We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free · Cited compliance answers

Compliance answers, traced to the source

Straight answers to 76 of the questions we hear most — DPDP, PCI DSS, RBI, SEBI, CERT-In, ISO 27001, SOC 2, Aadhaar and more. Every answer is drawn only from our verified compliance registry and cites the issuing body’s own document, with a last-verified date.

What does DPDP Act compliance require for a business in India?

The DPDP Act 2023 requires businesses in India to comply with several provisions, including:

- Registration of Consent Managers, which will be required starting 13 November 2026 under Rule 4 of the Digital Personal Data Protection Rules, 2025 [1]. Consent Managers must meet specific eligibility criteria set out in Part A of the First Schedule, including being incorporated in India, having a minimum net worth of INR 2 crore, and demonstrating sound financial and operational capacity [3].

- Adherence to data protection principles and practices as outlined in the DPDP Rules 2025, which were notified on 13 November 2025 [2].

- Compliance with penalties for non-compliance, with the maximum penalty for the highest tier of offenses (such as failure to take reasonable security safeguards to prevent a personal data breach) capped at ₹250 crore per instance, effective May 2027 [5].

The exact details of these requirements and their implementation dates should be verified against the official documents and notifications.

5 verified sources
[1] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part A https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)

What are the DPDP Act penalties for a data breach?

The DPDP Act 2023 caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

Reference: [1]

5 verified sources
[1] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)

When do the DPDP Rules take effect and what are the key deadlines?

The DPDP Rules 2025 were notified on 13 November 2025 [1]. Key provisions, including those constituting and empowering the Data Protection Board, became effective on the same day [2]. The breach notification timeline under Rule 7 is effective from May 2027 [3], while the Consent Manager registration framework under Rule 4 will come into force on 13 November 2026 [5].

5 verified sources
[2] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)
[4] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

What are the rights of a Data Principal under the DPDP Act?

The DPDP Act 2023 outlines several rights for Data Principals, though the specific details are not provided in the given context. To determine the exact rights, refer to section 6(4) of the DPDP Act 2023, which pertains to the manner of exercising rights under this section. Additionally, section 13 covers grievance redressal mechanisms. The notice accompanying or preceding a consent request must inform the Data Principal of these rights [1].

5 verified sources
[1] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[2] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

What is the personal data breach notification requirement under the DPDP Rules?

A data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language. This is under Rule 7 of the DPDP Rules 2025 [1]. The rule is effective as of May 2027 [1].

5 verified sources
[3] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[4] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Act 2023 — Breach notification timeline (Rule 7) https://cybersigmacs.com/compliance-registry/#dpdp-breach-notification

What is the penalty structure under the DPDP Act across its tiers?

The penalty structure under the DPDP Act 2023 across its tiers is as follows:

- The highest tier, for failure to take reasonable security safeguards to prevent a personal data breach, has a penalty ceiling of up to ₹250 crore per instance.

- Lower tiers have penalties capped at ₹200 crore, ₹150 crore, and below, respectively; the exact amounts for these tiers are not specified in the context.

- The Data Protection Board determines the specific penalties based on the facts of each case.

- These penalties will come into effect on May 2027.

- The information was last verified on 2026-08-01.

[Cited facts: [1]]

5 verified sources
[1] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[3] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

Who is a Significant Data Fiduciary under the DPDP Act?

A Significant Data Fiduciary (SDF) is notified by the Central Government under Section 10 of the DPDP Act 2023 based on factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the State and public order. [1]

5 verified sources
[1] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[2] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)

What is PCI DSS and who must comply with it?

PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance with PCI DSS is mandatory for QSAs [1], and entities that handle cardholder data, such as e-commerce merchants [2, 4], must adhere to its standards. The standard provides a framework for protecting cardholder data and includes requirements for security management, policies, procedures, network architecture, software design, and other critical protective measures.

5 verified sources
[1] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[2] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What changed in PCI DSS v4.0.1?

The context indicates that PCI DSS v4.0.1 was published on 11 June 2024 and is a limited revision with no new requirements added or removed compared to v4.0. Therefore, there were no changes in requirements between v4.0 and v4.0.1. [1]

5 verified sources
[2] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[3] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — Document Library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the NPCI and UPI security requirements?

The NPCI and UPI security requirements include:

1. Volume-cap compliance for Third-Party Application Providers (TPAPs), with a deadline of 31 December 2026, as per NPCI's volume-cap guidelines for UPI (referencing circular NPCI/UPI/OC-97/2020-21).

2. Audit and compliance obligations on TPAPs, including audits by CERT-In empanelled auditors and UPI data storage within India, as detailed in NPCI's Guidelines for Third-Party Application Providers in UPI (circular OC 97, 2020).

These requirements are effective as of their respective deadlines and are enforced through various circulars and guidelines issued by NPCI.

5 verified sources
[1] NPCI UPI circulars (official listing) https://www.npci.org.in/circulars/upi (verified 2026-08-07)
[2] NPCI UPI circulars (official listing; OC 97 direct PDF withdrawn) https://www.npci.org.in/what-we-do/upi/circular (verified 2026-08-11)
[3] NPCI UPI TPAP Security Audit — Requirements for UPI Apps https://cybersigmacs.com/knowledge-center/npci-tpap-audit/
[4] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[5] Free NPCI UPI / TPAP Self-Assessment — Security Audit Readiness https://cybersigmacs.com/self-assessment/npci-upi/

What is the PCI DSS v4.0.1 effective date and what are the key deadlines?

The PCI DSS v4.0.1 effective date is 31 March 2025. Key deadlines include:

- Future-dated v4.x requirements becoming mandatory in assessments from 31 March 2025 [1].

The last-verified date for this information is 2026-08-01.

5 verified sources
[2] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

When did the future-dated PCI DSS v4.0 requirements become mandatory?

The future-dated PCI DSS v4.0 requirements became mandatory in assessments from 31 March 2025. [1]

5 verified sources
[2] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[4] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the NPCI and UPI security and audit requirements?

NPCI and UPI security and audit requirements include:

1. **Audit Obligations**: TPAPs must undergo audits conducted by CERT-In empanelled auditors. These audits are part of the TPAP guidelines (OC 97, 2020) which impose audit and compliance obligations on TPAPs. ([1])

2. **Data Storage**: UPI data must be stored within India. PSP banks retain audit rights over TPAP UPI infrastructure. ([1])

3. **Volume-Cap Compliance**: Existing TPAPs exceeding the volume-cap must comply by 31 December 2026, following a two-year extension from the original deadline of 31 December 2024. ([2])

4. **API Usage Monitoring**: PSPs and acquiring banks must monitor and control API usage as per NPCI's Guidelines on usage of UPI APIs (OC 215 series, May 2025), with non-compliance potentially leading to API restrictions, penalties, or suspension of new customer onboarding. ([2])

5. **Security Audits**: Pre-go-live and periodic security audits are required for TPAPs, PSP banks, aggregators, and fintechs across various payment systems including UPI, IMPS, RuPay, NACH, AePS, and NETC. ([4])

These requirements ensure compliance and security standards are met in the UPI ecosystem. ([1][2][4])

5 verified sources
[1] NPCI UPI circulars (official listing; OC 97 direct PDF withdrawn) https://www.npci.org.in/what-we-do/upi/circular (verified 2026-08-11)
[2] NPCI UPI circulars (official listing) https://www.npci.org.in/circulars/upi (verified 2026-08-07)
[3] NPCI UPI TPAP Security Audit — Requirements for UPI Apps https://cybersigmacs.com/knowledge-center/npci-tpap-audit/
[4] NPCI & UPI Audit Services | CERT-In Empanelled TPAP Audit https://cybersigmacs.com/npci-audit-services/
[5] Free NPCI UPI / TPAP Self-Assessment — Security Audit Readiness https://cybersigmacs.com/self-assessment/npci-upi/

What are the PCI DSS merchant levels?

PCI DSS merchant levels are classified by Visa into four levels based on annual transaction volume:

- Level 1: More than 6 million Visa transactions per year across all channels (or any merchant designated Level 1 by Visa, e.g., after a compromise) - annual on-site assessment and Report on Compliance (ROC) plus quarterly network scan. [2]

- Level 2: 1 to 6 million transactions per year - annual Self-Assessment Questionnaire (SAQ) and quarterly scan. [2]

- Level 3: 20,000 to 1 million Visa e-commerce transactions per year - SAQ and quarterly scan. [2]

- Level 4: Fewer than 20,000 Visa e-commerce transactions, or up to 1 million total transactions per year - SAQ and scan as required by the acquirer. [2]

Other card brands set broadly similar but not identical thresholds; the acquirer confirms a merchant's level. [2]

5 verified sources
[1] PCI SSC - Document Library (Self-Assessment Questionnaires) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] Visa - Account Information Security (AIS) Program and PCI https://corporate.visa.com/en/resources/security-compliance.html (verified 2026-08-13)
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the PCI DSS SAQ types and when is a ROC required instead?

PCI DSS defines nine SAQ types, each scoped to how a merchant handles cardholder data:

- SAQ A (fully outsourced e-commerce or mail/telephone order, no data handling)

- SAQ A-EP (e-commerce that partially controls the payment page)

- SAQ B (imprint machines or standalone dial-out terminals, no electronic storage)

- SAQ B-IP (standalone PTS-approved IP-connected terminals)

- SAQ C-VT (web-based virtual terminal, one transaction at a time)

- SAQ C (payment application connected to the internet)

- SAQ P2PE (hardware terminals in a validated PCI P2PE solution)

- SAQ D for Merchants (all others that store, process or transmit cardholder data - the most comprehensive)

- SAQ D for Service Providers (applies to service providers)

A merchant who cannot meet an SAQ's eligibility criteria, or who is a Level 1 merchant, completes a full Report on Compliance (ROC) instead of an SAQ [1].

5 verified sources
[1] PCI SSC - Document Library (Self-Assessment Questionnaires) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the 12 requirements of PCI DSS?

The 12 requirements of PCI DSS are:

1. Build and maintain a secure network.

2. Build and maintain secure systems and applications.

3. Protect cardholder data.

4. Encrypt cardholder data during transmission over open, public networks.

5. Develop and maintain secure systems and applications.

6. Maintain a vulnerability management program.

7. Implement strong access control measures.

8. Regularly monitor and test networks.

9. Maintain a policy that addresses information security for employees and contractors.

10. Track and monitor all access to network resources and cardholder data.

11. Regularly test security systems and processes.

12. Maintain a written information security policy.

These requirements are structured under six goals as outlined in PCI DSS v4.0.1, which was published in June 2024. [1]

5 verified sources
[1] PCI SSC - Document Library (PCI DSS v4.0.1) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What is CERT-In empanelment and why does it matter for VAPT?

CERT-In empanelment refers to the process where cybersecurity firms and professionals are evaluated and certified by the Computer Emergency Response Team - India (CERT-In) to ensure they meet certain standards and criteria for handling cybersecurity services. This empanelment is crucial for Value Added Penetration Testing (VAPT) because:

- Regulators and enterprises increasingly require CERT-In empanelment to ensure the quality and reliability of cybersecurity services. [2]

- CERT-In empanelment ensures that VAPT partners adhere to specific standards and methodologies, enhancing the trustworthiness of the services provided. [3]

Thus, choosing a CERT-In empanelled VAPT partner is important for ensuring compliance and the quality of the security assessments conducted. [2]

5 verified sources
[1] CERT-In Empanelment Explained: Why It Matters for Your Audit https://cybersigmacs.com/blog/cert-in-empanelment-explained/
[2] Why CERT-In Empanelment Matters When Choosing a VAPT Partner https://cybersigmacs.com/blog/cert-in-empanelled-vapt-partner/
[3] CERT-In Empanelled vs Non-Empanelled Auditors: Why It Matters for Your VAPT https://cybersigmacs.com/blog/cert-in-empanelled-vs-non-empanelled-auditor/
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In VAPT for Government Tenders | Safe-to-Host https://cybersigmacs.com/cert-in-vapt-for-government-tenders/

What is the CERT-In 6-hour incident reporting requirement?

The CERT-In 6-hour incident reporting requirement states that specified cyber incidents must be reported to CERT-In within 6 hours of noticing. This requirement is effective as of 28 June 2022 and applies to service providers, intermediaries, data centres, body corporates, and government organisations. [1][4]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Compliance: Directions, 6-Hour Incident Reporting & Audit Guide https://cybersigmacs.com/blog/cert-in-compliance-audit/
[3] CERT-In Directions Explained — Incident Reporting & Log Retention https://cybersigmacs.com/knowledge-center/cert-in-directions/
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What logs must be retained under the CERT-In directions?

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What logs must be retained and for how long under the CERT-In directions?

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What records must VPN and cloud providers retain under the CERT-In directions?

VPN and cloud providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What is ISO 27001 certification and what does it involve?

ISO 27001 certification involves establishing, implementing, maintaining, and continually improving an information security management system (ISMS) according to the requirements specified in the ISO/IEC 27001 standard [2]. This standard, published in October 2022 as the third edition, is titled "Information security, cybersecurity and privacy protection — Information security management systems — Requirements" [2]. The certification process ensures that an organization has a robust framework for managing information security risks effectively [5].

5 verified sources
[1] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[4] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[5] ISO 27001 Hub — Certification Guide, Cost, ISMS https://cybersigmacs.com/hub/iso-27001/

What is the ISO 27001:2022 transition deadline for existing certificates?

The ISO 27001:2022 transition deadline for existing certificates is 31 October 2025. This is the end of the IAF three-year transition window for ISO/IEC 27001:2013 certificates. Certificates not transitioned to the 2022 revision by this date will lapse. [1]

5 verified sources
[1] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO/IEC 27001 — 2022-revision transition deadline https://cybersigmacs.com/compliance-registry/#iso-27001-2022-transition
[4] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[5] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)

How many controls are in ISO 27001:2022 Annex A and what are the four themes?

ISO 27001:2022 Annex A contains 93 controls organised into four themes:

- Organisational (37 controls, clause 5)

- People (8 controls, clause 6)

- Physical (14 controls, clause 7)

- Technological (34 controls, clause 8)

These numbers reflect a restructuring from the 2013 edition, where the count fell through consolidation and merging rather than a reduction in scope. [1]

5 verified sources
[1] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[2] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[3] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[4] ISO/IEC 27001 — Annex A control count (2022 revision) https://cybersigmacs.com/compliance-registry/#iso27001-annexa-control-count
[5] ISO 27001:2022 Annex A Controls Explained | All 4 Themes https://cybersigmacs.com/iso-27001-annex-a/

What is a Statement of Applicability in ISO 27001?

A Statement of Applicability (SoA) in ISO 27001 is a document that must be produced as part of the organization's information-security risk-treatment process. According to ISO/IEC 27001:2022 clause 6.1.3(d), the SoA must include the necessary controls (whether from Annex A or elsewhere), the justification for their inclusion, whether each necessary control is implemented, and the justification for excluding any of the Annex A controls. The SoA is a mandatory, auditable document that serves as the reference point for auditors to confirm that all applicable controls are addressed. [1]

5 verified sources
[1] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[2] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[3] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[4] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[5] ISO/IEC 27001 — Statement of Applicability (clause 6.1.3) https://cybersigmacs.com/compliance-registry/#iso27001-statement-of-applicability

What is the difference between SOC 2 Type I and Type II?

The difference between SOC 2 Type I and Type II is explained in [2] and [4]. Type I provides an assessment of controls at a specific point in time, while Type II offers a more comprehensive view over a specified period, typically six months. Both types evaluate controls related to security, availability, confidentiality, processing integrity, and privacy, but Type II includes the results of ongoing testing and monitoring.

5 verified sources
[1] SOC 2 Explained — Trust Services Criteria, Type I vs Type II https://cybersigmacs.com/knowledge-center/soc-2/
[2] SOC 2 Type 1 vs Type 2: Differences and Which to Choose https://cybersigmacs.com/blog/soc-2-type-1-vs-type-2/
[3] SOC 2 for SaaS Companies — Type II Readiness, Criteria & Evidence https://cybersigmacs.com/industries/saas/soc-2/
[4] SOC 2 Hub — Type I vs II, Cost, Readiness in India https://cybersigmacs.com/hub/soc-2/
[5] SOC 2 Compliance for Indian SaaS Companies: A Practical Guide https://cybersigmacs.com/blog/soc-2-compliance-india/

What are the five SOC 2 Trust Services Criteria?

The five SOC 2 Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy. [1]

5 verified sources
[1] AICPA - 2017 Trust Services Criteria (With Revised Points of Focus - 2022) https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[2] AICPA TSP Section 100, paragraphs .14 and .15 https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[3] AICPA TSP Section 100 — common criteria and points of focus https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[4] SOC 2 (AICPA) — Trust Services Criteria - current version https://cybersigmacs.com/compliance-registry/#soc2-trust-services-criteria
[5] SOC 2 Explained — Trust Services Criteria, Type I vs Type II https://cybersigmacs.com/knowledge-center/soc-2/

What are the RBI cyber security requirements for banks?

RBI's cyber security requirements for banks include:

1. Reporting cyber incidents to RBI within 2 to 6 hours of detection, along with a board-approved cyber security policy, SOC capability, and cyber crisis management plans. This requirement is detailed in the Cyber Security Framework in Banks, effective since 2 June 2016 [1].

2. Adherence to the IT Governance Master Direction, which mandates an IT governance framework, information/cyber security policies, and periodic IT risk assurance for regulated entities, effective from 1 April 2024 [5].

5 verified sources
[1] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[2] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] RBI — Cyber Security Framework in Banks https://cybersigmacs.com/compliance-registry/#rbi-cyber-framework-2016
[5] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)

What are the RBI data localisation (storage of payment data) requirements?

RBI requires payment system providers to store the entire data relating to their payment systems only in India, with compliance by October 2018. This includes end-to-end transaction data. [1]

5 verified sources
[1] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[2] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] RBI — Payment system data storage in India https://cybersigmacs.com/compliance-registry/#rbi-payment-data-localisation

What are the RBI minimum security standards for digital payment channels?

The RBI minimum security standards for digital payment channels, including internet banking, mobile payments, and card payments, are detailed in the Digital Payment Security Controls Master Direction issued on 18 February 2021 [1]. These standards are binding on scheduled commercial banks, small finance banks, payments banks, and card-issuing non-banking financial companies (NBFCs).

5 verified sources
[1] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)
[2] RBI — Digital Payment Security Controls Master Direction https://cybersigmacs.com/compliance-registry/#rbi-dpsc-2021
[3] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[4] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[5] RBI Master Direction on Digital Payment Security Controls https://cybersigmacs.com/knowledge-center/rbi-digital-payment-security-controls/

What is the RBI IT governance and outsourcing requirement for regulated entities?

Regulated entities must adhere to the following RBI IT governance and outsourcing requirements:

1. **IT Governance**: An IT governance framework, information/cyber security policies, and periodic IT risk assurance are required. This is effective from 1 April 2024, as per the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) [1].

2. **IT Outsourcing**: Material IT outsourcing by regulated entities must be governed, including vendor risk, audit rights, and concentration risk. This became effective on 1 October 2023, as per the Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) [2].

5 verified sources
[1] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)
[2] Reserve Bank of India (Master Direction RBI/2023-24/102) https://www.rbi.org.in/ (verified 2026-08-01)
[3] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[4] RBI — IT Governance Master Direction https://cybersigmacs.com/compliance-registry/#rbi-it-governance-md
[5] RBI — IT Outsourcing Master Direction https://cybersigmacs.com/compliance-registry/#rbi-it-outsourcing-md

What is the RBI data localisation requirement for payment system data?

The RBI data localisation requirement for payment system data mandates that all system providers ensure the entire data relating to the payment systems they operate is stored in a system only in India. This includes full end-to-end transaction details and any information collected, carried, or processed as part of the payment message or instruction. Compliance was required within six months of the circular's issuance, which was on 6 April 2018, with submission of a System Audit Report conducted by a CERT-In empanelled auditor. This applies to all Payment System Providers authorised under the Payment and Settlement Systems Act, 2007.

Sources: [1], [2]

5 verified sources
[1] RBI Notification RBI/2017-18/153 - Storage of Payment System Data https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244 (verified 2026-08-13)
[2] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[3] RBI — Storage of Payment System Data (data localisation) https://cybersigmacs.com/compliance-registry/#rbi-payment-data-localisation
[4] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the RBI Payment Aggregator Directions 2025 net-worth requirements?

A non-bank entity carrying on payment-aggregator business must obtain RBI authorisation and must have a minimum net worth of INR 15 crore at the time of application, rising to a minimum net worth of INR 25 crore by the end of the third financial year after authorisation, maintained thereafter. [1]

5 verified sources
[1] RBI Master Direction RBI/DPSS/2025-26/141 - Regulation of Payment Aggregators Directions, 2025 https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12896 (verified 2026-08-13)
[2] RBI — Regulation of Payment Aggregators Directions, 2025 https://cybersigmacs.com/compliance-registry/#rbi-payment-aggregators-directions-2025
[3] RBI Notification RBI/2017-18/153 - Storage of Payment System Data https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244 (verified 2026-08-13)
[4] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[5] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)

RBI / payments

See RBI hub

What is a System Audit Report (SAR) for payment aggregators?

A System Audit Report (SAR) for payment aggregators requires an authorisation and a System Audit Report conducted by a CERT-In empanelled auditor, as mandated by the RBI Payment Aggregator (PA-PG) Guidelines [2].

5 verified sources
[1] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[2] RBI Payment Aggregator (PA-PG) Guidelines — System Audit & Compliance https://cybersigmacs.com/knowledge-center/rbi-payment-aggregator-guidelines/
[3] SAR Audit: System Audit Report Requirements in India https://cybersigmacs.com/sar-audit/
[4] IRDAI Information and Cybersecurity Guidelines, 2026 — clause on audit submission https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[5] Payment Aggregator & PPI Audit | RBI PSS Compliance https://cybersigmacs.com/rbi-pss-compliance-audit/

What is the SAR (System Audit Report) submission requirement for payment aggregators?

The SAR (System Audit Report) submission requirement for payment aggregators is that they must obtain a System Audit Report by a CERT-In empanelled auditor as mandated by the RBI Payment Aggregator (PA-PG) Guidelines [4]. However, the specific submission deadline is not detailed in the provided context. For precise submission timing, refer to the relevant RBI guidelines directly.

5 verified sources
[1] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[2] SAR Audit: System Audit Report Requirements in India https://cybersigmacs.com/sar-audit/
[3] IRDAI Information and Cybersecurity Guidelines, 2026 — clause on audit submission https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[4] RBI Payment Aggregator (PA-PG) Guidelines — System Audit & Compliance https://cybersigmacs.com/knowledge-center/rbi-payment-aggregator-guidelines/
[5] BBPS Audit — Security Requirements for Bharat Bill Payment System https://cybersigmacs.com/knowledge-center/bbps-audit/

What is SEBI CSCRF and who must comply with it?

SEBI CSCRF stands for the Cybersecurity and Cyber Resilience Framework issued by the Securities and Exchange Board of India (SEBI). It mandates various cybersecurity practices and compliance requirements for regulated entities under SEBI's purview. Specifically, all entities regulated by SEBI, except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), must comply with this framework. The compliance timeline was initially set to be fully in force by 31 August 2025, but due to extensions, it is now fully effective as of 31 August 2025. [2]

5 verified sources
[1] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[2] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[3] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

Which entities must comply with the SEBI CSCRF and what are the categories?

All regulated entities under SEBI must comply with the Cybersecurity and Cyber Resilience Framework (CSCRF) as per [1] and [2]. These entities are categorized into five groups:

1. Market Infrastructure Institutions (MIIs)

2. Qualified Registered Entities (Qualified REs)

3. Mid-size Registered Entities (Mid-size REs)

4. Small-size Registered Entities (Small-size REs)

5. Self-certification Registered Entities (Self-certification REs)

Portfolio Managers and Merchant Bankers were re-categorized by circular 2025/119 of 28 August 2025 ([2]).

5 verified sources
[1] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[2] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[3] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

What is the audit and reporting requirement under the SEBI CSCRF?

Audits must be conducted by a CERT-In empanelled organisation, as stated in the SEBI CSCRF framework. The VAPT report must be submitted within one month of completing the VAPT activity, after approval from the RE's IT Committee. Findings must be closed within three months of report submission, following a graded approach based on the criticality of the observations. Revalidation of the VAPT must be completed within five months of its completion. These requirements are effective from 20 August 2024. [1][4]

5 verified sources
[1] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[2] SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2025/1756380695925.pdf (verified 2026-08-04)
[3] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

What is the effective date of the SEBI CSCRF for different entity categories?

The effective date of the SEBI CSCRF is 20 August 2024, with compliance timelines extended to 31 August 2025 due to circulars [1]. The framework applies proportionately by category starting from this date, as detailed in circular [2].

5 verified sources
[1] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[2] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[3] SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2025/1756380695925.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

What are AUA and KUA under the Aadhaar ecosystem?

AUA and KUA refer to Authentication User Agencies and KYC User Agencies under the Aadhaar ecosystem. These agencies must have their operations audited annually (and on need) by a certified information systems auditor as per the Aadhaar (Authentication and Offline Verification) Regulations, 2021, together with the Aadhaar (Data Security) Regulations, 2016, and the UIDAI Information Security Policy. [1][5]

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[3] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[4] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/
[5] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit

What is a UIDAI AUA/KUA security audit and who must undergo it?

A UIDAI AUA/KUA security audit is an annual (and on need) audit of the operations of Authentication User Agencies (AUAs) and eKYC User Agencies (KUAs) by a certified information systems auditor. The audit ensures compliance with the Aadhaar (Authentication and Offline Verification) Regulations, 2021, the Aadhaar (Data Security) Regulations, 2016, and the UIDAI Information Security Policy. AUAs and KUAs must have the results of these audits shared with UIDAI upon request.

This requirement applies to AUAs and KUAs in the Aadhaar ecosystem [1, 3].

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[3] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[5] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/

How often must a UIDAI AUA/KUA security audit be performed?

A UIDAI AUA/KUA security audit must be performed annually and on demand. [1]

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[3] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[5] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/

What are the UIDAI data security regulations that AUA/KUA must follow?

AUA/KUA must follow the UIDAI (Aadhaar) Data Security Regulations, 2016 [1].

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[3] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[4] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is CKYC and what does CKYC compliance require?

CKYC stands for Central Know Your Customer (KYC) framework, which is operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) under the guidelines set by the Reserve Bank of India (RBI). CKYC compliance requires regulated entities to upload KYC records of their customers into the Central KYC Records Registry (CKYCR) within 10 days of establishing an account-based relationship with the customer [3]. The KYC records must be submitted using CERSAI templates, which can change over time [4]. Additionally, customers can provide consent to have their KYC records retrieved from the CKYCR using a KYC Identifier [5]. The applicability of CKYC was phased between 2016 and 2021, with different timelines for Scheduled Commercial Banks and other regulated entities [1].

5 verified sources
[1] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[2] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[3] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)

What is CKYC and what is the CERSAI/CKYC registry requirement?

CKYC stands for Central KYC (Know Your Customer) Records, which is managed through the Central KYC Records Registry (CKYCR) operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) [1]. The CKYC registry requirement mandates that regulated entities capture and upload customer KYC records into the CKYCR within 10 days of establishing an account-based relationship with the customer [3]. This applies to both individuals and legal entities, with the requirement for legal entities being phased in, starting from 1 April 2021 [5].

5 verified sources
[1] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[2] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[3] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)

What is ISNP and who needs ISNP certification?

ISNP stands for Insurance Self Network Platform [2]. It is subject to an IRDAI-mandated security audit requirement [1, 3, 4]. Specifically, Insurance Self-Network Platforms operating under IRDAI permission must undergo an annual ISNP security audit, which involves controls assessment, gap closure, and audit readiness [1, 4]. This requirement applies to insurance companies, brokers, web aggregators, and technology providers that deal with the ISNP [3].

The ISNP security audit must be conducted by an external Certified Information Systems Auditor (CISA), a Chartered Accountant holding DISA (ICAI), or a CERT-In empanelled expert [4]. The resulting report should be presented to the Board or its sub-committee [4].

5 verified sources
[1] ISNP Security Audit (Insurance Self-Network Platform) | IRDAI https://cybersigmacs.com/isnp-cybersecurity-audit/
[2] ISNP Full Form: IRDAI Insurance Self Network Platform https://cybersigmacs.com/isnp-certification/
[3] Industries That Require ISNP Security Audit https://cybersigmacs.com/isnp-cybersecurity-audit/industries/
[4] IRDAI - circular on online filing for Insurance Self Network Platform (IRDA/INT/CIR/ECM/083/04/2017), citing the governing e-commerce guidelines https://irdai.gov.in/document-detail?documentId=384920 (verified 2026-08-07)
[5] ISO 27001 Explained — ISMS, Annex A Controls & Certification https://cybersigmacs.com/knowledge-center/iso-27001/

What are the IRDAI cyber security requirements for insurers?

The IRDAI cyber security requirements for insurers, as per the Information and Cyber Security Guidelines, 2026 [1], include:

- All Insurers, including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, must comply with these guidelines.

- Insurers are responsible for ensuring that Insurance Agents, Micro-Insurance Agents, Point of Sale Persons, and Individual Surveyors follow a minimum security framework under the Insurer’s Board-approved policy, even though these entities are expressly outside the purview of the guidelines themselves.

These guidelines became effective on 6 April 2026 [1].

5 verified sources
[1] IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-07)
[2] IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) https://irdai.gov.in/document-detail?documentId=3314780 (verified 2026-08-07)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[5] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What are the IRDAI information and cyber security requirements for insurers?

The IRDAI Information and Cyber Security Guidelines, 2026 (Version 2.0) outline the requirements for insurers. These guidelines apply to all Insurers, including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, and cover all data created, received, or maintained by Regulated Entities in any form. Insurers are responsible for ensuring that Insurance Agents, Micro-Insurance Agents, Point of Sale Persons, and Individual Surveyors follow a minimum security framework under the Insurer’s Board-approved policy. The guidelines were effective from 6 April 2026, replacing the 2023 version. [1][5]

5 verified sources
[1] IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-07)
[2] IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) https://irdai.gov.in/document-detail?documentId=3314780 (verified 2026-08-07)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] IRDAI — Information and Cybersecurity Guidelines, 2026 (current) https://cybersigmacs.com/compliance-registry/#irdai-infosec-guidelines-2026
[5] IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)

What is CMMI and what is new in CMMI v3.0?

CMMI (Capability Maturity Model Integration) is a framework designed to help organizations improve their processes and achieve better outcomes. CMMI V3.0 introduces updates to the model, including the eight domains, Maturity Levels 1–5, and all 31 Practice Areas. The updated version provides a comprehensive guide covering the appraisal lifecycle, CMMI AIM, and other relevant aspects of the model. [1]

5 verified sources
[1] CMMI V3.0 — Domains, Maturity Levels, Practice Areas & Appraisal Guide https://cybersigmacs.com/knowledge-center/cmmi/
[2] Free CMMI Self-Assessment — Maturity Level 2/3 Readiness (V3.0) https://cybersigmacs.com/self-assessment/cmmi/
[3] CMMI Consulting & Appraisal-Readiness (Level 2/3) https://cybersigmacs.com/cmmi-consulting/
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] CMMC Program - 32 CFR Part 170 and the DFARS 48 CFR acquisition rule (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)

What is the UAE PDPL (Personal Data Protection Law)?

The UAE PDPL (Personal Data Protection Law) is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It came into effect on 2 January 2022 [3]. The law outlines various obligations and rights for controllers and processors of personal data, including reporting breaches, appointing a Data Protection Officer, honoring data-subject rights, securing data, conducting data protection impact assessments, and controlling cross-border transfers [1]. Consent is the default basis for processing personal data, with specific exceptions outlined in the law [2]. The law also provides for an enforcement structure, including mechanisms for filing complaints and imposing penalties, though the issuance of the Executive Regulation detailing the law's implementation remains unresolved [4].

5 verified sources
[1] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[2] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 4-6 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[3] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[4] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 24-28 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[5] UAE Personal Data Protection Law (PDPL) https://cybersigmacs.com/knowledge-center/uae-pdpl/

What is Saudi Arabia NCA ECC (Essential Cybersecurity Controls)?

Saudi Arabia NCA ECC (Essential Cybersecurity Controls) is a framework consisting of 108 main controls and 92 sub-controls organized into 4 main domains and 28 subdomains. It applies to government agencies and private-sector entities owning, operating, or hosting Critical National Infrastructure within the Kingdom, including their affiliated companies and entities both inside and outside the Kingdom. The framework was first issued as ECC-1:2018 and updated to ECC-2:2024, which mandates compliance through self-assessments, periodic reports, and field auditing visits by the National Cybersecurity Authority (NCA). Compliance is required by Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439H. The framework includes specific requirements for establishing an independent cybersecurity department, filling all cybersecurity positions with full-time, qualified Saudi nationals, and documenting and approving a cybersecurity strategy. [1][2][3][4]

5 verified sources
[1] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[2] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] NCA - ECC-2:2024 (English), Figures 3-4 and Table 1 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is SAMA CSF?

SAMA CSF (Saudi Arabia) is a Cyber Security Framework issued by the Saudi Central Bank (SAMA) in May 2017. It applies to all SAMA-regulated Member Organizations, including banks, insurance and reinsurance companies, financing companies, credit bureaus, and the Financial Market Infrastructure. The framework is principle-based and draws on NIST, ISF, ISO, Basel, and PCI standards. Member Organizations are expected to operate at maturity level 3 or higher. [1]

5 verified sources
[1] SAMA Rulebook — Cyber Security Framework https://rulebook.sama.gov.sa/en/cyber-security-framework-2 (verified 2026-08-04)
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What is the Qatar NIA framework?

The Qatar NIA (National Information Assurance) framework is mandated by Qatar's National Cyber Security Agency (NCSA) for government entities and critical infrastructure. The current revision of the National Information Assurance Policy is version 2.1, effective as of May 2023, which supersedes version 2.0. This framework provides security controls, classification, and compliance approaches for organizations within the jurisdiction. [1][5]

5 verified sources
[1] NCSA Qatar (official portal) https://ncsa.gov.qa/en/ (verified 2026-08-01)
[2] Qatar NIA — Complete National Information Assurance Guide https://cybersigmacs.com/knowledge-center/qatar-nia/
[3] National Cybersecurity Framework Compliance in the USA https://cybersigmacs.com/national-cyber-compliance-usa/
[4] National Cybersecurity Framework Compliance in Qatar https://cybersigmacs.com/national-cyber-compliance-qatar/
[5] Qatar NIA (NCSA) — National Information Assurance Policy version https://cybersigmacs.com/compliance-registry/#qatar-nia

What are the penalties under the UAE PDPL and who enforces it?

The UAE PDPL establishes administrative penalties for violations [2]. The enforcement structure includes mechanisms for data subjects to file complaints with the UAE Data Office (Article 24) and for grievances against the Office's decisions to be addressed (Article 25). The law also provides for administrative penalties for violations (Article 26), though the specific nature and details of these penalties are not detailed within the provided context. The Executive Regulation to detail the law's implementation, including potential penalties, has not yet been issued [1].

For more detailed information on penalties and enforcement, refer to the official UAE Legislation portal for Federal Decree-Law 45/2021, specifically Articles 24-26 [1, 2].

5 verified sources
[1] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 24-28 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[2] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[3] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 4-6 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[4] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[5] UAE PDPL — Complaints, penalties and Executive Regulation (Articles 24-28) https://cybersigmacs.com/compliance-registry/#uae-pdpl-enforcement

Who must comply with the SAMA Cyber Security Framework?

The SAMA Cyber Security Framework must be complied with by all SAMA-regulated Member Organizations, including banks, insurance and reinsurance companies, financing companies, credit bureaus, and the Financial Market Infrastructure. [1]

5 verified sources
[1] SAMA Rulebook — Cyber Security Framework https://rulebook.sama.gov.sa/en/cyber-security-framework-2 (verified 2026-08-04)
[2] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] SAMA Cyber Security Framework — Complete Compliance Guide https://cybersigmacs.com/knowledge-center/sama-csf/

Who must comply with the Qatar National Information Assurance (NIA) framework?

The Qatar National Information Assurance (NIA) framework mandates compliance for government entities and critical infrastructure. This is stated in verified fact [1].

5 verified sources
[1] NCSA Qatar (official portal) https://ncsa.gov.qa/en/ (verified 2026-08-01)
[2] Qatar NIA — Complete National Information Assurance Guide https://cybersigmacs.com/knowledge-center/qatar-nia/
[3] Qatar NIA (NCSA) — National Information Assurance Policy version https://cybersigmacs.com/compliance-registry/#qatar-nia
[4] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)
[5] UAE Information Assurance (NESA) — Complete Compliance Guide https://cybersigmacs.com/knowledge-center/uae-ia-nesa/

AI / ISO 42001

See our services

When does the EU AI Act take effect and what are its key dates?

The EU AI Act takes effect with several key dates:

- **2 August 2024**: Regulation (EU) 2024/1689 entered into force, marking the commencement of the Act. [3]

- **2 February 2025**: Chapters I and II (general provisions and prohibited AI practices) apply. [4]

- **2 August 2025**: Governance rules and obligations for general-purpose AI (GPAI) model providers apply, along with other obligations under Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78 (notifying authorities, general-purpose AI models, governance, penalties, and confidentiality). [3, 4]

- **2 August 2026**: The main provisions of the Regulation apply, except for Article 6(1) concerning high-risk classification for AI as a safety component of products already regulated under Union law. [4]

- **2 December 2027**: Postponed deadline for high-risk AI systems designated under Article 6(2) and Annex III. [1]

- **2 August 2028**: Postponed deadline for AI embedded in products regulated under Annex I sectoral legislation. [1]

- **2 August 2027**: Compliance deadline for providers of general-purpose AI models placed on the market before 2 August 2025. [5]

- **31 December 2030**: Compliance deadline for AI systems that are components of the large-scale IT systems listed in Annex X and placed on the market before 2 August 2027. [5]

These dates reflect the staggered implementation of various aspects of the EU AI Act. [4, 5]

5 verified sources
[1] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[2] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[3] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)
[4] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)

What are the penalties under the EU AI Act?

Penalties under the EU AI Act include:

- Up to EUR 35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, for infringement of the Article 5 prohibited-practices rules. [3]

- Up to EUR 15,000,000 or 3% for breach of most other operator obligations. [3]

- Up to EUR 7,500,000 or 1% for supplying incorrect, incomplete, or misleading information to notified bodies or national authorities. [3]

For Small and Medium-sized Enterprises (SMEs) including start-ups, each ceiling is the lower rather than the higher of the two figures. [3]

5 verified sources
[1] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[3] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[4] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)

What risk categories does the EU AI Act define?

The EU AI Act defines high-risk AI systems, which are subject to specific obligations and deadlines as per the regulation. However, the context provided does not explicitly list the specific risk categories defined by the EU AI Act. Therefore, based solely on the given context, I cannot provide a definitive list of risk categories.

For a precise answer, you should refer to the primary source of the EU AI Act. [1] [2] [3] [4] [5]

5 verified sources
[1] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[2] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[3] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[4] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[5] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)

What is ISO 42001 and what does an AI management system require?

ISO 42001 is the first AI management system (AIMS) standard, published in December 2023 by ISO/IEC, which specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. However, the specific requirements and clauses of ISO 42001 are not detailed in the provided context [1]. For more detailed information on what an AI management system requires, including mapping to the EU AI Act and NIST AI RMF, refer to the resource provided [4].

5 verified sources
[1] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[4] ISO 42001 Explained: The AI Management System Standard https://cybersigmacs.com/blog/iso-42001-explained/
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is HIPAA compliance?

HIPAA compliance involves adhering to the Health Insurance Portability and Accountability Act's Security Rule, which became effective on 20 April 2005 for most covered entities, with small health plans having until 20 April 2006. This rule mandates the implementation of administrative, physical, and technical safeguards for electronic protected health information (ePHI). Specifically, covered entities must notify affected individuals without unreasonable delay, but no later than 60 calendar days following the discovery of a breach of unsecured ePHI, unless a law-enforcement delay applies. For breaches affecting 500 or more individuals, the covered entity must also notify the Secretary of the Department of Health and Human Services contemporaneously with the notification to individuals. For breaches affecting fewer than 500 individuals, the entity must maintain a log and report them not later than 60 days after the end of the calendar year in which they were discovered. [1][2][3][4]

5 verified sources
[1] US HHS — HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html (verified 2026-08-11)
[2] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[3] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[4] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework (CSF) 2.0, released on 26 February 2024, is organised around six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS), and RECOVER (RC) [3]. It defines four Tiers of risk governance rigor: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4) [2]. The framework provides a taxonomy of high-level cybersecurity outcomes without prescribing specific methods for achieving these outcomes [4]. It is designed to be applicable to organizations of various sizes, sectors, and maturity levels [4]. The GOVERN function is new in version 2.0 and focuses on establishing and monitoring cybersecurity risk management strategies [3].

5 verified sources
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is the SWIFT Customer Security Programme (CSP)?

The SWIFT Customer Security Programme (CSP) is a framework designed to enhance the security of financial transactions involving SWIFT. It includes a set of mandatory and advisory security controls that organizations connected to SWIFT must attest against annually. Key aspects include:

- An independent assessment became mandatory for attestations starting in 2021, replacing pure self-attestation.

- The latest version, CSCF v2026, introduces several changes, such as requiring multi-factor authentication for external privileged access, recognizing Swift Universal Confirmation as a transaction validation option, and adding controls related to system hardening, malware protection, and security training.

- The framework consists of 32 controls, with 26 being mandatory and 6 advisory.

- Customer client connectors have been made a mandatory in-scope component, impacting the scope of assessments for some users.

- The current attestation period runs from July to December 2026, based on the controls outlined in CSCF v2026, which was published in mid-2025. [1][2][3][4][5]

5 verified sources
[1] SWIFT — Customer Security Programme (official) https://www.swift.com/myswift/customer-security-programme (verified 2026-08-11)
[2] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[3] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[4] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[5] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)

What is OWASP ASVS?

OWASP ASVS (Application Security Verification Standard) is a framework for assessing the security of web applications and APIs. It consists of 345 verification requirements organized into 17 chapters (V1-V17), effective from May 2025 [2][3]. The requirements are categorized into three verification levels (L1-L3), with Level 1 containing 70 requirements, Level 2 containing 183, and Level 3 containing 92 [4]. Each application verified at a higher level is expected to satisfy the requirements of the lower levels as well [4]. The latest version is v5.0.0, which includes substantial restructuring compared to previous versions [1].

5 verified sources
[1] OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) https://github.com/OWASP/ASVS/tree/master/5.0/en (verified 2026-08-11)
[3] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[4] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[5] Application Security Testing Services | OWASP ASVS https://cybersigmacs.com/application-security-testing/

What are the SWIFT CSP mandatory controls and the attestation deadline?

The SWIFT CSP mandatory controls are 26 out of the 32 controls in the Customer Security Controls Framework (CSCF) v2026. The attestation deadline for compliance against CSCF v2026 is between July and December 2026.

Mandatory controls: 26

Attestation deadline: July to December 2026 [3]

5 verified sources
[1] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[2] SWIFT — Customer Security Programme (official) https://www.swift.com/myswift/customer-security-programme (verified 2026-08-11)
[3] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[4] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[5] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)

What is the HIPAA breach notification requirement?

According to HIPAA, the breach notification requirement involves two main aspects:

1. For breaches involving 500 or more individuals, the covered entity must notify the Secretary contemporaneously with the notice to individuals, following discovery of the breach [1].

2. For breaches involving fewer than 500 individuals, the entity must maintain a log and report them not later than 60 days after the end of the calendar year in which they were discovered [1].

Additionally, following discovery of a breach, a covered entity must notify each affected individual "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach", except where a law-enforcement delay under § 164.412 applies [2].

5 verified sources
[1] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[2] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[3] US HHS — HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html (verified 2026-08-11)
[4] EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (verified 2026-08-04)
[5] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)

What are the five functions of the NIST Cybersecurity Framework?

The five functions of the NIST Cybersecurity Framework are GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), and RESPOND (RS). GOVERN is new in version 2.0 and covers how an organisation establishes and monitors its cybersecurity risk management strategy, expectations, and policy. [1]

5 verified sources
[1] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What are the three levels of the OWASP Application Security Verification Standard (ASVS)?

The three levels of the OWASP Application Security Verification Standard (ASVS) are Level 1, Level 2, and Level 3. [1] [2]

5 verified sources
[1] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[3] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[4] OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) https://github.com/OWASP/ASVS/tree/master/5.0/en (verified 2026-08-11)
[5] OWASP ASVS — Requirements are split across three verification levels https://cybersigmacs.com/compliance-registry/#owasp-asvs-5-levels

What are the maximum administrative fines under GDPR Article 83?

The maximum administrative fines under GDPR Article 83 are:

- Up to EUR 10 million, or up to 2% of total worldwide annual turnover of the preceding financial year - for breaches of obligations such as security of processing, records of processing, and data protection by design and by default.

- Up to EUR 20 million, or up to 4% of total worldwide annual turnover - for breaches of the basic principles for processing (including conditions for consent), data subjects' rights, and the rules on transfers to third countries.

Fines must be effective, proportionate, and dissuasive. [1][2]

5 verified sources
[1] Regulation (EU) 2016/679 (GDPR), Article 83 - EUR-Lex https://eur-lex.europa.eu/eli/reg/2016/679/oj (verified 2026-08-13)
[2] EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (verified 2026-08-04)
[3] Regulation (EU) 2016/679 (GDPR), Article 30 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)
[4] GDPR — Administrative fines (Article 83) https://cybersigmacs.com/compliance-registry/#gdpr-article-83-fines
[5] Regulation (EU) 2016/679 (GDPR), Articles 35-36 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)

What are the six functions of the NIST Cybersecurity Framework 2.0?

The six functions of the NIST Cybersecurity Framework 2.0 are:

- GOVERN (GV) - establishing and monitoring the organization's cybersecurity risk management strategy, expectations, and policy.

- IDENTIFY (ID)

- PROTECT (PR)

- DETECT (DE)

- RESPOND (RS)

- RECOVER (RC)

These functions are intended to be performed concurrently and continuously. [2][5]

5 verified sources
[1] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST CSF — CSF 2.0 - six core functions https://cybersigmacs.com/compliance-registry/#nist-csf-2-functions
[5] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

Global / other

See our services

What are the key control domains of the Saudi NCA Essential Cybersecurity Controls (ECC)?

The key control domains of the Saudi NCA Essential Cybersecurity Controls (ECC) are:

1. Cybersecurity Governance

2. Cybersecurity Defense

3. Cybersecurity Resilience

4. Third-Party and Cloud Computing Cybersecurity [2]

5 verified sources
[1] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[2] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - ECC-2:2024 (English), Figures 3-4 and Table 1 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What are the levels of the CMMC (Cybersecurity Maturity Model Certification)?

The CMMC (Cybersecurity Maturity Model Certification) defines three levels:

- Level 1 (Foundational) - 17 practices protecting Federal Contract Information (FCI), verified by annual self-assessment. [1]

- Level 2 (Advanced) - the 110 security requirements of NIST SP 800-171 Revision 2, protecting Controlled Unclassified Information (CUI), most requiring a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO). [1]

- Level 3 (Expert) - Level 2 plus a subset of NIST SP 800-172 requirements for the highest-value CUI, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). [1]

5 verified sources
[1] 32 CFR Part 170 - CMMC Program (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[2] CMMC (US DoD) — Three levels and final-rule status https://cybersigmacs.com/compliance-registry/#cmmc-levels-final-rule
[3] CMMC Program - 32 CFR Part 170 and the DFARS 48 CFR acquisition rule (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[4] 32 CFR Part 170 - CMMC Program scope and assessment (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[5] US Federal Register — CMMC Program rule (32 CFR 170) https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program (verified 2026-08-01)

What is the ISO 22301 standard and what does it require?

ISO 22301:2019 is a standard for business continuity management systems, published on 30 October 2019, replacing the 2012 first edition. It does not specify detailed requirements but provides a framework for organizations to establish, implement, maintain, and continually improve their business continuity management systems. The amendment ISO 22301:2019/Amd 1:2024, published in February 2024, adds considerations for climate change to the management system requirements, though these amendments supplement the original standard rather than replace it. [1][2]

5 verified sources
[1] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[2] ISO 22301:2019 (iso.org) https://www.iso.org/standard/75106.html (verified 2026-08-11)
[3] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[4] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[5] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)

Have a question that isn’t here?

Ask our Compliance Assistant for a cited answer, or talk to a CERT-In empanelled, PCI QSA senior consultant.

Talk to an expert

Informational only, grounded on our verified registry and current as of each source’s last-verified date — not legal advice. Confirm against the primary source for your specific situation.