Free GRC tools for Indian organisations.
ISO 27001, RBI IT Framework, and DPDP Act compliance tools built around Indian regulatory requirements — not generic global frameworks.
Compliance and risk tools
ISO 27001:2022 Control Checklist
All 93 Annex A controls across 4 themes — Organisational, People, Physical, and Technological. Track implementation status per control, filter by theme or status, and export to CSV for audit submissions. Progress saved in browser.
Open checklist → India — BFSIRBI IT Framework Checklist
Master Direction on IT Framework (2021) compliance tracker for scheduled commercial banks, UCBs, and NBFCs. 9 sections, 50+ requirements. Mandatory vs recommended tagged. Mandatory gap counter for audit readiness. Export to CSV.
Open checklist → India — DPDP ActDPDP Data Processing Register
Build a DPDP Act 2023 compliant Record of Processing Activities. Document processing purpose, lawful basis, data types, processors, retention, and DPIA notes for each activity. Tracks high-risk activities and cross-border transfers. Export CSV and JSON.
Open register →The compliance landscape Indian security teams are navigating
Indian organisations in regulated sectors face a layered compliance environment that most global GRC frameworks do not adequately address. The tools on this platform are built around Indian-specific requirements rather than mapping to generic global controls.
CERT-In Directions 2022
Mandatory for all organisations operating in India. Key requirements: 6-hour incident notification window for 20 specified incident types, log retention in India for 180 days minimum, NTP time synchronisation, designated point of contact for CERT-In correspondence.
RBI Master Directions
IT Framework (2021) for banks and NBFCs. Mandatory CISO with direct Board reporting line. SOC requirement. Regular VAPT by CERT-In empanelled organisations. Data localisation for payment data. Mandatory DR testing and BCP. Quarterly Board cybersecurity reporting.
DPDP Act 2023
Digital Personal Data Protection Act — India's primary data privacy law. Data Fiduciaries must: obtain valid consent, maintain records of processing, respond to data principal requests, notify Data Protection Board of breaches, and appoint a Data Protection Officer if designated a Significant Data Fiduciary.
SEBI CSCRF 2024
Cyber Security and Cyber Resilience Framework for all SEBI-regulated entities — stockbrokers, AMCs, portfolio managers, depositories. Risk-based tier categorisation. VAPT frequency by tier. CISO independent Board reporting. Incident notification to SEBI for significant incidents.
ISO 27001:2022
The international standard for information security management systems. 93 Annex A controls across 4 themes — updated in 2022 to include controls for threat intelligence, cloud security, ICT supply chain, and data masking. Widely required in enterprise vendor contracts and government supplier frameworks in India.
IRDAI Cybersecurity Guidelines
Insurance Regulatory and Development Authority of India cybersecurity guidelines for life and general insurance companies. Covers: information security governance, access management, network security, data protection, and incident response — largely aligned with CERT-In requirements.
GRC compliance questions
Which compliance framework should an Indian IT company prioritise first?
The answer depends on your customer base and sector. If you sell to enterprise clients, ISO 27001 certification is the most commonly required credential — it unlocks contracts with large Indian enterprises and MNCs that require their suppliers to be certified. If you are in the BFSI sector (banking, insurance, capital markets), RBI/SEBI/IRDAI sector-specific requirements are mandatory — you have no choice. CERT-In Directions 2022 apply to every organisation operating in India regardless of sector. DPDP Act 2023 applies to any organisation processing personal data of Indian residents. In practice: start with CERT-In readiness (fastest to implement, lowest cost, mandatory), then ISO 27001 if enterprise sales are a priority, then sector-specific frameworks.
What does the RBI IT Framework require for the CISO role specifically?
The RBI IT Framework is explicit: the CISO must be a designated full-time role, not an additional charge to another position. The CISO must not report to the CTO or CIO — they must have an independent reporting line directly to the Board or a Board committee. The rationale is to prevent security concerns from being filtered through operational leadership who may have competing priorities. The CISO must present a quarterly cybersecurity status report to the Board covering the threat landscape, significant incidents, VAPT findings and remediation status, and the security programme roadmap. Banks that have a person with the CISO title but reporting to the CTO do not meet this requirement.
Is ISO 27001 certification mandatory for Indian companies?
ISO 27001 certification is not legally mandatory for any category of Indian organisation — unlike CERT-In compliance or RBI IT Framework compliance. However, it has become effectively mandatory in practice for IT services companies, software product companies, and BPOs serving large enterprise clients, because enterprise procurement requires it. The Government of India's MEITY has encouraged ISO 27001 adoption but not mandated it. The upcoming National Cybersecurity Policy and potential future DPDP Rules may change this picture — organisations with ISO 27001 certification will be significantly better positioned for any future mandatory requirements. The checklist on this platform helps whether you are pursuing certification or simply using ISO 27001 as a self-assessment framework.
What is a Significant Data Fiduciary under the DPDP Act?
The DPDP Act 2023 creates a higher-obligation category called Significant Data Fiduciary (SDF). The government designates specific organisations as SDFs based on: volume of personal data processed, sensitivity of data, risk to data principals, potential impact to national security, and the organisation's market influence. SDFs have additional obligations beyond standard Data Fiduciaries: mandatory appointment of a Data Protection Officer (DPO) based in India, mandatory appointment of an independent data auditor, and periodic Data Protection Impact Assessments (DPIAs). As of 2024, the government had not yet published the list of designated SDFs — this will emerge once the DPDP Rules are finalised. Large social media platforms, major data brokers, and significant financial data processors are widely expected to be designated.
Indian regulatory compliance tools
SEBI CSCRF 2024 Checklist
Cyber Security and Cyber Resilience Framework — August 2024 revision. Tier selector (1–5) filters requirements by entity type. Covers governance, SOC, VAPT, third-party risk, DR, audit, and training. Status saved in browser. Export CSV.
Open checklist → Mandatory — All IndiaCERT-In Directions 2022
Mandatory for every organisation operating in India. 7 sections covering incident reporting, 180-day log retention in India, NTP synchronisation, VPN logging, data centres, and crypto exchanges. Mandatory gaps counter. Links to Deadline Calculator.
Open checklist → ISO · CERT-In · RBI · DPDP · SEBI · IRDAICross-Framework Regulatory Mapper
Select the frameworks your organisation must comply with. See which controls are shared across frameworks — do the work once and satisfy multiple regulators. 10 domains, 50+ controls mapped. Highlights shared controls in brass. Export CSV.
Open mapper →Risk register and policy templates
Risk Register Builder
Build and maintain an ISO 27001-aligned information security risk register. Interactive 5×5 risk matrix with live preview. 7 risk categories, treatment tracking, risk owner assignment. Load 4 example risks. Export CSV and JSON.
Open builder → 10 TemplatesSecurity Policy Template Library
10 complete, customisable security policy templates. Enter your organisation name and details — download a ready-to-use policy document. Covers: Acceptable Use, Access Control, Password, Incident Response, Remote Work, Data Classification, Change Management, Backup, Vendor Management, Physical Security.
Open library →