Executive Summary
For Indian SaaS selling to US enterprises, SOC 2 is frequently the difference between winning and losing. This case (client name withheld under NDA) shows how CyberSigma took a SaaS platform from no attestation to Type II readiness and unblocked a stalled enterprise deal.
Client Overview
The client is a B2B SaaS platform serving enterprise customers, with a live US enterprise deal blocked in the security-review stage for lack of SOC 2.
- Industry: B2B SaaS
- Region: India / US
- Scope: SOC 2 (Security, Availability, Confidentiality)
Challenge
A signed-but-pending US enterprise contract required SOC 2 Type II. The client had no attestation, no evidence-collection process, and a compressed timeline.
- No SOC 2 attestation and no ISMS
- Enterprise deal blocked in security review
- No continuous evidence-collection process
- Compressed buyer timeline
Objectives
- Achieve SOC 2 Type I readiness fast, then Type II
- Map controls to the Trust Services Criteria
- Stand up continuous evidence collection
- Unblock the enterprise deal
Our Approach
1. Criteria Scoping
We selected the Trust Services Criteria the buyer required and scoped the ISMS boundary.
2. Controls & Evidence
Implemented and documented controls with evidence collection set up from day one for the Type II window.
3. Type I readiness
Reached Type I readiness quickly to give the buyer immediate assurance.
4. Type II & Audit Coordination
Ran the observation window and coordinated the attestation.
Solution
- Selected the Trust Services Criteria the buyer required and scoped the ISMS
- Implemented and documented controls with day-one evidence collection
- Reached Type I readiness quickly for immediate buyer assurance
- Ran the Type II observation window and coordinated the attestation
Results
- Enterprise deal unblocked from the security-review stage
- SOC 2 Type I readiness reached in weeks
- Continuous evidence-collection process established
- Clear path to a Type II report on the buyer's timeline
Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.
What We Delivered
- Trust Services Criteria scoping matched to actual customer commitments
- Control implementation plan with day-one evidence collection
- Policy and control documentation set mapped to the criteria
- Readiness assessment before the observation window
- Audit coordination with the CPA firm through to the report
The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.
Lessons Learned
- The observation window is unforgiving: a control implemented mid-window produces exceptions for every month before it — sequencing readiness before the window opens is the whole game.
- Deprovisioning was the sampled exception risk: leaver access reconciled monthly, not annually, is what clean Type II periods are made of.
- Scoping only the criteria the buyer actually required kept the programme proportionate — categories can be added at the next examination.
Talk to the team that ran this engagement
This was a real SOC 2 Readiness & Attestation engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.
Explore SOC 2 readiness · more case studies
Liked the case study? Share on:


