We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free · Cited compliance answers

Compliance answers, traced to the source

Straight answers to 129 of the questions we hear most — DPDP, PCI DSS, RBI, SEBI, CERT-In, ISO 27001, SOC 2, Aadhaar and more. Every answer is drawn only from our verified compliance registry and cites the issuing body’s own document, with a last-verified date.

What does DPDP Act compliance require for a business in India?

The DPDP Act 2023 requires businesses in India to comply with several provisions, including:

- Registration of Consent Managers, which will be required starting 13 November 2026 under Rule 4 of the Digital Personal Data Protection Rules, 2025 [1]. Consent Managers must meet specific eligibility criteria set out in Part A of the First Schedule, including being incorporated in India, having a minimum net worth of INR 2 crore, and demonstrating sound financial and operational capacity [3].

- Adherence to data protection principles and practices as outlined in the DPDP Rules 2025, which were notified on 13 November 2025 [2].

- Compliance with penalties for non-compliance, with the maximum penalty for the highest tier of offenses (such as failure to take reasonable security safeguards to prevent a personal data breach) capped at ₹250 crore per instance, effective May 2027 [5].

The exact details of these requirements and their implementation dates should be verified against the official documents and notifications.

5 verified sources
[1] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part A https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)

What are the DPDP Act penalties for a data breach?

The DPDP Act 2023 caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

Reference: [1]

5 verified sources
[1] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)

When do the DPDP Rules take effect and what are the key deadlines?

The DPDP Rules 2025 were notified on 13 November 2025 [1]. Key provisions, including those constituting and empowering the Data Protection Board, became effective on the same day [2]. The breach notification timeline under Rule 7 is effective from May 2027 [3], while the Consent Manager registration framework under Rule 4 will come into force on 13 November 2026 [5].

5 verified sources
[2] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)
[4] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

What are the rights of a Data Principal under the DPDP Act?

The DPDP Act 2023 outlines several rights for Data Principals, though the specific details are not provided in the given context. To determine the exact rights, refer to section 6(4) of the DPDP Act 2023, which pertains to the manner of exercising rights under this section. Additionally, section 13 covers grievance redressal mechanisms. The notice accompanying or preceding a consent request must inform the Data Principal of these rights [1].

5 verified sources
[1] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[2] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[4] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

What is the personal data breach notification requirement under the DPDP Rules?

A data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language. This is under Rule 7 of the DPDP Rules 2025 [1]. The rule is effective as of May 2027 [1].

5 verified sources
[3] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[4] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Act 2023 — Breach notification timeline (Rule 7) https://cybersigmacs.com/compliance-registry/#dpdp-breach-notification

What is the penalty structure under the DPDP Act across its tiers?

The penalty structure under the DPDP Act 2023 across its tiers is as follows:

- The highest tier, for failure to take reasonable security safeguards to prevent a personal data breach, has a penalty ceiling of up to ₹250 crore per instance.

- Lower tiers have penalties capped at ₹200 crore, ₹150 crore, and below, respectively; the exact amounts for these tiers are not specified in the context.

- The Data Protection Board determines the specific penalties based on the facts of each case.

- These penalties will come into effect on May 2027.

- The information was last verified on 2026-08-01.

[Cited facts: [1]]

5 verified sources
[1] DPDP Act 2023, the Schedule (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[3] DPDP Act 2023, section 5 (official Gazette text) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-01)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

Who is a Significant Data Fiduciary under the DPDP Act?

A Significant Data Fiduciary (SDF) is notified by the Central Government under Section 10 of the DPDP Act 2023 based on factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the State and public order. [1]

5 verified sources
[1] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[2] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[3] MeitY - Digital Personal Data Protection Rules, 2025, First Schedule Part B https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)
[5] DPDP Rules 2025 (phased commencement) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf (verified 2026-08-01)

What is the personal data breach notification timeline under the DPDP Rules?

Under the DPDP Rules 2025, Rule 7, a data fiduciary must intimate the Data Protection Board of India without delay upon becoming aware of a personal data breach. A detailed report must be submitted within 72 hours (this timeline is extendable by the Board). [1][2]

5 verified sources
[1] Digital Personal Data Protection Rules, 2025, Rule 7 - MeitY https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-13)
[3] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[4] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[5] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)

RBI & payments (India)

See RBI hub

What are the RBI cyber security requirements for banks?

RBI's cyber security requirements for banks include:

1. Reporting cyber incidents to RBI within 2 to 6 hours of detection, along with a board-approved cyber security policy, SOC capability, and cyber crisis management plans. This requirement is detailed in the Cyber Security Framework in Banks, effective since 2 June 2016 [1].

2. Adherence to the IT Governance Master Direction, which mandates an IT governance framework, information/cyber security policies, and periodic IT risk assurance for regulated entities, effective from 1 April 2024 [5].

5 verified sources
[1] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[2] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] RBI — Cyber Security Framework in Banks https://cybersigmacs.com/compliance-registry/#rbi-cyber-framework-2016
[5] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)

What is a System Audit Report (SAR) for payment aggregators?

A System Audit Report (SAR) for payment aggregators requires an authorisation and a System Audit Report conducted by a CERT-In empanelled auditor, as mandated by the RBI Payment Aggregator (PA-PG) Guidelines [2].

5 verified sources
[1] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[2] RBI Payment Aggregator (PA-PG) Guidelines — System Audit & Compliance https://cybersigmacs.com/knowledge-center/rbi-payment-aggregator-guidelines/
[3] SAR Audit: System Audit Report Requirements in India https://cybersigmacs.com/sar-audit/
[4] IRDAI Information and Cybersecurity Guidelines, 2026 — clause on audit submission https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[5] Payment Aggregator & PPI Audit | RBI PSS Compliance https://cybersigmacs.com/rbi-pss-compliance-audit/

What are the RBI data localisation (storage of payment data) requirements?

RBI requires payment system providers to store the entire data relating to their payment systems only in India, with compliance by October 2018. This includes end-to-end transaction data. [1]

5 verified sources
[1] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[2] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] RBI — Payment system data storage in India https://cybersigmacs.com/compliance-registry/#rbi-payment-data-localisation

What are the RBI minimum security standards for digital payment channels?

The RBI minimum security standards for digital payment channels, including internet banking, mobile payments, and card payments, are detailed in the Digital Payment Security Controls Master Direction issued on 18 February 2021 [1]. These standards are binding on scheduled commercial banks, small finance banks, payments banks, and card-issuing non-banking financial companies (NBFCs).

5 verified sources
[1] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)
[2] RBI — Digital Payment Security Controls Master Direction https://cybersigmacs.com/compliance-registry/#rbi-dpsc-2021
[3] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[4] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[5] RBI Master Direction on Digital Payment Security Controls https://cybersigmacs.com/knowledge-center/rbi-digital-payment-security-controls/

What is the RBI IT governance and outsourcing requirement for regulated entities?

Regulated entities must adhere to the following RBI IT governance and outsourcing requirements:

1. **IT Governance**: An IT governance framework, information/cyber security policies, and periodic IT risk assurance are required. This is effective from 1 April 2024, as per the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) [1].

2. **IT Outsourcing**: Material IT outsourcing by regulated entities must be governed, including vendor risk, audit rights, and concentration risk. This became effective on 1 October 2023, as per the Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) [2].

5 verified sources
[1] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)
[2] Reserve Bank of India (Master Direction RBI/2023-24/102) https://www.rbi.org.in/ (verified 2026-08-01)
[3] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[4] RBI — IT Governance Master Direction https://cybersigmacs.com/compliance-registry/#rbi-it-governance-md
[5] RBI — IT Outsourcing Master Direction https://cybersigmacs.com/compliance-registry/#rbi-it-outsourcing-md

What is the SAR (System Audit Report) submission requirement for payment aggregators?

The SAR (System Audit Report) submission requirement for payment aggregators is that they must obtain a System Audit Report by a CERT-In empanelled auditor as mandated by the RBI Payment Aggregator (PA-PG) Guidelines [4]. However, the specific submission deadline is not detailed in the provided context. For precise submission timing, refer to the relevant RBI guidelines directly.

5 verified sources
[1] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[2] SAR Audit: System Audit Report Requirements in India https://cybersigmacs.com/sar-audit/
[3] IRDAI Information and Cybersecurity Guidelines, 2026 — clause on audit submission https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[4] RBI Payment Aggregator (PA-PG) Guidelines — System Audit & Compliance https://cybersigmacs.com/knowledge-center/rbi-payment-aggregator-guidelines/
[5] BBPS Audit — Security Requirements for Bharat Bill Payment System https://cybersigmacs.com/knowledge-center/bbps-audit/

What is the RBI data localisation requirement for payment system data?

The RBI data localisation requirement for payment system data mandates that all system providers ensure the entire data relating to the payment systems they operate is stored in a system only in India. This includes full end-to-end transaction details and any information collected, carried, or processed as part of the payment message or instruction. Compliance was required within six months of the circular's issuance, which was on 6 April 2018, with submission of a System Audit Report conducted by a CERT-In empanelled auditor. This applies to all Payment System Providers authorised under the Payment and Settlement Systems Act, 2007.

Sources: [1], [2]

5 verified sources
[1] RBI Notification RBI/2017-18/153 - Storage of Payment System Data https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244 (verified 2026-08-13)
[2] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[3] RBI — Storage of Payment System Data (data localisation) https://cybersigmacs.com/compliance-registry/#rbi-payment-data-localisation
[4] RBI System Audit Report (SAR) & Payment Data Localisation https://cybersigmacs.com/knowledge-center/rbi-system-audit-sar/
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the RBI Payment Aggregator Directions 2025 net-worth requirements?

A non-bank entity carrying on payment-aggregator business must obtain RBI authorisation and must have a minimum net worth of INR 15 crore at the time of application, rising to a minimum net worth of INR 25 crore by the end of the third financial year after authorisation, maintained thereafter. [1]

5 verified sources
[1] RBI Master Direction RBI/DPSS/2025-26/141 - Regulation of Payment Aggregators Directions, 2025 https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12896 (verified 2026-08-13)
[2] RBI — Regulation of Payment Aggregators Directions, 2025 https://cybersigmacs.com/compliance-registry/#rbi-payment-aggregators-directions-2025
[3] RBI Notification RBI/2017-18/153 - Storage of Payment System Data https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244 (verified 2026-08-13)
[4] Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) https://www.rbi.org.in/ (verified 2026-08-01)
[5] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)

What is the RBI Master Direction on Digital Payment Security Controls?

The RBI Master Direction on Digital Payment Security Controls (RBI/2020-21/74, DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21), dated 18 February 2021, sets out a robust governance structure and common minimum standards of security controls for digital payment products and services. It covers areas such as internet banking, mobile banking, and card payments, along with customer protection and grievance redressal. It applies to Scheduled Commercial Banks (excluding Regional Rural Banks), Small Finance Banks, Payments Banks, and credit-card-issuing NBFCs, and took effect within six months of being placed on the RBI website. [1]

5 verified sources
[1] RBI Master Direction - Digital Payment Security Controls (RBI/2020-21/74) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032 (verified 2026-08-13)
[2] Reserve Bank of India (Master Direction, 18 Feb 2021) https://www.rbi.org.in/ (verified 2026-08-01)
[3] RBI — Master Direction on Digital Payment Security Controls (2021) https://cybersigmacs.com/compliance-registry/#rbi-digital-payment-security-controls-2021
[4] RBI Master Direction RBI/DPSS/2025-26/141 - Regulation of Payment Aggregators Directions, 2025 https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12896 (verified 2026-08-13)
[5] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)

What is the Sarbanes-Oxley Act (SOX)?

The Sarbanes-Oxley Act of 2002 (SOX) is a U.S. federal law enacted on 30 July 2002, which reformed corporate financial reporting and auditing. It created the Public Company Accounting Oversight Board (PCAOB) and is enforced primarily by the U.S. Securities and Exchange Commission. The act applies to U.S. public companies and their auditors. Key provisions include:

- Section 302 requires senior executives to personally certify the accuracy of financial statements.

- Section 404 requires management, and the external auditor, to assess and report on the effectiveness of internal control over financial reporting.

Reference: [1]

5 verified sources
[1] U.S. Congress (congress.gov) - H.R.3763, Sarbanes-Oxley Act of 2002 https://www.congress.gov/bill/107th-congress/house-bill/3763 (verified 2026-08-13)
[2] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[3] Digital Personal Data Protection Rules, 2025, Rule 7 - MeitY https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-13)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)

What is the RBI Cyber Security Framework for banks?

The RBI Cyber Security Framework for banks, issued on 2 June 2016, requires scheduled commercial banks to put in place a board-approved cyber-security policy distinct from their IT or IS-security policy, to implement a baseline cyber-security and resilience framework, and to arrange continuous surveillance (for example through a Security Operations Centre). It also mandates the maintenance of a Cyber Crisis Management Plan and the reporting of all cyber-security incidents, whether successful or attempted, to the RBI. The framework requires banks to report cyber incidents to the RBI within 2 to 6 hours of detection. [1][2][5]

5 verified sources
[1] RBI Notification RBI/2015-16/418 - Cyber Security Framework in Banks https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=10435 (verified 2026-08-13)
[2] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)
[4] RBI Master Direction - Digital Payment Security Controls (RBI/2020-21/74) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032 (verified 2026-08-13)
[5] RBI — Cyber Security Framework in Banks https://cybersigmacs.com/compliance-registry/#rbi-cyber-framework-2016

What is the RBI IT Governance Risk Controls and Assurance Master Direction 2023?

The RBI IT Governance Risk Controls and Assurance Master Direction 2023, effective 1 April 2024, is a consolidated direction that replaces earlier RBI IT-governance and cyber-risk instructions. It applies to regulated entities including scheduled commercial banks (excluding RRBs), small finance banks, payments banks, NBFCs in the specified layers, credit information companies, and all-India financial institutions (NABARD, EXIM Bank, NHB, SIDBI, NaBFID). The direction mandates a board-level IT governance framework covering strategic alignment, risk management, resource and performance management, and business continuity and disaster recovery, alongside an IT and information-security risk management framework and periodic information systems audits.

Source: [1], [2]

5 verified sources
[1] RBI Master Direction RBI/2023-24/107 - IT Governance, Risk, Controls and Assurance Practices https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562 (verified 2026-08-13)
[2] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)
[3] RBI — IT Governance, Risk, Controls and Assurance Practices Directions (2023) https://cybersigmacs.com/compliance-registry/#rbi-it-governance-md-2023
[4] RBI Master Direction - Digital Payment Security Controls (RBI/2020-21/74) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032 (verified 2026-08-13)
[5] Reserve Bank of India (Master Direction RBI/2023-24/102) https://www.rbi.org.in/ (verified 2026-08-01)

What is the RBI Account Aggregator framework?

The RBI Account Aggregator framework, governed by the Master Direction - Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 ([1]), allows NBFC-Account Aggregators to retrieve and consolidate a customer's financial information from multiple financial information providers and share it with financial information users only with the customer's explicit consent. These Aggregators must be registered with the RBI and hold a net owned fund of at least two crore rupees. The framework ensures that no financial information can be retrieved, shared, or transferred without explicit, standardised consent, and the Account Aggregators act solely as data intermediaries without storing, using, or transacting on the data. This framework was issued and enforced by the RBI on 2 September 2016.

5 verified sources
[1] RBI Master Direction DNBR.PD.009/03.10.119/2016-17 - NBFC Account Aggregator https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=10598 (verified 2026-08-13)
[2] RBI Master Direction RBI/DPSS/2025-26/141 - Regulation of Payment Aggregators Directions, 2025 https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12896 (verified 2026-08-13)
[3] RBI Notification RBI/2015-16/418 - Cyber Security Framework in Banks https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=10435 (verified 2026-08-13)
[4] RBI Master Direction RBI/2023-24/107 - IT Governance, Risk, Controls and Assurance Practices https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562 (verified 2026-08-13)
[5] Reserve Bank of India (notification, 2 June 2016) https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=1721 (verified 2026-08-01)

What is SEBI CSCRF and who must comply with it?

SEBI CSCRF stands for the Cybersecurity and Cyber Resilience Framework issued by the Securities and Exchange Board of India (SEBI). It mandates various cybersecurity practices and compliance requirements for regulated entities under SEBI's purview. Specifically, all entities regulated by SEBI, except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), must comply with this framework. The compliance timeline was initially set to be fully in force by 31 August 2025, but due to extensions, it is now fully effective as of 31 August 2025. [2]

5 verified sources
[1] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[2] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[3] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

Which entities must comply with the SEBI CSCRF and what are the categories?

All regulated entities under SEBI must comply with the Cybersecurity and Cyber Resilience Framework (CSCRF) as per [1] and [2]. These entities are categorized into five groups:

1. Market Infrastructure Institutions (MIIs)

2. Qualified Registered Entities (Qualified REs)

3. Mid-size Registered Entities (Mid-size REs)

4. Small-size Registered Entities (Small-size REs)

5. Self-certification Registered Entities (Self-certification REs)

Portfolio Managers and Merchant Bankers were re-categorized by circular 2025/119 of 28 August 2025 ([2]).

5 verified sources
[1] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[2] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[3] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

What is the audit and reporting requirement under the SEBI CSCRF?

Audits must be conducted by a CERT-In empanelled organisation, as stated in the SEBI CSCRF framework. The VAPT report must be submitted within one month of completing the VAPT activity, after approval from the RE's IT Committee. Findings must be closed within three months of report submission, following a graded approach based on the criticality of the observations. Revalidation of the VAPT must be completed within five months of its completion. These requirements are effective from 20 August 2024. [1][4]

5 verified sources
[1] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[2] SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2025/1756380695925.pdf (verified 2026-08-04)
[3] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

What is the effective date of the SEBI CSCRF for different entity categories?

The effective date of the SEBI CSCRF is 20 August 2024, with compliance timelines extended to 31 August 2025 due to circulars [1]. The framework applies proportionately by category starting from this date, as detailed in circular [2].

5 verified sources
[1] SEBI — extension circular 2025/96 (official PDF, 30 June 2025) https://www.sebi.gov.in/sebi_data/attachdocs/jun-2025/1751286353420.pdf (verified 2026-08-04)
[2] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[3] SEBI — technical clarifications circular 2025/119 (official PDF, 28 August 2025) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2025/1756380695925.pdf (verified 2026-08-04)
[4] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)
[5] SEBI — CSCRF circular 2024/113 (official PDF, 20 August 2024) https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf (verified 2026-08-04)

Aadhaar / UIDAI / CKYC

See UIDAI AUA/KUA audit

What are AUA and KUA under the Aadhaar ecosystem?

AUA and KUA refer to Authentication User Agencies and KYC User Agencies under the Aadhaar ecosystem. These agencies must have their operations audited annually (and on need) by a certified information systems auditor as per the Aadhaar (Authentication and Offline Verification) Regulations, 2021, together with the Aadhaar (Data Security) Regulations, 2016, and the UIDAI Information Security Policy. [1][5]

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[3] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[4] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/
[5] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit

What is a UIDAI AUA/KUA security audit and who must undergo it?

A UIDAI AUA/KUA security audit is an annual (and on need) audit of the operations of Authentication User Agencies (AUAs) and eKYC User Agencies (KUAs) by a certified information systems auditor. The audit ensures compliance with the Aadhaar (Authentication and Offline Verification) Regulations, 2021, the Aadhaar (Data Security) Regulations, 2016, and the UIDAI Information Security Policy. AUAs and KUAs must have the results of these audits shared with UIDAI upon request.

This requirement applies to AUAs and KUAs in the Aadhaar ecosystem [1, 3].

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[3] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[5] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/

What is CKYC and what does CKYC compliance require?

CKYC stands for Central Know Your Customer (KYC) framework, which is operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) under the guidelines set by the Reserve Bank of India (RBI). CKYC compliance requires regulated entities to upload KYC records of their customers into the Central KYC Records Registry (CKYCR) within 10 days of establishing an account-based relationship with the customer [3]. The KYC records must be submitted using CERSAI templates, which can change over time [4]. Additionally, customers can provide consent to have their KYC records retrieved from the CKYCR using a KYC Identifier [5]. The applicability of CKYC was phased between 2016 and 2021, with different timelines for Scheduled Commercial Banks and other regulated entities [1].

5 verified sources
[1] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[2] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[3] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)

How often must a UIDAI AUA/KUA security audit be performed?

A UIDAI AUA/KUA security audit must be performed annually and on demand. [1]

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[3] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[5] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/

What is CKYC and what is the CERSAI/CKYC registry requirement?

CKYC stands for Central KYC (Know Your Customer) Records, which is managed through the Central KYC Records Registry (CKYCR) operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) [1]. The CKYC registry requirement mandates that regulated entities capture and upload customer KYC records into the CKYCR within 10 days of establishing an account-based relationship with the customer [3]. This applies to both individuals and legal entities, with the requirement for legal entities being phased in, starting from 1 April 2021 [5].

5 verified sources
[1] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[2] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[3] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)

What are the UIDAI data security regulations that AUA/KUA must follow?

AUA/KUA must follow the UIDAI (Aadhaar) Data Security Regulations, 2016 [1].

5 verified sources
[1] UIDAI compliance checklist for controls the AUA/KUA must have in place https://uidai.gov.in/images/Compliance_checklist_for_certifying_compliance_with_controls__that_the_AUAKUA_is_required_to_have_in_place.pdf (verified 2026-08-11)
[2] UIDAI (Aadhaar) — AUA / KUA audit duty https://cybersigmacs.com/compliance-registry/#aua-kua-audit
[3] AUA & KUA Full Form | UIDAI Aadhaar Security Audit https://cybersigmacs.com/uidai-aua-kua-compliance-security-audit/
[4] UIDAI AUA/KUA Compliance & Security Audit — Aadhaar https://cybersigmacs.com/knowledge-center/uidai-aua-kua/
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What are the NPCI and UPI security requirements?

The NPCI and UPI security requirements include:

1. Volume-cap compliance for Third-Party Application Providers (TPAPs), with a deadline of 31 December 2026, as per NPCI's volume-cap guidelines for UPI (referencing circular NPCI/UPI/OC-97/2020-21).

2. Audit and compliance obligations on TPAPs, including audits by CERT-In empanelled auditors and UPI data storage within India, as detailed in NPCI's Guidelines for Third-Party Application Providers in UPI (circular OC 97, 2020).

These requirements are effective as of their respective deadlines and are enforced through various circulars and guidelines issued by NPCI.

5 verified sources
[1] NPCI UPI circulars (official listing) https://www.npci.org.in/circulars/upi (verified 2026-08-07)
[2] NPCI UPI circulars (official listing; OC 97 direct PDF withdrawn) https://www.npci.org.in/what-we-do/upi/circular (verified 2026-08-11)
[3] NPCI UPI TPAP Security Audit — Requirements for UPI Apps https://cybersigmacs.com/knowledge-center/npci-tpap-audit/
[4] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[5] Free NPCI UPI / TPAP Self-Assessment — Security Audit Readiness https://cybersigmacs.com/self-assessment/npci-upi/

What are the NPCI and UPI security and audit requirements?

NPCI and UPI security and audit requirements include:

1. **Audit Obligations**: TPAPs must undergo audits conducted by CERT-In empanelled auditors. These audits are part of the TPAP guidelines (OC 97, 2020) which impose audit and compliance obligations on TPAPs. ([1])

2. **Data Storage**: UPI data must be stored within India. PSP banks retain audit rights over TPAP UPI infrastructure. ([1])

3. **Volume-Cap Compliance**: Existing TPAPs exceeding the volume-cap must comply by 31 December 2026, following a two-year extension from the original deadline of 31 December 2024. ([2])

4. **API Usage Monitoring**: PSPs and acquiring banks must monitor and control API usage as per NPCI's Guidelines on usage of UPI APIs (OC 215 series, May 2025), with non-compliance potentially leading to API restrictions, penalties, or suspension of new customer onboarding. ([2])

5. **Security Audits**: Pre-go-live and periodic security audits are required for TPAPs, PSP banks, aggregators, and fintechs across various payment systems including UPI, IMPS, RuPay, NACH, AePS, and NETC. ([4])

These requirements ensure compliance and security standards are met in the UPI ecosystem. ([1][2][4])

5 verified sources
[1] NPCI UPI circulars (official listing; OC 97 direct PDF withdrawn) https://www.npci.org.in/what-we-do/upi/circular (verified 2026-08-11)
[2] NPCI UPI circulars (official listing) https://www.npci.org.in/circulars/upi (verified 2026-08-07)
[3] NPCI UPI TPAP Security Audit — Requirements for UPI Apps https://cybersigmacs.com/knowledge-center/npci-tpap-audit/
[4] NPCI & UPI Audit Services | CERT-In Empanelled TPAP Audit https://cybersigmacs.com/npci-audit-services/
[5] Free NPCI UPI / TPAP Self-Assessment — Security Audit Readiness https://cybersigmacs.com/self-assessment/npci-upi/

Insurance (IRDAI / ISNP)

See ISNP certification

What is ISNP and who needs ISNP certification?

ISNP stands for Insurance Self Network Platform [2]. It is subject to an IRDAI-mandated security audit requirement [1, 3, 4]. Specifically, Insurance Self-Network Platforms operating under IRDAI permission must undergo an annual ISNP security audit, which involves controls assessment, gap closure, and audit readiness [1, 4]. This requirement applies to insurance companies, brokers, web aggregators, and technology providers that deal with the ISNP [3].

The ISNP security audit must be conducted by an external Certified Information Systems Auditor (CISA), a Chartered Accountant holding DISA (ICAI), or a CERT-In empanelled expert [4]. The resulting report should be presented to the Board or its sub-committee [4].

5 verified sources
[1] ISNP Security Audit (Insurance Self-Network Platform) | IRDAI https://cybersigmacs.com/isnp-cybersecurity-audit/
[2] ISNP Full Form: IRDAI Insurance Self Network Platform https://cybersigmacs.com/isnp-certification/
[3] Industries That Require ISNP Security Audit https://cybersigmacs.com/isnp-cybersecurity-audit/industries/
[4] IRDAI - circular on online filing for Insurance Self Network Platform (IRDA/INT/CIR/ECM/083/04/2017), citing the governing e-commerce guidelines https://irdai.gov.in/document-detail?documentId=384920 (verified 2026-08-07)
[5] ISO 27001 Explained — ISMS, Annex A Controls & Certification https://cybersigmacs.com/knowledge-center/iso-27001/

What are the IRDAI cyber security requirements for insurers?

The IRDAI cyber security requirements for insurers, as per the Information and Cyber Security Guidelines, 2026 [1], include:

- All Insurers, including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, must comply with these guidelines.

- Insurers are responsible for ensuring that Insurance Agents, Micro-Insurance Agents, Point of Sale Persons, and Individual Surveyors follow a minimum security framework under the Insurer’s Board-approved policy, even though these entities are expressly outside the purview of the guidelines themselves.

These guidelines became effective on 6 April 2026 [1].

5 verified sources
[1] IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-07)
[2] IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) https://irdai.gov.in/document-detail?documentId=3314780 (verified 2026-08-07)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)
[5] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What are the IRDAI information and cyber security requirements for insurers?

The IRDAI Information and Cyber Security Guidelines, 2026 (Version 2.0) outline the requirements for insurers. These guidelines apply to all Insurers, including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, and cover all data created, received, or maintained by Regulated Entities in any form. Insurers are responsible for ensuring that Insurance Agents, Micro-Insurance Agents, Point of Sale Persons, and Individual Surveyors follow a minimum security framework under the Insurer’s Board-approved policy. The guidelines were effective from 6 April 2026, replacing the 2023 version. [1][5]

5 verified sources
[1] IRDAI - Information and Cybersecurity Guidelines, 2026 (official document portal) https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-07)
[2] IRDAI - Information and Cyber Security Guidelines, 2023 (official document portal) https://irdai.gov.in/document-detail?documentId=3314780 (verified 2026-08-07)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] IRDAI — Information and Cybersecurity Guidelines, 2026 (current) https://cybersigmacs.com/compliance-registry/#irdai-infosec-guidelines-2026
[5] IRDAI Information and Cybersecurity Guidelines, 2026 — Annexure IV https://irdai.gov.in/en/document-detail?documentId=9189223 (verified 2026-08-08)

What is CERT-In empanelment and why does it matter for VAPT?

CERT-In empanelment refers to the process where cybersecurity firms and professionals are evaluated and certified by the Computer Emergency Response Team - India (CERT-In) to ensure they meet certain standards and criteria for handling cybersecurity services. This empanelment is crucial for Value Added Penetration Testing (VAPT) because:

- Regulators and enterprises increasingly require CERT-In empanelment to ensure the quality and reliability of cybersecurity services. [2]

- CERT-In empanelment ensures that VAPT partners adhere to specific standards and methodologies, enhancing the trustworthiness of the services provided. [3]

Thus, choosing a CERT-In empanelled VAPT partner is important for ensuring compliance and the quality of the security assessments conducted. [2]

5 verified sources
[1] CERT-In Empanelment Explained: Why It Matters for Your Audit https://cybersigmacs.com/blog/cert-in-empanelment-explained/
[2] Why CERT-In Empanelment Matters When Choosing a VAPT Partner https://cybersigmacs.com/blog/cert-in-empanelled-vapt-partner/
[3] CERT-In Empanelled vs Non-Empanelled Auditors: Why It Matters for Your VAPT https://cybersigmacs.com/blog/cert-in-empanelled-vs-non-empanelled-auditor/
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In VAPT for Government Tenders | Safe-to-Host https://cybersigmacs.com/cert-in-vapt-for-government-tenders/

What is the CERT-In 6-hour incident reporting requirement?

The CERT-In 6-hour incident reporting requirement states that specified cyber incidents must be reported to CERT-In within 6 hours of noticing. This requirement is effective as of 28 June 2022 and applies to service providers, intermediaries, data centres, body corporates, and government organisations. [1][4]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Compliance: Directions, 6-Hour Incident Reporting & Audit Guide https://cybersigmacs.com/blog/cert-in-compliance-audit/
[3] CERT-In Directions Explained — Incident Reporting & Log Retention https://cybersigmacs.com/knowledge-center/cert-in-directions/
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What logs must be retained under the CERT-In directions?

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What logs must be retained and for how long under the CERT-In directions?

ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What records must VPN and cloud providers retain under the CERT-In directions?

VPN and cloud providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service. [1]

5 verified sources
[1] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[2] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[3] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[4] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)
[5] CERT-In Directions (official PDF) https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf (verified 2026-07-31)

What is CMMI and what is new in CMMI v3.0?

CMMI (Capability Maturity Model Integration) is a framework designed to help organizations improve their processes and achieve better outcomes. CMMI V3.0 introduces updates to the model, including the eight domains, Maturity Levels 1–5, and all 31 Practice Areas. The updated version provides a comprehensive guide covering the appraisal lifecycle, CMMI AIM, and other relevant aspects of the model. [1]

5 verified sources
[1] CMMI V3.0 — Domains, Maturity Levels, Practice Areas & Appraisal Guide https://cybersigmacs.com/knowledge-center/cmmi/
[2] Free CMMI Self-Assessment — Maturity Level 2/3 Readiness (V3.0) https://cybersigmacs.com/self-assessment/cmmi/
[3] CMMI Consulting & Appraisal-Readiness (Level 2/3) https://cybersigmacs.com/cmmi-consulting/
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] CMMC Program - 32 CFR Part 170 and the DFARS 48 CFR acquisition rule (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)

PCI DSS & payments security

See PCI DSS hub

What is PCI DSS and who must comply with it?

PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance with PCI DSS is mandatory for QSAs [1], and entities that handle cardholder data, such as e-commerce merchants [2, 4], must adhere to its standards. The standard provides a framework for protecting cardholder data and includes requirements for security management, policies, procedures, network architecture, software design, and other critical protective measures.

5 verified sources
[1] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[2] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What changed in PCI DSS v4.0.1?

The context indicates that PCI DSS v4.0.1 was published on 11 June 2024 and is a limited revision with no new requirements added or removed compared to v4.0. Therefore, there were no changes in requirements between v4.0 and v4.0.1. [1]

5 verified sources
[2] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[3] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — Document Library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What is the PCI DSS v4.0.1 effective date and what are the key deadlines?

The PCI DSS v4.0.1 effective date is 31 March 2025. Key deadlines include:

- Future-dated v4.x requirements becoming mandatory in assessments from 31 March 2025 [1].

The last-verified date for this information is 2026-08-01.

5 verified sources
[2] PCI SSC — PCI DSS v4.0 Supplemental ROC Template: DESV, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

When did the future-dated PCI DSS v4.0 requirements become mandatory?

The future-dated PCI DSS v4.0 requirements became mandatory in assessments from 31 March 2025. [1]

5 verified sources
[2] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)
[4] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the PCI DSS merchant levels?

PCI DSS merchant levels are classified by Visa into four levels based on annual transaction volume:

- Level 1: More than 6 million Visa transactions per year across all channels (or any merchant designated Level 1 by Visa, e.g., after a compromise) - annual on-site assessment and Report on Compliance (ROC) plus quarterly network scan. [2]

- Level 2: 1 to 6 million transactions per year - annual Self-Assessment Questionnaire (SAQ) and quarterly scan. [2]

- Level 3: 20,000 to 1 million Visa e-commerce transactions per year - SAQ and quarterly scan. [2]

- Level 4: Fewer than 20,000 Visa e-commerce transactions, or up to 1 million total transactions per year - SAQ and scan as required by the acquirer. [2]

Other card brands set broadly similar but not identical thresholds; the acquirer confirms a merchant's level. [2]

5 verified sources
[1] PCI SSC - Document Library (Self-Assessment Questionnaires) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] Visa - Account Information Security (AIS) Program and PCI https://corporate.visa.com/en/resources/security-compliance.html (verified 2026-08-13)
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the PCI DSS SAQ types and when is a ROC required instead?

PCI DSS defines nine SAQ types, each scoped to how a merchant handles cardholder data:

- SAQ A (fully outsourced e-commerce or mail/telephone order, no data handling)

- SAQ A-EP (e-commerce that partially controls the payment page)

- SAQ B (imprint machines or standalone dial-out terminals, no electronic storage)

- SAQ B-IP (standalone PTS-approved IP-connected terminals)

- SAQ C-VT (web-based virtual terminal, one transaction at a time)

- SAQ C (payment application connected to the internet)

- SAQ P2PE (hardware terminals in a validated PCI P2PE solution)

- SAQ D for Merchants (all others that store, process or transmit cardholder data - the most comprehensive)

- SAQ D for Service Providers (applies to service providers)

A merchant who cannot meet an SAQ's eligibility criteria, or who is a Level 1 merchant, completes a full Report on Compliance (ROC) instead of an SAQ [1].

5 verified sources
[1] PCI SSC - Document Library (Self-Assessment Questionnaires) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[5] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What are the 12 requirements of PCI DSS?

The 12 requirements of PCI DSS are:

1. Build and maintain a secure network.

2. Build and maintain secure systems and applications.

3. Protect cardholder data.

4. Encrypt cardholder data during transmission over open, public networks.

5. Develop and maintain secure systems and applications.

6. Maintain a vulnerability management program.

7. Implement strong access control measures.

8. Regularly monitor and test networks.

9. Maintain a policy that addresses information security for employees and contractors.

10. Track and monitor all access to network resources and cardholder data.

11. Regularly test security systems and processes.

12. Maintain a written information security policy.

These requirements are structured under six goals as outlined in PCI DSS v4.0.1, which was published in June 2024. [1]

5 verified sources
[1] PCI SSC - Document Library (PCI DSS v4.0.1) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[2] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI SSC — Information Supplement: PCI DSS v4.x Targeted Risk Analysis Guidance (November 2023) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What is PCI PIN Security?

PCI PIN Security is a standard from the PCI Security Standards Council governing the secure management, processing, and transmission of personal identification number (PIN) data during payment card transactions at ATMs and point-of-sale terminals. It applies to acquirers, processors, and their agents that handle PIN-based transactions and cryptographic key management. The requirements are grouped into control objectives covering secure equipment and key management, PIN encryption, and the generation, distribution, and destruction of cryptographic keys. [1]

5 verified sources
[1] PCI Security Standards Council - PIN Security Requirements https://www.pcisecuritystandards.org/standards/pin-security/ (verified 2026-08-13)
[2] PCI Security Standards Council - PCI 3DS Core Security Standard https://www.pcisecuritystandards.org/standards/pci-3ds-core/ (verified 2026-08-13)
[3] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[4] PCI Security Standards Council - Point-to-Point Encryption (P2PE) https://www.pcisecuritystandards.org/standards/point-to-point-encryption-p2pe/ (verified 2026-08-13)
[5] PCI SSC — PCI DSS v4.x ROC Template FAQs, Revision 1 (December 2022) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)

What is PCI Point-to-Point Encryption (P2PE)?

PCI Point-to-Point Encryption (P2PE) is a standard defined by the PCI Security Standards Council. It specifies requirements for solutions that cryptographically protect account data from the point of capture at a merchant device until it reaches a secure decryption environment. This standard applies to P2PE solution providers, component providers, and merchants using PCI-listed P2PE solutions. A validated P2PE solution can significantly reduce a merchant's applicable PCI DSS scope. The requirements encompass secure devices, secure applications, encryption and decryption environments, and cryptographic key operations. [1]

5 verified sources
[1] PCI Security Standards Council - Point-to-Point Encryption (P2PE) https://www.pcisecuritystandards.org/standards/point-to-point-encryption-p2pe/ (verified 2026-08-13)
[2] PCI SSC — SAQ Instructions and Guidelines, v4.0.1 r1 (April 2025) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-04)
[3] PCI P2PE — Validated point-to-point encryption solutions https://cybersigmacs.com/compliance-registry/#pci-p2pe
[4] PCI SSC - Document Library (Self-Assessment Questionnaires) https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-13)
[5] PCI Security Standards Council - PIN Security Requirements https://www.pcisecuritystandards.org/standards/pin-security/ (verified 2026-08-13)

What is the PCI 3DS Core Security Standard?

The PCI 3DS Core Security Standard, from the PCI Security Standards Council, defines physical and logical security requirements for environments where EMV 3-D Secure functions such as the Access Control Server (ACS), Directory Server (DS) and 3DS Server (3DSS) are performed. It applies to entities performing these 3DS functions and is separate and independent from PCI DSS. It is structured in two parts: baseline security requirements for the environment, and 3DS-specific requirements protecting 3DS data, technologies and processes that support card-not-present authentication. [1]

5 verified sources
[1] PCI Security Standards Council - PCI 3DS Core Security Standard https://www.pcisecuritystandards.org/standards/pci-3ds-core/ (verified 2026-08-13)
[2] PCI Security Standards Council - PIN Security Requirements https://www.pcisecuritystandards.org/standards/pin-security/ (verified 2026-08-13)
[3] PCI 3DS — PCI 3DS Core Security Standard for 3-D Secure environments https://cybersigmacs.com/compliance-registry/#pci-3ds-core
[4] PCI Security Standards Council - Point-to-Point Encryption (P2PE) https://www.pcisecuritystandards.org/standards/point-to-point-encryption-p2pe/ (verified 2026-08-13)
[5] PCI SSC document library https://www.pcisecuritystandards.org/document_library/ (verified 2026-08-01)

What is the PCI Software Security Framework?

The PCI Software Security Framework (SSF) is a collection of standards and validation programmes from the PCI Security Standards Council that promotes security in payment software and replaced PA-DSS. It comprises two standards: the Secure Software Standard, which assesses payment-software products, and the Secure Software Lifecycle (Secure SLC) Standard, which assesses a vendor's ongoing secure-development processes. It applies to payment-software vendors and their products; PA-DSS was formally retired at the end of October 2022, after which the SSF became the applicable framework. [1]

5 verified sources
[1] PCI SSC - Software Security Framework https://www.pcisecuritystandards.org/standards/software-security-framework/ (verified 2026-08-13)
[2] PCI Security Standards Council - PIN Security Requirements https://www.pcisecuritystandards.org/standards/pin-security/ (verified 2026-08-13)
[3] PCI Security Standards Council - PCI 3DS Core Security Standard https://www.pcisecuritystandards.org/standards/pci-3ds-core/ (verified 2026-08-13)
[4] PCI SSF — Software Security Framework (successor to PA-DSS) https://cybersigmacs.com/compliance-registry/#pci-ssf
[5] NIST - Privacy Framework v1.0 (CSRC) https://csrc.nist.gov/pubs/itlb/2020/06/nist-privacy-framework/final (verified 2026-08-13)

VAPT & application security

See VAPT services

What is OWASP ASVS?

OWASP ASVS (Application Security Verification Standard) is a framework for assessing the security of web applications and APIs. It consists of 345 verification requirements organized into 17 chapters (V1-V17), effective from May 2025 [2][3]. The requirements are categorized into three verification levels (L1-L3), with Level 1 containing 70 requirements, Level 2 containing 183, and Level 3 containing 92 [4]. Each application verified at a higher level is expected to satisfy the requirements of the lower levels as well [4]. The latest version is v5.0.0, which includes substantial restructuring compared to previous versions [1].

5 verified sources
[1] OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) https://github.com/OWASP/ASVS/tree/master/5.0/en (verified 2026-08-11)
[3] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[4] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[5] Application Security Testing Services | OWASP ASVS https://cybersigmacs.com/application-security-testing/

What are the three levels of the OWASP Application Security Verification Standard (ASVS)?

The three levels of the OWASP Application Security Verification Standard (ASVS) are Level 1, Level 2, and Level 3. [1] [2]

5 verified sources
[1] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[3] OWASP — Application Security Verification Standard project https://owasp.org/www-project-application-security-verification-standard/ (verified 2026-08-04)
[4] OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) https://github.com/OWASP/ASVS/tree/master/5.0/en (verified 2026-08-11)
[5] OWASP ASVS — Requirements are split across three verification levels https://cybersigmacs.com/compliance-registry/#owasp-asvs-5-levels

ISO 27001 & ISMS

See ISO 27001 hub

What is ISO 27001 certification and what does it involve?

ISO 27001 certification involves establishing, implementing, maintaining, and continually improving an information security management system (ISMS) according to the requirements specified in the ISO/IEC 27001 standard [2]. This standard, published in October 2022 as the third edition, is titled "Information security, cybersecurity and privacy protection — Information security management systems — Requirements" [2]. The certification process ensures that an organization has a robust framework for managing information security risks effectively [5].

5 verified sources
[1] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[4] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[5] ISO 27001 Hub — Certification Guide, Cost, ISMS https://cybersigmacs.com/hub/iso-27001/

What is the ISO 27001:2022 transition deadline for existing certificates?

The ISO 27001:2022 transition deadline for existing certificates is 31 October 2025. This is the end of the IAF three-year transition window for ISO/IEC 27001:2013 certificates. Certificates not transitioned to the 2022 revision by this date will lapse. [1]

5 verified sources
[1] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO/IEC 27001 — 2022-revision transition deadline https://cybersigmacs.com/compliance-registry/#iso-27001-2022-transition
[4] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[5] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)

How many controls are in ISO 27001:2022 Annex A and what are the four themes?

ISO 27001:2022 Annex A contains 93 controls organised into four themes:

- Organisational (37 controls, clause 5)

- People (8 controls, clause 6)

- Physical (14 controls, clause 7)

- Technological (34 controls, clause 8)

These numbers reflect a restructuring from the 2013 edition, where the count fell through consolidation and merging rather than a reduction in scope. [1]

5 verified sources
[1] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[2] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[3] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[4] ISO/IEC 27001 — Annex A control count (2022 revision) https://cybersigmacs.com/compliance-registry/#iso27001-annexa-control-count
[5] ISO 27001:2022 Annex A Controls Explained | All 4 Themes https://cybersigmacs.com/iso-27001-annex-a/

What is a Statement of Applicability in ISO 27001?

A Statement of Applicability (SoA) in ISO 27001 is a document that must be produced as part of the organization's information-security risk-treatment process. According to ISO/IEC 27001:2022 clause 6.1.3(d), the SoA must include the necessary controls (whether from Annex A or elsewhere), the justification for their inclusion, whether each necessary control is implemented, and the justification for excluding any of the Annex A controls. The SoA is a mandatory, auditable document that serves as the reference point for auditors to confirm that all applicable controls are addressed. [1]

5 verified sources
[1] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[2] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[3] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)
[4] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[5] ISO/IEC 27001 — Statement of Applicability (clause 6.1.3) https://cybersigmacs.com/compliance-registry/#iso27001-statement-of-applicability

What is ISO/IEC 27002 and how does it relate to ISO 27001?

ISO/IEC 27002 is an international standard from ISO and IEC that provides a reference set of information security controls with detailed implementation guidance. It is a companion to ISO/IEC 27001 and is not certifiable on its own; organizations use it to implement the controls selected in an ISO/IEC 27001 Information Security Management System (ISMS). [1]

The 2022 edition of ISO/IEC 27002 reorganizes the controls into the same four themes as ISO/IEC 27001:2022 Annex A—organizational, people, physical, and technological—and covers 93 controls. [1]

ISO/IEC 27001 Annex A contains 93 controls organized into these four themes, which aligns with the controls provided in ISO/IEC 27002. [2]

5 verified sources
[1] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)
[2] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[3] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[4] ISO/IEC 27001:2022 - Information security management systems (ISO) https://www.iso.org/standard/27001 (verified 2026-08-13)
[5] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)

Cloud security & privacy

See our services

What is ISO/IEC 27701 (PIMS)?

ISO/IEC 27701 is an international standard from ISO and IEC that specifies requirements and guidance for a Privacy Information Management System (PIMS). It applies to organizations acting as PII controllers and PII processors and adds privacy-specific requirements and controls on top of an information security management system. [1]

5 verified sources
[1] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[2] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)
[3] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)
[4] ISO/IEC 27018 - Protection of PII in public clouds (ISO) https://www.iso.org/standard/27018 (verified 2026-08-13)
[5] ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) https://www.iso.org/standard/42001 (verified 2026-08-13)

What is ISO/IEC 27017 for cloud security?

ISO/IEC 27017 is an international standard from ISO and IEC providing a code of practice for information security controls for cloud services, based on ISO/IEC 27002. It gives cloud-specific implementation guidance for both cloud service providers and cloud service customers and adds cloud-specific controls covering shared roles and responsibilities, return or removal of customer assets, segregation in virtual environments, and administrative operations. [1]

5 verified sources
[1] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)
[2] ISO/IEC 27018 - Protection of PII in public clouds (ISO) https://www.iso.org/standard/27018 (verified 2026-08-13)
[3] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)
[4] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[5] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)

What is ISO/IEC 27018 for PII in the cloud?

ISO/IEC 27018 is an international standard from ISO and IEC establishing controls to protect personally identifiable information (PII) in public cloud computing environments where the cloud provider acts as a PII processor. It applies to public cloud service providers that process PII on behalf of their customers and builds on ISO/IEC 27002, addressing consent, transparency, restrictions on use, disclosure and cross-border handling of cloud-processed PII, and accountability. [1]

5 verified sources
[1] ISO/IEC 27018 - Protection of PII in public clouds (ISO) https://www.iso.org/standard/27018 (verified 2026-08-13)
[2] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)
[3] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[4] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)
[5] ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) https://www.iso.org/standard/42001 (verified 2026-08-13)

What is the CSA Cloud Controls Matrix and STAR?

The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing published by the Cloud Security Alliance (CSA), organised into 17 domains of cloud security and privacy controls and mapped to leading standards and regulations. It defines responsibilities between cloud service providers and customers and is used to assess cloud security posture. Together with the Consensus Assessments Initiative Questionnaire (CAIQ), the CCM is the basis for CSA's Security, Trust, Assurance and Risk (STAR) programme and its public registry of provider self-assessments and third-party certifications. [1][2][3]

5 verified sources
[1] CSA Cloud Controls Matrix (Cloud Security Alliance) https://cloudsecurityalliance.org/research/cloud-controls-matrix (verified 2026-08-13)
[2] CSA CCM / STAR — Cloud Controls Matrix and the STAR registry https://cybersigmacs.com/compliance-registry/#csa-ccm-star
[3] CSA CCM & STAR — Complete Cloud Security Controls & Assurance Guide https://cybersigmacs.com/knowledge-center/csa-ccm/
[4] CIS Critical Security Controls Version 8 (Center for Internet Security) https://www.cisecurity.org/controls/v8 (verified 2026-08-13)
[5] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)

What is FedRAMP?

FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government-wide programme providing a standardised approach to security assessment, authorisation and continuous monitoring for cloud products and services, based on NIST SP 800-53 controls. It is operated by the General Services Administration and maintains a marketplace of authorised cloud services, authorising agencies and recognised third-party assessment organisations. Cloud service providers must obtain a FedRAMP authorisation (Low, Moderate or High baseline) to sell cloud services to U.S. federal agencies. [1]

4 verified sources
[1] General Services Administration - FedRAMP.gov https://www.fedramp.gov/ (verified 2026-08-13)
[2] FedRAMP (US) — U.S. government cloud security authorisation programme https://cybersigmacs.com/compliance-registry/#fedramp
[3] FedRAMP — Complete Guide to Cloud Authorisation (Low/Mod/High) https://cybersigmacs.com/knowledge-center/fedramp/
[4] NIST SP 800-53 Rev. 5 — Control Families & How to Use It https://cybersigmacs.com/knowledge-center/nist-800-53/

What is StateRAMP or GovRAMP?

StateRAMP or GovRAMP is a non-profit programme that standardises cloud security verification for state, local, tribal, and education (SLTT) government entities. It was rebranded from StateRAMP to GovRAMP in 2025 to reflect a broader whole-of-state mission. The programme is built on NIST SP 800-53 control baselines and operates on a complete-once, use-many model, allowing a provider to be authorised once and reused across participating jurisdictions. Verification levels scale by control count. It applies to cloud service providers selling to participating government entities and to the governments requiring independent security validation. [1][2]

2 verified sources
[1] StateRAMP / GovRAMP - official site https://govramp.org/ (verified 2026-08-13)
[2] StateRAMP / GovRAMP — Cloud security authorisation for state and local government https://cybersigmacs.com/compliance-registry/#stateramp-govramp

What is the difference between SOC 2 Type I and Type II?

The difference between SOC 2 Type I and Type II is explained in [2] and [4]. Type I provides an assessment of controls at a specific point in time, while Type II offers a more comprehensive view over a specified period, typically six months. Both types evaluate controls related to security, availability, confidentiality, processing integrity, and privacy, but Type II includes the results of ongoing testing and monitoring.

5 verified sources
[1] SOC 2 Explained — Trust Services Criteria, Type I vs Type II https://cybersigmacs.com/knowledge-center/soc-2/
[2] SOC 2 Type 1 vs Type 2: Differences and Which to Choose https://cybersigmacs.com/blog/soc-2-type-1-vs-type-2/
[3] SOC 2 for SaaS Companies — Type II Readiness, Criteria & Evidence https://cybersigmacs.com/industries/saas/soc-2/
[4] SOC 2 Hub — Type I vs II, Cost, Readiness in India https://cybersigmacs.com/hub/soc-2/
[5] SOC 2 Compliance for Indian SaaS Companies: A Practical Guide https://cybersigmacs.com/blog/soc-2-compliance-india/

What are the five SOC 2 Trust Services Criteria?

The five SOC 2 Trust Services Criteria are Security, Availability, Processing Integrity, Confidentiality, and Privacy. [1]

5 verified sources
[1] AICPA - 2017 Trust Services Criteria (With Revised Points of Focus - 2022) https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[2] AICPA TSP Section 100, paragraphs .14 and .15 https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[3] AICPA TSP Section 100 — common criteria and points of focus https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[4] SOC 2 (AICPA) — Trust Services Criteria - current version https://cybersigmacs.com/compliance-registry/#soc2-trust-services-criteria
[5] SOC 2 Explained — Trust Services Criteria, Type I vs Type II https://cybersigmacs.com/knowledge-center/soc-2/

What is a SOC 1 report?

A SOC 1 report is a reporting framework governed by the AICPA under attestation standard SSAE 18 (AT-C section 320), examining the controls at a service organisation that are relevant to its user entities' internal control over financial reporting (ICFR). The report can be a Type 1 (design of controls at a point in time) or Type 2 (design and operating effectiveness over a period) and is used by user entities and their financial-statement auditors. [1]

5 verified sources
[1] SOC 1 - SOC for Service Organizations: ICFR (AICPA & CIMA) https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1 (verified 2026-08-13)
[3] AICPA - 2017 Trust Services Criteria (With Revised Points of Focus - 2022) https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[4] AICPA TSP Section 100, paragraphs .14 and .15 https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)
[5] AICPA TSP Section 100 — common criteria and points of focus https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (verified 2026-08-08)

ISO management systems

See our services

What is the ISO 22301 standard and what does it require?

ISO 22301:2019 is a standard for business continuity management systems, published on 30 October 2019, replacing the 2012 first edition. It does not specify detailed requirements but provides a framework for organizations to establish, implement, maintain, and continually improve their business continuity management systems. The amendment ISO 22301:2019/Amd 1:2024, published in February 2024, adds considerations for climate change to the management system requirements, though these amendments supplement the original standard rather than replace it. [1][2]

5 verified sources
[1] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[2] ISO 22301:2019 (iso.org) https://www.iso.org/standard/75106.html (verified 2026-08-11)
[3] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[4] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[5] ISO/IEC 27001 (iso.org) https://www.iso.org/standard/27001 (verified 2026-08-11)

What is ISO/IEC 20000-1 for IT service management?

ISO/IEC 20000-1 is an international standard jointly published by ISO and IEC that specifies requirements to establish, implement, maintain and continually improve a service management system (SMS) for the planning, design, transition, delivery and improvement of services. It applies to any organisation delivering services, regardless of type or size, and is the only part of the ISO/IEC 20000 family to which an organisation can be certified. [1]

5 verified sources
[1] ISO/IEC 20000-1:2018 - IT service management (ISO) https://www.iso.org/standard/70636.html (verified 2026-08-13)
[2] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[3] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)
[4] ISO/IEC 27005:2022 - Information security risk management (ISO) https://www.iso.org/standard/80585.html (verified 2026-08-13)
[5] ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) https://www.iso.org/standard/42001 (verified 2026-08-13)

What is ISO 9001 for quality management?

ISO 9001 is the international standard published by ISO specifying requirements for a quality management system (QMS). It applies to organisations of any size and sector that need to consistently provide products and services meeting customer and applicable regulatory requirements and to enhance customer satisfaction. Its requirements are structured around context of the organisation, leadership, planning, support, operation, performance evaluation and improvement (Plan-Do-Check-Act). [1]

5 verified sources
[1] ISO 9001:2015 - Quality management systems (ISO) https://www.iso.org/standard/62085.html (verified 2026-08-13)
[2] ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) https://www.iso.org/standard/42001 (verified 2026-08-13)
[3] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[4] ISO/IEC 20000-1:2018 - IT service management (ISO) https://www.iso.org/standard/70636.html (verified 2026-08-13)
[5] ISO 31000:2018 - Risk management (ISO) https://www.iso.org/standard/65694.html (verified 2026-08-13)

What is ISO/IEC 27005 for information security risk?

ISO/IEC 27005 is a framework that provides guidance on managing information security risks. It supports the establishment and operation of information security risk management within an ISO/IEC 27001 ISMS. The standard applies to organizations of all types and sizes, offering a structured approach for identifying, analyzing, evaluating, and treating information security risks, aligned with ISO/IEC 27001:2022 and ISO 31000:2018. [1]

5 verified sources
[1] ISO/IEC 27005:2022 - Information security risk management (ISO) https://www.iso.org/standard/80585.html (verified 2026-08-13)
[2] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[3] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)
[4] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[5] ISO/IEC 27017:2015 - Cloud services security controls (ISO) https://www.iso.org/standard/43757.html (verified 2026-08-13)

What is ISO 31000 risk management?

ISO 31000 is an international standard published by ISO that provides principles, a framework, and a process for managing risk of any type faced by an organisation. It centres on creating and protecting value and describes a risk management process including scope and context establishment, risk assessment (identification, analysis, evaluation), risk treatment, monitoring, and communication. [1]

5 verified sources
[1] ISO 31000:2018 - Risk management (ISO) https://www.iso.org/standard/65694.html (verified 2026-08-13)
[2] ISO/IEC 27005:2022 - Information security risk management (ISO) https://www.iso.org/standard/80585.html (verified 2026-08-13)
[3] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[4] ISO/IEC 20000-1:2018 - IT service management (ISO) https://www.iso.org/standard/70636.html (verified 2026-08-13)
[5] ISO 9001:2015 - Quality management systems (ISO) https://www.iso.org/standard/62085.html (verified 2026-08-13)

What is ISO 42001 and what does an AI management system require?

ISO 42001 is the first AI management system (AIMS) standard, published in December 2023 by ISO/IEC, which specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. However, the specific requirements and clauses of ISO 42001 are not detailed in the provided context [1]. For more detailed information on what an AI management system requires, including mapping to the EU AI Act and NIST AI RMF, refer to the resource provided [4].

5 verified sources
[1] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[2] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[3] ISO 22301:2019/Amd 1:2024 (iso.org) https://www.iso.org/standard/88412.html (verified 2026-08-07)
[4] ISO 42001 Explained: The AI Management System Standard https://cybersigmacs.com/blog/iso-42001-explained/
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is ISO/IEC 42001 for AI management systems?

ISO/IEC 42001:2023 is the first certifiable international standard for an Artificial Intelligence Management System (AIMS), published in December 2023. It specifies requirements for establishing, implementing, maintaining and continually improving an AIMS, so that an organisation developing, providing or using AI does so responsibly. [1]

5 verified sources
[1] ISO/IEC 42001:2023 - Artificial intelligence management system (ISO) https://www.iso.org/standard/42001 (verified 2026-08-13)
[2] ISO/IEC 42001 (iso.org) https://www.iso.org/standard/42001 (verified 2026-08-11)
[3] ISO — ISO/IEC 27001:2022 catalogue entry https://www.iso.org/standard/27001 (verified 2026-08-08)
[4] ISO/IEC 27701 - Privacy information management (ISO) https://www.iso.org/standard/27701 (verified 2026-08-13)
[5] ISO/IEC 27002:2022 - Information security controls (ISO) https://www.iso.org/standard/75652.html (verified 2026-08-13)

NIST frameworks

See our services

What is the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework (CSF) 2.0, released on 26 February 2024, is organised around six Functions: GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS), and RECOVER (RC) [3]. It defines four Tiers of risk governance rigor: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4) [2]. The framework provides a taxonomy of high-level cybersecurity outcomes without prescribing specific methods for achieving these outcomes [4]. It is designed to be applicable to organizations of various sizes, sectors, and maturity levels [4]. The GOVERN function is new in version 2.0 and focuses on establishing and monitoring cybersecurity risk management strategies [3].

5 verified sources
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What are the five functions of the NIST Cybersecurity Framework?

The five functions of the NIST Cybersecurity Framework are GOVERN (GV), IDENTIFY (ID), PROTECT (PR), DETECT (DE), and RESPOND (RS). GOVERN is new in version 2.0 and covers how an organisation establishes and monitors its cybersecurity risk management strategy, expectations, and policy. [1]

5 verified sources
[1] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What are the maximum administrative fines under GDPR Article 83?

The maximum administrative fines under GDPR Article 83 are:

- Up to EUR 10 million, or up to 2% of total worldwide annual turnover of the preceding financial year - for breaches of obligations such as security of processing, records of processing, and data protection by design and by default.

- Up to EUR 20 million, or up to 4% of total worldwide annual turnover - for breaches of the basic principles for processing (including conditions for consent), data subjects' rights, and the rules on transfers to third countries.

Fines must be effective, proportionate, and dissuasive. [1][2]

5 verified sources
[1] Regulation (EU) 2016/679 (GDPR), Article 83 - EUR-Lex https://eur-lex.europa.eu/eli/reg/2016/679/oj (verified 2026-08-13)
[2] EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (verified 2026-08-04)
[3] Regulation (EU) 2016/679 (GDPR), Article 30 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)
[4] GDPR — Administrative fines (Article 83) https://cybersigmacs.com/compliance-registry/#gdpr-article-83-fines
[5] Regulation (EU) 2016/679 (GDPR), Articles 35-36 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)

What are the six functions of the NIST Cybersecurity Framework 2.0?

The six functions of the NIST Cybersecurity Framework 2.0 are:

- GOVERN (GV) - establishing and monitoring the organization's cybersecurity risk management strategy, expectations, and policy.

- IDENTIFY (ID)

- PROTECT (PR)

- DETECT (DE)

- RESPOND (RS)

- RECOVER (RC)

These functions are intended to be performed concurrently and continuously. [2][5]

5 verified sources
[1] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST CSF — CSF 2.0 - six core functions https://cybersigmacs.com/compliance-registry/#nist-csf-2-functions
[5] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What is NIST SP 800-53?

NIST SP 800-53 is a U.S. National Institute of Standards and Technology publication providing a comprehensive catalog of security and privacy controls for information systems and organizations. It supports U.S. federal agencies (and is widely used by others) in protecting operations, assets, and individuals from a broad range of threats and privacy risks. Revision 5 consolidates security and privacy controls into a single catalog, makes them outcome-based and control-organisation-neutral, and groups them into 20 control families. [1]

5 verified sources
[1] NIST SP 800-53 Rev. 5 - Security and Privacy Controls (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final (verified 2026-08-13)
[2] NIST SP 800-171 Rev. 3 - Protecting CUI (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/171/r3/final (verified 2026-08-13)
[3] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] OWASP Application Security Verification Standard 5.0 repository (CC BY-SA) https://github.com/OWASP/ASVS/tree/master/5.0/en (verified 2026-08-11)

What is NIST SP 800-171 and CUI?

NIST SP 800-171 is a U.S. National Institute of Standards and Technology publication that provides recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organizations. It applies to contractors, universities, and other nonfederal entities that process, store, or transmit CUI on behalf of U.S. federal agencies. [1]

5 verified sources
[1] NIST SP 800-171 Rev. 3 - Protecting CUI (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/171/r3/final (verified 2026-08-13)
[2] NIST SP 800-53 Rev. 5 - Security and Privacy Controls (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final (verified 2026-08-13)
[3] 32 CFR Part 170 - CMMC Program (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[4] NIST SP 800-171 — Protecting Controlled Unclassified Information (CUI) https://cybersigmacs.com/compliance-registry/#nist-sp-800-171
[5] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)

What is the NIST Privacy Framework?

The NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management (Version 1.0) is a voluntary framework from the U.S. National Institute of Standards and Technology to help organisations identify and manage privacy risk. It is organised into five functions (Identify-P, Govern-P, Control-P, Communicate-P and Protect-P) subdivided into categories and subcategories, and is designed to align structurally with the NIST Cybersecurity Framework. It is technology-, sector- and law-agnostic and can be used by organisations of any size. [1]

5 verified sources
[1] NIST - Privacy Framework v1.0 (CSRC) https://csrc.nist.gov/pubs/itlb/2020/06/nist-privacy-framework/final (verified 2026-08-13)
[2] NIST SP 800-53 Rev. 5 - Security and Privacy Controls (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final (verified 2026-08-13)
[3] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)
[4] NIST Privacy Framework — Voluntary privacy risk-management framework (v1.0) https://cybersigmacs.com/compliance-registry/#nist-privacy-framework

What is NIST SP 800-207 Zero Trust Architecture?

NIST SP 800-207, Zero Trust Architecture, is a U.S. NIST publication defining zero trust concepts and an abstract model of components, deployment scenarios, and use cases for enterprises adopting zero trust. It describes zero trust as moving defenses from static network perimeters to focus on users, assets, and resources, with access decisions made per session based on policy and continuous verification. It is aimed at enterprise network architects and is a widely referenced federal baseline for zero-trust guidance. [1]

5 verified sources
[1] NIST SP 800-207 - Zero Trust Architecture (CSRC) https://csrc.nist.gov/pubs/sp/800/207/final (verified 2026-08-13)
[2] NIST SP 800-207 (Zero Trust) — Zero Trust Architecture https://cybersigmacs.com/compliance-registry/#nist-sp-800-207-zta
[3] NIST SP 800-171 Rev. 3 - Protecting CUI (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/171/r3/final (verified 2026-08-13)
[4] NIST SP 800-53 Rev. 5 - Security and Privacy Controls (NIST CSRC) https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final (verified 2026-08-13)
[5] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)

Security baselines

See our services

What are the CIS Critical Security Controls v8?

The CIS Critical Security Controls v8 are a prioritised set of cybersecurity best practices published and maintained by the Center for Internet Security (CIS). This version consolidates the guidance into 18 top-level Controls containing 153 Safeguards, organised into three Implementation Groups (IG1 to IG3) scaled to an organisation's risk and resources. They apply to organisations of any size and are mapped to other frameworks such as the NIST Cybersecurity Framework. [1]

5 verified sources
[1] CIS Critical Security Controls Version 8 (Center for Internet Security) https://www.cisecurity.org/controls/v8 (verified 2026-08-13)
[2] CIS Controls — CIS Critical Security Controls v8 - 18 controls, 153 safeguards https://cybersigmacs.com/compliance-registry/#cis-controls-v8
[3] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] CIS Controls v8 Explained — The 18 Controls & Implementation Groups https://cybersigmacs.com/knowledge-center/cis-controls/
[5] NCA ECC (Saudi Arabia) — Essential Cybersecurity Controls versions https://cybersigmacs.com/compliance-registry/#nca-ecc

What is the HITRUST CSF?

The HITRUST CSF is a certifiable security and privacy control framework created and maintained by HITRUST. It harmonises and maps to more than 60 authoritative sources—such as ISO 27001, the NIST publications, HIPAA, and PCI DSS—into a single control library. Originally focused on healthcare, it is applicable across sectors and risk levels. Organisations can achieve HITRUST certification (e1, i1, or r2) through validated assessments performed with an authorised external assessor. [1]

5 verified sources
[1] HITRUST CSF (HITRUST Alliance) https://hitrustalliance.net/hitrust-framework (verified 2026-08-13)
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-13)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[5] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What is UK Cyber Essentials?

UK Cyber Essentials is a UK government-backed minimum standard of cyber security for organizations of all sizes, developed by the National Cyber Security Centre (NCSC) and delivered through IASME as the official partner. It certifies organizations against five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. [1]

5 verified sources
[1] National Cyber Security Centre (NCSC) - Cyber Essentials https://www.ncsc.gov.uk/cyberessentials/overview (verified 2026-08-13)
[2] Cyber Essentials (UK) — NCSC-backed baseline cyber security certification https://cybersigmacs.com/compliance-registry/#uk-cyber-essentials
[3] Cyber Essentials & National Cyber Compliance UK https://cybersigmacs.com/national-cyber-compliance-uk/
[4] Cyber Essentials (UK) — Complete Certification Guide https://cybersigmacs.com/knowledge-center/cyber-essentials/
[5] Cybersecurity Services UK | VAPT, ISO 27001, Cyber Essentials https://cybersigmacs.com/cybersecurity-services-uk/

What is the Australian Essential Eight?

The Australian Essential Eight is a set of prioritised baseline mitigation strategies published by the Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC). The eight strategies are:

1. Patch applications

2. Patch operating systems

3. Multi-factor authentication

4. Restrict administrative privileges

5. Application control

6. Restrict Microsoft Office macros

7. User application hardening

8. Regular backups

It is supported by the Essential Eight Maturity Model, which defines Maturity Levels Zero to Three; organisations are advised to reach the same maturity level across all eight strategies before progressing to a higher level. [1] [3] [4]

5 verified sources
[1] Australian Cyber Security Centre (ASD) - Essential Eight https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight (verified 2026-08-13)
[2] National Cyber Security Centre (NCSC) - Cyber Essentials https://www.ncsc.gov.uk/cyberessentials/overview (verified 2026-08-13)
[3] Essential Eight (Australia) — ASD/ACSC eight prioritised mitigation strategies with maturity model https://cybersigmacs.com/compliance-registry/#au-essential-eight
[4] Essential Eight — Complete Guide to the ASD Mitigation Strategies https://cybersigmacs.com/knowledge-center/essential-eight/
[5] VAPT & Security Testing in Australia https://cybersigmacs.com/vapt-security-testing-australia/

What is COBIT 2019?

COBIT 2019 is ISACA's framework for the governance and management of enterprise information and technology, and the successor to COBIT 5. It is built around six governance principles and 40 governance and management objectives grouped into five domains (Evaluate-Direct-Monitor, Align-Plan-Organise, Build-Acquire-Implement, Deliver-Service-Support, and Monitor-Evaluate-Assess). It is designed to be tailored to an organisation's size, strategy, risk profile and sourcing model using components such as processes, structures, policies, information, skills and culture, and applies to any enterprise seeking to align IT with business goals while balancing value, risk and resources. [1]

5 verified sources
[1] ISACA - COBIT https://www.isaca.org/resources/cobit (verified 2026-08-13)
[2] COBIT 2019 — ISACA enterprise IT governance framework https://cybersigmacs.com/compliance-registry/#cobit-2019
[3] ISO 22301:2019 (iso.org) https://www.iso.org/standard/75106.html (verified 2026-08-11)
[4] COBIT Explained — IT Governance Framework by ISACA https://cybersigmacs.com/knowledge-center/cobit/
[5] Personal Data Protection Committee (PDPC) Thailand - official portal https://www.pdpc.or.th/ (verified 2026-08-13)

What is MITRE ATT&CK?

MITRE ATT&CK is a globally accessible, curated knowledge base of adversary tactics and techniques based on real-world observations, maintained by the MITRE Corporation. It is structured around tactics (adversary goals), techniques and sub-techniques (how goals are achieved) and procedures, organised into matrices for Enterprise, Mobile and ICS environments. It is used across the private sector, government, and the security community as a foundation for threat modelling, detection engineering, and defensive assessment, and is freely available. [1]

5 verified sources
[1] MITRE - ATT&CK knowledge base https://attack.mitre.org/ (verified 2026-08-13)
[2] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[3] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[4] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)
[5] RBI — Master Direction, Know Your Customer (KYC) Direction, 2016 (updated 14 August 2025) https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566 (verified 2026-08-07)

What are CIS Benchmarks?

CIS Benchmarks are consensus-developed secure configuration recommendations from the Center for Internet Security (CIS) for hardening technologies against attack, distinct from the outcome-oriented CIS Critical Security Controls. They cover more than 100 baselines across many vendor product families, including operating systems, cloud platforms, containers, databases, network devices, mobile devices and server and desktop software. They are produced through a global consensus process, available as free PDFs for non-commercial use, and mapped to frameworks such as the NIST CSF, ISO 27001, PCI DSS and HIPAA. [1]

5 verified sources
[1] CIS - CIS Benchmarks https://www.cisecurity.org/cis-benchmarks (verified 2026-08-13)
[2] CIS Critical Security Controls Version 8 (Center for Internet Security) https://www.cisecurity.org/controls/v8 (verified 2026-08-13)
[3] CIS Benchmarks — Consensus secure-configuration baselines https://cybersigmacs.com/compliance-registry/#cis-benchmarks
[4] CIS Controls — CIS Critical Security Controls v8 - 18 controls, 153 safeguards https://cybersigmacs.com/compliance-registry/#cis-controls-v8
[5] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)

What are the MAS Technology Risk Management Guidelines?

The MAS Technology Risk Management (TRM) Guidelines are risk-management principles and best-practice standards issued by the Monetary Authority of Singapore (MAS) for financial institutions. These guidelines, revised in 2021, set expectations for technology-risk governance and oversight, secure system development, resilience, incident response, and third-party and cloud-risk management to strengthen cyber resilience. They apply to all MAS-regulated financial institutions, including banks, insurers, fund managers, and payment service providers. The guidelines were issued on 18 January 2021. [1][2]

5 verified sources
[1] MAS - Technology Risk Management Guidelines https://www.mas.gov.sg/regulation/guidelines/technology-risk-management-guidelines (verified 2026-08-13)
[2] MAS TRM (Singapore) — Technology Risk Management Guidelines (2021) https://cybersigmacs.com/compliance-registry/#mas-trm-guidelines
[3] RBI Master Direction RBI/2023-24/107 - IT Governance, Risk, Controls and Assurance Practices https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562 (verified 2026-08-13)
[4] MAS TRM — Complete Technology Risk Management Guide https://cybersigmacs.com/knowledge-center/mas-trm/
[5] NIST - Privacy Framework v1.0 (CSRC) https://csrc.nist.gov/pubs/itlb/2020/06/nist-privacy-framework/final (verified 2026-08-13)

What are the SWIFT CSP mandatory controls and the attestation deadline?

The SWIFT CSP mandatory controls are 26 out of the 32 controls in the Customer Security Controls Framework (CSCF) v2026. The attestation deadline for compliance against CSCF v2026 is between July and December 2026.

Mandatory controls: 26

Attestation deadline: July to December 2026 [3]

5 verified sources
[1] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[2] SWIFT — Customer Security Programme (official) https://www.swift.com/myswift/customer-security-programme (verified 2026-08-11)
[3] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[4] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[5] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)

What are the levels of the CMMC (Cybersecurity Maturity Model Certification)?

The CMMC (Cybersecurity Maturity Model Certification) defines three levels:

- Level 1 (Foundational) - 17 practices protecting Federal Contract Information (FCI), verified by annual self-assessment. [1]

- Level 2 (Advanced) - the 110 security requirements of NIST SP 800-171 Revision 2, protecting Controlled Unclassified Information (CUI), most requiring a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO). [1]

- Level 3 (Expert) - Level 2 plus a subset of NIST SP 800-172 requirements for the highest-value CUI, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). [1]

5 verified sources
[1] 32 CFR Part 170 - CMMC Program (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[2] CMMC (US DoD) — Three levels and final-rule status https://cybersigmacs.com/compliance-registry/#cmmc-levels-final-rule
[3] CMMC Program - 32 CFR Part 170 and the DFARS 48 CFR acquisition rule (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[4] 32 CFR Part 170 - CMMC Program scope and assessment (eCFR) https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170 (verified 2026-08-11)
[5] US Federal Register — CMMC Program rule (32 CFR 170) https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program (verified 2026-08-01)

Global privacy laws

See our services

What is the CCPA and CPRA in California?

The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), provide California residents with rights over the personal information businesses collect about them. Businesses subject to these laws include for-profit entities doing business in California that meet certain thresholds (over 25 million US dollars gross annual revenue; buying, selling, or sharing the personal information of 100,000 or more California residents; or deriving 50 percent or more of revenue from selling residents' personal information). Consumers have rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive information, and non-discrimination. The CPRA's additional protections took effect on 1 January 2023. These laws are enforced by the California Attorney General and the California Privacy Protection Agency. [1]

5 verified sources
[1] California Attorney General - California Consumer Privacy Act (CCPA) https://oag.ca.gov/privacy/ccpa (verified 2026-08-13)
[2] CCPA / CPRA (US-California) — California consumer privacy law, as amended by the CPRA https://cybersigmacs.com/compliance-registry/#ccpa-cpra-california
[3] CCPA / CPRA — Complete California Consumer Privacy Compliance Guide https://cybersigmacs.com/knowledge-center/ccpa-cpra/
[4] Cybersecurity Audit in the USA https://cybersigmacs.com/cybersecurity-audit-usa/
[5] National Cybersecurity Framework Compliance in the USA https://cybersigmacs.com/national-cyber-compliance-usa/

What is Brazil LGPD data protection law?

The Brazil LGPD (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018) regulates the processing of personal data by individuals and public or private entities to protect the fundamental rights of freedom and privacy. It is enforced by the Autoridade Nacional de Proteção de Dados (ANPD). This law applies to any processing carried out in Brazil, or that offers goods or services to or processes the data of individuals located in Brazil. It sets out legal bases for processing, data-subject rights, and administrative penalties (fines up to 2 percent of Brazil revenue, capped at 50 million reais per infraction). [1]

5 verified sources
[1] Presidencia da Republica (Planalto) - Lei No. 13.709/2018 https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm (verified 2026-08-13)
[2] LGPD (Brazil) — Brazil General Data Protection Law (Lei 13.709/2018) https://cybersigmacs.com/compliance-registry/#lgpd-brazil
[3] Regulation (EU) 2016/679 (GDPR), Articles 37-39 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)
[4] Personal Data Protection Commission (PDPC) Singapore - PDPA https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act (verified 2026-08-13)
[5] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)

What is PIPEDA in Canada?

PIPEDA, or the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), is Canada's federal private-sector privacy law [1]. It governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activity and sets rules for electronic documents and signatures. The act is overseen by the Office of the Privacy Commissioner of Canada through a complaint-and-investigation mechanism. It applies to private-sector organizations across Canada, except in provinces with substantially similar legislation, and includes mandatory breach-reporting and record-keeping provisions. Last verified on 2026-08-13.

4 verified sources
[1] Justice Laws Website (Government of Canada) - PIPEDA (S.C. 2000, c. 5) https://laws-lois.justice.gc.ca/eng/acts/P-8.6/ (verified 2026-08-13)
[2] PIPEDA (Canada) — Canada federal private-sector privacy law https://cybersigmacs.com/compliance-registry/#pipeda-canada
[3] PIPEDA — Complete Canada Privacy Compliance Guide https://cybersigmacs.com/knowledge-center/pipeda/
[4] OSFI B-13 — Technology & Cyber Risk Management Guide (Canada) https://cybersigmacs.com/knowledge-center/osfi-b13/

What is Singapore PDPA?

Singapore PDPA refers to the Personal Data Protection Act 2012, which governs the collection, use, disclosure, and care of personal data by organizations in Singapore. It establishes the national Do Not Call registry and is administered and enforced by the Personal Data Protection Commission (PDPC). The act imposes several data-protection obligations including consent, purpose-limitation, protection, accountability, and mandatory data-breach-notification on private-sector organizations. These obligations became effective on 2 July 2014.

Source: [1]

5 verified sources
[1] Personal Data Protection Commission (PDPC) Singapore - PDPA https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act (verified 2026-08-13)
[2] PDPA Singapore — Complete Data Protection Compliance Guide https://cybersigmacs.com/knowledge-center/pdpa-singapore/
[3] PDPA (Singapore) — Singapore Personal Data Protection Act 2012 https://cybersigmacs.com/compliance-registry/#pdpa-singapore
[4] VAPT & Security Testing in Singapore https://cybersigmacs.com/vapt-security-testing-singapore/
[5] Cyber Security Audit Singapore | ISO 27001 & MAS-Aligned https://cybersigmacs.com/cybersecurity-audit-singapore/

What is POPIA in South Africa?

POPIA, or the Protection of Personal Information Act 4 of 2013, is a framework in South Africa that gives effect to the constitutional right to privacy by regulating how public and private bodies process personal information. It is monitored and enforced by the Information Regulator (South Africa). The substantive conditions for lawful processing under POPIA became fully enforceable on 1 July 2021, requiring responsible parties to meet eight conditions for lawful processing and to safeguard personal information. Penalties include administrative fines and, for some offences, imprisonment. [1][2][4]

5 verified sources
[1] Information Regulator (South Africa) - POPIA https://inforegulator.org.za/ (verified 2026-08-13)
[2] POPIA (South Africa) — South Africa Protection of Personal Information Act 4 of 2013 https://cybersigmacs.com/compliance-registry/#popia-south-africa
[3] VAPT & Security Testing in South Africa https://cybersigmacs.com/vapt-security-testing-south-africa/
[4] POPIA — Complete South Africa Data Protection Compliance Guide https://cybersigmacs.com/knowledge-center/popia/
[5] AI & LLM Security South Africa | LLM Pen Testing https://cybersigmacs.com/ai-security-south-africa/

What is the Thailand Personal Data Protection Act?

The Thailand Personal Data Protection Act B.E. 2562 (2019) is a comprehensive data protection law enforced by the Personal Data Protection Committee (PDPC). It governs the collection, use, and disclosure of personal data by data controllers and processors, requiring a lawful basis (often consent), data-subject rights, security safeguards, and rules on cross-border transfers. Its main operative provisions became effective on 1 June 2022. [1]

5 verified sources
[1] Personal Data Protection Committee (PDPC) Thailand - official portal https://www.pdpc.or.th/ (verified 2026-08-13)
[2] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[3] Digital Personal Data Protection Rules, 2025, Rule 7 - MeitY https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-13)
[4] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[5] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)

What is UK GDPR and the Data Protection Act 2018?

The UK GDPR together with the Data Protection Act 2018 form the United Kingdom's data protection framework, regulated and enforced by the Information Commissioner's Office (ICO). The UK GDPR sets the core principles, lawful bases, and data-subject rights, while the DPA 2018 supplements it with UK-specific exemptions, rules for law enforcement and intelligence processing, and the ICO's powers and penalties. It applies to organizations processing the personal data of individuals in the UK; the DPA 2018 took effect on 25 May 2018, and the UK GDPR applied following the Brexit transition. [1]

5 verified sources
[1] ICO - Data Protection Act 2018 / UK GDPR https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-protection-act-2018/ (verified 2026-08-13)
[2] UK GDPR & DPA 2018 — UK data protection legal framework https://cybersigmacs.com/compliance-registry/#uk-gdpr-dpa-2018
[3] Regulation (EU) 2016/679 (GDPR), Articles 37-39 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)
[4] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[5] Regulation (EU) 2016/679 (GDPR), Articles 35-36 - EUR-Lex consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679 (verified 2026-08-11)

What is the Australia Privacy Act and the Australian Privacy Principles?

The Australia Privacy Act and the Australian Privacy Principles (APPs) are governed by the Privacy Act 1988, which is Australia's principal legislation protecting the handling of personal information. Regulated by the Office of the Australian Information Commissioner (OAIC), the APPs consist of 13 principles that dictate how APP entities must collect, use, disclose, store, secure, and provide access to personal information. This act applies to most Australian Government agencies and private-sector organizations with an annual turnover exceeding AUD 3 million, among other entities. The APPs commenced on 12 March 2014. [1]

5 verified sources
[1] OAIC - Australian Privacy Principles https://www.oaic.gov.au/privacy/australian-privacy-principles (verified 2026-08-13)
[2] Privacy Act (Australia) — Privacy Act 1988 and the 13 Australian Privacy Principles https://cybersigmacs.com/compliance-registry/#australia-privacy-act-apps
[3] NIST - Privacy Framework v1.0 (CSRC) https://csrc.nist.gov/pubs/itlb/2020/06/nist-privacy-framework/final (verified 2026-08-13)
[4] Australian Cyber Security Centre (ASD) - Essential Eight https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight (verified 2026-08-13)
[5] California Attorney General - California Consumer Privacy Act (CCPA) https://oag.ca.gov/privacy/ccpa (verified 2026-08-13)

What is HIPAA compliance?

HIPAA compliance involves adhering to the Health Insurance Portability and Accountability Act's Security Rule, which became effective on 20 April 2005 for most covered entities, with small health plans having until 20 April 2006. This rule mandates the implementation of administrative, physical, and technical safeguards for electronic protected health information (ePHI). Specifically, covered entities must notify affected individuals without unreasonable delay, but no later than 60 calendar days following the discovery of a breach of unsecured ePHI, unless a law-enforcement delay applies. For breaches affecting 500 or more individuals, the covered entity must also notify the Secretary of the Department of Health and Human Services contemporaneously with the notification to individuals. For breaches affecting fewer than 500 individuals, the entity must maintain a log and report them not later than 60 days after the end of the calendar year in which they were discovered. [1][2][3][4]

5 verified sources
[1] US HHS — HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html (verified 2026-08-11)
[2] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[3] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[4] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is the SWIFT Customer Security Programme (CSP)?

The SWIFT Customer Security Programme (CSP) is a framework designed to enhance the security of financial transactions involving SWIFT. It includes a set of mandatory and advisory security controls that organizations connected to SWIFT must attest against annually. Key aspects include:

- An independent assessment became mandatory for attestations starting in 2021, replacing pure self-attestation.

- The latest version, CSCF v2026, introduces several changes, such as requiring multi-factor authentication for external privileged access, recognizing Swift Universal Confirmation as a transaction validation option, and adding controls related to system hardening, malware protection, and security training.

- The framework consists of 32 controls, with 26 being mandatory and 6 advisory.

- Customer client connectors have been made a mandatory in-scope component, impacting the scope of assessments for some users.

- The current attestation period runs from July to December 2026, based on the controls outlined in CSCF v2026, which was published in mid-2025. [1][2][3][4][5]

5 verified sources
[1] SWIFT — Customer Security Programme (official) https://www.swift.com/myswift/customer-security-programme (verified 2026-08-11)
[2] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[3] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[4] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)
[5] Swift — Customer Security Controls Framework v2026, Detailed Description (1 July 2025) https://www.swift.com/myswift/customer-security-programme-document-centre (verified 2026-08-11)

What is the HIPAA breach notification requirement?

According to HIPAA, the breach notification requirement involves two main aspects:

1. For breaches involving 500 or more individuals, the covered entity must notify the Secretary contemporaneously with the notice to individuals, following discovery of the breach [1].

2. For breaches involving fewer than 500 individuals, the entity must maintain a log and report them not later than 60 days after the end of the calendar year in which they were discovered [1].

Additionally, following discovery of a breach, a covered entity must notify each affected individual "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach", except where a law-enforcement delay under § 164.412 applies [2].

5 verified sources
[1] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[2] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[3] US HHS — HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html (verified 2026-08-11)
[4] EUR-Lex — Regulation (EU) 2016/679 (GDPR), consolidated text https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679 (verified 2026-08-04)
[5] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)

What is the GLBA Safeguards Rule?

The GLBA Safeguards Rule (16 CFR Part 314), mandated by the 1999 Gramm-Leach-Bliley Act, requires financial institutions under FTC jurisdiction to develop, implement and maintain an information security programme with administrative, technical and physical safeguards to protect customer information. It is enforced by the Federal Trade Commission and applies to entities engaged in activities that are financial in nature. The amended rule also requires reporting to the FTC of notification events in which the unencrypted customer information of 500 or more consumers is acquired without authorization. [1]

5 verified sources
[1] Federal Trade Commission - Gramm-Leach-Bliley Act / Safeguards Rule https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act (verified 2026-08-13)
[2] eCFR — 45 CFR Part 164 (HIPAA Security and Breach Notification Rules) https://www.ecfr.gov/current/title-45/part-164 (verified 2026-08-04)
[3] GLBA (US) — FTC Safeguards Rule under the Gramm-Leach-Bliley Act https://cybersigmacs.com/compliance-registry/#glba-safeguards-rule
[4] GLBA & FTC Safeguards Rule — Financial Data Security Compliance Guide https://cybersigmacs.com/knowledge-center/glba-safeguards/
[5] HIPAA (US) — The Security Rule is built on three classes of safeguard https://cybersigmacs.com/compliance-registry/#hipaa-security-safeguards

What is FISMA?

FISMA stands for the Federal Information Security Modernization Act of 2014 [1]. This act amended the 2002 Federal Information Security Management Act and updated the U.S. federal government information-security framework. Under this act, CISA, with OMB oversight, administers the implementation of information-security policies for non-national-security federal Executive Branch systems. It mandates that the head of each federal agency must provide information-security protections commensurate with risk, report on the effectiveness of their security programs, and report major information-security incidents. [1]

2 verified sources
[1] CISA - Federal Information Security Modernization Act https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act (verified 2026-08-13)
[2] FISMA (US) — Federal Information Security Modernization Act of 2014 https://cybersigmacs.com/compliance-registry/#fisma-2014

What is the HITECH Act?

The HITECH Act is part of the American Recovery and Reinvestment Act of 2009, administered by the U.S. Department of Health and Human Services. It promotes the adoption and meaningful use of electronic health records while strengthening the privacy and security protections established under HIPAA. Key aspects include extending HIPAA Security Rule safeguards, direct liability to business associates, establishing tiered civil monetary penalties, and introducing breach-notification requirements for covered entities and business associates handling protected health information. [1]

5 verified sources
[1] U.S. HHS - HITECH Act Enforcement Interim Final Rule https://www.hhs.gov/hipaa/for-professionals/special-topics/hitech-act-enforcement-interim-final-rule/index.html (verified 2026-08-13)
[2] The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - MeitY https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-08-13)
[3] Digital Personal Data Protection Rules, 2025, Rule 7 - MeitY https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-13)
[4] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)

What is the FFIEC IT Examination Handbook?

The FFIEC IT Examination Handbook is a set of examination booklets issued by the Federal Financial Institutions Examination Council to guide examiners in assessing the IT and cybersecurity risk of U.S. financial institutions and their service providers. It comprises booklets such as Information Security, Management, Business Continuity Management, and Architecture, Infrastructure and Operations, covering governance, risk identification, controls, incident response and third-party oversight. It applies to banks, credit unions and other financial institutions supervised by the FFIEC member agencies. [1]

5 verified sources
[1] FFIEC - IT Examination Handbook InfoBase https://ithandbook.ffiec.gov/it-booklets/information-security (verified 2026-08-13)
[2] FFIEC — IT Examination Handbook for U.S. financial institutions https://cybersigmacs.com/compliance-registry/#ffiec-it-handbook
[3] FFIEC Cybersecurity Assessment — CAT & IT Handbook Compliance Guide https://cybersigmacs.com/knowledge-center/ffiec-cat/
[5] SOC 2 (AICPA) — What a SOC 2 report is https://cybersigmacs.com/compliance-registry/#soc2-engagement-nature

EU regulations

See our services

When does the EU AI Act take effect and what are its key dates?

The EU AI Act takes effect with several key dates:

- **2 August 2024**: Regulation (EU) 2024/1689 entered into force, marking the commencement of the Act. [3]

- **2 February 2025**: Chapters I and II (general provisions and prohibited AI practices) apply. [4]

- **2 August 2025**: Governance rules and obligations for general-purpose AI (GPAI) model providers apply, along with other obligations under Chapter III Section 4, Chapter V, Chapter VII, Chapter XII, and Article 78 (notifying authorities, general-purpose AI models, governance, penalties, and confidentiality). [3, 4]

- **2 August 2026**: The main provisions of the Regulation apply, except for Article 6(1) concerning high-risk classification for AI as a safety component of products already regulated under Union law. [4]

- **2 December 2027**: Postponed deadline for high-risk AI systems designated under Article 6(2) and Annex III. [1]

- **2 August 2028**: Postponed deadline for AI embedded in products regulated under Annex I sectoral legislation. [1]

- **2 August 2027**: Compliance deadline for providers of general-purpose AI models placed on the market before 2 August 2025. [5]

- **31 December 2030**: Compliance deadline for AI systems that are components of the large-scale IT systems listed in Annex X and placed on the market before 2 August 2027. [5]

These dates reflect the staggered implementation of various aspects of the EU AI Act. [4, 5]

5 verified sources
[1] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[2] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[3] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)
[4] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)

What are the penalties under the EU AI Act?

Penalties under the EU AI Act include:

- Up to EUR 35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, for infringement of the Article 5 prohibited-practices rules. [3]

- Up to EUR 15,000,000 or 3% for breach of most other operator obligations. [3]

- Up to EUR 7,500,000 or 1% for supplying incorrect, incomplete, or misleading information to notified bodies or national authorities. [3]

For Small and Medium-sized Enterprises (SMEs) including start-ups, each ceiling is the lower rather than the higher of the two figures. [3]

5 verified sources
[1] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[3] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[4] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)
[5] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)

What risk categories does the EU AI Act define?

The EU AI Act defines high-risk AI systems, which are subject to specific obligations and deadlines as per the regulation. However, the context provided does not explicitly list the specific risk categories defined by the EU AI Act. Therefore, based solely on the given context, I cannot provide a definitive list of risk categories.

For a precise answer, you should refer to the primary source of the EU AI Act. [1] [2] [3] [4] [5]

5 verified sources
[1] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)
[2] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[3] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-07)
[4] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[5] EU AI Act — official text (EUR-Lex 2024/1689) https://eur-lex.europa.eu/eli/reg/2024/1689/oj (verified 2026-08-07)

What is the EU NIS2 Directive?

The EU NIS2 Directive (Directive (EU) 2022/2555) is a cybersecurity directive adopted on 14 December 2022, which lays down measures for a high common level of cybersecurity across the European Union. It repeals the earlier NIS Directive (EU) 2016/1148 and applies to essential and important entities across critical sectors such as energy, transport, banking, health, digital infrastructure, and public administration. The directive imposes cybersecurity risk-management measures, governance accountability, and significant-incident reporting, backed by supervision and enforcement. Each member state must transpose this directive into its national law. [1]

5 verified sources
[1] Directive (EU) 2022/2555 (NIS2) - EUR-Lex https://eur-lex.europa.eu/eli/dir/2022/2555/oj (verified 2026-08-13)
[2] NIS2 (EU) — EU-wide cybersecurity directive for essential and important entities https://cybersigmacs.com/compliance-registry/#eu-nis2-directive
[3] Regulation (EU) 2022/2554 (DORA) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2022/2554/oj (verified 2026-08-13)
[4] EUR-Lex — Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (verified 2026-08-04)
[5] Regulation (EU) 2026/1744 (Digital Omnibus on AI) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 2026-08-07)

What is DORA (the Digital Operational Resilience Act)?

DORA (the Digital Operational Resilience Act) is a directly applicable EU regulation, Regulation (EU) 2022/2554, adopted on 14 December 2022. It sets uniform requirements for the security of network and information systems of financial entities and their critical ICT third-party providers. The act applies to a broad range of EU-regulated financial entities such as banks, insurers, investment firms, and payment institutions. It requires ICT risk management, ICT-related incident reporting, digital operational resilience testing, and oversight of ICT third-party risk. It became applicable across all member states on 17 January 2025. [1][2]

5 verified sources
[1] Regulation (EU) 2022/2554 (DORA) - EUR-Lex https://eur-lex.europa.eu/eli/reg/2022/2554/oj (verified 2026-08-13)
[2] DORA (EU) — Digital Operational Resilience Act for the financial sector https://cybersigmacs.com/compliance-registry/#eu-dora-regulation
[3] Official Gazette text (MeitY PDF) https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf (verified 2026-07-31)
[4] DORA Compliance — Digital Operational Resilience Act Complete Guide https://cybersigmacs.com/knowledge-center/dora/
[5] MeitY - Digital Personal Data Protection Rules, 2025 (official page) https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa (verified 2026-08-08)

GCC frameworks

See our services

What is the UAE PDPL (Personal Data Protection Law)?

The UAE PDPL (Personal Data Protection Law) is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It came into effect on 2 January 2022 [3]. The law outlines various obligations and rights for controllers and processors of personal data, including reporting breaches, appointing a Data Protection Officer, honoring data-subject rights, securing data, conducting data protection impact assessments, and controlling cross-border transfers [1]. Consent is the default basis for processing personal data, with specific exceptions outlined in the law [2]. The law also provides for an enforcement structure, including mechanisms for filing complaints and imposing penalties, though the issuance of the Executive Regulation detailing the law's implementation remains unresolved [4].

5 verified sources
[1] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[2] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 4-6 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[3] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[4] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 24-28 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[5] UAE Personal Data Protection Law (PDPL) https://cybersigmacs.com/knowledge-center/uae-pdpl/

What is Saudi Arabia NCA ECC (Essential Cybersecurity Controls)?

Saudi Arabia NCA ECC (Essential Cybersecurity Controls) is a framework consisting of 108 main controls and 92 sub-controls organized into 4 main domains and 28 subdomains. It applies to government agencies and private-sector entities owning, operating, or hosting Critical National Infrastructure within the Kingdom, including their affiliated companies and entities both inside and outside the Kingdom. The framework was first issued as ECC-1:2018 and updated to ECC-2:2024, which mandates compliance through self-assessments, periodic reports, and field auditing visits by the National Cybersecurity Authority (NCA). Compliance is required by Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439H. The framework includes specific requirements for establishing an independent cybersecurity department, filling all cybersecurity positions with full-time, qualified Saudi nationals, and documenting and approving a cybersecurity strategy. [1][2][3][4]

5 verified sources
[1] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[2] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] NCA - ECC-2:2024 (English), Figures 3-4 and Table 1 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is SAMA CSF?

SAMA CSF (Saudi Arabia) is a Cyber Security Framework issued by the Saudi Central Bank (SAMA) in May 2017. It applies to all SAMA-regulated Member Organizations, including banks, insurance and reinsurance companies, financing companies, credit bureaus, and the Financial Market Infrastructure. The framework is principle-based and draws on NIST, ISF, ISO, Basel, and PCI standards. Member Organizations are expected to operate at maturity level 3 or higher. [1]

5 verified sources
[1] SAMA Rulebook — Cyber Security Framework https://rulebook.sama.gov.sa/en/cyber-security-framework-2 (verified 2026-08-04)
[2] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[3] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)
[4] NIST — Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (verified 2026-08-04)

What is the Qatar NIA framework?

The Qatar NIA (National Information Assurance) framework is mandated by Qatar's National Cyber Security Agency (NCSA) for government entities and critical infrastructure. The current revision of the National Information Assurance Policy is version 2.1, effective as of May 2023, which supersedes version 2.0. This framework provides security controls, classification, and compliance approaches for organizations within the jurisdiction. [1][5]

5 verified sources
[1] NCSA Qatar (official portal) https://ncsa.gov.qa/en/ (verified 2026-08-01)
[2] Qatar NIA — Complete National Information Assurance Guide https://cybersigmacs.com/knowledge-center/qatar-nia/
[3] National Cybersecurity Framework Compliance in the USA https://cybersigmacs.com/national-cyber-compliance-usa/
[4] National Cybersecurity Framework Compliance in Qatar https://cybersigmacs.com/national-cyber-compliance-qatar/
[5] Qatar NIA (NCSA) — National Information Assurance Policy version https://cybersigmacs.com/compliance-registry/#qatar-nia

What are the penalties under the UAE PDPL and who enforces it?

The UAE PDPL establishes administrative penalties for violations [2]. The enforcement structure includes mechanisms for data subjects to file complaints with the UAE Data Office (Article 24) and for grievances against the Office's decisions to be addressed (Article 25). The law also provides for administrative penalties for violations (Article 26), though the specific nature and details of these penalties are not detailed within the provided context. The Executive Regulation to detail the law's implementation, including potential penalties, has not yet been issued [1].

For more detailed information on penalties and enforcement, refer to the official UAE Legislation portal for Federal Decree-Law 45/2021, specifically Articles 24-26 [1, 2].

5 verified sources
[1] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 24-28 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[2] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[3] UAE Legislation portal - Federal Decree-Law 45/2021, Articles 4-6 (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[4] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)
[5] UAE PDPL — Complaints, penalties and Executive Regulation (Articles 24-28) https://cybersigmacs.com/compliance-registry/#uae-pdpl-enforcement

Who must comply with the SAMA Cyber Security Framework?

The SAMA Cyber Security Framework must be complied with by all SAMA-regulated Member Organizations, including banks, insurance and reinsurance companies, financing companies, credit bureaus, and the Financial Market Infrastructure. [1]

5 verified sources
[1] SAMA Rulebook — Cyber Security Framework https://rulebook.sama.gov.sa/en/cyber-security-framework-2 (verified 2026-08-04)
[2] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] SAMA Cyber Security Framework — Complete Compliance Guide https://cybersigmacs.com/knowledge-center/sama-csf/

Who must comply with the Qatar National Information Assurance (NIA) framework?

The Qatar National Information Assurance (NIA) framework mandates compliance for government entities and critical infrastructure. This is stated in verified fact [1].

5 verified sources
[1] NCSA Qatar (official portal) https://ncsa.gov.qa/en/ (verified 2026-08-01)
[2] Qatar NIA — Complete National Information Assurance Guide https://cybersigmacs.com/knowledge-center/qatar-nia/
[3] Qatar NIA (NCSA) — National Information Assurance Policy version https://cybersigmacs.com/compliance-registry/#qatar-nia
[4] Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) https://www.rbi.org.in/ (verified 2026-08-01)
[5] UAE Information Assurance (NESA) — Complete Compliance Guide https://cybersigmacs.com/knowledge-center/uae-ia-nesa/

What is the Bahrain Personal Data Protection Law?

The Bahrain Personal Data Protection Law (Law No. 30 of 2018) is Bahrain's national data protection statute, enforced by the Personal Data Protection Authority established under the Ministry of Justice and Islamic Affairs. It applies to the processing of personal data of individuals in Bahrain by data managers and processors in the public or private sector. As a core rule, it prohibits processing personal data without the data subject's explicit consent except on specified legal grounds, and it restricts transferring personal data outside Bahrain unless an adequate level of protection or a specific authorisation exists. [1]

5 verified sources
[1] Kingdom of Bahrain, Personal Data Protection Authority - Law No. 30 of 2018 https://www.pdp.gov.bh/en/index.html (verified 2026-08-13)
[2] Bahrain PDPL — Bahrain Personal Data Protection Law (Law No. 30 of 2018) https://cybersigmacs.com/compliance-registry/#bahrain-pdpl
[3] Sultanate of Oman, MTCIT - Royal Decree 6/2022 Personal Data Protection Law https://mtcit.gov.om/sectors/governance/personal (verified 2026-08-13)
[4] Personal Data Protection Commission (PDPC) Singapore - PDPA https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act (verified 2026-08-13)
[5] UAE Legislation portal - Federal Decree-Law on Protection of Personal Data (official) https://uaelegislation.gov.ae/en/legislations/1972 (verified 2026-08-11)

What is the Oman Personal Data Protection Law?

The Oman Personal Data Protection Law, promulgated by Royal Decree 6/2022, is Oman's national data protection statute. It is enforced by the Ministry of Transport, Communications and Information Technology. This law governs the processing of personal data and grants data owners rights including consent, withdrawal of consent, correction, and deletion. Controllers and processors are subject to certain obligations under this law. The law consists of 32 articles spread across five chapters and requires the data owner's consent before processing personal data. An Executive Regulation supporting the law is expected to be issued in 2024. [1]

5 verified sources
[1] Sultanate of Oman, MTCIT - Royal Decree 6/2022 Personal Data Protection Law https://mtcit.gov.om/sectors/governance/personal (verified 2026-08-13)
[2] Kingdom of Bahrain, Personal Data Protection Authority - Law No. 30 of 2018 https://www.pdp.gov.bh/en/index.html (verified 2026-08-13)
[3] Oman PDPL — Oman Personal Data Protection Law (Royal Decree 6/2022) https://cybersigmacs.com/compliance-registry/#oman-pdpl
[4] Bahrain PDPL — Bahrain Personal Data Protection Law (Law No. 30 of 2018) https://cybersigmacs.com/compliance-registry/#bahrain-pdpl
[5] Personal Data Protection Commission (PDPC) Singapore - PDPA https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act (verified 2026-08-13)

Other frameworks

See our services

What are the key control domains of the Saudi NCA Essential Cybersecurity Controls (ECC)?

The key control domains of the Saudi NCA Essential Cybersecurity Controls (ECC) are:

1. Cybersecurity Governance

2. Cybersecurity Defense

3. Cybersecurity Resilience

4. Third-Party and Cloud Computing Cybersecurity [2]

5 verified sources
[1] NCA — Essential Cybersecurity Controls ECC – 2 : 2024 (English) https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[2] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Figures 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[3] NCA - ECC-2:2024 (English), Cybersecurity Governance controls 1-1 and 1-2 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[4] NCA - ECC-2:2024 (English), Figures 3-4 and Table 1 https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)
[5] NCA - Essential Cybersecurity Controls ECC - 2 : 2024 (English), Implementation and Compliance section https://cdn.nca.gov.sa/api/files/public/upload/86e09090-44e4-481f-bc28-355673607654_ECC--2024-EN.pdf (verified 2026-08-11)

What is TISAX in the automotive industry?

TISAX (Trusted Information Security Assessment Exchange) is an assessment and results-exchange mechanism for information security governed by the ENX Association on behalf of the German automotive industry association VDA. Vehicle manufacturers, suppliers, and service providers use it to demonstrate and mutually recognize information security across the automotive supply chain, avoiding duplicate audits. Assessments are performed by ENX-approved audit providers against the VDA Information Security Assessment (ISA) catalogue, which is based on key aspects of ISO/IEC 27001, and the resulting labels are valid for three years. [1][2][3]

5 verified sources
[1] ENX Association - TISAX https://enx.com/en-US/TISAX/ (verified 2026-08-13)
[2] TISAX — Automotive information security assessment and exchange https://cybersigmacs.com/compliance-registry/#tisax
[3] TISAX — Complete Automotive Information Security Assessment Guide https://cybersigmacs.com/knowledge-center/tisax/
[4] ISO/SAE 21434 & UNECE R155 — Complete Automotive Cybersecurity Guide https://cybersigmacs.com/knowledge-center/iso-21434-automotive/
[5] ISO 31000:2018 - Risk management (ISO) https://www.iso.org/standard/65694.html (verified 2026-08-13)

Have a question that isn’t here?

Ask our Compliance Assistant for a cited answer, or talk to a CERT-In empanelled, PCI QSA senior consultant.

Talk to an expert

Informational only, grounded on our verified registry and current as of each source’s last-verified date — not legal advice. Confirm against the primary source for your specific situation.