32 verified compliance facts across 20 frameworks — DPDP phasing, CERT-In obligations, RBI directions, GCC frameworks, PCI DSS lifecycle — each with its primary source, a last-verified date and an append-only changelog.
Six-hour reporting, 180-day in-India logs, NTP sync and provider records — every obligation traced to the primary text, arranged as a working checklist.
The board-pack one-pager: enactment, the Rules of 13 Nov 2025, Phase II (Nov 2026), and the May 2027 substantive framework — every date sourced to the Gazette.
One incident, every clock: CERT-In’s 6 hours, DPDP Rule 7’s without-delay-plus-72, RBI’s 2–6 hours, and the sector regulators — side by side, every number sourced.
All nine SAQ types: the channel pattern each matches, who it is for, and the eligibility catch that usually trips people.
Why we publish these openly
A reference is only trustworthy if it can be checked. Every fact here carries its primary source and a last-verified date, corrections append to a changelog rather than silently editing, and the whole library is maintained by the CERT-In empanelled, PCI QSA-authorised team at CyberSigma — the same people who use it in real assessments. Spot an error? Tell us.