Skip to content
Vatsin Workspace
Buying guides

HR software security checklist for Indian buyers: VAPT, ISO 27001, SOC 2, DPDP and CERT-In

An HR software security checklist for Indian buyers: what to ask about VAPT, ISO 27001, SOC 2, DPDP, CERT-In reporting and data residency, and what to accept.

Vatsin Workspace team

Last checked 6 min read

HR software holds the most sensitive data a company keeps about its people: salaries, bank accounts, PAN and Aadhaar, medical leave, disciplinary records. Yet in many evaluations the security questions come last, in a spreadsheet sent the week before signing. This HR software security checklist is meant to be used earlier, when you still have a choice. It is neutral: the same questions apply to every vendor, including us.

HR software security checklist: ask for documents

Ask for evidence, not adjectives. A vendor that says "bank-grade security" and cannot share a certificate, a test letter or a contract clause has not answered the question. The items below each have a document you can ask for.

1. A CERT-In empanelled VAPT

A vulnerability assessment and penetration test is the first thing most Indian enterprise and government buyers ask for, and for good reason: it is an outside expert trying to break in.

Ask for a CERT-In empanelled VAPT, meaning one done by an organisation on CERT-In's list of empanelled information security auditors, and check:

  • Date. Within the last twelve months, and after any major release.
  • Scope. The web application, the APIs and the mobile apps you will use. For a multi-company cloud product, tenant isolation (can one customer see another's data?) should be in scope.
  • Closure. A retest or closure letter showing the high and critical findings were fixed. A report full of open findings is not a pass.

CERT-In's cyber security audit guidelines of July 2025 expect a full audit at least once a year and after significant changes. Vendors usually share a summary letter rather than the full report; that is reasonable.

2. ISO 27001 for SaaS vendors

ISO 27001 for SaaS vendors shows that the company runs an information security management system with risk assessment, controls, internal audits and management review. Check three things on the certificate:

  • Version. Only ISO/IEC 27001:2022 certificates are current; the transition from the 2013 version ended on 31 October 2025.
  • Scope. It should name the product and the hosting, not only an office or a different business line.
  • Certification body. It should be accredited, by NABCB in India or another member of the International Accreditation Forum. You can look certificates up on the IAF's public database. Cheap certificates from unaccredited bodies do exist.

ISO/IEC 27701, the privacy management standard, is a useful addition for a product that holds personal data at this scale.

3. SOC 2 Type II report

A SOC 2 report is an attestation by a licensed CPA firm against the trust services criteria. Type I looks at the design of controls on one date. A SOC 2 Type II report looks at whether they actually operated over a period, usually six to twelve months. If your parent company or your clients are in the US, they will probably ask for Type II. Indian enterprises usually accept ISO 27001 instead. Read the auditor's exceptions section; that is where the real findings are.

4. DPDP readiness

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (notified on 13 November 2025, with most duties applying from 13 May 2027), your company is the data fiduciary for employee data and the HR vendor is usually your data processor. The duties are yours; the contract has to pass them down. Look for a data processing agreement that covers:

  • the security safeguards the Rules require: encryption or masking, access control, logging and monitoring, backups;
  • breach notice to you quickly enough that you can inform the Data Protection Board and affected employees without delay and send the detailed report within 72 hours;
  • retention and deletion when the contract ends, with a certificate;
  • a current list of sub-processors (hosting, email, SMS, messaging), with notice of changes;
  • help with employee requests: access, correction, erasure.

The HR side of these duties, including how much Aadhaar data you actually need, is in the DPDP Act post for HR.

5. CERT-In reporting duties

The CERT-In Directions of 28 April 2022 apply to service providers and body corporates generally, including SaaS vendors. Ask how the vendor meets them:

  • 6-hour reporting of the listed cyber incidents to CERT-In from the time they are noticed;
  • logs kept for a rolling 180 days within India;
  • clocks synchronised with the NIC or NPL time servers, or a traceable source;
  • a point of contact registered with CERT-In.

A vendor that does not know these exist has not read the rules its own customers are bound by.

6. Data residency in India

Data residency in India is partly law and partly policy. The DPDP Act allows transfers abroad except to countries the government restricts, and CERT-In requires certain logs in India. Many buyers, especially banks, insurers and public sector companies, require India hosting as policy anyway. Ask:

  • Which cloud region holds production data, and where are backups kept?
  • Which sub-processors handle data outside India, and for what?
  • Can support staff outside India see your data?
  • For government buyers: is the hosting on a MeitY-empanelled cloud?

7. Everyday controls you can test in a trial

Not everything needs a certificate. In a trial, check for yourself: single sign-on, two-factor authentication, role-based access down to field level for salary and bank details, an audit log you can read, export controls, session time-outs, and what the mobile app does if a phone is lost. Shared admin passwords are a common weak point in HR and IT teams; we covered how to handle them in shared password management for IT teams.

A worked example: scoring three vendors

A 900-employee textile group in Coimbatore shortlisted three HR vendors and scored them out of 10 on evidence only.

ItemVendor AVendor BVendor C
VAPT within 12 months, closure letter220 (2023 report)
ISO 27001:2022, product in scope21 (office only)2
SOC 2 Type II001
DPA with breach notice and sub-processors211
CERT-In duties explained101
India hosting and backups111
Total856

The group did not need SOC 2, so Vendor A's zero there did not matter. Vendor B's ISO certificate covered only its office, which is a common surprise.

What not to accept

  • A certificate you cannot verify, or one from an unaccredited body.
  • A VAPT older than a year, or one that excludes the mobile app.
  • "We are DPDP compliant" without a data processing agreement.
  • A refusal to name sub-processors.

Security is one part of a wider evaluation; our HRMS guide for manufacturing covers the rest. If Vatsin HRMS is on your list, our security page describes how the product handles access, logging and data; put the same questions to us as to every other vendor. Have your own IT or legal team review the contract terms.

Sources

Questions people ask

What is a CERT-In empanelled VAPT?

A vulnerability assessment and penetration test carried out by an organisation on CERT-In's list of empanelled information security auditors. Ask for the date, the scope (web, API, mobile apps), and a closure or retest letter showing the findings were fixed.

Is ISO 27001 or SOC 2 more important for an Indian HR software buyer?

Indian enterprises usually ask for ISO/IEC 27001:2022. SOC 2 Type II matters more to buyers with US parents or US clients. Either way, check that the certificate or report covers the product you are buying, not just an office.

What must an HR software vendor do under the DPDP Act?

The vendor is usually your data processor. You, as the data fiduciary, carry the duties, so your contract must pass them down: security safeguards, breach notice fast enough for you to meet the 72-hour detailed report, deletion at the end, and a list of sub-processors.

Does HR data have to be stored in India?

The DPDP Act allows transfers abroad except to countries the government restricts, and CERT-In requires certain logs to be kept in India. Many buyers still ask for India hosting as policy. Ask where the data, the backups and the support staff sit.

All posts

Book a free demo
HR software security checklist for Indian buyers: VAPT, ISO 27001, SOC 2, DPDP and CERT-In | Vatsin