HR software security checklist for Indian buyers: VAPT, ISO 27001, SOC 2, DPDP and CERT-In
An HR software security checklist for Indian buyers: what to ask about VAPT, ISO 27001, SOC 2, DPDP, CERT-In reporting and data residency, and what to accept.
Last checked 6 min read
HR software holds the most sensitive data a company keeps about its people: salaries, bank accounts, PAN and Aadhaar, medical leave, disciplinary records. Yet in many evaluations the security questions come last, in a spreadsheet sent the week before signing. This HR software security checklist is meant to be used earlier, when you still have a choice. It is neutral: the same questions apply to every vendor, including us.
HR software security checklist: ask for documents
Ask for evidence, not adjectives. A vendor that says "bank-grade security" and cannot share a certificate, a test letter or a contract clause has not answered the question. The items below each have a document you can ask for.
1. A CERT-In empanelled VAPT
A vulnerability assessment and penetration test is the first thing most Indian enterprise and government buyers ask for, and for good reason: it is an outside expert trying to break in.
Ask for a CERT-In empanelled VAPT, meaning one done by an organisation on CERT-In's list of empanelled information security auditors, and check:
- Date. Within the last twelve months, and after any major release.
- Scope. The web application, the APIs and the mobile apps you will use. For a multi-company cloud product, tenant isolation (can one customer see another's data?) should be in scope.
- Closure. A retest or closure letter showing the high and critical findings were fixed. A report full of open findings is not a pass.
CERT-In's cyber security audit guidelines of July 2025 expect a full audit at least once a year and after significant changes. Vendors usually share a summary letter rather than the full report; that is reasonable.
2. ISO 27001 for SaaS vendors
ISO 27001 for SaaS vendors shows that the company runs an information security management system with risk assessment, controls, internal audits and management review. Check three things on the certificate:
- Version. Only ISO/IEC 27001:2022 certificates are current; the transition from the 2013 version ended on 31 October 2025.
- Scope. It should name the product and the hosting, not only an office or a different business line.
- Certification body. It should be accredited, by NABCB in India or another member of the International Accreditation Forum. You can look certificates up on the IAF's public database. Cheap certificates from unaccredited bodies do exist.
ISO/IEC 27701, the privacy management standard, is a useful addition for a product that holds personal data at this scale.
3. SOC 2 Type II report
A SOC 2 report is an attestation by a licensed CPA firm against the trust services criteria. Type I looks at the design of controls on one date. A SOC 2 Type II report looks at whether they actually operated over a period, usually six to twelve months. If your parent company or your clients are in the US, they will probably ask for Type II. Indian enterprises usually accept ISO 27001 instead. Read the auditor's exceptions section; that is where the real findings are.
4. DPDP readiness
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (notified on 13 November 2025, with most duties applying from 13 May 2027), your company is the data fiduciary for employee data and the HR vendor is usually your data processor. The duties are yours; the contract has to pass them down. Look for a data processing agreement that covers:
- the security safeguards the Rules require: encryption or masking, access control, logging and monitoring, backups;
- breach notice to you quickly enough that you can inform the Data Protection Board and affected employees without delay and send the detailed report within 72 hours;
- retention and deletion when the contract ends, with a certificate;
- a current list of sub-processors (hosting, email, SMS, messaging), with notice of changes;
- help with employee requests: access, correction, erasure.
The HR side of these duties, including how much Aadhaar data you actually need, is in the DPDP Act post for HR.
5. CERT-In reporting duties
The CERT-In Directions of 28 April 2022 apply to service providers and body corporates generally, including SaaS vendors. Ask how the vendor meets them:
- 6-hour reporting of the listed cyber incidents to CERT-In from the time they are noticed;
- logs kept for a rolling 180 days within India;
- clocks synchronised with the NIC or NPL time servers, or a traceable source;
- a point of contact registered with CERT-In.
A vendor that does not know these exist has not read the rules its own customers are bound by.
6. Data residency in India
Data residency in India is partly law and partly policy. The DPDP Act allows transfers abroad except to countries the government restricts, and CERT-In requires certain logs in India. Many buyers, especially banks, insurers and public sector companies, require India hosting as policy anyway. Ask:
- Which cloud region holds production data, and where are backups kept?
- Which sub-processors handle data outside India, and for what?
- Can support staff outside India see your data?
- For government buyers: is the hosting on a MeitY-empanelled cloud?
7. Everyday controls you can test in a trial
Not everything needs a certificate. In a trial, check for yourself: single sign-on, two-factor authentication, role-based access down to field level for salary and bank details, an audit log you can read, export controls, session time-outs, and what the mobile app does if a phone is lost. Shared admin passwords are a common weak point in HR and IT teams; we covered how to handle them in shared password management for IT teams.
A worked example: scoring three vendors
A 900-employee textile group in Coimbatore shortlisted three HR vendors and scored them out of 10 on evidence only.
| Item | Vendor A | Vendor B | Vendor C |
|---|---|---|---|
| VAPT within 12 months, closure letter | 2 | 2 | 0 (2023 report) |
| ISO 27001:2022, product in scope | 2 | 1 (office only) | 2 |
| SOC 2 Type II | 0 | 0 | 1 |
| DPA with breach notice and sub-processors | 2 | 1 | 1 |
| CERT-In duties explained | 1 | 0 | 1 |
| India hosting and backups | 1 | 1 | 1 |
| Total | 8 | 5 | 6 |
The group did not need SOC 2, so Vendor A's zero there did not matter. Vendor B's ISO certificate covered only its office, which is a common surprise.
What not to accept
- A certificate you cannot verify, or one from an unaccredited body.
- A VAPT older than a year, or one that excludes the mobile app.
- "We are DPDP compliant" without a data processing agreement.
- A refusal to name sub-processors.
Security is one part of a wider evaluation; our HRMS guide for manufacturing covers the rest. If Vatsin HRMS is on your list, our security page describes how the product handles access, logging and data; put the same questions to us as to every other vendor. Have your own IT or legal team review the contract terms.