Skip to content
Pillar 01 · Compliance & Risk · Powered by dcomply

The regulatory back-office
that scales with you.

DPDP, SOC 2, ISO 27001, VAPT, POSH, CERT-In, RBI and SEBI compliance — delivered by named CAs, CSs and DPOs on the dcomply platform. Fixed-price retainers, not surprise invoices.

₹250 CrMax DPDP penalty
6 hrsCERT-In reporting SLA
60–80%Cost reduction vs in-house
Named DPOOn every account

The Digital Personal Data Protection Act 2023 made India one of the most consequential privacy jurisdictions in the world. Penalties go up to ₹250 crore per violation. The compliance window closes in May 2027. Most Indian businesses — including businesses that think they are not touching personal data — fall under scope the moment they take an email address or a phone number.

Enterprise buyers, meanwhile, are refusing to sign without SOC 2 Type II or ISO 27001. Banks demand DPDP certificates before releasing credit lines. RBI and SEBI are tightening master directions every quarter. The CERT-In 6-hour breach-reporting window is not a suggestion.

Running this in-house means a Chief Compliance Officer, a Data Protection Officer, two or three analysts, a security engineer, auditor fees and a lot of overtime. For most companies under ₹500 crore in revenue, that is three to five times what the problem is worth.

Cosmoura runs compliance as a retainer. A named lead — CA, CS or DPO depending on the framework — owns your account. Our in-house SaaS platform dcomply.in automates evidence collection, policy versioning and buyer-questionnaire response. Our sister concern Decipher Consultancy Services builds the AI tooling that handles the repetitive bits. You get regulator-grade compliance without a regulator-grade cost base.

DPDP deadline: The Act is in force. Rules are being notified in phases. Significant Data Fiduciary classification is coming. Prepare now; retrofit later costs 4–6× more.

Eight services. One compliance partner.

DPDP is where most clients start. Add SOC 2, ISO 27001 and sector-specific packs as your buyers and regulators demand them.

Featured · Deadline May 2027

DPDP Readiness

from ₹25,000

Done-for-you Digital Personal Data Protection Act compliance in 15–30 days. Gap assessment, personal-data mapping, consent architecture, vendor review and DPAs, policies, employee training. Live on dcomply platform for ongoing rights-request handling.

  • 12-point gap audit against DPDP Act 2023
  • Personal-data map + record of processing activities
  • Consent flow design (web, app, in-person)
  • Vendor DPA negotiation + sub-processor register
DPDP-ready in 30 days · board sign-off ready Discuss →

Ongoing

Virtual DPO Service

from ₹2,499/mo

A named Data Protection Officer on retainer. Rights-request handling (access, correction, deletion), breach response within statutory windows, monthly compliance reporting, regulator liaison. The DPO role, without the full-time hire.

  • Named DPO with 5+ years privacy experience
  • Rights-request SLA: 72h acknowledgement
  • Breach response + CERT-In coordination
  • Monthly privacy posture report to board
DPO coverage without a ₹30L hire Discuss →

Audit-ready

SOC 2 Readiness

from ₹3,00,000

SOC 2 Type I and Type II preparation. Policy drafting (TSC-aligned), evidence collection via dcomply, control mapping, auditor coordination. We take you from zero to audit-ready in 90 days, then run the Type II observation window with you.

  • Type I in 60–75 days, Type II in +90 days
  • 64 TSC-mapped policies drafted + reviewed
  • Evidence collection automated via dcomply
  • Big-4 and boutique auditor coordination
Clean audit report · enterprise sales unlocked Discuss →

Certification

ISO 27001 / 27701

from ₹2,50,000

ISMS build-out, Statement of Applicability, risk register, internal audit, management review, and certification body coordination. ISO 27701 (privacy extension) layered on top where DPDP + GDPR scope demands it.

  • ISMS scoping + boundary definition
  • Risk register + treatment plan + SoA
  • Internal audit + management review cycle
  • Certification body liaison (BSI, DNV, TÜV)
ISO 27001 certified · common-controls layered Discuss →

Security

VAPT & Pen Testing

from ₹50,000

Web, mobile, infrastructure and API penetration testing by CERT-In empanelled partners. OWASP + CIS benchmarked. Fix-verify cycles included. Report in the format your buyer or regulator actually wants.

  • Web app + mobile + API + infra VAPT
  • CERT-In empanelled testing partners
  • Fix-verify cycles until clean report
  • Reports for ISO / SOC 2 / RBI / buyer-ask
Clean VAPT · 30 days end to end Discuss →

Industry-regulated

RBI / SEBI / IRDAI Packs

quote-driven

Sector-specific compliance for NBFCs, PA-PGs, PPIs, Account Aggregators, AMCs, brokers and insurers. Master directions mapped to controls. Monthly / quarterly returns filed. Scrutiny and inspection response support.

  • Master direction mapping (category-specific)
  • Monthly / quarterly return filing
  • Inspection + scrutiny response support
  • Category-change applications (PA to PA-PG, etc.)
Regulator-grade compliance · zero drift Discuss →

Workplace

POSH & Labour Law

from ₹35,000

Internal Complaints Committee setup, external member appointment, mandatory POSH training (English + Hindi + regional), annual report filing. Shops & Establishment, Factories Act, and state-specific labour returns.

  • ICC constitution + external member panel
  • Annual POSH training (3 modes available)
  • Annual report to district officer
  • State labour returns + S&E compliance
POSH + labour compliant · zero notice risk Discuss →

Incident

CERT-In Reporting

from ₹25,000

Breach notification setup within 6-hour statutory window. Log retention policy (180 days), incident response playbooks, tabletop exercises, VAPT scheduling. On-call coordination when something actually fires.

  • 6-hour breach reporting workflow setup
  • 180-day log retention architecture
  • Incident response playbook library
  • Quarterly tabletop exercises + on-call support
Breach-ready · 6-hour window hit, every time Discuss →

Twelve weeks to audit-ready.

The schedule compresses for DPDP-only engagements (4–6 weeks) and extends for multi-framework engagements (16–20 weeks).

01

Discovery + gap audit

Week 1

We walk your current state against the framework you need to comply with — DPDP Act, SOC 2, ISO 27001, or sector-specific regulation. Interviews with engineering, HR, finance, legal and vendor management. Written gap report with risk-prioritised action list.

  • Interviews with 6–10 stakeholders
  • Document + policy review
  • Written gap report with heat map
02

Scope, plan, policies

Week 2–4

Scope statement locked. 12-week deliverable calendar signed off. Policy library drafted (DPDP: ~15 policies; SOC 2: ~40 policies; ISO 27001: ~45 policies + SoA). Risk register populated. Control-to-evidence mapping started.

  • 12-week deliverable calendar
  • Full policy library drafted
  • Risk register + treatment plan
03

Implementation + evidence

Week 4–12

Controls implemented across engineering, HR, vendor and infrastructure. Evidence collected into dcomply platform (automated where possible). Employee training rolled out. Vendor DPAs renegotiated. Breach response tabletop run.

  • Control implementation (weekly cadence)
  • Evidence automation via dcomply
  • Employee + vendor + infra sign-offs
04

Audit + ongoing retainer

Week 12+

External auditor engaged (for SOC 2 / ISO 27001) or regulator coordination (for DPDP / sector-specific). After certification, retainer continues at a reduced rate — rights-request handling, continuous monitoring, annual re-certification prep.

  • Auditor / regulator coordination
  • Ongoing Virtual DPO service
  • Annual recertification prep built in

In-house. Traditional consultant. Cosmoura.

Honest comparison on cost, speed, coverage and the parts most consultants quietly skip.

In-house team Traditional consultant Cosmoura retainer
DPO role ₹25–40L/yr full-time hire Not offered Named DPO from ₹2,499/mo
Multi-framework (SOC 2 + ISO + DPDP) 18+ months typical Sequential — 24 months Parallel tracks — 6–9 months
Evidence collection Manual spreadsheets Shared drive upload Automated via dcomply platform
Breach response SLA Depends on team Business hours only 6-hour window, on-call 24×7
Buyer questionnaire response 2–3 days per questionnaire Case-by-case Answer library · 24h turnaround
Cost (SOC 2 + ISO + DPDP) ₹60L+/yr fully loaded ₹35–50L one-time + hourly ₹25–35L one-time + ₹5L/yr retainer
Regulator liaison Legal team handles Added fee Included — DPO is your face

Three structural advantages, not three promises.

01

DPO role, done for you.

The DPDP Act requires a named DPO for Significant Data Fiduciaries. We give you one on retainer from ₹2,499 a month, with the same training and accountability as a full-time hire.

02

Common controls, mapped once.

SOC 2, ISO 27001 and DPDP share roughly 60% of their controls. We map them once and run three parallel audit tracks. Cuts your total compliance effort by ~40%.

03

Platform, not just paperwork.

Evidence collection runs on dcomply.in — our in-house compliance platform. Automated collection, auditor-ready exports, buyer questionnaire answer library. You do not maintain a spreadsheet.

Everything you get in the retainer.

Named compliance lead on your account (CA / CS / DPO)
Monthly compliance calendar with reminders and deliverables
Access to dcomply platform for your team (self-serve + dashboards)
Quarterly review call with action list and risk register
Document templates — policies, DPAs, SOPs, consent forms
Audit coordination with external auditors and regulators
Dedicated Slack / WhatsApp channel with your team
48-hour SLA on day-to-day questions during business hours

Questions compliance teams ask us.

01 How is Cosmoura different from a traditional compliance consultant? +

Our back-office runs on Decipher AI and the dcomply platform. That means we deliver the same quality a traditional CA/CS firm does, at 3–4× the throughput and 60–80% lower cost per deliverable. You still get senior human signoffs on everything.

02 Can you handle multiple frameworks at once (SOC 2 + ISO 27001 + DPDP)? +

Yes — this is the most common engagement. We map overlapping controls once and run parallel audit tracks, which cuts your overall effort by roughly 40% versus sequential projects. Typical multi-framework engagement runs 6–9 months end to end.

03 Do you provide the auditor, or just the readiness work? +

We prepare you fully and coordinate with external auditors / regulators of your choice. For SOC 2 and ISO 27001 we have preferred audit partners we can introduce; for RBI/SEBI/CERT-In we work with your appointed authorities.

04 What happens after the initial engagement? +

Most clients move onto a monthly retainer (Virtual DPO + ongoing compliance management) starting from ₹25,000/month. This handles rights requests, policy updates when regulations change, quarterly reviews and audit renewals.

05 Do you work with businesses outside Delhi NCR? +

Yes — our delivery is fully online across India. On-site training and workshops are available in NCR, Mumbai, Bangalore and Hyderabad on request.

06 Is this legal advice? +

No. We provide compliance implementation and documentation services. For specific legal disputes or interpretations, consult your appointed legal counsel.

07 What is a Significant Data Fiduciary (SDF) under DPDP? +

An SDF is a data processor classified by the Data Protection Board as significant based on volume, sensitivity, risk and critical infrastructure impact. SDFs must appoint a DPO (not a Virtual DPO), conduct annual data protection impact assessments, and submit to annual audits. We prepare clients ahead of SDF notification.

08 Can you handle breach response if something actually happens? +

Yes. We maintain an on-call rota, run quarterly tabletop exercises, and coordinate CERT-In reporting within the 6-hour statutory window. Breach retainer is included in Growth tier and above.

Start your DPDP + SOC 2 journey.
Audit-ready in 12 weeks.

Free 30-minute compliance audit. We benchmark your current posture against DPDP, SOC 2 and your sector regulator, then come back with a sequenced plan.