FN9iXKxqFQKBR7CUOaYT38AYN2X5Bmb4DWtiDtviDtPqMzbFH4qvL+jhIcCoVCoYgLJTgUCoVCERdKcCgUCoUiLpTgUCgUCkVcKMGhUCgUirhQgkOhUCgUcaEEh0KhUCjiQgkOhUKhUMSFEhwKhUKhiAslOBQKhUIRF0pwKBQKhSIulOBQKBQKRVwowaFQKBSKuFCCQ6FQKBRxoQSHQqFQKOJCCQ6FQqFQxMX\/AXWWO+GkUXPmAAAAAElFTkSuQmCC\" alt=\"SkillArbitrage\">\n    <\/div>\n  <\/div>\n<\/div>\n<\/figure>\n\n<a id=\"h2-3\"><\/a><\/p>\n<h2 id=\"choosing-an-auditor-for-soc-2-compliance-for-indian-service-providers\">Choosing an auditor for SOC 2 compliance for Indian service providers<\/h2>\n<p>Choosing an auditor for SOC 2 compliance for Indian service providers narrows the field faster than most buyers expect, because only a licensed CPA firm can issue the report and the person who signs it has to be a CPA. An Indian Chartered Accountant firm cannot sign a SOC 2 opinion on CA credentials alone. That one requirement explains most of what you will see the moment you start searching.<\/p>\n<p>Search for SOC 2 in India and you will find domestic consultancies advertising certification. What the majority of them sell is readiness work: gap assessment, policy drafting, tooling, evidence collection, with the opinion itself signed by a partnered CPA firm licensed in a US state. That arrangement is legitimate and it is common. The problem is a partnership that goes undisclosed, leaving you to discover whose name appears on the report late in the engagement.<\/p>\n<p>Ask early, and ask about independence while you are at it. The firm that designs and implements your controls should not be the firm that audits them, because a firm examining its own work carries a self review problem that a sharp vendor risk reviewer will spot inside the report. A smarter strategy is to buy readiness from one party and the examination from another, with the paperwork kept separate.<\/p>\n<p>Now, a piece of vocabulary that will save you an awkward moment in a sales call. SOC 2 produces an attestation report, not a certification. There is no certificate, no pass mark and no body that stamps approval, so &#8220;SOC 2 certified&#8221; on your website is technically wrong, and any reviewer who handles these reports weekly will notice it.<\/p>\n<p>ISO\/IEC 27001 works the other way round. An accredited certification body issues a certificate, it runs for three years subject to surveillance audits, Annex A in the 2022 revision carries 93 controls, and the scope usually covers your whole information security management system rather than one named service. If your buyers are European, or your work arrives through global procurement, that certificate is often the thing being requested.<\/p>\n<p>The report itself is restricted use. You share it under a non-disclosure agreement with customers and prospects, never as a public download, and the general use version of the same examination is a SOC 3 report, which is the one you can publish. Buyers typically want a report whose period ended within the last twelve months. For the gap between your period end and their review date, management issues a bridge letter, sometimes called a gap letter, confirming no material changes; it is your statement rather than auditor assurance, and it does not stretch far.<\/p>\n<p>Read a SOC 2 report before you commission your own. One runs to five parts: the auditor&#8217;s opinion, management&#8217;s assertion, the system description written against the AICPA description criteria, the controls with the tests performed and their results, and any other information management chooses to attach. Your subservice provider&#8217;s report carries the same five, so the annual review from the previous section comes down to reading the opinion and the testing results and noting what you find. Go straight to the testing results and ten minutes will tell you more than a control matrix ever does.<\/p>\n<p>Send these five questions to every firm on your shortlist before you agree to a demo.<\/p>\n<ol>\n<li>Which legal entity signs the opinion, and in which US state is that firm licensed?<\/li>\n<li>Who is the CPA signing our report, and how many SOC 2 examinations has this team completed for companies in our industry and at our size?<\/li>\n<li>If we buy readiness support from you, which separate entity performs the examination?<\/li>\n<li>What observation window would you recommend for our first Type 2, and what is the reasoning behind it?<\/li>\n<li>Can we see a sample evidence request list before we sign?<\/li>\n<\/ol>\n<p>The answers separate the firms that examine controls from the firms selling you a logo. If this turns out to be the part of the work you find interesting rather than tedious, it is also a career in its own right: the same control and evidence discipline sits at the centre of the <a href=\"https:\/\/skillarbitra.ge\/blog\/data-privacy-consultant-career-india\/\" target=\"_blank\" rel=\"noopener\">data privacy consultant path in India<\/a>, and the European record keeping duty explained in <a href=\"https:\/\/skillarbitra.ge\/blog\/gdpr-article-30-records-of-processing\/\" target=\"_blank\" rel=\"noopener\">GDPR Article 30<\/a> rests on the same habit of writing down what you actually do.<\/p>\n<h2 id=\"frequently-asked-questions\">Frequently asked questions<\/h2>\n<p><strong>Is SOC 2 mandatory for Indian companies?<\/strong><\/p>\n<p>No Indian law requires a SOC 2 report. It is a contractual expectation from a customer in the United States or Europe, and it stalls deals rather than triggering penalties. Your statutory duties for personal data sit separately, in the DPDP Act and Rules.<\/p>\n<p><strong>Can an Indian Chartered Accountant firm issue a SOC 2 report?<\/strong><\/p>\n<p>Not on CA credentials alone. The report must be issued by a licensed CPA firm and signed by a CPA, which is a United States licence. Indian firms take on readiness and evidence work, then partner with a CPA firm for the examination. Ask which entity signs.<\/p>\n<p><strong>How long is a SOC 2 report valid?<\/strong><\/p>\n<p>It does not expire, because it describes a period rather than granting a status. Buyers want a report whose period ended within the last twelve months, and expect a bridge letter covering the months since. Most providers move to a rolling annual Type 2.<\/p>\n<p><strong>Should you do SOC 2 or ISO 27001 first?<\/strong><\/p>\n<p>Follow your buyers. Customers in the United States ask for SOC 2, while European and global procurement more often asks for ISO\/IEC 27001 certification. The control overlap is large, so whichever you build first carries much of the work for the second.<\/p>\n<h2 id=\"references\">References<\/h2>\n<ol>\n<li>AICPA and CIMA, 2017 Trust Services Criteria (With Revised Points of Focus, 2022). https:\/\/www.aicpa-cima.com\/resources\/download\/2017-trust-services-criteria-with-revised-points-of-focus-2022<\/li>\n<li>AICPA and CIMA, SOC 2: SOC for Service Organizations, Trust Services Criteria. https:\/\/www.aicpa-cima.com\/topic\/audit-assurance\/audit-and-assurance-greater-than-soc-2<\/li>\n<li>AICPA and CIMA, 2018 SOC 2 Description Criteria (With Revised Implementation Guidance, 2022). https:\/\/www.aicpa-cima.com\/resources\/download\/get-description-criteria-for-your-organizations-soc-2-r-report<\/li>\n<li>AICPA and CIMA, SOC 3: SOC for Service Organizations, Trust Services Criteria for General Use Report. https:\/\/www.aicpa-cima.com\/topic\/audit-assurance\/audit-and-assurance-greater-than-soc-3<\/li>\n<li>ISO\/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements. https:\/\/www.iso.org\/standard\/27001.html<\/li>\n<li>Press Information Bureau, Government of India, Digital Personal Data Protection Rules, 2025, notified 14 November 2025. https:\/\/static.pib.gov.in\/WriteReadData\/specificdocs\/documents\/2025\/nov\/doc20251117695301.pdf<\/li>\n<\/ol>\n<hr>\n<p><em>This article is general information about an assurance framework and its scope, current as of 18 August 2026. It is not legal, audit or compliance advice on any specific system, contract or engagement. Whether a particular scope, category selection or observation window suits your situation depends on facts this article cannot see. Consult a qualified professional before acting.<\/em><\/p>\n\n\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Is SOC 2 mandatory for Indian companies?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No Indian law requires a SOC 2 report. It is a contractual expectation from a customer in the United States or Europe, and it stalls deals rather than triggering penalties. Your statutory duties for personal data sit separately, in the DPDP Act and Rules.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Can an Indian Chartered Accountant firm issue a SOC 2 report?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Not on CA credentials alone. The report must be issued by a licensed CPA firm and signed by a CPA, which is a United States licence. Indian firms take on readiness and evidence work, then partner with a CPA firm for the examination. Ask which entity signs.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How long is a SOC 2 report valid?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"It does not expire, because it describes a period rather than granting a status. Buyers want a report whose period ended within the last twelve months, and expect a bridge letter covering the months since. Most providers move to a rolling annual Type 2.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Should you do SOC 2 or ISO 27001 first?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Follow your buyers. Customers in the United States ask for SOC 2, while European and global procurement more often asks for ISO\/IEC 27001 certification. The control overlap is large, so whichever you build first carries much of the work for the second.\"\n      }\n    }\n  ]\n}\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>SOC 2 compliance for Indian service providers is an attestation, not a certificate, signed by a licensed CPA firm, with security as the only mandatory category<\/p>\n","protected":false},"author":35,"featured_media":4784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1538],"tags":[1579,1450,1580,1578],"class_list":["post-4783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-privancy","tag-cybersecurity-compliance","tag-data-security","tag-indian-it-service-providers","tag-soc-2-compliance"],"_links":{"self":[{"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/posts\/4783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/comments?post=4783"}],"version-history":[{"count":2,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/posts\/4783\/revisions"}],"predecessor-version":[{"id":4786,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/posts\/4783\/revisions\/4786"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/media\/4784"}],"wp:attachment":[{"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/media?parent=4783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/categories?post=4783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/skillarbitra.ge\/blog\/wp-json\/wp\/v2\/tags?post=4783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}