Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India

  • Home
  • Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India
Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India
Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India
Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India
Fortinet SOCaaS Explained — FortiGuard SOC-as-a-Service in India

P J Networks · Fortinet partner, Delhi NCR

Fortinet SOCaaSWhat FortiGuard SOC-as-a-Service actually covers — and what an Indian enterprise still has to solve

FortiGuard SOC-as-a-Service gives you Fortinet’s own analysts watching your telemetry around the clock, triaging alerts and escalating verified incidents with response recommendations attached. It is a capable, properly certified detection service, and for an estate standardised on Fortinet it deploys in days.

This page is the explainer we wish existed when clients ask us about it. Every capability below is taken from Fortinet’s own published documentation — the SOCaaS data sheet, the ordering guide and the current product documentation — rather than from a sales conversation. Where the service stops, we say so, and where an Indian obligation begins, we say that too. We are a Fortinet partner; we are not going to pretend the product does things it does not, because you would find out later and at a worse moment.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The service level

The Fortinet SOCaaS SLA, and what the clock actually measures

Fortinet publishes escalation targets by severity. These are the published figures — and the header on Fortinet’s own table is the part worth reading twice.

Severity Escalation target How it reaches you
CriticalP1 15 minutes Portal alert and email notification
HighP2 45 minutes Portal alert and email notification
MediumP3 90 minutes Portal alert and email notification
LowP4 6 hours Portal alert and email notification

Alert escalation is defined by Fortinet as the notification response time when an alert is detected, delivered as a portal alert and email notification. The commitment is therefore to tell you, quickly and reliably, within those windows. It is not a commitment to contain the threat — that is a different product, covered below. Service requests carry a separate three-business-day target.

You may also see an older Fortinet solution brief promising notification “within 15 minutes” without qualification. That wording predates the current matrix, where 15 minutes applies to Critical severity only. If a quote you are reading cites the unqualified figure, ask which document it came from.

Two products, one name

Fabric Monitoring vs Multi-Vendor Monitoring

This is the distinction that decides whether SOCaaS fits your estate, and it is the one most often skipped. “Fortinet SOCaaS” refers to two different delivery models with different analytics platforms, different licences and very different onboarding timelines.

FABRIC MONITORINGFortinet estate only · onboards in daysFortiGate / SASEFortiEDR, FortiWebFortiAnalyzeron-prem or CloudMULTI-VENDOR MONITORINGseparate licence · 1 GB/day per seat · 10–15 business days per vendorCisco, Palo Alto,AWS, Azure, Okta…Collector+ agents / APIFortiSIEManalytics tierFortiGuard SOCaaSmonitor · triage · escalateBoth paths end at the same service — which escalates rather than contains, retains logs 90 days by default, and has no India data centre.That boundary, not the diagram, is what an Indian buyer has to plan around.

Fabric Monitoring

Fortinet estate

FortiAnalyzer — on-premises or Cloud — is the analytics platform, and only FortiGate may route logs through it directly.

Onboarding. Days. Fortinet describes onboarding as typically taking only a few days.

Licensing. Bundled per device against the monitored product’s SKU.

Multi-Vendor Monitoring

Fortinet plus third-party

FortiSIEM is the analytics platform, which brings its full connector catalogue — Cisco, Check Point, CrowdStrike, Palo Alto, AWS, Azure, Okta and several hundred more.

Onboarding. 10–15 business days for simple vendors, and case-specific for more complex ones.

Licensing. A separate licence, metered at 1 GB per day per seat.

So the answer to “does Fortinet SOCaaS support third-party devices?” is a genuine yes — the FortiSIEM connector catalogue behind Multi-Vendor Monitoring runs to several hundred sources. The caveat is commercial and operational rather than technical: it is a separate licence, metered per seat by data volume, and each vendor takes its own onboarding cycle. For a heterogeneous estate the arithmetic often lands closer to an MSSP-operated SIEM; for a Fortinet-standardised one, Fabric Monitoring is hard to beat on speed.

Requirements

What SOCaaS integrates with

The supported product list, with the version floors and the one omission that catches people out.

Supported

FortiGate

Version 6.4.5 or later.

Supported

FortiAnalyzer

Version 6.4.5 or later. Mandatory analytics tier for Fabric Monitoring.

Supported

FortiSASE

SOCaaS is included with the Advanced and Comprehensive tiers.

Supported

FortiClient EMS, FortiEDR, FortiEndpoint

FortiEDR monitoring requires that network is already monitored — FortiSASE or at least one FortiGate.

Supported

FortiWeb and FortiAppSec Cloud

Licensed against their own SKUs.

Not supported

FortiMail

Email security is not part of the SOCaaS integration list. If email is your main threat vector — and for most Indian enterprises it still is — that telemetry needs monitoring somewhere else.

Scope boundaries

What Fortinet SOCaaS does not do

None of these are defects. They are the documented edges of the service, and knowing them before you sign is the difference between a good decision and a surprise during an incident.

Escalation, not containment

Fortinet defines the response element of SOCaaS as advisory: remote assistance following a verified event notification, and recommendations for remediation and containment. The data sheet is consistent, describing the deliverable as an analysis, verdict, severity and incident response guidance. Autonomous containment requires the separately purchased Managed FortiGate Service, which acts on FortiGate only and needs your authorisation per change unless you opt into blanket pre-authorisation.

Logs are retained for 90 days by default

Stated in Fortinet’s own service-overview FAQ. This is the single most consequential number for an Indian buyer, and we come back to it below.

The reports are operational, not regulatory

The published catalogue is six weekly operational reports covering SOC monitoring, threat protection, configuration tuning, logging, device health and application control. There is no PCI, ISO, SEBI or CERT-In formatted report in the catalogue, and no incident-filing workflow.

The SLA clock ends at the notification

Fortinet is precise about this: the metric is alert escalation, defined as notification response time when an alert is detected, delivered as a portal alert and email. What happens after the email arrives is yours to own.

India, specifically

Four things to resolve before SOCaaS satisfies an Indian regulator

Fortinet’s documentation is global, so it does not speak to CERT-In, SEBI or the RBI. These are the four points where the service scope and Indian obligations meet — and the last one is good news.

Retention

90 days by default, against a 180-day rule

CERT-In’s Directions of 28 April 2022 require that logs be maintained “for a rolling period of 180 days and the same shall be maintained within the Indian jurisdiction”. SOCaaS retains 90 days by default. Both halves of that clause need answering, and the practical resolution is to keep an India-resident system of record — typically a FortiAnalyzer you own — and treat SOCaaS as a detection overlay on top of it.

Residency

No India data centre for SOCaaS

Fortinet lists its SOC data centres as Burnaby, Plano, Nice, Paris, Madrid, Frankfurt, Prague, Singapore, Tokyo and Sydney. FortiAnalyzer Cloud likewise has no India region. FortiSASE does have Indian points of presence including Bengaluru, Pune, Delhi and Mumbai — but once SOCaaS is enabled, those logs are forwarded onward to a SOCaaS data centre. Fortinet raises this itself: its onboarding checklist asks which region logs will be forwarded from and notes that data sovereignty may be impacted.

The clock

A six-hour obligation met by a six-hour notification

CERT-In requires specified incidents to be reported “within 6 hours of noticing such incidents”. A Low-severity alert under Fortinet’s matrix carries a six-hour escalation target — which can consume the entire regulatory window before anyone at your organisation has read the email. The obligation to determine, draft and file remains yours, and nothing in SOCaaS produces an Annexure-I formatted report.

Certification

This one Fortinet passes — with a caveat

Worth stating plainly because the opposite is often assumed: SOCaaS is named in the scope of Fortinet’s ISO/IEC 27001:2022 certificate, and Fortinet also holds ISO 27017, ISO 27018 and a SOC 2 report. Where SEBI expects an outsourced SOC provider to be certified for the services outsourced to it — mandatory for market infrastructure institutions, and recommended rather than mandatory for Qualified REs since the technical clarification of 28 August 2025 — Fortinet meets it. The residual question is jurisdictional rather than certificational: the certified entity is Fortinet Technologies Canada, with no India-resident audited facility.

The full set of Indian reporting deadlines, each mapped to its instrument, is on our six-hour clock page, and the retention and evidence requirements are covered under compliance services.

Where we fit

How a local SOC complements it

We are a Fortinet partner and we are not trying to talk you out of Fortinet technology. The question worth answering is which parts of the operation you want a partner in India to own.

India-resident retention

A rolling 180 days held within Indian jurisdiction, as CERT-In requires, with your FortiAnalyzer or our platform as the system of record.

The filing, not just the alert

Someone who owns the six-hour clock end to end — determining whether it is reportable, drafting it and filing it — rather than handing you a notification and a deadline.

Estates that are not all Fortinet

Most real networks are mixed. We monitor Fortinet alongside Cisco, Dell, Palo Alto and Sophos on one platform — see technology partners and our SOC as a Service model.

P J Networks analysts monitoring a mixed Fortinet and multi-vendor estate from the Delhi NCR operations floor
Where the escalations land — our floor, Delhi NCR

If your estate is standardised on Fortinet, your obligations are light and you want the fastest path to 24×7 coverage, FortiGuard SOCaaS on its own may genuinely be the right answer. We would rather tell you that than sell you something larger. Where it usually is not enough is a mixed estate, a regulated sector, or an organisation that needs the reporting workflow owned rather than advised. Our Fortinet practice covers the product side, and our SOC service covers the operations side.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

Fortinet SOCaaS, answered

What is Fortinet SOCaaS?

FortiGuard SOC-as-a-Service is Fortinet’s subscription security operations service. Fortinet’s analysts monitor your telemetry around the clock, triage the alerts, and escalate verified incidents to you through a portal and by email, with response recommendations attached. Its documented scope covers four areas: monitoring and detection, investigation and analysis, containment and response guidance, and service reporting. It is a detection and escalation service rather than a service that acts on your network.

What is the Fortinet SOCaaS SLA?

Fortinet publishes escalation targets by severity: 15 minutes for Critical, 45 minutes for High, 90 minutes for Medium and 6 hours for Low, each delivered as a portal alert and an email notification. Service requests carry a three-business-day target. The important nuance is what the clock measures — Fortinet defines it as notification response time from detection, so the SLA is met when the email is sent, not when the threat is contained.

Does Fortinet SOCaaS support non-Fortinet devices?

Yes, under the Multi-Vendor Monitoring model, and the capability is genuine rather than nominal. That model uses FortiSIEM as the analytics platform, so every data source and connector FortiSIEM supports becomes available — several hundred, including Cisco, Check Point, CrowdStrike, Palo Alto, AWS, Azure and Okta. Three things to plan for: it is a separate licence metered at 1 GB per day per seat, it requires collectors and often agents to be deployed, and Fortinet quotes 10 to 15 business days to onboard a simple vendor, longer for complex ones. The Fabric Monitoring model, by contrast, covers Fortinet products only.

Does Fortinet SOCaaS include incident response?

It includes response guidance, not response execution. Fortinet defines the containment and response element as remote assistance and recommendations following a verified event notification. To have someone actually change a configuration or block traffic on your behalf you need the Managed FortiGate Service, purchased separately, which acts on FortiGate devices only and requires your authorisation for each change unless you grant blanket pre-authorisation.

How long does Fortinet SOCaaS retain logs?

Ninety days by default, per Fortinet’s service-overview FAQ. For Indian organisations this matters because CERT-In requires a rolling 180 days retained within Indian jurisdiction. The gap is normally closed by keeping your own India-resident FortiAnalyzer as the system of record, with SOCaaS layered on for detection.

Is Fortinet SOCaaS enough for CERT-In compliance?

Not on its own, and this is a scope question rather than a criticism of the product. Three things sit outside it: retention defaults to 90 days against a 180-day requirement, there is no India data centre for the service, and the SLA ends at a notification while the obligation to determine, draft and file within six hours stays with you. Organisations generally pair SOCaaS with India-resident retention and a partner who owns the reporting workflow. That is the arrangement we most often build.

What does Fortinet SOCaaS cost?

Fortinet does not publish list pricing for SOCaaS, and we are not going to invent a figure. What is documented is the licensing structure: Multi-Vendor Monitoring is its own SKU metered at 1 GB per day per seat, the FortiGate add-on is licensed per device with each member of an HA pair needing its own licence, and SOCaaS is included with the Advanced and Comprehensive tiers of FortiSASE. FortiFlex and FortiPoints are supported for FortiGate SOCaaS. Pricing is available through a Fortinet partner against your device list.

Which Fortinet products does SOCaaS monitor?

FortiGate and FortiAnalyzer from version 6.4.5, plus FortiClient EMS, FortiSASE, FortiEDR, FortiEndpoint, FortiWeb and FortiAppSec Cloud. FortiMail is not on the supported list, so email telemetry needs to be monitored elsewhere. FortiEDR monitoring also carries a dependency: it is only available if network is already monitored, meaning FortiSASE or at least one FortiGate.

Fortinet SOCaaS or a managed SOC from an Indian provider?

It depends on how uniform your estate is and how much of the compliance workflow you want to own. For an estate standardised on Fortinet, SOCaaS is a strong, well-certified detection layer that deploys in days. For a genuinely mixed estate, the multi-vendor route means a separate licence, per-seat data metering and a much longer onboarding, at which point an MSSP-operated SIEM is often simpler and cheaper. And where CERT-In retention, Indian data residency and six-hour filing are live obligations, most organisations end up wanting an India-resident partner in the loop regardless. We are happy to tell you when SOCaaS alone is the right answer — for some of our Fortinet-standardised clients, it is.

Next step

Work out whether SOCaaS covers you, or only part of you

Send us your device list and your sector. We will tell you which SOCaaS model fits, what it would leave uncovered, and whether you need anything from us at all.

P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com

Fortinet, FortiGuard, FortiGate, FortiAnalyzer, FortiSIEM, FortiSASE and FortiEDR are trademarks of Fortinet, Inc. This page is independent explanatory material prepared by P J Networks Pvt Ltd, a Fortinet partner, and summarises Fortinet’s published documentation as at July 2026. Product scope and service levels change — verify against Fortinet’s current data sheet and ordering guide before purchase.