Regulatory Calendar · Updated July 2026
India Cybersecurity & Compliance Deadlines 2026: The Complete Regulatory Calendar
Six major cyber-compliance clocks are running at once in India. This is the single calendar that puts every live deadline, penalty and core obligation — across the DPDP Act, SEBI CSCRF, RBI, CERT-In, PCI DSS and IRDAI — in one place, with the primary source for each. Compiled by CyberSigma's CERT-In empanelled, PCI SSC-listed QSA auditors.
At a glance
The master compliance calendar
Every live obligation across the six regimes, who it applies to, and its date or status. Dates can be revised by the regulator — confirm the current requirement for your entity category before you plan around it.
| Framework | Obligation | Applies to | Date / status |
|---|---|---|---|
| DPDP Act 2023 + Rules | DPDP Rules notified; Data Protection Board established | All Data Fiduciaries | 13 Nov 2025 (done) |
| DPDP Act 2023 + Rules | Consent Manager registration window | Consent Managers | ~Nov 2026 (expected) |
| DPDP Act 2023 + Rules | Hard enforcement — full obligations + penalties live | All Data Fiduciaries | 13 May 2027 |
| SEBI CSCRF | Framework implementation date | SEBI Regulated Entities | 31 Aug 2025 (in effect) |
| SEBI CSCRF | First cyber audit completed | Qualified & Mid-size REs | 30 Jun 2026 |
| CERT-In Directions 2022 | Report cyber incidents within 6 hours of detection | All body corporates / service providers | In force since 28 Jun 2022 |
| PCI DSS v4.0.1 | v3.2.1 retired; v4.0 the only active standard | Card-data merchants & service providers | 31 Mar 2024 (done) |
| PCI DSS v4.0.1 | Future-dated v4.0.1 requirements become mandatory | Card-data merchants & service providers | 31 Mar 2025 (done) |
| RBI IT Governance MD | IT governance, risk, controls & assurance obligations | Banks, NBFCs, co-operative banks | In effect (2023 MD) |
| RBI Digital Lending | Digital-lending / LSP governance & data controls | REs with digital-lending arrangements | In effect |
| IRDAI Cyber Guidelines | Information & cyber-security governance and audit | Insurers & intermediaries | Ongoing / annual |
1. DPDP Act — enforcement lands 13 May 2027
The Digital Personal Data Protection Act passed in 2023, but the operative detail arrived with the DPDP Rules, notified on 13 November 2025, which trigger an ~18-month transition to 13 May 2027. Maximum penalty for failing reasonable security safeguards is ₹250 crore. Consent, data-mapping and safeguard work takes most organisations the better part of that window. Full deadline and penalty detail is in our DPDP & SEBI readiness briefing; the scope of work is on our DPDP Act compliance services page, and the practical control list is the 150-point DPDP checklist.
2. SEBI CSCRF — 30 June 2026 is the nearest hard date
SEBI's Cybersecurity & Cyber Resilience Framework applies from 31 August 2025; Qualified and Mid-size Regulated Entities must complete their first cyber audit by 30 June 2026, across six domains (Govern, Identify, Protect, Detect, Respond, Recover). See our SEBI CSCRF compliance service and the CSCRF implementation tracker.
3. CERT-In — the 6-hour reporting rule is already live
The CERT-In Directions of 28 April 2022 (in force since 28 June 2022) require reporting of specified cyber incidents within 6 hours of noticing them, plus log retention and clock synchronisation. Many organisations meet the audit requirement with a CERT-In empanelled VAPT.
4. PCI DSS, RBI and IRDAI — the standing obligations
- PCI DSS v4.0.1 — v3.2.1 retired 31 March 2024; the block of future-dated v4.0.1 requirements (including MFA into the CDE and targeted risk analyses) became mandatory 31 March 2025. Validation is annual. See PCI DSS QSA assessment.
- RBI — the Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023) and the digital-lending / outsourcing directions are in effect, audited on operating effectiveness. See RBI cybersecurity audit.
- IRDAI — information and cyber-security governance with periodic audit obligations for insurers and intermediaries. See IRDAI cybersecurity audit.
Where readiness actually breaks down
Across the programmes CyberSigma's auditors run, the same weak points recur regardless of framework: consent and data-mapping treated as a legal formality rather than an engineering task; continuous vulnerability management that lapses between annual tests; third-party / vendor risk that is documented but never verified; and incident-response plans that have never been exercised. Documentation is rarely the blocker — evidence that controls actually operate is. Every one of these regimes is audited on operating effectiveness, not intent.
Free DPDP Act readiness checklist
Consent, data-principal rights, breach reporting and Significant Data Fiduciary duties — mapped to actionable controls by CyberSigma’s DPDP consultants.
Primary sources
- PIB — DPDP Rules, 2025 notified (Nov 2025)
- SEBI — CSCRF for Regulated Entities (Aug 2024)
- CERT-In — Directions under Section 70B (28 Apr 2022)
- PCI SSC — Document Library (PCI DSS v4.0.1)
- RBI — Master Directions
- IRDAI — official site
This calendar is for general information and reflects the position as of July 2026; regulatory dates can be revised — confirm the current requirement for your entity category. For a scoped assessment, talk to CyberSigma.
