We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Registry v1.6.0 · every date sourced

India compliance deadlines tracker

The dated obligations from the India Compliance Registry in one timeline — each verified against the Gazette, the regulator or the standards body, never a blog. Governed by our editorial policy.

Upcoming

DPDP Act 2023Phase II — one year from notification13 November 2026

Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023Phase III — substantive framework1 May 2027

Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023Penalty ceiling1 May 2027

The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

Source: DPDP Act 2023, the Schedule (official Gazette text) · last verified 2026-08-01

DPDP Act 2023Breach notification timeline (Rule 7)1 May 2027

Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.

Source: DPDP Rules 2025, Rule 7 · last verified 2026-08-01

DPDP Act 2023Notice contents (section 5)1 May 2027

Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.

Source: DPDP Act 2023, section 5 (official Gazette text) · last verified 2026-08-01

In force

DPDP Act 2023Phase I — in force on notification13 November 2025

Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.

Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01

DPDP Act 2023DPDP Rules 2025 notification13 November 2025

Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).

Source: MeitY / PIB — DPDP Rules 2025 · last verified 2026-08-01

CMMC (US DoD)Programme and acquisition rule dates10 November 2025

The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.

Source: US Federal Register — CMMC Program rule (32 CFR 170) · last verified 2026-08-01

ISO/IEC 270012022-revision transition deadline31 October 2025

The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.

Source: ISO/IEC 27001 (iso.org) · last verified 2026-08-01

EU AI ActCommencement and GPAI obligations2 August 2025

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).

Source: EU AI Act — official text (EUR-Lex 2024/1689) · last verified 2026-08-01

OWASP ASVSCurrent version1 May 2025

OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).

Source: OWASP ASVS project · last verified 2026-08-01

PCI DSSv4.x lifecycle dates31 March 2025

PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.

Source: PCI Security Standards Council (official blog) · last verified 2026-08-01

SEBI CSCRFIssuance and compliance timeline20 August 2024

SEBI issued the Cybersecurity and Cyber Resilience Framework circular on 20 August 2024. Compliance timelines were extended more than once; for most regulated entities (excluding MIIs, KRAs and QRTAs) the final compliance date became 31 August 2025, with recurring half-yearly cyber-audit and reporting cycles thereafter.

Source: SEBI — CSCRF FAQs (official PDF, June 2025) · last verified 2026-08-01

RBIIT Governance Master Direction1 April 2024

Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

Source: Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) · last verified 2026-08-01

NIST CSFVersion 2.0 release26 February 2024

NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.

Source: NIST (official release announcement) · last verified 2026-08-01

NCA ECC (Saudi Arabia)Essential Cybersecurity Controls versions1 January 2024

Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018; the updated ECC-2:2024 restructures the framework into 4 domains, 28 subdomains and 108 main controls, binding government entities and critical-infrastructure operators.

Source: National Cybersecurity Authority (Saudi Arabia) · last verified 2026-08-01

ISO/IEC 42001Publication1 December 2023

ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.

Source: ISO/IEC 42001 (iso.org) · last verified 2026-08-01

RBIIT Outsourcing Master Direction1 October 2023

Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

Source: Reserve Bank of India (Master Direction RBI/2023-24/102) · last verified 2026-08-01

DPDP Act 2023Enactment11 August 2023

Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.

Source: Official Gazette text (MeitY PDF) · last verified 2026-07-31

Qatar NIA (NCSA)National Information Assurance Policy version1 May 2023

Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.

Source: NCSA Qatar (official portal) · last verified 2026-08-01

IRDAIInformation and Cyber Security Guidelines, 202324 April 2023

IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 — a data-centric, risk-based security framework for insurers and regulated intermediaries, superseding the 2017 guidelines.

Source: IRDAI (official document) · last verified 2026-08-01

CERT-In DirectionsProvider record-keeping28 June 2022

Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsTime synchronisation28 June 2022

System clocks must be synchronised to NIC or NPL time sources.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsLog retention28 June 2022

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIncident reporting window28 June 2022

Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

CERT-In DirectionsIssue and commencement28 June 2022

Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

Source: CERT-In Directions (official PDF) · last verified 2026-07-31

UAE PDPLEnactment and effect2 January 2022

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued in 2021 and came into effect on 2 January 2022. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.

Source: UAE legislation portal / official summaries · last verified 2026-08-01

RBIDigital Payment Security Controls Master Direction18 February 2021

Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

Source: Reserve Bank of India (Master Direction, 18 Feb 2021) · last verified 2026-08-01

SWIFT CSPProgramme and independent assessment1 January 2021

SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.

Source: SWIFT — Customer Security Programme (official) · last verified 2026-08-01

ISO 223012019 revision publication30 October 2019

ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.

Source: ISO 22301:2019 (iso.org) · last verified 2026-08-01

RBIPayment system data storage in India6 October 2018

RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

Source: Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) · last verified 2026-08-01

GDPRApplication date25 May 2018

Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).

Source: GDPR — official text (EUR-Lex 2016/679) · last verified 2026-08-01

SAMA CSF (Saudi Arabia)Cyber Security Framework issuance1 May 2017

The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017, applying to SAMA-regulated banks, insurers and finance companies; principle-based, drawing on ISO, Basel and PCI DSS.

Source: SAMA — Cyber Security Framework (official PDF) · last verified 2026-08-01

RBICyber Security Framework in Banks2 June 2016

RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Source: Reserve Bank of India (notification, 2 June 2016) · last verified 2026-08-01

HIPAA (US)Security Rule compliance date20 April 2005

Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.

Source: US HHS — HIPAA Security Rule · last verified 2026-08-01

This tracker regenerates daily from the registry data file; additions and corrections append to the registry changelog and are never silently edited. Machine-readable version: /compliance-registry.json. Spotted an error? Tell us via the contact page.