Skip to content
⚙️ Industry pack · SaaS · IT Services · Global

SOC 2, ISO 27001, DPDP + GDPR.
Buyer-questionnaire ready.

SOC 2 Type II, ISO 27001, DPDP + GDPR, USD invoicing, FIRC collection, SEIS and SOFTEX filings, buyer-questionnaire turnaround and trademark + patent for Indian SaaS and IT services firms selling to global buyers.

SOC 2Type I + Type II prep
27001ISMS + certification
GDPRDPA + EU rep ready
48hQuery SLA

For Indian SaaS and IT services firms selling to global buyers, compliance is a sales enabler, not a cost centre. Enterprise buyers in the US, EU and APAC refuse to sign without SOC 2 Type II or ISO 27001. Procurement teams send 200-item buyer questionnaires (VSAQ, CAIQ, SIG, SIG-Lite) that take weeks to answer. European customers demand GDPR Data Processing Agreements and Standard Contractual Clauses. UK customers want a UK representative. A single blocked deal because of a compliance gap can cost multiples of a year of compliance spend.

At the same time, Indian SaaS and IT services firms are Indian legal entities. DPDP Act applies to Indian data processing. FEMA governs USD invoicing and FIRC collection. SEIS and SOFTEX need monthly STPI filings. LRS and ODI tracking matters for founders with international earnings. Ind-AS 115 revenue recognition is non-trivial for SaaS subscription models.

Running this split — compliance in one hemisphere, finance in another — is where most firms break. Compliance team does not know what FIRC is. Finance team does not know what a VSAQ is. Legal team is somewhere else again. The founder ends up personally stitching the whole thing together, which is the most expensive version of all three functions.

Cosmoura runs the full SaaS and IT services back-office as one retainer. Named DPO plus named CA plus named CS plus named IP attorney on your account. SOC 2 + ISO 27001 + DPDP + GDPR with common controls mapped once. USD invoicing + FIRC + SEIS + SOFTEX in one book. Trademark India + Madrid Protocol in one portfolio. Decipher Consultancy Services (our sister concern) builds the buyer-questionnaire answer library and the evidence collection automation. One operating group, one invoice, one point of contact when a deal is on the line.

Trigger moment: A $5M enterprise deal just stalled on a SOC 2 Type II requirement. A European customer asked for your GDPR Data Processing Agreement and you don't have one. Your SEIS claim for last financial year is still unfiled. The procurement team at your biggest buyer just sent a 180-item security questionnaire. If one or more of these is open — call us this week.

Three profiles we build the pack around.

The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.

01

Early-stage SaaS (seed to Series A)

DPDP consent + buyer-questionnaire readiness + early SOC 2 Type I prep + ESOP + Delaware flip (if planned) + USD invoicing. From ₹25k–75k/mo. Focus on sales-unblocking.

02

Scale-stage SaaS + IT services

SOC 2 Type II + ISO 27001 + DPDP + GDPR parallel tracks. Virtual DPO. USD invoicing + FIRC + SEIS + SOFTEX. ESOP for 100+ grantees. Multi-geography customer DPA negotiation. Buyer questionnaire answer library.

03

Public-market-aspiration (pre-IPO)

ISO 27001 renewed, SOC 2 Type II on continuous observation, Ind-AS 115 revenue recognition clean, cap table hygiene, ESOP tax clarity for grantees, SEBI ICDR preparation 18–24 months out.

Four regulatory realities we solve for.

SOC 2 + ISO 27001 for buyer questionnaires

Enterprise buyers (US, EU, APAC) require SOC 2 Type II or ISO 27001 before signing. We take you from zero to audit-ready in 90–120 days with common controls mapped across both frameworks.

DPDP + GDPR for European buyers

DPDP for India processing, GDPR for EU data subjects, UK GDPR for UK users. We draft DPAs, Standard Contractual Clauses, Transfer Impact Assessments, and set up EU representative plus UK representative where required.

USD invoicing + FEMA + SEIS / SOFTEX

Export invoicing templates, FIRC and BRC collection, SEIS registration, SOFTEX monthly filings via STPI, LRS tracking, ODI compliance for founders with international earnings. Avoid blocked remittances and FEMA notices.

Buyer security questionnaires

VSAQ, CAIQ, SIG, SIG-Lite, custom buyer questionnaires. We maintain your answer library, update after every audit cycle, and respond to incoming questionnaires within 24 hours with named engineering + security signoffs.

The retainer, mapped to SaaS & IT Services.

Each pack pulls from the right pillars. Pick one or bundle all four.

Hero · Audit-ready

SOC 2 + ISO 27001 pack

Compliance & Risk

ISMS build-out, 64-control TSC-mapped policy library, Type I in 60–75 days + Type II in +90 days, ISO 27001 Statement of Applicability, auditor coordination (Big-4 and boutique), buyer questionnaire answer library populated.

  • ISMS build-out + risk register + SoA
  • 64 TSC + 45 ISO policies drafted (shared controls)
  • Type I + Type II prep in parallel with ISO stages
  • Buyer questionnaire answer library
Audit-ready in 90 days · enterprise sales unlocked Explore →

Data Protection

DPDP + GDPR + data residency pack

Compliance & Risk

DPDP consent architecture for Indian processing, GDPR DPA plus Standard Contractual Clauses for EU buyers, EU representative and UK representative appointment, cross-border Transfer Impact Assessments, customer DPA negotiation playbook.

  • DPDP consent + ROPA for India processing
  • GDPR DPA + SCCs + Transfer Impact Assessment
  • EU + UK representative appointment
  • Customer DPA negotiation playbook
GDPR-ready · EU + UK sales flowing Explore →

Finance

SaaS finance pack

Finance & Accounting

ARR / MRR tracking with cohort breakdown, USD invoicing templates, FIRC and BRC collection and reconciliation, SEIS and SOFTEX monthly STPI filings, Ind-AS 115 revenue recognition for subscription models, deferred revenue schedule.

  • ARR / MRR with cohort + churn tracking
  • USD invoicing + FIRC collection + reconciliation
  • SEIS + SOFTEX monthly STPI filings
  • Ind-AS 115 revenue recognition + deferred revenue
USD books clean · SEIS claimed · FEMA compliant Explore →

IP

IP + trademark + patent pack

IP & Brand Protection

Trademark India plus Madrid Protocol (110+ countries), copyright for product UI and code, patent drafting for novel architecture, non-compete and IP assignment agreements for engineering team.

  • Trademark India + Madrid Protocol international
  • Copyright for product + marketing content
  • Patent drafting for novel architecture
  • Non-compete + IP assignment library
Global IP portfolio · engineering IP secured Explore →

Four weeks to a clean back-office.

Most new saas & it services clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.

01

Readiness + sales-blocker audit

Week 1–2

We walk your SOC 2 / ISO / DPDP / GDPR posture, review your last 3 months of buyer questionnaires (and what blocked deals), audit your USD invoicing and FIRC collection history, and check your SEIS / SOFTEX status. Written report with ranked sales-unblocking priorities.

  • SOC 2 / ISO / DPDP / GDPR gap audit
  • Buyer questionnaire blocker review
  • USD + FIRC + SEIS gap check
02

Policy + evidence buildout

Week 2–10

64 TSC-mapped policies drafted for SOC 2 + 45 ISO 27001 policies + 15 DPDP policies + GDPR DPA templates + SCCs — common controls shared across frameworks. Risk register built. Evidence collection started on dcomply platform. Buyer questionnaire answer library populated.

  • 124 policies drafted (common controls shared)
  • Risk register + treatment plan
  • Buyer questionnaire library populated
03

Audit + buyer release

Week 10–20

SOC 2 Type I audit completed, Type II observation window opened. ISO 27001 Stage 1 and Stage 2 audits. GDPR DPA and SCCs released to EU buyers. EU + UK representatives appointed. Buyer questionnaire turnaround SLA dropped to 24 hours.

  • SOC 2 Type I + Type II report
  • ISO 27001 certified
  • GDPR DPA + representatives live
04

Live + annual cadence

Ongoing

Continuous Type II observation evidence collection. Annual ISO 27001 surveillance audit. Annual SOC 2 Type II report. Continuous Virtual DPO coverage. Monthly SEIS + SOFTEX filing + FIRC collection + USD books close. Buyer questionnaire SLA on 24 hours.

  • Continuous Type II evidence collection
  • Annual ISO + SOC 2 + DPO coverage
  • Monthly SEIS + USD + FIRC cadence

Generic CA firm. Self-run team. Cosmoura.

Honest comparison on cost, coverage and the parts most firms quietly skip.

Generic CA firm Self-run team Cosmoura retainer
Named DPO + CA + CS + IP attorney Partner on paper only ₹60L+/yr fully loaded 4 named leads, direct contact
SOC 2 + ISO + DPDP + GDPR parallel Sequential projects 18+ months Parallel — 6–9 months
Buyer questionnaire turnaround Case-by-case 2–3 days typical 24-hour answer library
GDPR DPA + EU + UK rep Separate counsel Rare in-house In-house + ongoing
SEIS + SOFTEX + USD + FEMA Separate CA for FEMA In-house CA In-house, included
Trademark India + Madrid Separate IP firm External counsel In-house, included
Total cost (full stack) ₹25–40L/yr across vendors ₹60L+/yr fully loaded ₹8–20L/yr fixed retainer

Eight things we handle, every month.

Named DPO + CA + CS + IP attorney on your account
SOC 2 + ISO 27001 + DPDP common controls library
GDPR DPA + SCCs + EU representative + UK representative
Buyer questionnaire response library (VSAQ, CAIQ, SIG)
USD invoicing + FIRC collection + SEIS / SOFTEX
Ind-AS 115 revenue recognition for SaaS
Trademark India + Madrid Protocol filings
Dedicated Slack / WhatsApp channel with 48-hour SLA

Questions saas & it services teams ask us.

01 How quickly can you take us from zero to SOC 2 Type II for Indian SaaS? +

Type I in 60–75 days, Type II in another 90 days (minimum observation window). Total 5–6 months for first-time clients. Faster if you already have ISO 27001 — 60% of controls overlap.

02 Do you work with early-stage startups or only post-Series A SaaS firms? +

Both. Pre-seed startups usually start with DPDP + buyer questionnaire readiness (₹25–50k/mo). Series A+ adds SOC 2 + ISO 27001 (₹2–3L/mo). Scale-ups add Virtual DPO + GDPR + customer DPA negotiation (₹5L+/mo).

03 Can you handle GDPR + UK GDPR for European buyers from India? +

Yes. GDPR Data Processing Agreement, Standard Contractual Clauses, EU representative appointment, data transfer impact assessments, breach notification setup. We also handle UK GDPR + UK representative post-Brexit. For most Indian SaaS firms selling to EU/UK, this unblocks a tier of enterprise customers.

04 What about USD invoicing, FIRC and SEIS / SOFTEX for IT services? +

Export invoicing templates, FIRC / BRC collection, STPI registration, SOFTEX monthly filings, SEIS claim preparation, ODI / LRS tracking for founders. All included in the SaaS finance pack. For most IT services firms, SEIS claim alone recovers more than our annual fee.

05 How do you handle customer DPA negotiation for enterprise contracts? +

We maintain a library of pre-approved DPA clauses, standard SCC riders, and your preferred liability caps and audit terms. When a customer sends their own DPA, we redline against your position within 48 hours, flag open issues, and route to your legal counsel only for exceptions. Dramatically speeds enterprise contracting.

06 Can you handle Delaware flip or Cayman structure for US fundraise? +

Yes. End-to-end — Delaware incorporation, share swap, FEMA FC-TRS filing, ODI compliance for Indian shareholders, tax implications per DTAA, ESOP migration to US entity. Executed with your legal counsel and tax advisor; we are the project manager plus the Indian compliance signoff.

07 What is Ind-AS 115 revenue recognition and why does it matter for SaaS? +

Ind-AS 115 governs how revenue is recognised across time for subscription contracts. For annual contracts invoiced upfront, revenue is recognised monthly, with deferred revenue booked on the balance sheet. Getting this right matters for your audit, your Series A diligence, and your eventual IPO filing. We book it correctly from month one.

08 Do you handle IT services firms (not SaaS) with different compliance needs? +

Yes. IT services (staffing, project-based consulting, offshore development) has lighter compliance surface than SaaS but heavier FEMA + USD invoicing + MSA negotiation surface. We offer a tuned IT-services pack that drops the SaaS-specific revenue-recognition pieces and adds MSA + SOW library.

A retainer built for saas & it services.
Live in two weeks.

Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.