Compliance guides
Plain English guides to the frameworks that matter.
Written by the people who run the assessments rather than by a content team. Each one answers a question we are actually asked, and points at the tool or checklist that does the work.
ISO 27001
- ISO 27001 certification process and timeline in IndiaWhat the stages are, how long each takes, and what determines the earliest defensible date.Open it
- SOC 2 or ISO 27001, which do you need?They answer different questions for different buyers. Pick on what your customers ask for.Open it
- Check your ISO 27001 readiness in five questionsA short survey covering the management system and the evidence behind the controls.Open it
- The evidence an auditor will actually ask forMapped control by control, so you find the gaps in month two rather than at the closing meeting.Open it
PCI DSS
- PCI DSS 4.0: what changed and what to doThe customised approach, targeted risk analysis, and why scope still decides the cost.Open it
- Am I even in scope? Check in four questionsConnected-to systems expand scope further than most people expect.Open it
- What a PCI DSS engagement costsWhere the money goes, and the one change that reduces it permanently.Open it
- Which SAQ applies to youEligibility turns on how you handle account data, not on your size.Open it
SOC 2
- SOC 2 audit cost and timeline in IndiaThe observation window is the part that sets your date, not the control work.Open it
- Type I or Type II, and how long a windowType I tests design on a date. Type II tests whether controls operated across a period.Open it
- Choosing Trust Services CriteriaSecurity is mandatory. The other four are a commercial decision, not a technical one.Open it
VAPT and penetration testing
- How to choose a VAPT provider in IndiaThe questions that separate a manual assessment from a scan with a cover page.Open it
- CERT-In empanelled or not, and when it mattersEmpanelment is a floor rather than a ceiling. Where the rules require it, nothing else is accepted.Open it
- Price your test scope yourselfRole count and integration surface drive the number more than codebase size.Open it
- Read a sample report before you buy oneThe deliverable is the thing you are actually purchasing, and it is usually seen too late.Open it
DPDP and data privacy
- DPDP Act compliance checklistEvery obligation broken into concrete checks with an owner and an evidence type.Open it
- How ready are you? Five questionsInventory, retention, consent, rights and breach notification, scored honestly.Open it
- What could this cost you?Penalty heads, how the Board weighs them, and which mitigations move the number.Open it
- Sequencing a DPDP programmeThe intuitive order is close to the worst one. Inventory gates everything else.Open it
Regulatory and strategy
- RBI cyber security expectationsSupervision now tests governance and evidence more than control existence.Open it
- SEBI CSCRF, trackedResilience rather than only security, with recovery that has to be demonstrated.Open it
- Continuous compliance or annual auditsEvidence with a time dimension cannot be produced retrospectively, which decides this for you.Open it
- One control set, many frameworksBuild the control once, evidence it once, map the same artefact to each framework.Open it
- Where every reporting clock runsCERT-In, the Data Protection Board and your sectoral regulator, on three different timelines.Open it
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












