Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →
Governance, Risk & Compliance

Free GRC tools for Indian organisations.

ISO 27001, RBI IT Framework, and DPDP Act compliance tools built around Indian regulatory requirements — not generic global frameworks.

Indian regulatory context

The compliance landscape Indian security teams are navigating

Indian organisations in regulated sectors face a layered compliance environment that most global GRC frameworks do not adequately address. The tools on this platform are built around Indian-specific requirements rather than mapping to generic global controls.

CERT-In Directions 2022

Mandatory for all organisations operating in India. Key requirements: 6-hour incident notification window for 20 specified incident types, log retention in India for 180 days minimum, NTP time synchronisation, designated point of contact for CERT-In correspondence.

RBI Master Directions

IT Framework (2021) for banks and NBFCs. Mandatory CISO with direct Board reporting line. SOC requirement. Regular VAPT by CERT-In empanelled organisations. Data localisation for payment data. Mandatory DR testing and BCP. Quarterly Board cybersecurity reporting.

DPDP Act 2023

Digital Personal Data Protection Act — India's primary data privacy law. Data Fiduciaries must: obtain valid consent, maintain records of processing, respond to data principal requests, notify Data Protection Board of breaches, and appoint a Data Protection Officer if designated a Significant Data Fiduciary.

SEBI CSCRF 2024

Cyber Security and Cyber Resilience Framework for all SEBI-regulated entities — stockbrokers, AMCs, portfolio managers, depositories. Risk-based tier categorisation. VAPT frequency by tier. CISO independent Board reporting. Incident notification to SEBI for significant incidents.

ISO 27001:2022

The international standard for information security management systems. 93 Annex A controls across 4 themes — updated in 2022 to include controls for threat intelligence, cloud security, ICT supply chain, and data masking. Widely required in enterprise vendor contracts and government supplier frameworks in India.

IRDAI Cybersecurity Guidelines

Insurance Regulatory and Development Authority of India cybersecurity guidelines for life and general insurance companies. Covers: information security governance, access management, network security, data protection, and incident response — largely aligned with CERT-In requirements.

Frequently asked

GRC compliance questions

Which compliance framework should an Indian IT company prioritise first?

The answer depends on your customer base and sector. If you sell to enterprise clients, ISO 27001 certification is the most commonly required credential — it unlocks contracts with large Indian enterprises and MNCs that require their suppliers to be certified. If you are in the BFSI sector (banking, insurance, capital markets), RBI/SEBI/IRDAI sector-specific requirements are mandatory — you have no choice. CERT-In Directions 2022 apply to every organisation operating in India regardless of sector. DPDP Act 2023 applies to any organisation processing personal data of Indian residents. In practice: start with CERT-In readiness (fastest to implement, lowest cost, mandatory), then ISO 27001 if enterprise sales are a priority, then sector-specific frameworks.

What does the RBI IT Framework require for the CISO role specifically?

The RBI IT Framework is explicit: the CISO must be a designated full-time role, not an additional charge to another position. The CISO must not report to the CTO or CIO — they must have an independent reporting line directly to the Board or a Board committee. The rationale is to prevent security concerns from being filtered through operational leadership who may have competing priorities. The CISO must present a quarterly cybersecurity status report to the Board covering the threat landscape, significant incidents, VAPT findings and remediation status, and the security programme roadmap. Banks that have a person with the CISO title but reporting to the CTO do not meet this requirement.

Is ISO 27001 certification mandatory for Indian companies?

ISO 27001 certification is not legally mandatory for any category of Indian organisation — unlike CERT-In compliance or RBI IT Framework compliance. However, it has become effectively mandatory in practice for IT services companies, software product companies, and BPOs serving large enterprise clients, because enterprise procurement requires it. The Government of India's MEITY has encouraged ISO 27001 adoption but not mandated it. The upcoming National Cybersecurity Policy and potential future DPDP Rules may change this picture — organisations with ISO 27001 certification will be significantly better positioned for any future mandatory requirements. The checklist on this platform helps whether you are pursuing certification or simply using ISO 27001 as a self-assessment framework.

What is a Significant Data Fiduciary under the DPDP Act?

The DPDP Act 2023 creates a higher-obligation category called Significant Data Fiduciary (SDF). The government designates specific organisations as SDFs based on: volume of personal data processed, sensitivity of data, risk to data principals, potential impact to national security, and the organisation's market influence. SDFs have additional obligations beyond standard Data Fiduciaries: mandatory appointment of a Data Protection Officer (DPO) based in India, mandatory appointment of an independent data auditor, and periodic Data Protection Impact Assessments (DPIAs). As of 2024, the government had not yet published the list of designated SDFs — this will emerge once the DPDP Rules are finalised. Large social media platforms, major data brokers, and significant financial data processors are widely expected to be designated.