Open resource, CC BY 4.0
India compliance registry
Every cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.
The table itself
This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.
Showing 24 of 24 rows
| Obligation | Regulator | Who it binds | What triggers it | Consequence |
|---|---|---|---|---|
| Reasonable security practices | MeitY | Any body corporate handling sensitive personal data | Holding SPDI as defined in the 2011 Rules | Compensation to the affected person under section 43A |
| Six hour incident reporting | CERT-In | Service providers, intermediaries, data centres, body corporates, government | Becoming aware of a reportable incident | Penalty under section 70B(7) of the IT Act |
| 180 day log retention in India | CERT-In | All entities in scope of the 2022 Directions | Operating ICT systems | Non-compliance treated as failure to comply with the Direction |
| NTP synchronisation to NIC or NPL | CERT-In | All entities in scope of the 2022 Directions | Operating ICT systems | Same as above |
| Customer records for five years | CERT-In | Data centre, VPS, cloud and VPN providers | Providing those services | Same as above |
| KYC and transaction records | CERT-In | Virtual asset service providers and exchanges | Providing virtual asset services | Same as above |
| Notice and consent | DPDP Board | Every Data Fiduciary | Processing personal data of a Data Principal | Up to 250 crore per the Schedule |
| Breach notification | DPDP Board | Every Data Fiduciary | A personal data breach | Up to 250 crore |
| Children's data duties | DPDP Board | Fiduciaries processing data of under 18s | Processing children's data | Up to 200 crore |
| Significant Data Fiduciary duties | DPDP Board | Those notified as SDF | Notification by the Central Government | Up to 150 crore |
| Cyber Security Framework | RBI | Scheduled commercial banks | Being a regulated bank | Supervisory action |
| Digital Payment Security Controls | RBI | Banks and payment operators | Offering digital payment products | Supervisory action |
| IT outsourcing controls | RBI | Regulated entities outsourcing IT | Material IT outsourcing | Supervisory action |
| Cyber Security and Cyber Resilience Framework | SEBI | Market infrastructure and intermediaries | SEBI registration category | Enforcement and reporting obligations |
| System audit | SEBI | Registered intermediaries | Registration category and size | Enforcement |
| Information and cyber security guidelines | IRDAI | Insurers and intermediaries | IRDAI registration | Supervisory action |
| Rail specific security certification | NPCI | Members on UPI, IMPS, RuPay | Connecting to the rail | Loss of certification for the rail |
| AUA and KUA audit | UIDAI | Authentication and eKYC user agencies | Holding AUA or KUA licence | Licence suspension |
| Aadhaar data protection | UIDAI | Anyone handling Aadhaar numbers | Storing or using Aadhaar | Penalties under the Aadhaar Act |
| Telecom licence security conditions | DoT | Licensed telecom operators | Holding a telecom licence | Licence action |
| Subscriber data protection | TRAI | Telecom service providers | Holding subscriber data | Regulatory action |
| Power sector cyber requirements | CEA | Grid connected power entities | Connection to the grid | Regulatory direction |
| Protected system obligations | NCIIPC | Entities with designated protected systems | Designation under section 70 | Penalties under section 70 |
| GIGW conformance | MeitY and STQC | Government websites and applications | Being a government digital service | Certification withheld |
Applicability is a legal question and this is a starting point, not advice. Where a row looks like it applies to you, read the instrument itself before acting.
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- Bare Acts and the gazette notifications, cited by section
- Regulator master directions and circulars, cited by number and date
- CERT-In advisories as published
What people use it for
Working out which rules actually apply to you before you start building a compliance programme around the wrong ones.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- DPDP compliance timelineWhat the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.Open it
- India incident reporting mapOne incident can trigger four different reporting duties on four different clocks. This shows you all of them on one page.Open it
Why one registry, rather than a page per regulator
Most Indian organisations of any size are bound by more than one instrument, and the obligations overlap in ways that are invisible if you read each one separately. A bank is under RBI supervision, the CERT-In Directions, the DPDP Act, and probably PCI DSS. A listed fintech adds SEBI's framework. A hospital adds health data considerations on top of DPDP.
Read individually, each produces a compliance programme. Read together, they produce roughly one programme with several reporting paths, because the underlying controls are largely the same: know your assets, control access, retain logs, detect incidents, report them, and be able to prove all of it.
This registry exists to make that overlap visible, so you build the control once and evidence it once.
The obligations that catch organisations out
Log retention. The CERT-In Directions require 180 days, maintained within India. Audits fail here more often than on the reporting clause, because retention is a budget decision made years ago by somebody who has left. Two questions worth asking today: do your logs cover the systems that would matter in an intrusion, and is the retention actually in India.
Multiple incident clocks. Reportable incidents go to CERT-In within six hours of noticing. Personal data breaches carry a separate DPDP obligation to the Board and to affected individuals. Supervised entities have their own regulator expectations on top. One detection process, three reporting paths.
Third party accountability. Outsourcing moves the work and not the accountability, under RBI supervision and under the DPDP Act alike. Contracts that predate these instruments almost never carry the obligations forward.
Retention of personal data. The DPDP Act requires you not to keep it past its purpose, which is where most estates are out of compliance today, because deleting data requires knowing where it is.
How to use the registry
Identify which instruments bind you, which is less obvious than it sounds. The CERT-In Directions have no small organisation exemption. The DPDP Act applies to processing digital personal data in India regardless of sector.
Then map each obligation to a control you already have, rather than to a new one. Most of what these instruments require is already partly in place; the gap is usually evidence rather than capability.
Then identify the single owner for each obligation. Where an obligation has no plausible owner, that is the finding. The commonest failure is IT, security and legal each assuming one of the others holds it.
Keeping it current
This is a live area. DPDP rules continue to develop, sectoral regulators issue and revise directions, and the frameworks themselves version.
Two habits keep a compliance register honest. Attach a source and a date to every obligation, so you can tell what has been checked recently. And review it on a fixed cadence rather than when something changes, because you will not hear about everything that changes.
Where an obligation's detail is still pending, record that explicitly rather than leaving a gap. A register that distinguishes not applicable from not yet defined is considerably more useful in a board conversation.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












