We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Regulatory Calendar · Updated July 2026

India Cybersecurity & Compliance Deadlines 2026: The Complete Regulatory Calendar

Six major cyber-compliance clocks are running at once in India. This is the single calendar that puts every live deadline, penalty and core obligation — across the DPDP Act, SEBI CSCRF, RBI, CERT-In, PCI DSS and IRDAI — in one place, with the primary source for each. Compiled by CyberSigma's CERT-In empanelled, PCI SSC-listed QSA auditors.

At a glance

6
Regulatory regimes tracked in one calendar
13 May 2027
DPDP Act hard enforcement (penalties to ₹250 cr)
30 Jun 2026
SEBI CSCRF first-audit deadline (Qualified & Mid-size REs)
6 hours
CERT-In incident-reporting window (in force since 2022)
31 Mar 2025
PCI DSS v4.0.1 future-dated requirements became mandatory
Ongoing
RBI IT-governance & digital-lending obligations (in effect)

The master compliance calendar

Every live obligation across the six regimes, who it applies to, and its date or status. Dates can be revised by the regulator — confirm the current requirement for your entity category before you plan around it.

FrameworkObligationApplies toDate / status
DPDP Act 2023 + RulesDPDP Rules notified; Data Protection Board establishedAll Data Fiduciaries13 Nov 2025 (done)
DPDP Act 2023 + RulesConsent Manager registration windowConsent Managers~Nov 2026 (expected)
DPDP Act 2023 + RulesHard enforcement — full obligations + penalties liveAll Data Fiduciaries13 May 2027
SEBI CSCRFFramework implementation dateSEBI Regulated Entities31 Aug 2025 (in effect)
SEBI CSCRFFirst cyber audit completedQualified & Mid-size REs30 Jun 2026
CERT-In Directions 2022Report cyber incidents within 6 hours of detectionAll body corporates / service providersIn force since 28 Jun 2022
PCI DSS v4.0.1v3.2.1 retired; v4.0 the only active standardCard-data merchants & service providers31 Mar 2024 (done)
PCI DSS v4.0.1Future-dated v4.0.1 requirements become mandatoryCard-data merchants & service providers31 Mar 2025 (done)
RBI IT Governance MDIT governance, risk, controls & assurance obligationsBanks, NBFCs, co-operative banksIn effect (2023 MD)
RBI Digital LendingDigital-lending / LSP governance & data controlsREs with digital-lending arrangementsIn effect
IRDAI Cyber GuidelinesInformation & cyber-security governance and auditInsurers & intermediariesOngoing / annual

1. DPDP Act — enforcement lands 13 May 2027

The Digital Personal Data Protection Act passed in 2023, but the operative detail arrived with the DPDP Rules, notified on 13 November 2025, which trigger an ~18-month transition to 13 May 2027. Maximum penalty for failing reasonable security safeguards is ₹250 crore. Consent, data-mapping and safeguard work takes most organisations the better part of that window. Full deadline and penalty detail is in our DPDP & SEBI readiness briefing; the scope of work is on our DPDP Act compliance services page, and the practical control list is the 150-point DPDP checklist.

2. SEBI CSCRF — 30 June 2026 is the nearest hard date

SEBI's Cybersecurity & Cyber Resilience Framework applies from 31 August 2025; Qualified and Mid-size Regulated Entities must complete their first cyber audit by 30 June 2026, across six domains (Govern, Identify, Protect, Detect, Respond, Recover). See our SEBI CSCRF compliance service and the CSCRF implementation tracker.

3. CERT-In — the 6-hour reporting rule is already live

The CERT-In Directions of 28 April 2022 (in force since 28 June 2022) require reporting of specified cyber incidents within 6 hours of noticing them, plus log retention and clock synchronisation. Many organisations meet the audit requirement with a CERT-In empanelled VAPT.

4. PCI DSS, RBI and IRDAI — the standing obligations

  • PCI DSS v4.0.1 — v3.2.1 retired 31 March 2024; the block of future-dated v4.0.1 requirements (including MFA into the CDE and targeted risk analyses) became mandatory 31 March 2025. Validation is annual. See PCI DSS QSA assessment.
  • RBI — the Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023) and the digital-lending / outsourcing directions are in effect, audited on operating effectiveness. See RBI cybersecurity audit.
  • IRDAI — information and cyber-security governance with periodic audit obligations for insurers and intermediaries. See IRDAI cybersecurity audit.

Where readiness actually breaks down

Across the programmes CyberSigma's auditors run, the same weak points recur regardless of framework: consent and data-mapping treated as a legal formality rather than an engineering task; continuous vulnerability management that lapses between annual tests; third-party / vendor risk that is documented but never verified; and incident-response plans that have never been exercised. Documentation is rarely the blocker — evidence that controls actually operate is. Every one of these regimes is audited on operating effectiveness, not intent.

Free DPDP Act readiness checklist

Consent, data-principal rights, breach reporting and Significant Data Fiduciary duties — mapped to actionable controls by CyberSigma’s DPDP consultants.

No spam. Unsubscribe anytime.

Primary sources

This calendar is for general information and reflects the position as of July 2026; regulatory dates can be revised — confirm the current requirement for your entity category. For a scoped assessment, talk to CyberSigma.