Run the audit before the auditor does. Find every gap while there is still time to close it.
A structured gap assessment against the framework you are being audited on: ISO 27001, SOC 2, DPDP Act, or a customer security questionnaire. Control mapping, evidence inventory, staff preparation, and a remediation plan sequenced to your audit date. Remote-first, 1-3 weeks.

- 1-3 weeksAssessment duration
- 6Frameworks covered
- Mock auditIncluded in scope
- Remote-firstAnywhere in India
This is not our security audit. It is a dry run of somebody else's.
Our cybersecurity audit finds technical weaknesses: misconfigurations, vulnerabilities, exploitable paths. This engagement answers a different question: when your certifying body, your customer, or your regulated client audits you against their framework, will you pass? The two compose well, but they are different engagements with different outputs.
- A security audit asks "where are you weak?" A readiness assessment asks "can you evidence what their checklist demands?"
- The readiness output is framed in the auditor's language: control references, evidence requests, nonconformity risk, not CVSS scores.
- Most clients who fail a first external audit fail on evidence and documentation, not on technology. This engagement exists for exactly that reason.
- If the assessment surfaces deep technical weaknesses, we scope a security audit or remediation separately rather than padding this engagement.
Eight workstreams, one question: will you pass?
Control mapping against the target framework
Every control in the framework you are facing (ISO 27001 Annex A, SOC 2 Trust Services Criteria, DPDP Act obligations, or the customer questionnaire itself) mapped to what your organization actually does today. Each control gets a status: implemented, partial, missing, or not applicable with a documented justification. The output is a control-by-control register, not a maturity score that hides the detail.
Evidence inventory: what you have vs what they will ask for
Auditors do not accept "we do that". They ask for the access review record, the tested restore log, the signed policy acknowledgement, the change ticket with approval. We build the evidence request list your auditor is likely to issue, then check each item: does it exist, does it cover the audit period, is it in a form an auditor will accept. Missing evidence is flagged early because some of it takes months to accumulate.
Policy and documentation gaps
The document set the framework expects: information security policy, access control, incident response, business continuity, vendor management, data protection and retention. We check what exists, what is missing, what is stale, and where the document says one thing while your team demonstrably does another. That last category is the one that widens audits, so it gets fixed first.
Technical control gaps
The technical controls the framework requires, verified rather than assumed: MFA coverage, access provisioning and deprovisioning, logging and log retention, backup and tested restores, endpoint protection, patching cadence, encryption at rest and in transit. Where a control is absent or partial, it goes into the gap register with effort and dependency noted so remediation can be sequenced realistically.
Interview preparation for your staff
Auditors interview control owners, and the answer either matches the documentation or it opens a line of enquiry. We rehearse each control owner: how the control works, how they know it operated, what they would say about an exception. One hour per owner changes fieldwork more than most technical remediation, and it is the part almost every first-time auditee skips.
Remediation plan sequenced by your audit timeline
Not a generic to-do list. Every gap gets an owner, an effort estimate, and a date worked backwards from the audit. Items that need elapsed time (evidence accumulation, a quarter of access reviews, three months of operating logs) start immediately. Items fixable in a week are scheduled where they fit. You always know what must be done by when, and what happens if it slips.
Framework selection guidance
Many organizations start this engagement unsure whether they need ISO 27001, SOC 2, or just a solid answer to a customer questionnaire. We map who is asking (an enterprise customer, an export market, an RBI or SEBI-regulated client, an internal board mandate) to the framework that actually satisfies them, so you do not spend a year certifying against the wrong standard.
Ongoing compliance calendar
Passing once is not the goal; staying auditable is. The assessment closes with a compliance calendar: which reviews recur quarterly, which evidence must be generated continuously, when surveillance audits and re-attestations fall due, and who owns each entry. It turns audit readiness from an annual scramble into a routine your team runs without us.
Four documents you walk away with.
Gap register
Every control in the target framework with a status, a severity, and a finding. The register is the single source of truth for what stands between you and a pass.
- Control-by-control mapping to the target framework
- Status per control: implemented, partial, missing, not applicable
- Severity ranked by audit impact, not just technical risk
- Written findings an auditor could read without translation
Evidence checklist
The evidence request list your auditor is likely to issue, with a status per item: exists, exists but insufficient, missing. Ordered by how long each item takes to produce.
- Likely evidence requests mapped per control
- What you hold today vs what must be generated
- Period-coverage flags: evidence that must start accumulating now
- Format notes: what auditors accept and what they reject
Remediation roadmap
The gap register turned into a plan: every item with a named owner, an effort estimate, and a date worked backwards from your audit or certification target.
- Owners and dates per remediation item
- Time-dependent items front-loaded (logs, reviews, operating evidence)
- Dependencies mapped so nothing blocks silently
- A realistic call on whether the audit date is achievable
Mock-audit findings
A rehearsal of the real thing: evidence requested with deadlines, control owners interviewed, documents sampled. The findings read like an auditor wrote them, because that is the point.
- Evidence requests issued with two-day deadlines, as an auditor would
- Control-owner interviews with question-by-question notes
- Findings classified the way your auditor will classify them
- A readiness verdict: proceed, proceed with conditions, or defer
Four reasons the dry run works.
We request evidence, not assurances
We do not ask whether you perform access reviews. We ask for the last review record with a two-day deadline, exactly as the auditor will. The difference between those two questions is the entire value of the engagement.
Frameworks we have taken clients through
ISO 27001, SOC 2, CERT-In, and sector frameworks for RBI and SEBI-regulated environments. We prepare you for certifying bodies and CPA firms we have actually sat across the table from.
Independent of the certifier
We are not the certification body and we do not resell one. Our only incentive is that you pass on the first attempt, because a deferred certification is a failed engagement for us too.
Sequenced to your date, honestly
If the audit date is not achievable, the assessment says so in week one, with the evidence for why and the earliest date that is. An honest "not yet" is cheaper than a failed Stage 2 audit.
Six situations where the dry run changes the outcome.
SaaS startup asked for SOC 2 by a customer
An enterprise prospect makes SOC 2 a condition of the contract. We map the Trust Services Criteria to what you run today, tell you honestly whether Type 1 satisfies the contract or Type 2 is required, and sequence the observation window so the deal timeline and the attestation timeline actually meet.
Manufacturer pursuing ISO 27001 for exports
Export customers and international tenders increasingly require ISO 27001. We scope the ISMS realistically (plant, office, OT boundaries), build the Annex A gap register, and prepare the documentation and operating evidence a certification body will sample at Stage 1 and Stage 2.
BFSI vendor facing an RBI-regulated client review
Banks and NBFCs push their regulatory obligations down their vendor chain: RBI cyber security framework expectations, outsourcing due diligence, SEBI CSCRF for market intermediaries. We translate the client's questionnaire into a control map and prepare the evidence pack their risk team expects to see.
Company preparing for DPDP enforcement
The DPDP Act 2023 applies whether or not anyone has audited you yet. We assess your consent flows, data inventory, retention practices, breach notification readiness, and processor contracts against the Act's obligations, so a regulator inquiry or a customer's DPDP clause finds a prepared organization.
Losing deals to security questionnaires
Every enterprise deal now arrives with a 200-question security review, and slow or weak answers stall pipelines. We build a reusable evidence library and a standard answer set mapped to the common questionnaire formats, so responses take days instead of weeks and stop costing you deals.
Enterprise vendor onboarding, Indian and global
Onboarding into a large Indian group or a global customer's vendor program means due diligence against their framework, on their timeline. We run the readiness pass against their specific checklist, close the gaps that block onboarding, and prepare your team for the assessor call.
ISO 27001, SOC 2, DPDP, or the questionnaire: which do you actually need first?
| Feature | ISO 27001 Certification | SOC 2 Attestation (Type 1 / 2) | DPDP Act 2023 Legal obligation | Customer questionnaires Deal requirement |
|---|---|---|---|---|
Who is asking for it | Enterprise buyers, export markets, tenders, regulated clients | SaaS customers, mostly US and global enterprise | The law: applies to processing digital personal data in India | Any enterprise customer during vendor onboarding |
What you receive at the end | A certificate from an accredited certification body | A CPA firm attestation report | No certificate exists; you evidence compliance when reviewed | A passed review and an unblocked deal |
Realistic first-time timeline | 6-12 months including operating evidence | Type 1 in months; Type 2 adds a 3-12 month observation window | Ongoing; enforcement readiness is achievable in weeks to months | Days to weeks with the right evidence on hand |
Renewal cycle | Three-year cycle with annual surveillance audits | Annual re-attestation | Continuous obligation | Per customer, often annually |
Best first move when | Multiple customers or tenders name it, or exports demand it | One or more SaaS customers explicitly require a SOC 2 report | You process personal data at scale (that is most businesses) | One live deal is blocked and the timeline is short |
Typical trap | Certifying an artificially narrow scope customers then reject | Buying a Type 1 when the customer contract demands Type 2 | Treating it as an IT project when it is a data-governance one | Answering aspirationally and being caught at renewal |
Six steps, 1-3 weeks, remote-first.
- 1
Kickoff and scoping
Day 1
Confirm the target framework, the audit or review date, the scope (entities, systems, locations, data), and who owns which control area. You get the document request list the same day so collection starts immediately.
- 2
Document review
Days 2-5
Policies, procedures, prior audit reports, existing certificates, contracts with security clauses, and the customer questionnaire if there is one. Reviewed against the framework before any workshop, so workshop time is spent on questions documents cannot answer.
- 3
Workshops and evidence testing
Days 4-8
Structured sessions with control owners across identity, infrastructure, operations, HR, and data protection. In parallel we issue evidence requests with deadlines and assess what arrives: does it exist, does it cover the period, would an auditor accept it.
- 4
Gap register delivered
Week 2
The control-by-control register with severity and findings, plus the evidence checklist. Walked through live with your team so every finding is understood and nothing lands as a surprise in a PDF.
- 5
Remediation plan
Week 2-3
The register becomes a roadmap: owners, effort, dates worked backwards from the audit. Time-dependent items (operating evidence, review cycles, log retention) are flagged to start now. We state plainly whether the target date is achievable.
- 6
Mock audit (optional, recommended)
Week 3 or pre-audit
A rehearsal under audit conditions: evidence requests with deadlines, control-owner interviews, document sampling. Best run either at the end of the assessment or two to four weeks before the real audit, after remediation has landed.
The questions that decide whether to book this.
Twelve evidence requests to make of your own team this week.
Access and identity
- The last access review, with outcomes per itemNot a statement that it happened.
- Access removal records for three recent leaversWith dates and approvals.
- The current privileged account listIncluding service accounts, with approvals.
- MFA coverage report against the full user listCoverage needs a denominator.
Operations
- Three changes with approval and testing evidenceChosen by you, not by the team.
- The last tested restore recordDate, scope, outcome. A schedule is not a test.
- Patch status against the asset inventoryUnknown assets are findings too.
- Log retention configuration vs the audit periodNinety days of logs cannot evidence a year.
Governance
- The policy set with review dates and sign-offsCheck the dates before the auditor does.
- Consent and data-inventory records for personal dataThe DPDP Act baseline.
- Vendor due-diligence records for two critical suppliersYour customers will ask about your vendors.
- The incident register, including minor incidentsAn empty register reads as "not operating".
The pages around this one.
Cybersecurity Audit & Compliance
The technical deep-dive: security audits, penetration testing, and compliance gap analysis that find the weaknesses a framework checklist cannot.
Learn moreMicrosoft 365 Security Audit India
A focused audit of your Microsoft 365 tenant: identity, mail flow, sharing, and the evidence trail auditors ask for from the platform most of your controls live in.
Learn moreBackup Audit India
Backup and restore evidence is the request that embarrasses the most audits. This engagement verifies coverage and tested restores before anyone external asks.
Learn moreFind out where you stand before the auditor does.
Tell us which framework or customer review you are facing and the date you are working to. We reply within 4 business hours with a scoped plan for a 1-3 week readiness assessment. No obligation, no retainer.
Related Services
Explore more solutions that work great with this service