Latest alerts
  1. Home
  2. Compliance
// compliance hub

Which rules apply to you — and what to do next.

Plain-language summaries of the regulations and standards our clients are asked about most, with the fastest route to meeting each one.

India

DPDP Act, 2023Deadline approaching

India's privacy law: notice & consent, security safeguards, breach reporting (72-hour report to the Board), data-principal rights. Penalties up to ₹250 crore.

Applies to
Any organisation processing digital personal data of people in India
Timing
Rules notified Nov 2025 · most duties apply ≈ May 2027
India

CERT-In Directions 2022

Report cyber incidents within 6 hours, keep ICT logs for 180 days in India, sync clocks to NIC/NPL, name a point of contact.

Applies to
Service providers, intermediaries, data centres, body corporates, government
Timing
In force since June 2022
Global

ISO/IEC 27001:2022

The international standard for an information security management system — 93 Annex A controls in 4 themes, certified by an accredited body.

Applies to
Anyone selling to enterprises or international customers
Timing
2013 certificates expired Oct 2025
Global

OWASP Top 10:2025

The reference list of web-application risks — broken access control, misconfiguration, supply-chain failures and more. The baseline for any VAPT.

Applies to
Every web application and API
Timing
Current edition
India

RBI · SEBI CSCRF · IRDAI

Sector cyber-security directions: governance, VAPT, SOC monitoring, third-party risk and cyber resilience.

Applies to
Banks, NBFCs, brokers, AMCs, insurers, fintechs
Timing
Ongoing regulator audits
Global

PCI DSS v4.0.1

Payment-card security: segmentation, vulnerability management, script integrity on payment pages, logging.

Applies to
Anyone storing, processing or transmitting card data
Timing
Future-dated requirements live since Mar 2025
USA

HIPAA Security Rule

Administrative, physical and technical safeguards for electronic patient data — and evidence your US clients will ask for.

Applies to
US healthcare providers and their offshore vendors (transcription, billing, BPO)
Timing
Required by US clients
USA / Global

SOC 2 · NIST CSF 2.0

Trust-services criteria and the NIST Cybersecurity Framework (Govern, Identify, Protect, Detect, Respond, Recover).

Applies to
SaaS and service companies selling to US enterprises
Timing
Asked in every security review

Facing more than one of these?

Most controls overlap. We map ISO 27001, DPDP and your sector's rules into one programme so you build evidence once.

Start with a risk assessment
// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check