SOC Service Providers in India — How to Choose One

  • Home
  • SOC Service Providers in India — How to Choose One

Vendor selection · India · Updated September 2026

SOC service providers in IndiaHow to shortlist one, what to ask, and which credentials actually prove what they appear to prove

Choosing a security operations provider in India is mostly an exercise in telling apart claims that sound identical. Every shortlist you assemble will say 24×7, AI-driven, SIEM-backed and CERT-In aligned. This guide sets out the criteria that separate those claims, in the order a buyer should apply them.

It is written so that it can be used against us as well as against our competitors. Where P J Networks does not meet a criterion, we say so on this page rather than leaving you to discover it in procurement.

A disclosure, up front. P J Networks is itself a SOC provider. This is not a neutral league table and you should not read it as one — we are one of the companies you would be evaluating. What we have published instead are the criteria we are willing to be measured against, including the ones where our own answer is no. If you read only one section, read Empanelment, certification, and what each one actually proves.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The landscape

The five kinds of provider you will actually meet

Almost every shortlist drawn up in India is a mix of these five. They are not tiers of quality — each is the right answer for some buyer — but they fail in different and fairly predictable ways, and the failure mode is what you are really selecting between.

Provider type Usually suits Good at Where it strains Tell-tale sign
Global MSSP Multinationals, market infrastructure institutions Genuine follow-the-sun coverage, mature process, deep threat intelligence, surge capacity for a major incident. India-specific reporting is often bolted on rather than native. At mid-market size you are a small account on a large panel. Your named analyst changes every quarter and sits in another country.
Indian pure-play MSSP Mid-market to large Indian enterprise CERT-In, SEBI and RBI reporting are native rather than translated. Analysts in your timezone, and a commercial conversation you can actually have. Depth varies enormously between firms with near-identical websites. Some are resellers with a SIEM licence and a small roster. Ask how many analysts the firm employs, not how many people the group employs.
IT-services SOC arm Existing outsourcing customers Bundles into an infrastructure contract you already hold. Procurement is straightforward and commercially efficient. Security competes with infrastructure for the same people and the same budget. The SOC may be a line item rather than a practice. The head of the SOC reports into an infrastructure P&L.
Boutique or regional specialist SMB, single-site, one regulated function Responsive, often strong sector knowledge, and you deal with people who know your estate by name. Round-the-clock cover rests on a thin roster. Key-person risk is real and surge capacity is limited. Ask who covers the 02:00 shift on Diwali, by name.
Product-vendor SOC Organisations standardised on one vendor The deepest possible knowledge of that vendor’s stack, and detections written by the people who wrote the product. Coverage stops where the vendor’s telemetry stops. Anything outside the estate is someone else’s problem. The detection catalogue maps to the product, not to your estate.

Scroll the table sideways on a narrow screen.

A practical shortlist has three names drawn from at least two of these categories. Three is enough to price against and few enough to run a real technical evaluation on; five produces a spreadsheet nobody reads. Drawing from two categories stops you comparing five versions of the same trade-off.

Credentials

Empanelment, certification, and what each one actually proves

This is where most Indian SOC evaluations go wrong, and it goes wrong in the buyer’s favour surprisingly rarely. Three credentials get quoted constantly on provider websites. Each proves something real, and none of them proves what it is usually used to imply.

Often misread

CERT-In empanelment is an auditor panel, not a SOC panel

The scheme is titled Empanelment of Information Security Auditing Organisations, and its terms and conditions (version 7.2, April 2024) qualify a firm to perform information security audits. The document is explicit that an auditor is contracted by the customer directly and that CERT-In is not a party to that contract. It makes no mention of security operations centres, monitoring, or managed security services anywhere in its terms. An empanelled firm may well run an excellent SOC — but the empanelment is not evidence of it, and it is routinely presented as though it were.

Where we say no

P J Networks is not CERT-In empanelled

We do not hold CERT-In empanelment and we do not perform CERT-In audits. If your board, your regulator or your customer requires an audit signed by an empanelled auditor, engage one — that is a separate engagement from monitoring, and any provider who tells you their monitoring contract satisfies that requirement is wrong. We work alongside whichever auditor you appoint and supply the log evidence and incident records they ask for.

Read the scope

An ISO 27001 certificate is only as good as its scope statement

Ask for the certificate itself rather than the logo on the slide. The scope line names which parts of the business are covered, and a certificate scoped to a head office or a development centre says nothing about the operations centre that will be watching your network at night. P J Networks holds ISO/IEC 27001:2022 with the NOC and SOC inside the certified scope, which is the specific thing worth checking on any provider.

Does not exist

There is no licence to operate a SOC in India

No Indian authority licenses, accredits or approves managed security service providers or security operations centres as such. A provider implying that it is government-approved to run a SOC is describing something that does not exist. Treat that as information about how the rest of their claims are likely to be worded.

Different animal

SOC 1 and SOC 2 are not this kind of SOC

SOC 1 and SOC 2 are System and Organization Controls attestation reports, issued by a licensed CPA firm under the AICPA framework. A security operations centre is an operational team that watches your environment. The acronym collision costs buyers real time in procurement, and occasionally produces an RFP that asks a monitoring provider to issue an attestation report it cannot issue.

A fair claim

When empanelment genuinely is a reason to prefer a provider

If you are deliberately consolidating audit and monitoring with one firm to reduce vendor count, empanelment is a legitimate tiebreaker — for the audit half of the scope. Price and scope the two halves separately so you can see what each costs. And note the independence question that follows: the same firm is then auditing controls it operates itself, which some boards and some regulators will not accept.

Sources for this section: CERT-In, Empanelment of Information Security Auditing Organisations — Terms and Conditions for Empanelment, version 7.2, April 2024. The absence of any licensing regime for managed security providers in India is a statement about what does not exist in the statute book; if you believe you have found one, we would genuinely like to see it.

India specifics

The regulatory questions that only apply here

A global provider can be excellent at detection and still be the wrong answer for an Indian regulated entity, because the reporting obligations attach to you and are discharged on your clock. These are the four that come up most often, with the question worth asking about each.

Instrument Clock What it actually requires Ask the provider
CERT-In 6 hours Specified cyber incidents must be reported to CERT-In within six hours of noticing them — the clock starts at notice, not at confirmation. Logs must be maintained for a rolling 180 days and held within Indian jurisdiction.Direction No. 20(3)/2022, 28 April 2022 Who drafts and files the report, you or us? Show me a redacted one you have actually filed. Where do my logs physically sit for those 180 days?
SEBI Three models CSCRF recognises an own or group SOC, a Market SOC, and a third-party managed SOC. Small-size and self-certification regulated entities are directed onto the Market SOC rather than choosing freely. On ISO 27001 for a third-party SOC, the technical clarification of 28 August 2025 made certification encouraged and recommended, not mandatory, for Qualified REs; it remains mandatory for market infrastructure institutions.CSCRF; FAQ 11 June 2025; clarification 28 August 2025 Which of the three models does your proposal place us in, and does our RE category actually permit it?
RBI Promptly The binding requirement in the cyber security framework is to report promptly. The 2 to 6 hours figure that circulates in vendor decks comes from an annexure template heading rather than the operative requirement — do not write an SLA against it without reading your own circular.Verify the current text applicable to your entity class What is your contractual notification time to us in writing, and does it start at detection or at triage?
DPDP May 2027 The DPDP Rules, 2025 were notified in November 2025 and commence in phases across eighteen months. Consent-manager registration lands November 2026. The substantive obligations — reasonable security safeguards under Rule 6 and breach notification under Rule 7 — land May 2027. Rule 7 requires the Board to be told without delay and a detailed report within 72 hours, running continuously. Penalties reach ₹250 crore for failure to take reasonable security safeguards.DPDP Act 2023; DPDP Rules 2025, notified November 2025 This is not operative yet. What in your service changes in May 2027, and is that change inside the fee we are signing today?

Scroll the table sideways on a narrow screen.

Insurance, separately: IRDAI’s 2023 information and cyber security guidelines were superseded in April 2026. If a provider’s proposal still cites the 2023 document as current, that tells you when their compliance content was last reviewed, which is a more useful signal than the citation itself.

Dates here are stated as months. Published sources disagree on the exact day within each DPDP tranche, and a month is what an organisation actually plans against. Regulatory instruments change: verify the current text applicable to your own entity before writing any of this into an SLA — including anything on this page. Nothing here is legal advice.

Due diligence

Twelve questions that separate an operations centre from an alerting service

Any provider can answer a questionnaire. These are phrased so that a vague answer is visible as a vague answer, and they are ordered so the cheap disqualifiers come first.

1. Who employs the analysts?

Ask for headcount the provider directly employs, split by tier — not a group figure. Subcontracted tier-one is common and not disqualifying on its own; undisclosed subcontracting is.

2. Where do they physically sit at 02:00?

A named location and a published roster. If nights route to another country or another company, ask what the language, escalation path and authority are at that hour.

3. Which SIEM, and who owns the licence?

If the provider owns it, model what happens on exit. If you own it, model what happens when you change provider. Either is workable; not knowing which you signed is not.

4. How is ingest priced?

GB per day, events per second, per endpoint, or flat. Then ask what happens in the month a noisy log source doubles your volume. A surprise ingest bill is the single most common reason a SOC contract sours in year two.

5. What is the containment authority?

Precisely which actions the provider may take without waking you: isolate a host, disable an account, block an indicator, kill a session. Get the list in the contract. “We will notify you” is monitoring, not response.

6. Define the SLA metrics, then tell me the exclusions.

Time to alert is easy to hit and tells you almost nothing. Ask for time to verified incident. Then read the exclusions — maintenance windows, log-source outages and P3/P4 carve-outs are where the headline number is really made.

7. What is your detection engineering cadence?

Who writes new detections, how often, and what triggers one. A provider that cannot name a detection it shipped last quarter is running somebody else’s default rule set and calling it a service.

8. Show ATT&CK coverage as evidence, not a slide.

Ask for the techniques you are covered for and the list you are not. The second list is the honest one, it is the one that tells you where you are exposed, and most providers will not produce it.

9. Walk me through a P1 at 03:00 on a public holiday.

Minute by minute, with the person who would actually be on shift rather than the pre-sales lead. This one question tends to settle the evaluation.

10. Where do my logs live, for how long, under whose jurisdiction?

Then check that answer against the 180-day CERT-In requirement above, and against any retention rule your own regulator imposes. These are frequently different numbers.

11. What do I take with me if I leave?

The log archive in a documented format, the detection rules written for your estate, and the case history. Agree it at signature. It is close to unwinnable at exit, which is precisely when you will want it.

12. Give me a reference in my sector, at my size, that left you.

Every provider can produce a happy reference. The instructive twenty minutes is with a customer who churned, and a provider willing to arrange that call is telling you something real.

If you want the commercial half of this conversation — what the fee actually buys, what drives it up, and the build-it-yourself comparison — that is set out separately on SOC as a service pricing in India, and the delivery models are compared on managed SOC services.

What to watch for

Eight signals worth more than a reference call

Collected from procurement processes we have won, lost, and occasionally advised somebody to walk away from.

Claim

“Government approved” or “government certified” SOC

There is no such approval for a security operations centre in India. Whatever the provider means by it, the phrase describes a thing that does not exist.

Headcount

500+ security professionals

Almost always a group figure. Ask how many sit in the SOC that would serve you, on which shifts, on whose payroll. The gap between the two numbers is sometimes an order of magnitude.

Automation

AI-driven, with no stated mechanism

Ask which specific decisions are automated, on what data, and what happens when the model is wrong at 03:00. If the answer stays at slide level, the term is doing marketing work rather than operational work.

SLA

Time-to-alert as the only committed metric

An alert can be generated automatically in seconds and mean nothing at all. Without a commitment on verified incidents, you have bought a notification service.

Pricing

“Unlimited” log ingest

Either collection is being quietly capped somewhere, or the price resets at renewal once your true volume is known. Ask which, and get the answer in the contract.

Currency

Compliance content that has gone stale

A proposal citing IRDAI’s superseded 2023 guidelines, or presenting the DPDP 72-hour rule as though it binds you today, is a proposal nobody has reviewed recently.

Commitment

A pilot with no exit

A twelve-month lock on an unproven detection capability. If the provider is confident, a ninety-day break clause costs them nothing.

Good sign

A provider who tells you when to buy elsewhere

Rarer than it should be, and the strongest single signal available to you. A provider who names the cases where a competitor fits better is a provider who expects the relationship to outlast the first renewal.

Where we fit

Where P J Networks fits — and where we do not

Applying the criteria above to ourselves, in the same words we would use if you were applying them to somebody else.

What we are

An in-house NOC and SOC in New Delhi, operating since 2002. ISO/IEC 27001:2022 certified with the NOC and SOC inside the certified scope. Fifty-plus in-house NOC and SOC engineers, tiers one to three on our own payroll rather than subcontracted. Fortinet, Cisco, Netskope and Trellix estates run day to day.

What we are not

Not CERT-In empanelled, and not an audit firm — if you need an empanelled auditor, appoint one and we will work alongside them. Not a product vendor, so there is no platform of our own we need you to buy. Not the cheapest quote you will receive, and not a fit if what you want is a tooling subscription with no analyst attached to it.

When someone else is the better answer

If you are consolidating audit and monitoring into one firm, an empanelled auditor with a credible SOC will suit you better than we will. If you are a SEBI small-size or self-certification RE directed onto the Market SOC, that is your route and we will tell you so rather than sell around it. If your estate is genuinely single-vendor, that vendor’s own SOC has telemetry depth we cannot match.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

More detail, depending on what you are trying to decide: how our SOC runs day to day, SOC as a service for the subscription model, managed SOC services for the delivery variants, MSSP versus an in-house SOC for the build-or-buy case, MDR versus SOC as a service for the category question, outsourced SOC for Indian banks if you are regulated by the RBI, and SOC versus NOC if you are scoping both. Network operations are covered on NOC services.

Answered

Choosing a SOC provider in India, answered

Is P J Networks CERT-In empanelled?

No. P J Networks does not hold CERT-In empanelment and does not perform CERT-In audits. We have said so plainly on this page because the question comes up in most procurement processes and the honest answer is easier to check than to argue with. If your requirement is an audit signed by an empanelled auditor, appoint one — it is a different engagement from monitoring, and we will work alongside them and provide the log and incident evidence they request.

What does CERT-In empanelment actually cover?

It is a panel of information security auditing organisations. The scheme is titled Empanelment of Information Security Auditing Organisations, and its terms and conditions, version 7.2 of April 2024, qualify a firm to carry out information security audits. The terms state that an auditor is contracted directly by the customer and that CERT-In is not a party to that contract, and they make no reference to security operations centres, monitoring or managed security services. An empanelled firm may also run a strong SOC, but empanelment on its own is not evidence about monitoring capability.

Is a licence or accreditation needed to run a SOC in India?

No. No Indian authority licenses, accredits or approves managed security service providers or security operations centres as a category. If a provider implies it is government approved to run a SOC, it is describing something that does not exist, and that is worth weighing when you read the rest of their claims.

How many providers should I shortlist?

Three, drawn from at least two of the five provider types. Three gives you enough to price against and few enough to run a genuine technical evaluation on, including the 03:00 walkthrough. Five tends to produce a comparison spreadsheet that nobody finishes reading, and drawing them all from one category means you are comparing five versions of the same trade-off.

Does my SOC provider need to be ISO 27001 certified?

It depends on who regulates you, and the position changed recently. Under SEBI’s CSCRF, the technical clarification of 28 August 2025 made ISO 27001 certification of a third-party SOC encouraged and recommended rather than mandatory for Qualified REs, while it remains mandatory for market infrastructure institutions. Outside SEBI, treat it as a strong signal rather than a rule — and in every case ask for the certificate and read its scope statement, because a certificate that does not cover the operations centre tells you very little.

Can a provider outside India monitor an Indian entity?

Yes, and many do. The constraint is not on who watches but on where the evidence lives: the CERT-In direction of April 2022 requires logs to be maintained for a rolling 180 days within Indian jurisdiction. Establish early where log storage physically sits, because retrofitting that after go-live is expensive and it is the point on which offshore proposals most often come apart.

How long before a new provider is actually detecting anything?

First log sources typically ingest within days. Meaningful detection coverage takes weeks, and the constraint is tuning rather than integration — a platform freshly pointed at your network produces a great deal of noise, and the value arrives with the baselining that follows. Treat a promise of reliable detection on day one as a description of alerting.

What is the difference between a SOC provider and an MSSP?

In Indian procurement the terms are used almost interchangeably, and the distinction that matters is not the label but the scope. An MSSP historically managed security devices — firewalls, gateways, endpoint consoles — while a SOC provider monitors, investigates and responds. Many firms now do both. Ask which of the two you are actually buying, because a device-management contract with monitoring language in it is a common and expensive misunderstanding. The build-or-buy comparison is set out on our page covering an MSSP versus an in-house SOC.

Does the DPDP Act change how I should buy a SOC today?

Not yet, and be careful with any proposal that says otherwise. The DPDP Rules, 2025 commence in phases: consent-manager registration in November 2026, and the substantive obligations including reasonable security safeguards and breach notification in May 2027. The sensible position when signing today is to ask what changes in May 2027 and whether that change sits inside the fee you are agreeing now, rather than to buy against an obligation that is not yet operative.

Next step

Put these questions to us first

Send us the twelve questions above before you send them to anyone else. You will get written answers, including the two where the answer is no, and you can use them as the baseline for the rest of your shortlist.

P J Networks Pvt Ltd · New Delhi · sanjay@pjnetworks.com