We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Proprietary data · August 2026 edition · methodology published

India Compliance Demand Index

What 1,819 real compliance engagements and 8,967 monitored public tenders say about where Indian compliance demand actually is — anonymised, suppression-ruled, and published with its method.

Key findings

29.8%

of categorised engagements are PCI DSS — payment security is India’s largest single compliance driver

23.5%

are VAPT and offensive security — testing demand rivals certification demand

+35%

engagement volume, 2025-Q4 → 2026-Q2 (535 → 724 new engagements)

11.4%

of engagements are renewals — compliance is becoming a recurring programme, not a one-off project

Framework demand mix

Share of 1,359 categorised engagements (Jul 2025 – Aug 2026 snapshot). PCI DSS — across Level 1 assessments, SAQ pathways and service-provider work — is the single largest framework family, with VAPT close behind; together they are more than half of all demand. DPDP-driven privacy work is the youngest segment and the one to watch through the May 2027 phase-in.

PCI DSS (all engagement types)29.8%
VAPT & offensive security (incl. red teaming)23.5%
ISO 27001 / ISMS8.3%
SOC 1 / SOC 2 (all types)7.4%
Privacy — DPDP & GDPR5.6%
Indian regulatory audits (IS audit, SAR, IRDAI ISNP, cyber audit)5.4%
Other frameworks (HIPAA, ISO 9001, ISO 20000, training…)20%

Demand is growing — and recurring

New engagements per quarter: 2025-Q4: 535 · 2026-Q1: 370 · 2026-Q2: 724. The 2026-Q2 figure is 35% above 2025-Q4, and 11.4% of all engagements are renewals — evidence that Indian buyers are moving from point-in-time certification to standing compliance programmes.

Who is buying: industry mix

Among 359 industry-tagged organisations from 1,109 real (non-synthetic) enquiries: technology companies and BFSI dominate, but manufacturing’s third place is the under-reported story — OT-adjacent enterprises are now compliance buyers.

IT & Technology39.8%
BFSI24%
Manufacturing & Energy18.4%
Healthcare & Pharma7.2%
Telecom4.2%
Retail & E-commerce3.3%
Education3.1%

The public-sector signal: 8,967 tenders

Since January 2026 our tender-monitoring system has captured 8,967 Indian public-sector security and compliance tenders — 5,987 in Q2 2026 alone. Cyber-security-audit tenders dominate the mix, confirming that CERT-In-empanelled audit capacity is what government demand is queuing for. (Caveat stated plainly: monitoring began in Q1 2026, so quarter-on-quarter growth partly reflects expanding coverage, not only market growth — we will not claim a trend until four clean quarters exist.)

Cyber security audit47.5%
Security (general)15.5%
Consultant hiring (deliverable-based)12.2%
Security manpower10.9%
ISO certification & audit2.2%
VAPT-specific0.7%

Methodology

Source: CyberSigma’s CRM engagement records (Jul 2025 – Aug 2026 snapshot; aggregation run 2 Aug 2026) and the firm’s public-tender monitoring system. Rules applied: AI-sourced/synthetic prospect records excluded entirely (1,109 real enquiries remain of the raw pool); 460 uncategorised engagement records excluded from the framework mix; 85 small categories (fewer than 10 records each) suppressed rather than published; no client names, no contract values, aggregates only. Percentages are shares of the stated denominators. This index is refreshed quarterly; corrections are appended, never silently made — see the editorial policy.

Cite as: CyberSigma Research, “India Compliance Demand Index”, August 2026 edition, cybersigmacs.com/research/india-compliance-demand-index/. Reuse of the aggregate figures with attribution is welcome.

Benchmark yourself against this demand

If your peers are buying PCI, VAPT and DPDP readiness, the free assessment tells you in two minutes where you stand on the same frameworks.