We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Registry v1.17.0 · every date sourced

India compliance deadlines tracker

The dated obligations from the India Compliance Registry in one timeline — each verified against the Gazette, the regulator or the standards body, never a blog. Governed by our editorial policy.

Upcoming

DPDP Act 2023Phase II — one year from notification13 November 2026

Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

NPCI / UPITPAP volume-cap compliance deadline - 31 December 202631 December 2026

NPCI's volume-cap guidelines for Third-Party Application Providers in UPI (referencing circular NPCI/UPI/OC-97/2020-21) were originally to bite from 31 December 2024. The compliance timeline for existing TPAPs exceeding the cap was extended by two years, to 31 December 2026. Separately, NPCI issued Guidelines on usage of UPI APIs (OC 215 series, May 2025) requiring PSPs and acquiring banks to monitor and control API usage, with non-compliance exposing them to API restriction, penalties or suspension of new customer onboarding.

Source: NPCI UPI circulars (official listing) · last verified 2026-08-07

DPDP Act 2023Phase III — substantive framework1 May 2027

Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023Penalty ceiling1 May 2027

The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

Source: DPDP Act 2023, the Schedule (official Gazette text) · last verified 2026-08-01

DPDP Act 2023Breach notification timeline (Rule 7)1 May 2027

Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.

Source: DPDP Rules 2025, Rule 7 · last verified 2026-08-01

DPDP Act 2023Notice contents (section 5)1 May 2027

Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.

Source: DPDP Act 2023, section 5 (official Gazette text) · last verified 2026-08-01

In force

EU AI ActTransitional deadlines for systems already on the market2 August 2026

Article 111 gives longer runways to AI already in service. Providers of general-purpose AI models placed on the market before 2 August 2025 must comply by 2 August 2027. High-risk systems placed on the market before 2 August 2026 are caught only if subject to significant design changes after that date — but providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 regardless. AI systems that are components of the large-scale IT systems listed in Annex X and placed on the market before 2 August 2027 must be brought into compliance by 31 December 2030.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-07

EU AI ActStaggered application under Article 1132 August 2026

Article 113 provides that the Regulation applies from 2 August 2026, with three exceptions: Chapters I and II (general provisions and prohibited AI practices) applied from 2 February 2025; Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 (notifying authorities, general-purpose AI models, governance, penalties and confidentiality) applied from 2 August 2025, with the exception of Article 101; and Article 6(1), covering high-risk classification for AI as a safety component of products already regulated under Union law, applies from 2 August 2027.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-07

EU AI ActDigital Omnibus on AI - high-risk deadlines postponed (current)27 July 2026

Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI) amends Regulation (EU) 2024/1689 and was published in the Official Journal on 24 July 2026, entering into force on 27 July 2026. It postpones the obligations for high-risk AI systems designated under Article 6(2) and Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products regulated under Annex I sectoral legislation to 2 August 2028. It also adds prohibitions to Article 5 covering AI that generates or manipulates realistic non-consensual intimate imagery of identifiable individuals. The Article 50 transparency duties applying from 2 August 2026 are unaffected.

Source: Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex · last verified 2026-08-07

SWIFT CSPFurther v2026 changes affecting scope and control expectations1 July 2026

Control 2.3 System Hardening now names Windows Management Instrumentation and PowerShell as native OS features to consider when shielding a Windows system. Control 2.9 Transaction Business Controls recognises Swift Universal Confirmation as a validation or reconciliation option alongside MT 900/910 and MT 940/950. Control 4.2 requires multi-factor authentication on one authentication stage for external privileged access managing firewalls, and Alliance Left and Right Security Officer accounts are now named as privileged accounts. Control 6.1 Malware Protection advises protecting non-Windows systems inside a secure zone or hosting a customer client connector. Control 7.2 Security Training and Awareness adds deepfakes as an example of AI-based threats.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

SWIFT CSPCustomer client connectors are now mandatory in scope, moving some users from architecture B to A41 July 2026

CSCF v2025 introduced the customer client connector — an endpoint consuming APIs, a middleware or a file transfer client — as an advisory in-scope component. In v2026 it becomes a mandatory in-scope component of fourteen basic cyber-hygiene controls: 1.2, 1.3, 1.4, 2.2, 2.3, 2.6, 2.7, 3.1, 4.1, 4.2, 5.1, 5.4, 6.1 and 6.4. All user endpoints that connect to Swift indirectly through a service provider sharing resources are progressively treated as customer connectors, whether server or client.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

SWIFT CSPControl 2.4 Back Office Data Flow Security became mandatory in v20261 July 2026

As announced in the previous version, control 2.4 Back Office Data Flow Security is mandatory in CSCF v2026, activating the phased approach in Appendix H. At minimum a user must now protect the bridging servers guarding flows between its secure zone and the back-office first hops where the exchange is not end-to-end protected, the flows between bridging servers and between bridging servers and the secure zone in the same circumstances, and the new direct flows between the secure zone and the back-office first hop.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

SWIFT CSPAttestation against CSCF v2026 runs July to December 20261 July 2026

Swift users must attest their compliance through the KYC Security Attestation (KYC-SA) application by the end of each year, against the CSCF in effect at that time. A new CSCF version is published each July and becomes the attestation basis from July of the following year. The document states the position for this cycle directly: users must attest between July 2026 and December 2026 against the controls listed in CSCF v2026, which was published in mid-2025.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

IRDAIInformation and Cybersecurity Guidelines, 2026 (current)6 April 2026

IRDAI released Version 2.0 of its Information and Cybersecurity Guidelines in April 2026, replacing the Information and Cyber Security Guidelines, 2023 dated 24 April 2023. They apply to insurers including foreign reinsurance branches, insurance intermediaries (brokers, corporate agents, web aggregators, TPAs), insurance repositories and the Insurance Information Bureau of India, and regulated entities are required to comply from the current financial year.

Source: IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) · last verified 2026-08-07

DPDP Act 2023Phase I — in force on notification13 November 2025

Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023DPDP Rules 2025 notification13 November 2025

Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).

Source: MeitY / PIB — DPDP Rules 2025 · last verified 2026-08-01

CMMC (US DoD)Programme and acquisition rule dates10 November 2025

The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.

Source: US Federal Register — CMMC Program rule (32 CFR 170) · last verified 2026-08-01

ISO/IEC 270012022-revision transition deadline31 October 2025

The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.

Source: ISO/IEC 27001 (iso.org) · last verified 2026-08-01

SEBI CSCRFIssuance and final compliance timeline31 August 2025

SEBI issued the Cybersecurity and Cyber Resilience Framework vide circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024 (Version 1.0, 205 pages). The compliance timeline was extended twice: circular 2025/45 of 28 March 2025 moved it by three months to 30 June 2025, and circular 2025/96 of 30 June 2025 moved it by a further two months to 31 August 2025. Both extensions applied to all regulated entities except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs) and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), which stayed on the original timeline. That final date has passed, so CSCRF is fully in force.

Source: SEBI — extension circular 2025/96 (official PDF, 30 June 2025) · last verified 2026-08-04

SEBI CSCRFLatest amendment: technical clarifications of 28 August 202528 August 2025

Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025 issues technical clarifications in four parts: Part A, principles for REs under multiple regulators' purview, introducing a Principle of Exclusivity and a Principle of Equivalence so an RE regulated by both SEBI and (for example) RBI can demonstrate compliance without duplicating work; Part B, technical clarifications; Part C, re-categorisation of Portfolio Managers and Merchant Bankers; and Part D, Cyber Security Audit Policy Guidelines from CERT-In.

Source: SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) · last verified 2026-08-04

EU AI ActThree penalty tiers under Article 992 August 2025

Infringement of the Article 5 prohibited-practices rules is subject to administrative fines of up to EUR 35 000 000 or 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher. Breach of most other operator obligations attracts up to EUR 15 000 000 or 3 %. Supplying incorrect, incomplete or misleading information to notified bodies or national authorities attracts up to EUR 7 500 000 or 1 %. For SMEs including start-ups, each ceiling is the lower rather than the higher of the two figures.

Source: EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal · last verified 2026-08-04

EU AI ActCommencement and GPAI obligations2 August 2025

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).

Source: EU AI Act — official text (EUR-Lex 2024/1689) · last verified 2026-08-07

SWIFT CSPFive reference architecture types determine which components are in scope1 July 2025

Each user must identify which of five reference architecture types most closely matches its deployment, because scope and applicable controls follow from that choice. The types are A1 (user owns the communication interface, and generally the messaging interface), A2, A3, A4 and B. Component or licence ownership is the key differentiator, and where more than one could apply the most comprehensive architecture must be chosen. Swift publishes a CSP architecture decision tree to support the determination.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

SWIFT CSPCSCF v2026 contains 32 controls — 26 mandatory and 6 advisory1 July 2025

The framework sets out 32 security controls, of which 26 are mandatory and 6 advisory, resting on three overarching objectives supported by seven security principles. Mandatory controls establish a security baseline for the entire Swift user community; advisory controls are optional best practices Swift recommends. The six advisory controls are 2.5A External Transmission Data Protection, 2.11A RMA Business Controls, 5.3A Staff Screening Process, 6.5A Intrusion Detection, 7.3A Penetration Testing and 7.4A Scenario-based Risk Assessment.

Source: Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) · last verified 2026-08-05

OWASP ASVSCurrent version1 May 2025

OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).

Source: OWASP ASVS project · last verified 2026-08-01

PCI DSSSAQ A: card-not-present with all account data functions fully outsourced1 April 2025

SAQ A covers e-commerce or mail/telephone-order merchants who outsource all processing of account data to PCI DSS compliant third parties, store, process and transmit no account data electronically on their own systems or premises, have confirmed those third parties are compliant for the services used, and retain any account data only on paper not received electronically. E-commerce merchants must additionally confirm that every element of the payment page delivered to the customer’s browser originates only and directly from a compliant third-party processor, and that their site is not susceptible to script-based attacks affecting their e-commerce systems. SAQ A does not apply to face-to-face channels or to service providers.

Source: PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) · last verified 2026-08-04

PCI DSSv4.x lifecycle dates31 March 2025

PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.

Source: PCI Security Standards Council (official blog) · last verified 2026-08-01

SEBI CSCRFThe Cyber Capability Index applies only to the top two categories20 August 2024

The Cyber Capability Index (CCI) applies only to MIIs and Qualified REs. MIIs must have their cyber resilience assessed against the CCI by a third party on a half-yearly basis; Qualified REs self-assess their cyber resilience using the CCI on a yearly basis.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFA Security Operations Centre is mandatory, with a Market SOC route for smaller entities20 August 2024

CSCRF mandates a SOC for all REs except client-based stock brokers with fewer than 100 clients. An RE may use its own or group SOC, any third-party managed SOC, or the Market SOC. Small-size and Self-certification category REs are required to onboard the Market SOC, which NSE and BSE must set up and which NSDL and/or CDSL may set up optionally.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFVAPT reporting, closure and revalidation deadlines20 August 2024

The VAPT report must be submitted within one month of completing the VAPT activity, after approval from the RE's IT Committee. Findings must be closed within three months of report submission, following a graded approach based on the criticality of the observations. Revalidation of the VAPT must be completed within five months of its completion.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFVAPT frequency depends on NCIIPC designation20 August 2024

REs identified as “Protected systems” and/or Critical Information Infrastructure by NCIIPC must complete at least two VAPT activities each year — one in each half of the financial year (April to September, October to March), each including report submission, closure and revalidation. All other REs must complete at least one, with the activity commencing in the first quarter of the financial year.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFAudits must be conducted by a CERT-In empanelled organisation20 August 2024

The framework states: “Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization.” The same requirement is restated for the VAPT and cyber audit that the Market SOC is to provide to small- and mid-size REs at affordable cost.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

SEBI CSCRFRegulated entities are sorted into five compliance categories20 August 2024

CSCRF applies proportionately by category: (i) Market Infrastructure Institutions (MIIs), (ii) Qualified REs, (iii) Mid-size REs, (iv) Small-size REs and (v) Self-certification REs. Entity-wise thresholds that determine which category an RE falls into are set out in the framework's “Thresholds for REs’ categorization” section.

Source: SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) · last verified 2026-08-04

RBIIT Governance Master Direction1 April 2024

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

Source: Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) · last verified 2026-08-01

NIST CSFThe CSF states outcomes and does not prescribe how to achieve them26 February 2024

NIST states that the CSF “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity”, and that it “does not prescribe how outcomes should be achieved”, instead linking to online resources describing practices and controls. This is why the CSF is not certifiable and why an organisation cannot be audited as “CSF compliant” the way it can against ISO/IEC 27001 or PCI DSS.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFFour Tiers describe rigour of risk governance26 February 2024

The framework defines four Tiers, quoted from the document: “Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4).” Tiers characterise the rigour of an organisation’s cybersecurity risk governance and management practices; they are not maturity levels and reaching Tier 4 is not a goal for every organisation.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFThe Core contains 22 Categories and 106 Subcategories26 February 2024

Beneath the six Functions, the CSF 2.0 Core is organised into 22 Categories and 106 Subcategories. Subcategories state outcomes, not controls, and are the level at which an organisation assesses and communicates its current and target state.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFSix Functions organise the Core26 February 2024

CSF 2.0 organises cybersecurity outcomes under six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS) and RECOVER (RC). GOVERN is new in 2.0 and covers how an organisation establishes and monitors its cybersecurity risk management strategy, expectations and policy.

Source: NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 · last verified 2026-08-04

NIST CSFVersion 2.0 release26 February 2024

NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.

Source: NIST (official release announcement) · last verified 2026-08-01

ISO 22301Amendment 1:2024 (climate action)1 February 2024

ISO published ISO 22301:2019/Amd 1:2024 in February 2024, adding consideration of climate change to the management system requirements. ISO 22301:2019 remains the current edition - the amendment supplements it rather than replacing it, and a next edition is in development with no confirmed publication date.

Source: ISO 22301:2019/Amd 1:2024 (iso.org) · last verified 2026-08-07

NCA ECC (Saudi Arabia)Essential Cybersecurity Controls versions1 January 2024

Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018. ECC-2:2024 consists of 4 cybersecurity main domains (Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party & Cloud Computing Cybersecurity), 28 subdomains, 108 main controls and 92 subcontrols. The Controls apply to government agencies in the Kingdom (including ministries, authorities and establishments) and their affiliated companies and entities inside and outside the Kingdom, and to all private-sector entities owning, operating or hosting Critical National Infrastructure; each entity must comply with all controls applicable to it.

Source: NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) · last verified 2026-08-04

ISO/IEC 42001Publication1 December 2023

ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.

Source: ISO/IEC 42001 (iso.org) · last verified 2026-08-01

RBIIT Outsourcing Master Direction1 October 2023

Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

Source: Reserve Bank of India (Master Direction RBI/2023-24/102) · last verified 2026-08-01

DPDP Act 2023Enactment11 August 2023

Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.

Source: Official Gazette text (MeitY PDF) · last verified 2026-07-31

Qatar NIA (NCSA)National Information Assurance Policy version1 May 2023

Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.

Source: NCSA Qatar (official portal) · last verified 2026-08-01

IRDAIInformation and Cyber Security Guidelines, 2023 (superseded)24 April 2023

IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 (ref IRDAI/GA&HR/GDL/MISC/88/04/2023), superseding the 2017 guidelines (IRDA/IT/GDL/MISC/082/04/2017) and three subsequent circulars. These were themselves superseded on 6 April 2026 by the IRDAI Information and Cybersecurity Guidelines, 2026 (Version 2.0) - the 2023 text is retained here as the previous baseline, not as the current requirement.

Source: IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) · last verified 2026-08-07

CERT-In DirectionsProvider record-keeping28 June 2022

Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsTime synchronisation28 June 2022

System clocks must be synchronised to NIC or NPL time sources.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsLog retention28 June 2022

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIncident reporting window28 June 2022

Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIssue and commencement28 June 2022

Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

UAE PDPLEnactment and effect2 January 2022

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued in 2021 and came into effect on 2 January 2022. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.

Source: UAE legislation portal / official summaries · last verified 2026-08-07

CKYC (CERSAI)Applicability was phased between 2016 and 20211 April 2021

The CKYCR live run began on 15 July 2016, phased, starting with new individual accounts. Scheduled Commercial Banks were required to upload KYC data for all new individual accounts opened on or after 1 January 2017 (with an initial allowance to 1 February 2017 for accounts opened during January 2017). Regulated entities other than SCBs were required to start uploading for new individual accounts opened on or after 1 April 2017. KYC records for accounts of Legal Entities opened on or after 1 April 2021 must also be uploaded.

Source: RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) · last verified 2026-08-07

RBIDigital Payment Security Controls Master Direction18 February 2021

Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

Source: Reserve Bank of India (Master Direction, 18 Feb 2021) · last verified 2026-08-01

SWIFT CSPProgramme and independent assessment1 January 2021

SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.

Source: SWIFT — Customer Security Programme (official) · last verified 2026-08-01

ISO 223012019 revision publication30 October 2019

ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.

Source: ISO 22301:2019 (iso.org) · last verified 2026-08-01

RBIPayment system data storage in India6 October 2018

RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

Source: Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) · last verified 2026-08-01

GDPRTwo tiers of administrative fine under Article 8325 May 2018

The lower tier is up to 10 000 000 EUR or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher — covering obligations of controllers and processors such as security of processing, records and breach notification. The higher tier is up to 20 000 000 EUR or 4 % of total worldwide annual turnover, whichever is higher — covering the basic principles for processing, conditions for consent, data-subject rights, and transfers to third countries.

Source: EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text · last verified 2026-08-04

GDPRBreach notification to the supervisory authority within 72 hours25 May 2018

A controller must notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours it must be accompanied by reasons for the delay.

Source: EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text · last verified 2026-08-04

GDPRApplication date25 May 2018

Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).

Source: GDPR — official text (EUR-Lex 2016/679) · last verified 2026-08-01

SAMA CSF (Saudi Arabia)Cyber Security Framework issuance1 May 2017

The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017. It applies to all SAMA-regulated Member Organizations — banks, insurance and reinsurance companies, financing companies, credit bureaus and the Financial Market Infrastructure — and is principle-based, drawing on NIST, ISF, ISO, Basel and PCI. Member Organizations are expected to operate at maturity level 3 or higher.

Source: SAMA Rulebook — Cyber Security Framework · last verified 2026-08-04

RBICyber Security Framework in Banks2 June 2016

RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Source: Reserve Bank of India (notification, 2 June 2016) · last verified 2026-08-01

CKYC (CERSAI)CERSAI operates the Central KYC Records Registry26 November 2015

The Master Direction defines the Central KYC Records Registry (CKYCR) as “an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer”. The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was authorised to act as and perform the functions of the CKYCR by Gazette Notification No. S.O. 3183(E) dated 26 November 2015.

Source: RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) · last verified 2026-08-07

HIPAA (US)Security Rule compliance date20 April 2005

Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.

Source: US HHS — HIPAA Security Rule · last verified 2026-08-01

This tracker regenerates daily from the registry data file; additions and corrections append to the registry changelog and are never silently edited. Machine-readable version: /compliance-registry.json. Spotted an error? Tell us via the contact page.