Tenth Floor Labs

Secure — ISO 27001 & SOC 2 Readiness

ISO 27001 and SOC 2 readiness that gets you audit-ready, not buried in paperwork

We implement ISO/IEC 27001:2022 and prepare you for SOC 2 Type I and Type II audits. That means scoping, policies, risk assessment, evidence collection, an independent internal audit and coordination with your certification body or CPA firm. It suits SaaS and service companies selling to enterprises.

Mon–Sat · 9am–8pm IST
Starting from
₹1.25L
one-time · auditor fees paid directly
Timeline
8–16 weeks
typical
After launch
Annual surveillance-audit support, or a vCISO retainer to keep controls running
Maulik Gupta, Founder & Lead Engineer
Maulik Gupta
Founder & Lead Engineer · you'll talk to me

Sound familiar?

"Our US prospect won't sign without a SOC 2 Type II report and a pentest."

  • Enterprise customers keep asking for ISO 27001 or SOC 2, and deals are slipping.
  • We bought a compliance platform, but nobody has time to work through 300 tasks.
  • Consultants we spoke to quoted months of paperwork that doesn't match how we work.
  • We don't know which auditor to pick or what they'll actually check.
  • Our engineers fear that compliance will slow down every release.

Built for

B2B SaaS companies selling to US, European or Indian enterprisesIT services, BPO and KPO firms with global clientsFintech and health-tech companies needing formal security assuranceSuppliers to EU firms facing NIS2 or DORA requirementsStartups using Sprinto, Vanta or Drata who need hands-on helpCompanies renewing or upgrading to ISO 27001:2022

What we do

What's included in ISO 27001 & SOC 2 Readiness.

01

ISO 27001 Implementation

Scope, ISMS setup, risk assessment, risk treatment plan and Statement of Applicability for ISO/IEC 27001:2022, fitted to how you really work.

02

SOC 2 Type I & Type II Readiness

Mapping to the Trust Services Criteria, control design, a readiness check and support through the Type II observation period.

03

Security Policies & Procedures

A complete, readable policy set that satisfies both ISO 27001 and SOC 2, so you write each policy once.

04

Evidence Collection & Compliance Platforms

We set up and run Sprinto, Vanta or Drata (or a simple shared folder) and collect the evidence auditors ask for.

05

ISO 27001 Internal Audit

The internal audit required by clause 9.2, done by a team member independent of your implementation work, plus the management review.

06

Auditor Selection & Coordination

We help you choose an accredited certification body or CPA firm, prepare your team and support you through the audit itself.

Who delivers this

Senior security people, not juniors.

Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.

Principal Security Advisor

Leads this service
Serving CISO · 31+ years in technology

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting

ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Security & Compliance Partner

Advises
India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified

GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Pricing

Transparent packages. Fixed quotes.

Your final quote is fixed after a 20-minute call — no surprise bills.

ISO 27001 Implementation

₹1.25L
one-time · under ~50 staff · 10–14 weeks
  • Gap analysis and ISMS scope
  • Risk assessment and Statement of Applicability
  • Full policy and procedure set
  • Staff security awareness session
  • Independent internal audit and management review
  • Support through Stage 1 and Stage 2 audits
Get this quote

SOC 2 Type I Readiness

₹1.25L
one-time · 8–12 weeks
  • Trust Services Criteria scoping
  • Control design and policy set
  • Compliance platform setup and evidence
  • Readiness assessment before the audit
  • CPA firm selection and coordination
Get this quote
Recommended

SOC 2 Type II / ISO + SOC 2 Programme

₹5L+
scoped after a call
  • ISO 27001 and SOC 2 controls built once, mapped to both
  • Support through the SOC 2 Type II observation period
  • Monthly evidence reviews and control checks
  • Independent ISO 27001 internal audit
  • Coordination with the certification body and CPA firm
  • Pentest and vendor reviews planned in
Get this quote

Ongoing costs after launch

No surprises: here's everything you may pay every month, stated upfront.

With us

Annual surveillance-audit support, or a vCISO retainer to keep controls running

See all ongoing plans
Paid to third parties, at cost, no markup

Certification body / CPA auditor fees · compliance platform subscription

  • —Certification-body fees for ISO 27001 Stage 1, Stage 2 and surveillance audits are paid directly by you to the accredited body.
  • —CPA-firm fees for the SOC 2 Type I or Type II report are paid directly by you to the audit firm.
  • —Compliance platform subscriptions (Sprinto, Vanta, Drata or similar) are paid directly by you.
  • —A penetration test, often required as evidence, is quoted separately (see VAPT).
  • —Security tools needed to meet controls (for example, device management or endpoint protection) are paid directly by you.

Want a quick estimate for your exact project? Try the cost estimator.

Process

From first message to launch.

Clear stages, a live preview link every week, and payments tied to milestones you approve.

  1. Step 01Weeks 1–2

    Scoping & gap analysis

    We agree scope, pick ISO 27001, SOC 2 or both, and show your gaps with a fixed-price plan.

  2. Step 02Weeks 3–10

    Build the controls

    Policies, risk assessment, technical fixes and platform setup, done alongside your team without stopping releases.

  3. Step 03Weeks 8–14

    Evidence & internal audit

    We collect evidence and run an independent internal audit and readiness check, then close any findings.

  4. Step 04Weeks 12–16+

    External audit

    Your certification body or CPA firm audits you. We prepare your team and support you through every session.

Technology

Tools we trust.

ISO/IEC 27001:2022ISO/IEC 27002:2022SOC 2AICPA Trust Services CriteriaSprintoVantaDrataNIST CSF 2.0GDPRDPDP Act 2023

Our promises

Working with us is low-risk.

Fixed quote

A clear, fixed price after a 20-minute call. No surprise bills.

Pay in milestones

Projects: 40% to start, 30% on design approval, 30% at launch.

You own everything

Code, domain, ad accounts, WhatsApp number and data — in your name.

Weekly previews

See real progress on a live link every week, not just status updates.

30 days of free fixes

Anything not working as agreed after launch, we fix at no cost.

Talk to the builder

No account managers. You speak with the engineers doing the work.

FAQ

Questions, answered.

What decides the cost of ISO 27001 or SOC 2 readiness?+

Company size, the number of products, locations and cloud accounts in scope, how much is already in place and whether you want ISO, SOC 2 or both. Doing both together costs much less than two separate projects.

How long until we are audit-ready?+

Usually 8–16 weeks. A SOC 2 Type II report also needs an observation period, often 3–12 months, before the CPA firm can issue it. Many companies get a Type I report first to unblock deals.

Do you issue the ISO 27001 certificate or SOC 2 report?+

No. ISO 27001 certificates are issued only by accredited certification bodies, and SOC 2 reports only by licensed CPA firms. We do the implementation, readiness and internal audit, and coordinate with your chosen auditor. That separation is what makes the certificate credible.

Who does the internal audit if you also implement?+

ISO 27001 clause 9.2 requires internal auditors to be objective and impartial. So the internal audit is done by a member of our team who did not work on your implementation, and we can bring in an outside auditor if you prefer.

Do we need Sprinto, Vanta or Drata?+

Not always. They save time on evidence collection, especially for SOC 2 Type II. We help you decide, and set up whichever you choose. Subscriptions are paid directly by you.

Will you sign an NDA?+

Yes, before scoping starts. We work inside your systems and compliance platform where possible, so sensitive evidence stays with you.

What happens after the audit?+

ISO 27001 needs yearly surveillance audits and SOC 2 needs a fresh report each year. Our vCISO plans keep controls running and evidence fresh, so next year's audit is routine.

Let's scope your project.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us