{"name":"CyberSigma India Compliance Registry","version":"1.6.0","updated":"2026-08-01","license":"CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/","attribution":"CyberSigma — https://cybersigmacs.com/compliance-registry/","changelog":[{"date":"2026-08-01","change":"v1.6.0: added DPDP notice contents (s.5(1), verified from the Gazette), HIPAA Security Rule compliance date, and ISO 22301:2019 publication."},{"date":"2026-08-01","change":"v1.5.0: added DPDP Rules breach-notification timeline (Rule 7: without delay + 72-hour detailed report), RBI Cyber Security Framework for Banks (2 June 2016; 2-6 hour incident reporting), and GDPR application date (25 May 2018)."},{"date":"2026-08-01","change":"v1.4.0: added SWIFT CSP (launched 2016; independent assessment mandatory from 2021), Qatar NIA Policy v2.1 (May 2023), and RBI Digital Payment Security Controls Master Direction (Feb 2021)."},{"date":"2026-08-01","change":"v1.3.0: added SAMA Cyber Security Framework (May 2017), Saudi NCA ECC-1:2018 / ECC-2:2024, US CMMC programme and acquisition rule dates, and UAE PDPL (Federal Decree-Law 45/2021)."},{"date":"2026-08-01","change":"v1.2.0: added RBI IT Governance Master Direction (Nov 2023), RBI IT Outsourcing Master Direction (Apr 2023), IRDAI Information & Cyber Security Guidelines 2023, ISO/IEC 42001:2023 publication, EU AI Act commencement and GPAI dates."},{"date":"2026-08-01","change":"v1.1.0: added DPDP penalty schedule (verified from the Gazette), SEBI CSCRF issuance and timelines, RBI payment-data localisation, PCI DSS v4.x lifecycle dates, ISO/IEC 27001:2022 transition end, NIST CSF 2.0 release."},{"date":"2026-08-01","change":"Initial public release: DPDP Act & Rules phasing, CERT-In Directions obligations, Aadhaar AUA/KUA and IRDAI ISNP audit duties, PCI DSS and OWASP ASVS current versions."}],"entries":[{"id":"dpdp-act-gazette","framework":"DPDP Act 2023","fact":"Enactment","value":"Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.","effective":"2023-08-11","source":{"label":"Official Gazette text (MeitY PDF)","url":"https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf"},"lastVerified":"2026-07-31"},{"id":"dpdp-rules-notified","framework":"DPDP Act 2023","fact":"DPDP Rules 2025 notification","value":"Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).","effective":"2025-11-13","source":{"label":"MeitY / PIB — DPDP Rules 2025","url":"https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf"},"note":"Gazette date corroborated across multiple law-firm analyses; the PIB document filename carries the press-release date (17 Nov), not the notification date.","lastVerified":"2026-08-01"},{"id":"dpdp-phase-1","framework":"DPDP Act 2023","fact":"Phase I — in force on notification","value":"Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.","effective":"2025-11-13","source":{"label":"DPDP Rules 2025 (phased commencement)","url":"https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf"},"lastVerified":"2026-08-01"},{"id":"dpdp-phase-2","framework":"DPDP Act 2023","fact":"Phase II — one year from notification","value":"Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.","effective":"2026-11-13","source":{"label":"DPDP Rules 2025 (phased commencement)","url":"https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf"},"lastVerified":"2026-08-01"},{"id":"dpdp-phase-3","framework":"DPDP Act 2023","fact":"Phase III — substantive framework","value":"Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.","effective":"2027-05","source":{"label":"DPDP Rules 2025 (phased commencement)","url":"https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf"},"lastVerified":"2026-08-01"},{"id":"certin-directions","framework":"CERT-In Directions","fact":"Issue and commencement","value":"Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.","effective":"2022-06-28","source":{"label":"CERT-In Directions (official PDF)","url":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"},"lastVerified":"2026-07-31"},{"id":"certin-6h","framework":"CERT-In Directions","fact":"Incident reporting window","value":"Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.","effective":"2022-06-28","source":{"label":"CERT-In Directions (official PDF)","url":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"},"lastVerified":"2026-07-31"},{"id":"certin-logs","framework":"CERT-In Directions","fact":"Log retention","value":"ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.","effective":"2022-06-28","source":{"label":"CERT-In Directions (official PDF)","url":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"},"lastVerified":"2026-07-31"},{"id":"certin-ntp","framework":"CERT-In Directions","fact":"Time synchronisation","value":"System clocks must be synchronised to NIC or NPL time sources.","effective":"2022-06-28","source":{"label":"CERT-In Directions (official PDF)","url":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"},"lastVerified":"2026-07-31"},{"id":"certin-provider-records","framework":"CERT-In Directions","fact":"Provider record-keeping","value":"Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.","effective":"2022-06-28","source":{"label":"CERT-In Directions (official PDF)","url":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"},"lastVerified":"2026-07-31"},{"id":"aua-kua-audit","framework":"UIDAI (Aadhaar)","fact":"AUA / KUA audit duty","value":"Authentication User Agencies and eKYC User Agencies must have operations audited annually (and on need) by a certified information systems auditor; the report is shared with UIDAI on request.","effective":null,"source":{"label":"UIDAI AUA/KUA Agreement (v4.0)","url":"https://uidai.gov.in/images/resource/AUA_KUA_Agreement_v_40.pdf"},"lastVerified":"2026-07-31"},{"id":"isnp-audit","framework":"IRDAI (ISNP)","fact":"ISNP audit duty","value":"Insurance Self-Network Platforms require IRDAI permission (with pre-launch security testing) and an annual audit by an auditor holding a recognised IS-audit qualification (e.g. CISA, or CA with DISA); adverse findings affecting policyholders are reported to IRDAI with an action plan.","effective":null,"source":{"label":"IRDAI","url":"https://www.irdai.gov.in/"},"note":"Summarised from IRDAI's ISNP framework; corroborated across multiple compliance publishers.","lastVerified":"2026-07-31"},{"id":"pci-dss-version","framework":"PCI DSS","fact":"Current version","value":"PCI DSS v4.0.1 is the current standard published by the PCI Security Standards Council.","effective":null,"source":{"label":"PCI SSC document library","url":"https://www.pcisecuritystandards.org/document_library/"},"lastVerified":"2026-08-01"},{"id":"owasp-asvs-version","framework":"OWASP ASVS","fact":"Current version","value":"OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).","effective":"2025-05","source":{"label":"OWASP ASVS project","url":"https://owasp.org/www-project-application-security-verification-standard/"},"lastVerified":"2026-08-01"},{"id":"dpdp-penalties","framework":"DPDP Act 2023","fact":"Penalty ceiling","value":"The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.","effective":"2027-05","source":{"label":"DPDP Act 2023, the Schedule (official Gazette text)","url":"https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf"},"note":"Amount verified directly against the Gazette PDF text ('may extend to two hundred and fifty crore rupees'). Enforcement follows the phased commencement (see dpdp-phase-3).","lastVerified":"2026-08-01"},{"id":"sebi-cscrf-issued","framework":"SEBI CSCRF","fact":"Issuance and compliance timeline","value":"SEBI issued the Cybersecurity and Cyber Resilience Framework circular on 20 August 2024. Compliance timelines were extended more than once; for most regulated entities (excluding MIIs, KRAs and QRTAs) the final compliance date became 31 August 2025, with recurring half-yearly cyber-audit and reporting cycles thereafter.","effective":"2024-08-20","source":{"label":"SEBI — CSCRF FAQs (official PDF, June 2025)","url":"https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf"},"note":"Extension history corroborated across law-firm analyses (circulars of 31 March 2025 and 30 June 2025).","lastVerified":"2026-08-01"},{"id":"rbi-payment-data-localisation","framework":"RBI","fact":"Payment system data storage in India","value":"RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.","effective":"2018-10-06","source":{"label":"Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018)","url":"https://www.rbi.org.in/"},"note":"Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.","lastVerified":"2026-08-01"},{"id":"pci-dss-4x-lifecycle","framework":"PCI DSS","fact":"v4.x lifecycle dates","value":"PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.","effective":"2025-03-31","source":{"label":"PCI Security Standards Council (official blog)","url":"https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x"},"lastVerified":"2026-08-01"},{"id":"iso-27001-2022-transition","framework":"ISO/IEC 27001","fact":"2022-revision transition deadline","value":"The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.","effective":"2025-10-31","source":{"label":"ISO/IEC 27001 (iso.org)","url":"https://www.iso.org/standard/27001"},"note":"Deadline corroborated across accredited certification bodies (BSI, SGS, LRQA); iso.org blocks automated verification.","lastVerified":"2026-08-01"},{"id":"nist-csf-2","framework":"NIST CSF","fact":"Version 2.0 release","value":"NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.","effective":"2024-02-26","source":{"label":"NIST (official release announcement)","url":"https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework"},"lastVerified":"2026-08-01"},{"id":"rbi-it-governance-md","framework":"RBI","fact":"IT Governance Master Direction","value":"Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.","effective":"2024-04-01","source":{"label":"Reserve Bank of India (Master Direction RBI/DoS/2023-24/107)","url":"https://www.rbi.org.in/"},"note":"Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.","lastVerified":"2026-08-01"},{"id":"rbi-it-outsourcing-md","framework":"RBI","fact":"IT Outsourcing Master Direction","value":"Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.","effective":"2023-10-01","source":{"label":"Reserve Bank of India (Master Direction RBI/2023-24/102)","url":"https://www.rbi.org.in/"},"note":"Direction number cited for retrieval via RBI notification search.","lastVerified":"2026-08-01"},{"id":"irdai-infosec-2023","framework":"IRDAI","fact":"Information and Cyber Security Guidelines, 2023","value":"IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 — a data-centric, risk-based security framework for insurers and regulated intermediaries, superseding the 2017 guidelines.","effective":"2023-04-24","source":{"label":"IRDAI (official document)","url":"https://irdai.gov.in/document-detail?documentId=3314780"},"lastVerified":"2026-08-01"},{"id":"iso-42001-published","framework":"ISO/IEC 42001","fact":"Publication","value":"ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.","effective":"2023-12","source":{"label":"ISO/IEC 42001 (iso.org)","url":"https://www.iso.org/standard/42001"},"note":"iso.org blocks automated verification; publication corroborated across accredited bodies and major assurance firms.","lastVerified":"2026-08-01"},{"id":"eu-ai-act-dates","framework":"EU AI Act","fact":"Commencement and GPAI obligations","value":"Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).","effective":"2025-08-02","source":{"label":"EU AI Act — official text (EUR-Lex 2024/1689)","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj"},"lastVerified":"2026-08-01"},{"id":"sama-csf","framework":"SAMA CSF (Saudi Arabia)","fact":"Cyber Security Framework issuance","value":"The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017, applying to SAMA-regulated banks, insurers and finance companies; principle-based, drawing on ISO, Basel and PCI DSS.","effective":"2017-05","source":{"label":"SAMA — Cyber Security Framework (official PDF)","url":"https://www.sama.gov.sa/en-US/Laws/BankingRules/SAMA%20Cyber%20Security%20Framework.pdf"},"lastVerified":"2026-08-01"},{"id":"nca-ecc","framework":"NCA ECC (Saudi Arabia)","fact":"Essential Cybersecurity Controls versions","value":"Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018; the updated ECC-2:2024 restructures the framework into 4 domains, 28 subdomains and 108 main controls, binding government entities and critical-infrastructure operators.","effective":"2024","source":{"label":"National Cybersecurity Authority (Saudi Arabia)","url":"https://nca.gov.sa/en/"},"note":"ECC-2:2024 structure corroborated across multiple assurance publishers; the NCA portal hosts the controlled document.","lastVerified":"2026-08-01"},{"id":"cmmc-rules","framework":"CMMC (US DoD)","fact":"Programme and acquisition rule dates","value":"The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.","effective":"2025-11-10","source":{"label":"US Federal Register — CMMC Program rule (32 CFR 170)","url":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program"},"note":"48 CFR effective date corroborated across defence-contracting counsel and assessor publications.","lastVerified":"2026-08-01"},{"id":"uae-pdpl","framework":"UAE PDPL","fact":"Enactment and effect","value":"UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued in 2021 and came into effect on 2 January 2022. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.","effective":"2022-01-02","source":{"label":"UAE legislation portal / official summaries","url":"https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws"},"lastVerified":"2026-08-01"},{"id":"swift-csp","framework":"SWIFT CSP","fact":"Programme and independent assessment","value":"SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.","effective":"2021","source":{"label":"SWIFT — Customer Security Programme (official)","url":"https://www.swift.com/myswift/customer-security-programme"},"lastVerified":"2026-08-01"},{"id":"qatar-nia","framework":"Qatar NIA (NCSA)","fact":"National Information Assurance Policy version","value":"Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.","effective":"2023-05","source":{"label":"NCSA Qatar (official portal)","url":"https://ncsa.gov.qa/en/"},"note":"Version and date corroborated across Qatar-focused GRC publishers; the NCSA portal hosts the controlled document.","lastVerified":"2026-08-01"},{"id":"rbi-dpsc-2021","framework":"RBI","fact":"Digital Payment Security Controls Master Direction","value":"Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.","effective":"2021-02-18","source":{"label":"Reserve Bank of India (Master Direction, 18 Feb 2021)","url":"https://www.rbi.org.in/"},"note":"Direction cited by title and date for retrieval via RBI notification search.","lastVerified":"2026-08-01"},{"id":"dpdp-breach-notification","framework":"DPDP Act 2023","fact":"Breach notification timeline (Rule 7)","value":"Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.","effective":"2027-05","source":{"label":"DPDP Rules 2025, Rule 7","url":"https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf"},"note":"Timelines corroborated across multiple legal publishers. Enforcement follows the phased commencement (see dpdp-phase-3). Runs in parallel with CERT-In’s 6-hour incident reporting — the same incident triggers both.","lastVerified":"2026-08-01"},{"id":"rbi-cyber-framework-2016","framework":"RBI","fact":"Cyber Security Framework in Banks","value":"RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.","effective":"2016-06-02","source":{"label":"Reserve Bank of India (notification, 2 June 2016)","url":"https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721"},"lastVerified":"2026-08-01"},{"id":"gdpr-application","framework":"GDPR","fact":"Application date","value":"Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).","effective":"2018-05-25","source":{"label":"GDPR — official text (EUR-Lex 2016/679)","url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"},"lastVerified":"2026-08-01"},{"id":"dpdp-notice-requirements","framework":"DPDP Act 2023","fact":"Notice contents (section 5)","value":"Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.","effective":"2027-05","source":{"label":"DPDP Act 2023, section 5 (official Gazette text)","url":"https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf"},"note":"Contents verified directly against the Gazette PDF text. Notice must be available in English or any Eighth Schedule language.","lastVerified":"2026-08-01"},{"id":"hipaa-security-rule","framework":"HIPAA (US)","fact":"Security Rule compliance date","value":"Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.","effective":"2005-04-20","source":{"label":"US HHS — HIPAA Security Rule","url":"https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html"},"lastVerified":"2026-08-01"},{"id":"iso-22301-2019","framework":"ISO 22301","fact":"2019 revision publication","value":"ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.","effective":"2019-10-30","source":{"label":"ISO 22301:2019 (iso.org)","url":"https://www.iso.org/standard/75106.html"},"note":"iso.org blocks automated verification; date corroborated across certification bodies.","lastVerified":"2026-08-01"}]}