ISO 27001, SOC 2 & DPDP documentation toolkits
The documents each framework actually requires — mandatory records, policies and registers — as tailorable starter templates you can build from. Written by a CERT-In empanelled, PCI QSA-authorised firm; every template is CyberSigma’s own original content.
Enter your work email and we’ll unlock the Excel + PDF instantly.
ISO/IEC 27001:2022
The full ISMS set: Scope, Information Security Policy, Risk Assessment & Treatment processes, Statement of Applicability, Risk Treatment Plan, Objectives, Internal Audit, Management Review, 12 Annex A policies and 5 registers.
SOC 2 (Trust Services Criteria)
Readiness set: System Description, TSC Control Matrix, and policies for access, change, incident response, vendor management, risk, availability and confidentiality — mapped to CC1–CC9.
DPDP Act 2023 + Rules 2025
Data Fiduciary set: Privacy Notice, RoPA, Consent Management, Data Principal Rights, Breach Response, Retention & Erasure, Processor Agreement, Children’s Data — with consent, rights and breach registers.
Templates get you started — we get you certified
These templates give you the right structure — the documents the standard mandates and the sections each must cover. The work that earns the certificate is tailoring them to your environment, running the risk assessment, implementing the controls and evidencing them. That’s where our assessors come in: we complete these documents with you and take you through to a clean audit.
These are original CyberSigma templates provided as-is for your own use. They are not a substitute for the ISO/IEC or AICPA standards, which must be licensed from their publishers, nor for professional advice.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
