Skip to main content

Open resource, CC BY 4.0

India compliance registry

Every cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.

The table itself

This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.

Showing 24 of 24 rows

ObligationRegulatorWho it bindsWhat triggers itConsequence
Reasonable security practicesMeitYAny body corporate handling sensitive personal dataHolding SPDI as defined in the 2011 RulesCompensation to the affected person under section 43A
Six hour incident reportingCERT-InService providers, intermediaries, data centres, body corporates, governmentBecoming aware of a reportable incidentPenalty under section 70B(7) of the IT Act
180 day log retention in IndiaCERT-InAll entities in scope of the 2022 DirectionsOperating ICT systemsNon-compliance treated as failure to comply with the Direction
NTP synchronisation to NIC or NPLCERT-InAll entities in scope of the 2022 DirectionsOperating ICT systemsSame as above
Customer records for five yearsCERT-InData centre, VPS, cloud and VPN providersProviding those servicesSame as above
KYC and transaction recordsCERT-InVirtual asset service providers and exchangesProviding virtual asset servicesSame as above
Notice and consentDPDP BoardEvery Data FiduciaryProcessing personal data of a Data PrincipalUp to 250 crore per the Schedule
Breach notificationDPDP BoardEvery Data FiduciaryA personal data breachUp to 250 crore
Children's data dutiesDPDP BoardFiduciaries processing data of under 18sProcessing children's dataUp to 200 crore
Significant Data Fiduciary dutiesDPDP BoardThose notified as SDFNotification by the Central GovernmentUp to 150 crore
Cyber Security FrameworkRBIScheduled commercial banksBeing a regulated bankSupervisory action
Digital Payment Security ControlsRBIBanks and payment operatorsOffering digital payment productsSupervisory action
IT outsourcing controlsRBIRegulated entities outsourcing ITMaterial IT outsourcingSupervisory action
Cyber Security and Cyber Resilience FrameworkSEBIMarket infrastructure and intermediariesSEBI registration categoryEnforcement and reporting obligations
System auditSEBIRegistered intermediariesRegistration category and sizeEnforcement
Information and cyber security guidelinesIRDAIInsurers and intermediariesIRDAI registrationSupervisory action
Rail specific security certificationNPCIMembers on UPI, IMPS, RuPayConnecting to the railLoss of certification for the rail
AUA and KUA auditUIDAIAuthentication and eKYC user agenciesHolding AUA or KUA licenceLicence suspension
Aadhaar data protectionUIDAIAnyone handling Aadhaar numbersStoring or using AadhaarPenalties under the Aadhaar Act
Telecom licence security conditionsDoTLicensed telecom operatorsHolding a telecom licenceLicence action
Subscriber data protectionTRAITelecom service providersHolding subscriber dataRegulatory action
Power sector cyber requirementsCEAGrid connected power entitiesConnection to the gridRegulatory direction
Protected system obligationsNCIIPCEntities with designated protected systemsDesignation under section 70Penalties under section 70
GIGW conformanceMeitY and STQCGovernment websites and applicationsBeing a government digital serviceCertification withheld

Applicability is a legal question and this is a starting point, not advice. Where a row looks like it applies to you, read the instrument itself before acting.

Where the facts come from

Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.

  • Bare Acts and the gazette notifications, cited by section
  • Regulator master directions and circulars, cited by number and date
  • CERT-In advisories as published

What people use it for

Working out which rules actually apply to you before you start building a compliance programme around the wrong ones.

Licence

Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.

Why one registry, rather than a page per regulator

Most Indian organisations of any size are bound by more than one instrument, and the obligations overlap in ways that are invisible if you read each one separately. A bank is under RBI supervision, the CERT-In Directions, the DPDP Act, and probably PCI DSS. A listed fintech adds SEBI's framework. A hospital adds health data considerations on top of DPDP.

Read individually, each produces a compliance programme. Read together, they produce roughly one programme with several reporting paths, because the underlying controls are largely the same: know your assets, control access, retain logs, detect incidents, report them, and be able to prove all of it.

This registry exists to make that overlap visible, so you build the control once and evidence it once.

The obligations that catch organisations out

Log retention. The CERT-In Directions require 180 days, maintained within India. Audits fail here more often than on the reporting clause, because retention is a budget decision made years ago by somebody who has left. Two questions worth asking today: do your logs cover the systems that would matter in an intrusion, and is the retention actually in India.

Multiple incident clocks. Reportable incidents go to CERT-In within six hours of noticing. Personal data breaches carry a separate DPDP obligation to the Board and to affected individuals. Supervised entities have their own regulator expectations on top. One detection process, three reporting paths.

Third party accountability. Outsourcing moves the work and not the accountability, under RBI supervision and under the DPDP Act alike. Contracts that predate these instruments almost never carry the obligations forward.

Retention of personal data. The DPDP Act requires you not to keep it past its purpose, which is where most estates are out of compliance today, because deleting data requires knowing where it is.

How to use the registry

Identify which instruments bind you, which is less obvious than it sounds. The CERT-In Directions have no small organisation exemption. The DPDP Act applies to processing digital personal data in India regardless of sector.

Then map each obligation to a control you already have, rather than to a new one. Most of what these instruments require is already partly in place; the gap is usually evidence rather than capability.

Then identify the single owner for each obligation. Where an obligation has no plausible owner, that is the finding. The commonest failure is IT, security and legal each assuming one of the others holds it.

Keeping it current

This is a live area. DPDP rules continue to develop, sectoral regulators issue and revise directions, and the frameworks themselves version.

Two habits keep a compliance register honest. Attach a source and a date to every obligation, so you can tell what has been checked recently. And review it on a fixed cadence rather than when something changes, because you will not hear about everything that changes.

Where an obligation's detail is still pending, record that explicitly rather than leaving a gap. A register that distinguishes not applicable from not yet defined is considerably more useful in a board conversation.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.