We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Original data · primary sources · citable

CyberSigma Research

Research from the practice, not the marketing team: what a CERT-In empanelled, PCI QSA-authorised firm sees across real assessments, published with sources and dates so it can be checked — and cited.

The first proprietary edition: what 1,800+ real engagements and 8,900+ monitored public tenders say about Indian compliance demand — PCI DSS and VAPT lead, demand up 35% since Q4, 11.4% of engagements now renewals. Anonymised, suppression-ruled, methodology published.

Read →

The full-length flagship report: every dated obligation sourced to the Gazette or regulator, plus PCI DSS, ISO 27001, SOC 2 and NIST CSF decoded control-by-control. ~150 printed pages, compiled from the open registry so it can never drift from the site.

Read →

India Compliance Registry

Open dataset · living

38 verified compliance facts across 20 frameworks — every entry with its primary source, a last-verified date and an append-only changelog. CC BY 4.0, machine-readable.

Read →

Coming: the India Compliance Index

An annual, data-backed reading of where Indian organisations actually stand against DPDP, RBI, SEBI and PCI obligations — built from anonymised assessment data, published with methodology. Our editorial policy governs everything that appears here.