We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Registry v1.25.0 · every date sourced

India compliance deadlines tracker

The dated obligations from the India Compliance Registry in one timeline — each verified against the Gazette, the regulator or the standards body, never a blog. Governed by our editorial policy.

Upcoming

DPDP Act 2023Phase II — one year from notification13 November 2026

Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

NPCI / UPITPAP volume-cap compliance deadline - 31 December 202631 December 2026

NPCI's volume-cap guidelines for Third-Party Application Providers in UPI (referencing circular NPCI/UPI/OC-97/2020-21) were originally to bite from 31 December 2024. The compliance timeline for existing TPAPs exceeding the cap was extended by two years, to 31 December 2026. Separately, NPCI issued Guidelines on usage of UPI APIs (OC 215 series, May 2025) requiring PSPs and acquiring banks to monitor and control API usage, with non-compliance exposing them to API restriction, penalties or suspension of new customer onboarding.

Source: NPCI UPI circulars (official listing) · last verified 2026-08-07

DPDP Act 2023Phase III — substantive framework1 May 2027

Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023Penalty ceiling1 May 2027

The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

Source: DPDP Act 2023, the Schedule (official Gazette text) · last verified 2026-08-01

DPDP Act 2023Breach notification timeline (Rule 7)1 May 2027

Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.

Source: DPDP Rules 2025, Rule 7 · last verified 2026-08-01

DPDP Act 2023Notice contents (section 5)1 May 2027

Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.

Source: DPDP Act 2023, section 5 (official Gazette text) · last verified 2026-08-01

In force

EU AI ActTransitional deadlines for systems already on the market2 August 2026

Article 111 gives longer runways to AI already in service. Providers of general-purpose AI models placed on the market before 2 August 2025 must comply by 2 August 2027. High-risk systems placed on the market before 2 August 2026 are caught only if subject to significant design changes after that date — but providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 regardless. AI systems that are components of the large-scale IT systems listed in Annex X and placed on the market before 2 August 2027 must be brought into compliance by 31 December 2030.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-07

EU AI ActStaggered application under Article 1132 August 2026

Article 113 provides that the Regulation applies from 2 August 2026, with three exceptions: Chapters I and II (general provisions and prohibited AI practices) applied from 2 February 2025; Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 (notifying authorities, general-purpose AI models, governance, penalties and confidentiality) applied from 2 August 2025, with the exception of Article 101; and Article 6(1), covering high-risk classification for AI as a safety component of products already regulated under Union law, applies from 2 August 2027.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-07

EU AI ActDigital Omnibus on AI - high-risk deadlines postponed (current)27 July 2026

Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI) amends Regulation (EU) 2024/1689 and was published in the Official Journal on 24 July 2026, entering into force on 27 July 2026. It postpones the obligations for high-risk AI systems designated under Article 6(2) and Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products regulated under Annex I sectoral legislation to 2 August 2028. It also adds prohibitions to Article 5 covering AI that generates or manipulates realistic non-consensual intimate imagery of identifiable individuals. The Article 50 transparency duties applying from 2 August 2026 are unaffected.

Source: Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex · last verified 2026-08-07

SWIFT CSPFurther v2026 changes affecting scope and control expectations1 July 2026

Control 2.3 System Hardening now names Windows Management Instrumentation and PowerShell as native OS features to consider when shielding a Windows system. Control 2.9 Transaction Business Controls recognises Swift Universal Confirmation as a validation or reconciliation option alongside MT 900/910 and MT 940/950. Control 4.2 requires multi-factor authentication on one authentication stage for external privileged access managing firewalls, and Alliance Left and Right Security Officer accounts are now named as privileged accounts. Control 6.1 Malware Protection advises protecting non-Windows systems inside a secure zone or hosting a customer client connector. Control 7.2 Security Training and Awareness adds deepfakes as an example of AI-based threats.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

SWIFT CSPCustomer client connectors are now mandatory in scope, moving some users from architecture B to A41 July 2026

CSCF v2025 introduced the customer client connector — an endpoint consuming APIs, a middleware or a file transfer client — as an advisory in-scope component. In v2026 it becomes a mandatory in-scope component of fourteen basic cyber-hygiene controls: 1.2, 1.3, 1.4, 2.2, 2.3, 2.6, 2.7, 3.1, 4.1, 4.2, 5.1, 5.4, 6.1 and 6.4. All user endpoints that connect to Swift indirectly through a service provider sharing resources are progressively treated as customer connectors, whether server or client.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

SWIFT CSPControl 2.4 Back Office Data Flow Security became mandatory in v20261 July 2026

As announced in the previous version, control 2.4 Back Office Data Flow Security is mandatory in CSCF v2026, activating the phased approach in Appendix H. At minimum a user must now protect the bridging servers guarding flows between its secure zone and the back-office first hops where the exchange is not end-to-end protected, the flows between bridging servers and between bridging servers and the secure zone in the same circumstances, and the new direct flows between the secure zone and the back-office first hop.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

SWIFT CSPAttestation against CSCF v2026 runs July to December 20261 July 2026

Swift users must attest their compliance through the KYC Security Attestation (KYC-SA) application by the end of each year, against the CSCF in effect at that time. A new CSCF version is published each July and becomes the attestation basis from July of the following year. The document states the position for this cycle directly: users must attest between July 2026 and December 2026 against the controls listed in CSCF v2026, which was published in mid-2025.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

IRDAIInformation and Cybersecurity Guidelines, 2026 (current)6 April 2026

IRDAI issued Version 2.0 of its Information and Cyber Security Guidelines in April 2026, replacing the Information and Cyber Security Guidelines, 2023 dated 24 April 2023. They apply to all Insurers including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, and to all data created, received or maintained by Regulated Entities in any form. Insurance Agents, Micro-Insurance Agents, Point of Sale Persons and Individual Surveyors are expressly outside their purview, though Insurers remain responsible for ensuring those entities follow a minimum security framework under the Insurer’s Board-approved policy.

Source: IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) · last verified 2026-08-07

IRDAIManagement representation is not acceptable1 April 2026

Certification under these guidelines may not rest on management representation or on reliance upon the work of other auditors, because the auditor is appointed by regulated entities that must protect policyholder and public data. The auditor is required to perform the work through interviews, document verification, compliance checks and adequate testing of controls.

Source: IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV clause 3 · last verified 2026-08-08

IRDAIAudit report submission deadline1 April 2026

Insurers must submit the Audit Report (Annexure III), signed by the auditor and accompanied by the comments of the Board, to IRDAI within 90 days from the end of the financial year OR within 30 days of completion of the audit, whichever is earlier. Foreign Reinsurance Branches whose IT systems interface with overseas parent companies must comply and have the auditor certify per Annexure VI, submitted at the end of every financial year.

Source: IRDAI Information and Cybersecurity Guidelines, 2026 — clause on audit submission · last verified 2026-08-08

IRDAIWho may perform the audit (Annexure IV)1 April 2026

Annexure IV sets two alternative routes. Either a Chartered Accountant firm registered with ICAI (partnership or LLP) with at least five years of continuous practice and four partners, including one CISA/DISA holder, one ICAI Fellow, one with three years of cyber or information security audit experience in insurance companies, banks or mutual funds, and one with IT-environment and remote-audit experience — OR, in the guidelines’ own words, a “Cert-In empanelled external systems Auditor holding CISA / DISA certifications”. The auditor must not have been debarred or declared ineligible for corrupt or fraudulent practices by the Government of India, a State Government, IRDAI, SEBI, RBI, ICAI, CERT-In or SFIO.

Source: IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV · last verified 2026-08-08

RBIRegulation of Payment Aggregators Directions, 202531 December 2025

The Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025 (RBI/DPSS/2025-26/141), issued 15 September 2025 and in force from 31 December 2025, consolidate the earlier 2020, 2021 and 2023 payment-aggregator guidelines into a single framework covering online and face-to-face (proximity) payment aggregators. A non-bank entity carrying on payment-aggregator business must obtain RBI authorisation, and must have a minimum net worth of INR 15 crore at the time of application, rising to a minimum net worth of INR 25 crore by the end of the third financial year after authorisation, maintained thereafter. The directions also cover governance, KYC of merchants, escrow-account operation, security and reporting.

Source: RBI Master Direction RBI/DPSS/2025-26/141 - Regulation of Payment Aggregators Directions, 2025 · last verified 2026-08-13

DPDP Act 2023Phase I — in force on notification13 November 2025

Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023DPDP Rules 2025 notification13 November 2025

Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).

Source: MeitY / PIB — DPDP Rules 2025 · last verified 2026-08-01

CMMC (US DoD)Programme and acquisition rule dates10 November 2025

The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.

Source: US Federal Register — CMMC Program rule (32 CFR 170) · last verified 2026-08-01

CMMC (US DoD)Phased contractual rollout (DFARS)10 November 2025

CMMC requirements enter DoD contracts through the DFARS acquisition rule (48 CFR) on a phased schedule. Phase 1 began 10 November 2025, with Level 1 and Level 2 self-assessment requirements appearing in select solicitations at the CMMC Program Office's discretion. From 10 November 2026, CMMC Level 2 certification (C3PAO-assessed) is added to new and renewing contracts involving CUI, with further phases extending coverage over the following period.

Source: CMMC Program - 32 CFR Part 170 and the DFARS 48 CFR acquisition rule (eCFR) · last verified 2026-08-11

ISO/IEC 270012022-revision transition deadline31 October 2025

The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.

Source: ISO/IEC 27001 (iso.org) · last verified 2026-08-11

SEBI CSCRFIssuance and final compliance timeline31 August 2025

SEBI issued the Cybersecurity and Cyber Resilience Framework vide circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024 (Version 1.0, 205 pages). The compliance timeline was extended twice: circular 2025/45 of 28 March 2025 moved it by three months to 30 June 2025, and circular 2025/96 of 30 June 2025 moved it by a further two months to 31 August 2025. Both extensions applied to all regulated entities except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs) and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), which stayed on the original timeline. That final date has passed, so CSCRF is fully in force.

Source: SEBI — extension circular 2025/96 (official PDF, 30 June 2025) · last verified 2026-08-04

SEBI CSCRFLatest amendment: technical clarifications of 28 August 202528 August 2025

Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025 issues technical clarifications in four parts: Part A, principles for REs under multiple regulators' purview, introducing a Principle of Exclusivity and a Principle of Equivalence so an RE regulated by both SEBI and (for example) RBI can demonstrate compliance without duplicating work; Part B, technical clarifications; Part C, re-categorisation of Portfolio Managers and Merchant Bankers; and Part D, Cyber Security Audit Policy Guidelines from CERT-In.

Source: SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) · last verified 2026-08-04

EU AI ActThree penalty tiers under Article 992 August 2025

Infringement of the Article 5 prohibited-practices rules is subject to administrative fines of up to EUR 35 000 000 or 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher. Breach of most other operator obligations attracts up to EUR 15 000 000 or 3 %. Supplying incorrect, incomplete or misleading information to notified bodies or national authorities attracts up to EUR 7 500 000 or 1 %. For SMEs including start-ups, each ceiling is the lower rather than the higher of the two figures.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-04

EU AI ActCommencement and GPAI obligations2 August 2025

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).

Source: EU AI Act — official text (EUR-Lex 2024/1689) · last verified 2026-08-07

SWIFT CSPFive reference architecture types determine which components are in scope1 July 2025

Each user must identify which of five reference architecture types most closely matches its deployment, because scope and applicable controls follow from that choice. The types are A1 (user owns the communication interface, and generally the messaging interface), A2, A3, A4 and B. Component or licence ownership is the key differentiator, and where more than one could apply the most comprehensive architecture must be chosen. Swift publishes a CSP architecture decision tree to support the determination.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

SWIFT CSPCSCF v2026 contains 32 controls — 26 mandatory and 6 advisory1 July 2025

The framework sets out 32 security controls, of which 26 are mandatory and 6 advisory, resting on three overarching objectives supported by seven security principles. Mandatory controls establish a security baseline for the entire Swift user community; advisory controls are optional best practices Swift recommends. The six advisory controls are 2.5A External Transmission Data Protection, 2.11A RMA Business Controls, 5.3A Staff Screening Process, 6.5A Intrusion Detection, 7.3A Penetration Testing and 7.4A Scenario-based Risk Assessment.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-11

OWASP ASVSCurrent version1 May 2025

OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).

Source: OWASP ASVS project · last verified 2026-08-01

PCI DSSSAQ A: card-not-present with all account data functions fully outsourced1 April 2025

SAQ A covers e-commerce or mail/telephone-order merchants who outsource all processing of account data to PCI DSS compliant third parties, store, process and transmit no account data electronically on their own systems or premises, have confirmed those third parties are compliant for the services used, and retain any account data only on paper not received electronically. E-commerce merchants must additionally confirm that every element of the payment page delivered to the customer’s browser originates only and directly from a compliant third-party processor, and that their site is not susceptible to script-based attacks affecting their e-commerce systems. SAQ A does not apply to face-to-face channels or to service providers.

Source: PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) · last verified 2026-08-04

PCI DSSv4.x lifecycle dates31 March 2025

PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.

Source: PCI Security Standards Council (official blog) · last verified 2026-08-01

DORA (EU)Digital Operational Resilience Act for the financial sector17 January 2025

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is a directly applicable EU regulation adopted on 14 December 2022 that sets uniform requirements for the security of network and information systems of financial entities and their critical ICT third-party providers. It applies to a broad range of EU-regulated financial entities - banks, insurers, investment firms, payment institutions and others - requiring ICT risk management, ICT-related incident reporting, digital operational resilience testing, and oversight of ICT third-party risk. It became applicable across all member states on 17 January 2025.

Source: Regulation (EU) 2022/2554 (DORA) - EUR-Lex · last verified 2026-08-13

OWASP ASVSVersion 5.0 chapter structure1 January 2025

OWASP ASVS 5.0 reorganises its requirements into 17 chapters (V1-V17): V1 Encoding and Sanitization, V2 Validation and Business Logic, V3 Web Frontend Security, V4 API and Web Service, V5 File Handling, V6 Authentication, V7 Session Management, V8 Authorization, V9 Self-contained Tokens, V10 OAuth and OIDC, V11 Cryptography, V12 Secure Communication, V13 Configuration, V14 Data Protection, V15 Secure Coding and Architecture, V16 Security Logging and Error Handling, V17 WebRTC. This is a substantial restructure from the v4.0.x chapter layout - a mapping is needed when moving an assessment from 4.0 to 5.0.

Source: OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) · last verified 2026-08-11

CMMC (US DoD)Who it applies to16 December 2024

CMMC applies to DoD contractors and subcontractors across the Defense Industrial Base that process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The required level flows down through the supply chain by the nature of the information handled: FCI-only work maps to Level 1, CUI to Level 2, and the most sensitive CUI to Level 3. An affirming senior official must attest to compliance in SPRS, and assessments carry a validity period (self-assessments affirmed annually; C3PAO certifications on a three-year cycle).

Source: 32 CFR Part 170 - CMMC Program scope and assessment (eCFR) · last verified 2026-08-11

CMMC (US DoD)Three levels and final-rule status16 December 2024

The Cybersecurity Maturity Model Certification (CMMC) Program final rule is codified at 32 CFR Part 170 and took effect on 16 December 2024. It defines three levels: Level 1 (Foundational) - 17 practices protecting Federal Contract Information (FCI), verified by annual self-assessment; Level 2 (Advanced) - the 110 security requirements of NIST SP 800-171 Revision 2, protecting Controlled Unclassified Information (CUI), most requiring a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO); Level 3 (Expert) - Level 2 plus a subset of NIST SP 800-172 requirements for the highest-value CUI, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Source: 32 CFR Part 170 - CMMC Program (eCFR) · last verified 2026-08-11

SEBI CSCRFThe Cyber Capability Index applies only to the top two categories20 August 2024

The Cyber Capability Index (CCI) applies only to MIIs and Qualified REs. MIIs must have their cyber resilience assessed against the CCI by a third party on a half-yearly basis; Qualified REs self-assess their cyber resilience using the CCI on a yearly basis.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFA Security Operations Centre is mandatory, with a Market SOC route for smaller entities20 August 2024

CSCRF mandates a SOC for all REs except client-based stock brokers with fewer than 100 clients. An RE may use its own or group SOC, any third-party managed SOC, or the Market SOC. Small-size and Self-certification category REs are required to onboard the Market SOC, which NSE and BSE must set up and which NSDL and/or CDSL may set up optionally.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFVAPT reporting, closure and revalidation deadlines20 August 2024

The VAPT report must be submitted within one month of completing the VAPT activity, after approval from the RE's IT Committee. Findings must be closed within three months of report submission, following a graded approach based on the criticality of the observations. Revalidation of the VAPT must be completed within five months of its completion.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFVAPT frequency depends on NCIIPC designation20 August 2024

REs identified as “Protected systems” and/or Critical Information Infrastructure by NCIIPC must complete at least two VAPT activities each year — one in each half of the financial year (April to September, October to March), each including report submission, closure and revalidation. All other REs must complete at least one, with the activity commencing in the first quarter of the financial year.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFAudits must be conducted by a CERT-In empanelled organisation20 August 2024

The framework states: “Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization.” The same requirement is restated for the VAPT and cyber audit that the Market SOC is to provide to small- and mid-size REs at affordable cost.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFRegulated entities are sorted into five compliance categories20 August 2024

CSCRF applies proportionately by category: (i) Market Infrastructure Institutions (MIIs), (ii) Qualified REs, (iii) Mid-size REs, (iv) Small-size REs and (v) Self-certification REs. Entity-wise thresholds that determine which category an RE falls into are set out in the framework's “Thresholds for REs’ categorization” section.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

PCI DSSStructure - six goals and twelve requirements11 June 2024

PCI DSS organises its controls into six goals (control objectives) that break down into 12 core requirements: build and maintain a secure network and systems (Req 1-2), protect account data (Req 3-4), maintain a vulnerability management programme (Req 5-6), implement strong access control measures (Req 7-9), regularly monitor and test networks (Req 10-11), and maintain an information security policy (Req 12). Each requirement contains testing procedures and, in v4.0, a defined and a customised approach. The current version, PCI DSS v4.0.1, was published in June 2024 as a limited revision of v4.0 that corrects minor errors and clarifies language without adding new requirements.

Source: PCI SSC - Document Library (PCI DSS v4.0.1) · last verified 2026-08-13

NIST SP 800-171Protecting Controlled Unclassified Information (CUI)14 May 2024

NIST Special Publication 800-171 gives recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organisations. It applies to contractors, universities and other nonfederal entities that process, store or transmit CUI on behalf of U.S. federal agencies, and underpins the DoD's CMMC Level 2. Revision 3 organises the security requirements into 17 families derived from NIST SP 800-53.

Source: NIST SP 800-171 Rev. 3 - Protecting CUI (NIST CSRC) · last verified 2026-08-13

RBIIT Governance Master Direction1 April 2024

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

Source: Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) · last verified 2026-08-01

RBIIT Governance, Risk, Controls and Assurance Practices Directions (2023)1 April 2024

The Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023 (RBI/2023-24/107), effective 1 April 2024, is a Master Direction that consolidates and supersedes earlier RBI IT-governance and cyber-risk instructions. It applies to regulated entities including scheduled commercial banks (excluding RRBs), small finance banks, payments banks, NBFCs in the specified layers, credit information companies, and all-India financial institutions (NABARD, EXIM Bank, NHB, SIDBI, NaBFID). It requires a board-level IT governance framework covering strategic alignment, risk management, resource and performance management, and business continuity and disaster recovery, plus an IT and information-security risk management framework and periodic information systems audits.

Source: RBI Master Direction RBI/2023-24/107 - IT Governance, Risk, Controls and Assurance Practices · last verified 2026-08-13

NIST CSFThe CSF states outcomes and does not prescribe how to achieve them26 February 2024

NIST states that the CSF “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity”, and that it “does not prescribe how outcomes should be achieved”, instead linking to online resources describing practices and controls. This is why the CSF is not certifiable and why an organisation cannot be audited as “CSF compliant” the way it can against ISO/IEC 27001 or PCI DSS.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFFour Tiers describe rigour of risk governance26 February 2024

The framework defines four Tiers, quoted from the document: “Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).” Tiers characterise the rigour of an organisation’s cybersecurity risk governance and management practices; they are not maturity levels and reaching Tier 4 is not a goal for every organisation.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFThe Core contains 22 Categories and 106 Subcategories26 February 2024

Beneath the six Functions, the CSF 2.0 Core is organised into 22 Categories and 106 Subcategories. Subcategories state outcomes, not controls, and are the level at which an organisation assesses and communicates its current and target state.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFSix Functions organise the Core26 February 2024

CSF 2.0 organises cybersecurity outcomes under six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS) and RECOVER (RC). GOVERN is new in 2.0 and covers how an organisation establishes and monitors its cybersecurity risk management strategy, expectations and policy.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFVersion 2.0 release26 February 2024

NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.

Source: NIST (official release announcement) · last verified 2026-08-01

NIST CSFCSF 2.0 - six core functions26 February 2024

The NIST Cybersecurity Framework 2.0, released on 26 February 2024 (NIST CSWP 29), is the first major revision since 2014. It organises cybersecurity outcomes into six core functions: Govern (new in 2.0 - establishing and monitoring the organisation's cybersecurity risk-management strategy, expectations and policy), Identify, Protect, Detect, Respond and Recover. CSF 2.0 broadens the framework's scope from critical infrastructure to organisations of all sizes and sectors, and strengthens its treatment of governance and supply-chain risk. The functions are intended to be performed concurrently and continuously.

Source: NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 · last verified 2026-08-13

ISO 22301Amendment 1:2024 (climate action)1 February 2024

ISO published ISO 22301:2019/Amd 1:2024 in February 2024, adding consideration of climate change to the management system requirements. ISO 22301:2019 remains the current edition - the amendment supplements it rather than replacing it, and a next edition is in development with no confirmed publication date.

Source: ISO 22301:2019/Amd 1:2024 (iso.org) · last verified 2026-08-07

NCA ECC (Saudi Arabia)Compliance evaluation mechanism1 January 2024

Under Article 10(3) of the NCA Statute and High Order No. 57231 (10/11/1439H), in-scope entities must ensure ongoing continuous compliance with the ECC. The NCA evaluates compliance through self-assessments, periodic reports of its compliance tool, and/or field auditing visits, and issues an ECC-2:2024 Assessment and Compliance Tool to organise assessment. Controls under Subdomain 4-2 (Cloud Computing and Hosting Cybersecurity) are binding on entities currently using or planning to use cloud computing and hosting services.

Source: NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section · last verified 2026-08-11

NCA ECC (Saudi Arabia)Essential Cybersecurity Controls versions1 January 2024

Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018. ECC-2:2024 consists of 4 cybersecurity main domains (Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party & Cloud Computing Cybersecurity), 28 subdomains, 108 main controls and 92 subcontrols. The Controls apply to government agencies in the Kingdom (including ministries, authorities and establishments) and their affiliated companies and entities inside and outside the Kingdom, and to all private-sector entities owning, operating or hosting Critical National Infrastructure; each entity must comply with all controls applicable to it.

Source: NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) · last verified 2026-08-11

NCA ECC (Saudi Arabia)Control coding scheme1 January 2024

ECC-2:2024 decodes as Essential Cybersecurity Controls, version 2, year of issuance 2024. Individual control codes are four-part: Main-domain . Subdomain . Main-control . Sub-control (for example 2-3-2-6). The methodological structure gives each subdomain an objective and a set of numbered control clauses.

Source: NCA - ECC-2:2024 (English), Figures 3-4 and Table 1 · last verified 2026-08-11

NCA ECC (Saudi Arabia)Saudization of cybersecurity positions and independent function1 January 2024

Under Cybersecurity Governance, ECC-2:2024 requires that a cybersecurity department be established that is INDEPENDENT of the IT/Communications department (control 1-2-1, per High Order No. 37140 dated 14/08/1438H), reporting to the head of the entity or their delegate; that ALL cybersecurity positions be filled with full-time, qualified SAUDI cybersecurity professionals (control 1-2-2); and that a cybersecurity supervisory committee be established (control 1-2-3). The cybersecurity strategy must be documented and approved by the Authorized Official and reviewed at planned intervals (subdomain 1-1).

Source: NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 · last verified 2026-08-11

NCA ECC (Saudi Arabia)Domain and subdomain structure1 January 2024

ECC-2:2024 organises its controls under 4 main domains and 28 subdomains: (1) Cybersecurity Governance - 10 subdomains (Strategy; Management; Policies and Procedures; Roles and Responsibilities; Risk Management; Cybersecurity in IT Project Management; Compliance with Standards, Laws and Regulations; Periodical Review and Audit; Cybersecurity in Human Resources; Awareness and Training Program). (2) Cybersecurity Defense - 15 subdomains (Asset Management; Identity and Access Management; Information Systems and Information Processing Facilities Protection; Email Protection; Network Security Management; Mobile Devices Security; Data and Information Protection; Cryptography; Backup and Recovery Management; Vulnerability Management; Penetration Testing; Cybersecurity Event Logs and Monitoring Management; Cybersecurity Incident and Threat Management; Physical Security; Web Application Security). (3) Cybersecurity Resilience - 1 subdomain (Resilience Aspects of Business Continuity Management). (4) Third-Party and Cloud Computing Cybersecurity - 2 subdomains (Third-Party Cybersecurity; Cloud Computing and Hosting Cybersecurity).

Source: NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 · last verified 2026-08-11

ISO/IEC 42001ISO/IEC 42001:2023 - AI management systems18 December 2023

ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS), published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AIMS, so that an organisation developing, providing or using AI does so responsibly. Organisations build the management system against clauses 4 to 10 and select applicable controls from Annex A, a reference set of 38 controls across 9 objectives covering areas such as data quality, the AI system lifecycle, transparency, human oversight and AI impact assessment. Certification is by an accredited body through a Stage 1 (documentation) and Stage 2 (operational) audit.

Source: ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) · last verified 2026-08-13

ISO/IEC 42001Publication1 December 2023

ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.

Source: ISO/IEC 42001 (iso.org) · last verified 2026-08-11

RBIIT Outsourcing Master Direction1 October 2023

Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

Source: Reserve Bank of India (Master Direction RBI/2023-24/102) · last verified 2026-08-01

DPDP Act 2023Enactment11 August 2023

Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.

Source: Official Gazette text (MeitY PDF) · last verified 2026-07-31

Qatar NIA (NCSA)National Information Assurance Policy version1 May 2023

Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.

Source: NCSA Qatar (official portal) · last verified 2026-08-01

IRDAIInformation and Cyber Security Guidelines, 2023 (superseded)24 April 2023

IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 (ref IRDAI/GA&HR/GDL/MISC/88/04/2023), superseding the 2017 guidelines (IRDA/IT/GDL/MISC/082/04/2017) and three subsequent circulars. These were themselves superseded on 6 April 2026 by the IRDAI Information and Cybersecurity Guidelines, 2026 (Version 2.0) - the 2023 text is retained here as the previous baseline, not as the current requirement.

Source: IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) · last verified 2026-08-07

CCPA / CPRA (US-California)California consumer privacy law, as amended by the CPRA1 January 2023

The California Consumer Privacy Act of 2018 gives California residents rights over the personal information businesses collect about them, and was amended by the voter-approved California Privacy Rights Act (Proposition 24), whose additional protections took effect on 1 January 2023. It is enforced by the California Attorney General and the California Privacy Protection Agency. It applies to for-profit businesses doing business in California that meet any threshold (over 25 million US dollars gross annual revenue; buying, selling or sharing the personal information of 100,000 or more California residents; or deriving 50 percent or more of revenue from selling residents personal information). Consumers have rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive information, and non-discrimination.

Source: California Attorney General - California Consumer Privacy Act (CCPA) · last verified 2026-08-13

NIS2 (EU)EU-wide cybersecurity directive for essential and important entities14 December 2022

Directive (EU) 2022/2555 (NIS2), adopted on 14 December 2022, lays down measures for a high common level of cybersecurity across the European Union and repeals the earlier NIS Directive (EU) 2016/1148. It applies to essential and important entities across critical sectors (energy, transport, banking, health, digital infrastructure, public administration and more) and imposes cybersecurity risk-management measures, governance accountability, and significant-incident reporting, backed by supervision and enforcement. As a directive it must be transposed into each member state's national law.

Source: Directive (EU) 2022/2555 (NIS2) - EUR-Lex · last verified 2026-08-13

PCI SSFSoftware Security Framework (successor to PA-DSS)31 October 2022

The PCI Software Security Framework (SSF) is a collection of standards and validation programmes from the PCI Security Standards Council that promotes security in payment software and replaced PA-DSS. It comprises two standards: the Secure Software Standard, which assesses payment-software products, and the Secure Software Lifecycle (Secure SLC) Standard, which assesses a vendor's ongoing secure-development processes. It applies to payment-software vendors and their products; PA-DSS was formally retired at the end of October 2022, after which the SSF became the applicable framework.

Source: PCI SSC - Software Security Framework · last verified 2026-08-13

ISO/IEC 27001Annex A control count (2022 revision)25 October 2022

ISO/IEC 27001:2022 Annex A contains 93 controls organised into four themes: Organisational (37 controls, clause 5), People (8 controls, clause 6), Physical (14 controls, clause 7) and Technological (34 controls, clause 8). This restructures the 114 controls across 14 domains of the 2013 edition - the count fell through consolidation and merging, not a reduction in scope. Organisations certified to ISO/IEC 27001:2013 were required to transition to the 2022 edition.

Source: ISO/IEC 27001:2022 - Information security management systems (ISO) · last verified 2026-08-13

ISO/IEC 27005Guidance on managing information security risks1 October 2022

ISO/IEC 27005 is an international standard jointly published by ISO and IEC that provides guidance to support the establishment and operation of information security risk management within an ISO/IEC 27001 ISMS. It applies to organisations of all types and sizes and gives a structured approach for identifying, analysing, evaluating and treating information security risks, aligned with ISO/IEC 27001:2022 and ISO 31000:2018. It is guidance rather than a certifiable requirements standard; the current edition is ISO/IEC 27005:2022.

Source: ISO/IEC 27005:2022 - Information security risk management (ISO) · last verified 2026-08-13

ISO/IEC 27001Current edition and title1 October 2022

The current edition is ISO/IEC 27001:2022, the third edition, published October 2022, titled “Information security, cybersecurity and privacy protection — Information security management systems — Requirements”. It specifies requirements for establishing, implementing, maintaining and continually improving an information security management system, and is the standard against which organisations are certified.

Source: ISO — ISO/IEC 27001:2022 catalogue entry · last verified 2026-08-08

CERT-In DirectionsProvider record-keeping28 June 2022

Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsTime synchronisation28 June 2022

System clocks must be synchronised to NIC or NPL time sources.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsLog retention28 June 2022

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIncident reporting window28 June 2022

Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIssue and commencement28 June 2022

Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

PDPA (Thailand)Thailand Personal Data Protection Act B.E. 2562 (2019)1 June 2022

Thailand's Personal Data Protection Act B.E. 2562 (2019) is the country's comprehensive data protection law, enforced by the Personal Data Protection Committee (PDPC). It governs the collection, use and disclosure of personal data by data controllers and processors, requiring a lawful basis (often consent), data-subject rights, security safeguards and rules on cross-border transfers. After pandemic-related postponements its main operative provisions took full effect on 1 June 2022, and it applies to organisations processing the personal data of individuals in Thailand, including certain extraterritorial processing.

Source: Personal Data Protection Committee (PDPC) Thailand - official portal · last verified 2026-08-13

ISO/IEC 27002Information security controls guidance (companion to 27001)15 February 2022

ISO/IEC 27002:2022 is an international standard from ISO and IEC that provides a reference set of information security controls with detailed implementation guidance. It is a guidance document and is not certifiable on its own; organisations use it to implement the controls selected in an ISO/IEC 27001 ISMS. The 2022 edition reorganises the controls into the same four themes as ISO/IEC 27001:2022 Annex A - organisational, people, physical and technological - covering 93 controls.

Source: ISO/IEC 27002:2022 - Information security controls (ISO) · last verified 2026-08-13

Oman PDPLOman Personal Data Protection Law (Royal Decree 6/2022)9 February 2022

The Personal Data Protection Law, promulgated by Royal Decree 6/2022, is Oman's national data protection statute, with the Ministry of Transport, Communications and Information Technology designated as the regulatory and enforcement authority. It governs the processing of personal data and grants data owners rights including consent, withdrawal of consent, correction and deletion, while imposing obligations on controllers and processors. The law comprises 32 articles across five chapters, requires the data owner's consent before processing, and is supported by an Executive Regulation issued in 2024.

Source: Sultanate of Oman, MTCIT - Royal Decree 6/2022 Personal Data Protection Law · last verified 2026-08-13

UAE PDPLEnactment and effect2 January 2022

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued on 20 September 2021, published in Official Gazette No. 712 (supplement) on 26 September 2021, and came into effect on 2 January 2022; the legislation portal lists it as Active. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.

Source: UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) · last verified 2026-08-11

UAE PDPLObligations and rights - article map2 January 2022

Federal Decree-Law 45/2021 requires controllers and processors to meet general obligations (Articles 7-8), report personal data breaches (Article 9), appoint a Data Protection Officer with defined roles (Articles 10-12), honour data-subject rights to information, portability, correction/erasure, restriction and objection (Articles 13-18), secure personal data (Article 20), run data protection impact assessments (Article 21) and control cross-border transfer and sharing (Articles 22-23).

Source: UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) · last verified 2026-08-11

UAE PDPLComplaints, penalties and Executive Regulation (Articles 24-28)2 January 2022

The law provides an enforcement structure: data subjects may file complaints with the UAE Data Office (Article 24), grievances against the Office's decisions are provided for (Article 25), and administrative penalties for violations are established (Article 26). Article 28 provides for an Executive Regulation to be issued to detail the law's implementation. The Decree-Law thus contemplates its own detailed regulations - whether that Executive Regulation has yet been issued is tracked separately and remains unresolved in public sources.

Source: UAE Legislation portal - Federal Decree-Law 45/2021, Articles 24-28 (official) · last verified 2026-08-11

UAE PDPLLawful processing and consent (Articles 4-6)2 January 2022

Federal Decree-Law 45/2021 makes consent the default basis for processing personal data, and Article 4 sets out the cases where personal data may be processed WITHOUT the owner's consent (including where necessary to protect the public interest, for legal proceedings, to protect the data subject's interests, or for the controller's legitimate purposes without prejudice to the data subject's rights). Article 5 fixes the personal-data processing controls (fair, transparent and lawful processing; specified purpose; accuracy; minimisation; and secure retention), and Article 6 sets the terms a valid consent must meet.

Source: UAE Legislation portal - Federal Decree-Law 45/2021, Articles 4-6 (official) · last verified 2026-08-11

SOC 2 (AICPA)Trust Services Criteria - current version1 January 2022

The criteria for a SOC 2 examination are set out in TSP Section 100, “2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus — 2022)”, established by the AICPA’s Assurance Services Executive Committee (ASEC). They cover five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. The 2022 revision updated the points of focus rather than the criteria themselves, which is why the document is still titled as the 2017 criteria.

Source: AICPA - 2017 Trust Services Criteria (With Revised Points of Focus - 2022) · last verified 2026-08-08

SOC 2 (AICPA)Common criteria structure1 January 2022

The common criteria are the criteria shared by all five trust services categories. They comprise 33 individual criteria organised across nine series, CC1 to CC9. Points of focus sit beneath the criteria and describe characteristics that may be considered when evaluating whether a criterion is met; the concept is drawn from COSO’s Internal Control — Integrated Framework, and points of focus are not themselves requirements to be met one by one.

Source: AICPA TSP Section 100 — common criteria and points of focus · last verified 2026-08-08

SOC 2 (AICPA)Security is near-universal but NOT mandatory1 January 2022

TSP Section 100 paragraph .14 states that the security category “is addressed in most trust services engagements”, and paragraph .15 adds that “although uncommon, there may be circumstances in which the security category is not addressed by a trust services examination”. Where security IS included, ASEC has determined the common criteria alone are suitable and no additional control activity criteria are needed. Where availability, processing integrity, confidentiality or privacy are included, a complete set consists of the common criteria plus the control activity criteria for that category.

Source: AICPA TSP Section 100, paragraphs .14 and .15 · last verified 2026-08-08

POPIA (South Africa)South Africa Protection of Personal Information Act 4 of 20131 July 2021

The Protection of Personal Information Act 4 of 2013 (POPIA) gives effect to the constitutional right to privacy by regulating how public and private bodies process personal information in South Africa. It is monitored and enforced by the Information Regulator (South Africa). Its substantive conditions for lawful processing became fully enforceable on 1 July 2021, requiring responsible parties to meet eight conditions for lawful processing and to safeguard personal information, with penalties including administrative fines and, for some offences, imprisonment.

Source: Information Regulator (South Africa) - POPIA · last verified 2026-08-13

CIS ControlsCIS Critical Security Controls v8 - 18 controls, 153 safeguards18 May 2021

The CIS Critical Security Controls (Version 8) are a prioritised set of cybersecurity best practices published and maintained by the Center for Internet Security (CIS). Version 8 consolidates the guidance into 18 top-level Controls containing 153 Safeguards, organised into three Implementation Groups (IG1 to IG3) scaled to an organisation's risk and resources. They apply to organisations of any size and are mapped to other frameworks such as the NIST Cybersecurity Framework.

Source: CIS Critical Security Controls Version 8 (Center for Internet Security) · last verified 2026-08-13

CKYC (CERSAI)Applicability was phased between 2016 and 20211 April 2021

The CKYCR live run began on 15 July 2016, phased, starting with new individual accounts. Scheduled Commercial Banks were required to upload KYC data for all new individual accounts opened on or after 1 January 2017 (with an initial allowance to 1 February 2017 for accounts opened during January 2017). Regulated entities other than SCBs were required to start uploading for new individual accounts opened on or after 1 April 2017. KYC records for accounts of Legal Entities opened on or after 1 April 2021 must also be uploaded.

Source: RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) · last verified 2026-08-07

RBIDigital Payment Security Controls Master Direction18 February 2021

Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

Source: Reserve Bank of India (Master Direction, 18 Feb 2021) · last verified 2026-08-01

RBIMaster Direction on Digital Payment Security Controls (2021)18 February 2021

The RBI Master Direction on Digital Payment Security Controls (RBI/2020-21/74, DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21), dated 18 February 2021, sets out a robust governance structure and common minimum standards of security controls for digital payment products and services. It covers areas such as internet banking, mobile banking and card payments, along with customer protection and grievance redressal. It applies to Scheduled Commercial Banks (excluding Regional Rural Banks), Small Finance Banks, Payments Banks and credit-card-issuing NBFCs, and took effect within six months of being placed on the RBI website.

Source: RBI Master Direction - Digital Payment Security Controls (RBI/2020-21/74) · last verified 2026-08-13

CSA CCM / STARCloud Controls Matrix and the STAR registry21 January 2021

The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing published by the Cloud Security Alliance (CSA), organised into 17 domains of cloud security and privacy controls and mapped to leading standards and regulations. It defines responsibilities between cloud service providers and customers and is used to assess cloud security posture. Together with the Consensus Assessments Initiative Questionnaire (CAIQ), the CCM is the basis for CSA's Security, Trust, Assurance and Risk (STAR) programme and its public registry of provider self-assessments and third-party certifications.

Source: CSA Cloud Controls Matrix (Cloud Security Alliance) · last verified 2026-08-13

MAS TRM (Singapore)Technology Risk Management Guidelines (2021)18 January 2021

The Technology Risk Management (TRM) Guidelines are risk-management principles and best-practice standards issued by the Monetary Authority of Singapore (MAS) for financial institutions. The revised 2021 guidelines set expectations for technology-risk governance and oversight, secure system development, resilience, incident response and third-party and cloud-risk management to strengthen cyber resilience. They apply to all MAS-regulated financial institutions - including banks, insurers, fund managers and payment service providers - and were issued on 18 January 2021.

Source: MAS - Technology Risk Management Guidelines · last verified 2026-08-13

SWIFT CSPProgramme and independent assessment1 January 2021

SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.

Source: SWIFT — Customer Security Programme (official) · last verified 2026-08-11

NIST SP 800-53Security and privacy controls catalog (Rev. 5)23 September 2020

NIST Special Publication 800-53, Revision 5, is a U.S. National Institute of Standards and Technology publication providing a comprehensive catalog of security and privacy controls for information systems and organisations. It supports U.S. federal agencies (and is widely used by others) in protecting operations, assets and individuals from a broad range of threats and privacy risks. Revision 5 consolidates security and privacy controls into a single catalog, makes them outcome-based and control-organisation-neutral, and groups them into 20 control families.

Source: NIST SP 800-53 Rev. 5 - Security and Privacy Controls (NIST CSRC) · last verified 2026-08-13

NIST SP 800-207 (Zero Trust)Zero Trust Architecture11 August 2020

NIST Special Publication 800-207, Zero Trust Architecture, is a U.S. NIST publication defining zero trust concepts and an abstract model of components, deployment scenarios and use cases for enterprises adopting zero trust. It describes zero trust as moving defences from static network perimeters to focus on users, assets and resources, with access decisions made per session based on policy and continuous verification. It is aimed at enterprise network architects and is a widely referenced federal baseline for zero-trust guidance.

Source: NIST SP 800-207 - Zero Trust Architecture (CSRC) · last verified 2026-08-13

NIST Privacy FrameworkVoluntary privacy risk-management framework (v1.0)16 January 2020

The NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management (Version 1.0) is a voluntary framework from the U.S. National Institute of Standards and Technology to help organisations identify and manage privacy risk. It is organised into five functions (Identify-P, Govern-P, Control-P, Communicate-P and Protect-P) subdivided into categories and subcategories, and is designed to align structurally with the NIST Cybersecurity Framework. It is technology-, sector- and law-agnostic and can be used by organisations of any size.

Source: NIST - Privacy Framework v1.0 (CSRC) · last verified 2026-08-13

ISO 223012019 revision publication30 October 2019

ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.

Source: ISO 22301:2019 (iso.org) · last verified 2026-08-11

Bahrain PDPLBahrain Personal Data Protection Law (Law No. 30 of 2018)1 August 2019

Law No. 30 of 2018 with respect to Personal Data Protection is Bahrain's national data protection statute, enforced by the Personal Data Protection Authority established under the Ministry of Justice and Islamic Affairs. It applies to the processing of personal data of individuals in Bahrain by data managers and processors in the public or private sector. As a core rule it prohibits processing personal data without the data subject's explicit consent except on specified legal grounds, and it restricts transferring personal data outside Bahrain unless an adequate level of protection or a specific authorisation exists.

Source: Kingdom of Bahrain, Personal Data Protection Authority - Law No. 30 of 2018 · last verified 2026-08-13

RBIPayment system data storage in India6 October 2018

RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

Source: Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) · last verified 2026-08-01

ISO/IEC 20000-1IT service management system requirements1 September 2018

ISO/IEC 20000-1 is an international standard jointly published by ISO and IEC that specifies requirements to establish, implement, maintain and continually improve a service management system (SMS) for the planning, design, transition, delivery and improvement of services. It applies to any organisation delivering services, regardless of type or size, and is the only part of the ISO/IEC 20000 family to which an organisation can be certified. The current third edition is ISO/IEC 20000-1:2018.

Source: ISO/IEC 20000-1:2018 - IT service management (ISO) · last verified 2026-08-13

LGPD (Brazil)Brazil General Data Protection Law (Lei 13.709/2018)14 August 2018

The Lei Geral de Protecao de Dados Pessoais (Law No. 13.709), enacted 14 August 2018, regulates the processing of personal data by individuals and public or private entities to protect the fundamental rights of freedom and privacy. It is enforced by the Autoridade Nacional de Protecao de Dados (ANPD). It applies to any processing carried out in Brazil, or that offers goods or services to or processes the data of individuals located in Brazil, and it sets out legal bases for processing, data-subject rights, and administrative penalties (fines up to 2 percent of Brazil revenue, capped at 50 million reais per infraction).

Source: Presidencia da Republica (Planalto) - Lei No. 13.709/2018 · last verified 2026-08-13

GDPRTwo tiers of administrative fine under Article 8325 May 2018

The lower tier is up to 10 000 000 EUR or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher — covering obligations of controllers and processors such as security of processing, records and breach notification. The higher tier is up to 20 000 000 EUR or 4 % of total worldwide annual turnover, whichever is higher — covering the basic principles for processing, conditions for consent, data-subject rights, and transfers to third countries.

Source: EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text · last verified 2026-08-04

GDPRBreach notification to the supervisory authority within 72 hours25 May 2018

A controller must notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours it must be accompanied by reasons for the delay.

Source: EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text · last verified 2026-08-04

GDPRApplication date25 May 2018

Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).

Source: GDPR — official text (EUR-Lex 2016/679) · last verified 2026-08-01

GDPRData protection officer (Articles 37-39)25 May 2018

GDPR Articles 37-39 require designation of a data protection officer (DPO) where processing is carried out by a public authority, or where the core activities consist of regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data or criminal-conviction data. The DPO is designated on the basis of professional qualities and expert knowledge of data protection law, must be involved in all data-protection matters, report to the highest management level, and cannot be dismissed or penalised for performing the role.

Source: Regulation (EU) 2016/679 (GDPR), Articles 37-39 - EUR-Lex consolidated text · last verified 2026-08-11

GDPRData protection impact assessment (Article 35)25 May 2018

GDPR Article 35 requires a data protection impact assessment (DPIA) before processing that is likely to result in a high risk to the rights and freedoms of natural persons - in particular for systematic and extensive automated evaluation (including profiling) with legal or similarly significant effects, large-scale processing of special categories of data, or large-scale systematic monitoring of a publicly accessible area. Where a DPIA indicates high residual risk absent mitigation, Article 36 requires prior consultation with the supervisory authority.

Source: Regulation (EU) 2016/679 (GDPR), Articles 35-36 - EUR-Lex consolidated text · last verified 2026-08-11

GDPRRecords of processing activities (Article 30)25 May 2018

GDPR Article 30 requires controllers and processors to maintain records of processing activities (RoPA) under their responsibility, including purposes, categories of data subjects and personal data, recipients, third-country transfers, retention time limits and a general description of technical and organisational security measures. The obligation has a limited exemption for organisations under 250 employees, which falls away where processing is not occasional, is likely to result in a risk to rights and freedoms, or involves special-category or criminal-conviction data.

Source: Regulation (EU) 2016/679 (GDPR), Article 30 - EUR-Lex consolidated text · last verified 2026-08-11

UK GDPR & DPA 2018UK data protection legal framework25 May 2018

The UK GDPR together with the Data Protection Act 2018 form the United Kingdom's data protection framework, regulated and enforced by the Information Commissioner's Office (ICO). The UK GDPR sets the core principles, lawful bases and data-subject rights, while the DPA 2018 supplements it with UK-specific exemptions, rules for law-enforcement and intelligence processing, and the ICO's powers and penalties. It applies to organisations processing the personal data of individuals in the UK; the DPA 2018 took effect on 25 May 2018 and the UK GDPR applied following the Brexit transition.

Source: ICO - Data Protection Act 2018 / UK GDPR · last verified 2026-08-13

RBIStorage of Payment System Data (data localisation)6 April 2018

The RBI circular on Storage of Payment System Data (RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018), dated 6 April 2018, requires all system providers to ensure that the entire data relating to the payment systems they operate is stored in a system only in India. This includes the full end-to-end transaction details and any information collected, carried or processed as part of the payment message or instruction. Providers were given six months to comply and to submit a System Audit Report conducted by a CERT-In empanelled auditor. It applies to all Payment System Providers authorised under the Payment and Settlement Systems Act, 2007.

Source: RBI Notification RBI/2017-18/153 - Storage of Payment System Data · last verified 2026-08-13

ISO 31000Principles and guidelines for risk management1 February 2018

ISO 31000 is an international standard published by ISO that provides principles, a framework and a process for managing risk of any type faced by an organisation. It is not specific to any industry or sector, can be applied to any activity at all levels, and is guidance rather than a certifiable requirements standard. It centres on creating and protecting value and describes a risk management process of scope and context establishment, risk assessment (identification, analysis, evaluation), risk treatment, monitoring and communication. The current edition is ISO 31000:2018.

Source: ISO 31000:2018 - Risk management (ISO) · last verified 2026-08-13

SAMA CSF (Saudi Arabia)Cyber Security Framework issuance1 May 2017

The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017. It applies to all SAMA-regulated Member Organizations — banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure — and is principle-based, drawing on NIST, ISF, ISO, Basel and PCI. Member Organizations are expected to operate at maturity level 3 or higher.

Source: SAMA Rulebook — Cyber Security Framework · last verified 2026-08-04

Account Aggregator (RBI)NBFC-Account Aggregator consent-based data-sharing framework2 September 2016

The Master Direction - Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 (RBI/DNBR/2016-17/46), issued and enforced by the RBI, governs a class of NBFC that retrieves and consolidates a customer's financial information from multiple financial information providers and shares it - only with the customer's explicit consent - with financial information users. Only companies registered with the RBI may operate as Account Aggregators, and each must hold a net owned fund of at least two crore rupees. No financial information may be retrieved, shared or transferred without explicit, standardised consent, and the AA acts purely as a data intermediary that does not store, use or transact on the data.

Source: RBI Master Direction DNBR.PD.009/03.10.119/2016-17 - NBFC Account Aggregator · last verified 2026-08-13

RBICyber Security Framework in Banks2 June 2016

RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Source: Reserve Bank of India (notification, 2 June 2016) · last verified 2026-08-01

RBICyber Security Framework in Banks (2016)2 June 2016

The RBI circular Cyber Security Framework in Banks (RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16), dated 2 June 2016, requires scheduled commercial banks to put in place a board-approved cyber-security policy distinct from their IT or IS-security policy, to implement a baseline cyber-security and resilience framework, and to arrange continuous surveillance (for example through a Security Operations Centre). Issued and supervised by the RBI CSITE Cell, it also requires banks to maintain a Cyber Crisis Management Plan and to report all cyber-security incidents, whether successful or attempted, to the RBI.

Source: RBI Notification RBI/2015-16/418 - Cyber Security Framework in Banks · last verified 2026-08-13

ISO/IEC 27017Code of practice for cloud-services security controls15 December 2015

ISO/IEC 27017:2015 is an international standard from ISO and IEC providing a code of practice for information security controls for cloud services, based on ISO/IEC 27002. It gives cloud-specific implementation guidance for both cloud service providers and cloud service customers and adds cloud-specific controls covering shared roles and responsibilities, return or removal of customer assets, segregation in virtual environments, and administrative operations.

Source: ISO/IEC 27017:2015 - Cloud services security controls (ISO) · last verified 2026-08-13

CKYC (CERSAI)CERSAI operates the Central KYC Records Registry26 November 2015

The Master Direction defines the Central KYC Records Registry (CKYCR) as “an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer”. The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was authorised to act as and perform the functions of the CKYCR by Gazette Notification No. S.O. 3183(E) dated 26 November 2015.

Source: RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) · last verified 2026-08-07

ISO 9001Quality management system requirements1 September 2015

ISO 9001 is the international standard published by ISO specifying requirements for a quality management system (QMS), and it is the only standard in the ISO 9000 family to which organisations can be certified. It applies to organisations of any size and sector that need to consistently provide products and services meeting customer and applicable regulatory requirements and to enhance customer satisfaction. Its requirements are structured around context of the organisation, leadership, planning, support, operation, performance evaluation and improvement (Plan-Do-Check-Act). The current edition is ISO 9001:2015.

Source: ISO 9001:2015 - Quality management systems (ISO) · last verified 2026-08-13

FISMA (US)Federal Information Security Modernization Act of 201418 December 2014

The Federal Information Security Modernization Act of 2014 amended the 2002 Federal Information Security Management Act and updated the U.S. federal government information-security framework. CISA, with OMB oversight, administers implementation of information-security policies for non-national-security federal Executive Branch systems. It requires the head of each federal agency to provide information-security protections commensurate with risk (44 U.S.C. 3554), to report on the effectiveness of their security programmes, and to report major information-security incidents.

Source: CISA - Federal Information Security Modernization Act · last verified 2026-08-13

PDPA (Singapore)Singapore Personal Data Protection Act 20122 July 2014

The Personal Data Protection Act 2012 governs the collection, use, disclosure and care of personal data by organisations in Singapore, and establishes the national Do Not Call registry. It is administered and enforced by the Personal Data Protection Commission (PDPC). Its main data-protection obligations came into force on 2 July 2014, and it imposes consent, purpose-limitation, protection, accountability and mandatory data-breach-notification obligations on private-sector organisations.

Source: Personal Data Protection Commission (PDPC) Singapore - PDPA · last verified 2026-08-13

Privacy Act (Australia)Privacy Act 1988 and the 13 Australian Privacy Principles12 March 2014

The Privacy Act 1988 is Australia's principal legislation protecting the handling of personal information, regulated by the Office of the Australian Information Commissioner (OAIC). At its core are the 13 Australian Privacy Principles (APPs), which govern how APP entities collect, use, disclose, store, secure and provide access to personal information. It applies to most Australian Government agencies and to private-sector organisations with annual turnover above AUD 3 million (plus certain others); the APPs commenced on 12 March 2014.

Source: OAIC - Australian Privacy Principles · last verified 2026-08-13

HITECH (US)Health IT adoption and strengthened HIPAA enforcement17 February 2009

The Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted as part of the American Recovery and Reinvestment Act of 2009 and is administered by the U.S. Department of Health and Human Services, with HIPAA enforcement carried out by its Office for Civil Rights. It promotes adoption and meaningful use of electronic health records while strengthening the privacy and security protections established under HIPAA. It extends HIPAA Security Rule safeguards and direct liability to business associates, establishes tiered civil monetary penalty categories, and introduces breach-notification requirements for covered entities and business associates handling protected health information.

Source: U.S. HHS - HITECH Act Enforcement Interim Final Rule · last verified 2026-08-13

HIPAA (US)Security Rule compliance date20 April 2005

Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.

Source: US HHS — HIPAA Security Rule · last verified 2026-08-11

SOX (US)Sarbanes-Oxley Act of 2002 (Sections 302 and 404)30 July 2002

The Sarbanes-Oxley Act of 2002 (Public Law 107-204), enacted 30 July 2002, reformed corporate financial reporting and auditing after major accounting scandals and created the Public Company Accounting Oversight Board (PCAOB). It is enforced primarily by the U.S. Securities and Exchange Commission and applies to U.S. public companies and their auditors. Section 302 requires senior executives to personally certify the accuracy of financial statements; Section 404 requires management, and the external auditor, to assess and report on the effectiveness of internal control over financial reporting.

Source: U.S. Congress (congress.gov) - H.R.3763, Sarbanes-Oxley Act of 2002 · last verified 2026-08-13

This tracker regenerates daily from the registry data file; additions and corrections append to the registry changelog and are never silently edited. Machine-readable version: /compliance-registry.json. Spotted an error? Tell us via the contact page.