We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Editorial policy

Compliance content is only useful if it can be trusted, and trust is a process, not a claim. These are the rules everything on this site is published under.

1. Primary sources or say so

Regulatory facts are verified against the primary text — Gazette PDFs, regulator portals, official standards bodies — before publication. Where an official portal cannot be read directly, the entry states how the fact was corroborated instead of hiding it.

2. Dated, versioned, auditable

Reference material carries a last-verified date and a version. Corrections and additions append to a changelog; entries are never silently edited, so anything cited from us last month can be audited this month.

3. Disputed precision is stated as disputed

Where authoritative sources disagree (for example on an exact commencement day), we publish the range and the disagreement — and tell readers to confirm with counsel — rather than picking a side quietly.

4. Written and reviewed by practitioners

Content is authored and reviewed by the CERT-In empanelled, PCI QSA-authorised team that uses it in real assessments. Author and reviewer names appear on articles; the practice, not a content agency, stands behind the claims.

5. Precise service language

We distinguish assessment, readiness, certification, attestation and audit precisely, and never imply a certification or designation that has not been made. Tools that read signals say so — they do not claim decisions that belong to regulators.

6. No unsupported claims about others

Comparison content asserts verifiable facts about ourselves and stays at category level about third parties. A dash in our comparison tables means we make no representation — evaluate the vendor directly.

7. Errors are reportable — and reported

Every open resource invites corrections. Confirmed errors are fixed with a changelog entry stating what changed and when. Tell us at contact@ / the contact page.

This policy governs the India Compliance Registry, the open resource library, CyberSigma Research, the knowledge centre and the blog. Last updated 1 August 2026.