25 security obligations on Indian IT & SaaS firms, and where each comes from

Indian law and regulators, what your regulated clients push down to you, what buyers demand, and foreign law that reaches you. Every card carries its source and the date we checked it.

  • 25obligations, in four groups
  • 7carry a reporting clock
  • 21dated milestones, 2025–2027
  • 11read from the primary text
What’s coming

The deadlines still ahead

From today, in order. Everything already in force is folded underneath. Click one to open its card.

Today · 5 Oct 2026
Already in force — 16 milestones since 17 Jan 2025
For

Showing 25 of 25

Indian law & regulators

9

What binds every Indian firm in this industry, or every firm doing a particular kind of work.

CERT-In Directions under section 70B(6), 28 April 2022

6 hours

Always. The Directions bind every “body corporate”, which is every Indian IT, ITES and software company.

Who it reaches

Always. The Directions bind every “body corporate”, which is every Indian IT, ITES and software company.

Status

In force since June 2022 (September 2022 for MSMEs).

What it requires

  • Report any of 20 listed incident types — ransomware, data breach, cloud and identity attacks among them — within six hours of noticing it.
  • Keep logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand.
  • Synchronise clocks to NIC or NPL NTP, or a source traceable to them.
  • Register a point of contact with CERT-In.

The clock

6 hours from the moment you notice it, to CERT-In.

What people get wrong

The duty cannot be handed to your client by contract. CERT-In's own FAQ: “Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with.” And logs may sit outside India, provided they can be produced in reasonable time (FAQ Q35).

CERT-In (MeitY). Source: CERT-In Directions and FAQ (May 2022). Read from the primary text, verified 2026-10-05.

Digital Personal Data Protection Act 2023 and DPDP Rules 2025

72 hours

Always — you are a Data Fiduciary for your own employees’ data even where you are only a processor for clients. A SaaS firm is a fiduciary for its own account holders and usually a processor for what customers load into the product.

Who it reaches

Always — you are a Data Fiduciary for your own employees’ data even where you are only a processor for clients. A SaaS firm is a fiduciary for its own account holders and usually a processor for what customers load into the product.

Status

Rules notified 13 November 2025. Data Protection Board live; Consent Managers from November 2026; the operational duties from 13 May 2027. A proposal to bring that forward was consulted on in early 2026 but has not been notified.

What it requires

  • Reasonable security safeguards: encryption, masking or tokenisation; access control; logging and review of access to personal data; backups (Rule 6).
  • Keep logs of processing for at least one year — longer than CERT-In’s 180 days — including processing done by a Data Processor (Rules 6 and 8).
  • Tell the Board without delay, with a detailed report within 72 hours; tell affected people without delay (Rule 7).
  • Bind every processor by a contract that carries security safeguards (section 8, Rule 6).

The clock

72 hours from a personal-data breach (from May 2027), to the Data Protection Board.

What people get wrong

Penalties — up to ₹250 crore for failing to keep safeguards — fall on the Data Fiduciary, not the processor; processors are bound through the contract. Offshore delivery has a carve-out: section 17(1)(d) disapplies most of the Act when an Indian firm processes non-residents’ data under a foreign contract, but the section 8(5) duty to keep reasonable security safeguards still applies.

Parliament; Rules by MeitY. Source: DPDP Rules 2025, G.S.R. 846(E). Read from the primary text, verified 2026-10-05.

IT Act section 43A and the SPDI Rules 2011

Always, until the DPDP Act replaces it.

Who it reaches

Always, until the DPDP Act replaces it.

Status

Still in force. The DPDP Act omits section 43A, but that provision only commences with the operational duties on 13 May 2027.

What it requires

  • A documented information-security programme; ISO/IEC 27001 is the standard the Rules name as recognised.

The controls it drives

MeitY. Source: DPDP commencement, G.S.R. 843(E) (via ICAI and taxmann). Two or more reputable secondary sources, verified 2026-10-05.

Companies (Accounts) Rules 2014 — electronic books of account

Always — every Indian company.

Who it reaches

Always — every Indian company.

Status

Daily-backup amendment in force since 5 August 2022.

What it requires

  • Back up electronic books of account daily, on servers physically located in India.
  • Disclose the cloud or service provider’s name and location to the Registrar annually.

The controls it drives

Ministry of Corporate Affairs. Source: Companies (Accounts) Amendment Rules 2022 (via AZB, Grant Thornton). Two or more reputable secondary sources, verified 2026-10-05.

CERT-In Comprehensive Cyber Security Audit Policy Guidelines v1.0

When a regulator, a government contract or a client asks for a CERT-In-empanelled audit — which regulated clients increasingly do.

Who it reaches

When a regulator, a government contract or a client asks for a CERT-In-empanelled audit — which regulated clients increasingly do.

Status

Issued 25 July 2025. A guideline: its force comes from whoever requires it.

What it requires

  • A comprehensive audit of all ICT systems at least once a year, by a CERT-In-empanelled auditor.
  • Vulnerability assessment and penetration testing in scope, and third-party and supply-chain risk.

What people get wrong

Not a statutory mandate for every private company — don’t let anyone sell it to you as one.

CERT-In. Source: CERT-In audit guidelines, 25 July 2025. Read from the primary text, verified 2026-10-05.

CERT-In technical guidelines on SBOM, CBOM, AIBOM and HBOM v2.0

Product

If you build software — guidance aimed squarely at software-export and software-services organisations.

Who it reaches

If you build software — guidance aimed squarely at software-export and software-services organisations.

Status

v1.0 October 2024; v2.0 9 July 2025. Advisory — sectoral rules (SEBI’s CSCRF) make SBOMs mandatory for regulated buyers.

What it requires

  • A software bill of materials for what you ship; a cryptographic BOM for post-quantum readiness; an AI BOM for model provenance.

What people get wrong

Advisory, not mandatory, on its own. Your SEBI-regulated customers will still ask for the SBOM.

The controls it drives

CERT-In. Source: CERT-In BOM guidelines (via Khaitan, AZB). Two or more reputable secondary sources, verified 2026-10-05.

DoT Other Service Provider guidelines (2020, revised 2021)

Services

Voice-based BPOs and contact centres only. Non-voice ITES left the regime in 2020.

Who it reaches

Voice-based BPOs and contact centres only. Non-voice ITES left the regime in 2020.

Status

Registration abolished 5 November 2020; liberalised again 23 June 2021. No restatement under the Telecommunications Act 2023 has been published.

What it requires

  • Keep call-detail records, usage data and system logs for voice traffic for one year — with a copy in India where the EPABX sits abroad.
  • Keep remote-agent activity logs for one year.

What people get wrong

OSP registration no longer exists. Anyone asking you for an OSP certificate is working from 2019.

Department of Telecommunications. Source: PIB, 23 June 2021. Read from the primary text, verified 2026-10-05.

SEZ Rules 2006, Rule 43A — work from home for IT/ITES units

Services

IT/ITES units in a Special Economic Zone letting staff work from home.

Who it reaches

IT/ITES units in a Special Economic Zone letting staff work from home.

Status

Inserted 14 July 2022. Up to 50% of employees, contract staff included, with one-year approvals.

What it requires

  • “SEZ Units will provide equipment and secured connectivity for the purpose of WFH to an employee.”

Department of Commerce. Source: SEZ (Amendment) Rules 2022 (via EY, AZB). Two or more reputable secondary sources, verified 2026-10-05.

MeitY cloud empanelment and Guidelines for Procurement of Cloud Services

Product

If you sell SaaS to Indian government departments (or resell cloud to them as an MSP or SI).

Who it reaches

If you sell SaaS to Indian government departments (or resell cloud to them as an MSP or SI).

Status

Current guidelines dated March 2026.

What it requires

  • Offer the service only from STQC-audited data centres, with all data processing inside India.
  • Encryption at rest, in transit and in processing; data-loss prevention; directory integration and role-based access; ISO/IEC 27018.

MeitY. Source: MeitY Guidelines for Procurement of Cloud Services. Read from the primary text, verified 2026-10-05.

Via your regulated clients

4

Rules that bind your bank, insurer or market client — and reach you through the contract they must sign with you.

RBI Managing Risks in Outsourcing Directions 2025

6 hours

If a bank or NBFC is your client. It replaced the 2023 IT-outsourcing Master Direction on 28 November 2025, issued separately for each type of regulated entity.

Who it reaches

If a bank or NBFC is your client. It replaced the 2023 IT-outsourcing Master Direction on 28 November 2025, issued separately for each type of regulated entity.

Status

In force. Existing agreements had to comply at renewal or by 10 April 2026, whichever came first.

What it requires

  • Report cyber incidents to the bank without undue delay, so the bank can report to the RBI within six hours of detection by you (para 56).
  • Accept audit and inspection — by the bank and by the RBI — of you and your subcontractors (para 69).
  • Keep the bank’s data separated and isolated, accessible only to people the bank authorises (para 65).
  • Store data only in India where regulation requires it; for an outsourced SOC, the bank keeps ownership of rules, logs and analytics (para 90).

The clock

6 hours from detection by you, the service provider, to the RBI, via your bank client.

What people get wrong

Most vendor contracts still cite the April 2023 Master Direction. It has been repealed — the 2025 Directions are the ones your client is now inspected against.

Your client’s side of thisYour bank client’s own RBI cybersecurity Directions

Reserve Bank of India. Source: RBI (Commercial Banks – Managing Risks in Outsourcing) Directions 2025. Read from the primary text, verified 2026-10-05.

RBI Master Direction: Storage of Payment System Data

If you process for a payment system operator — as a vendor, gateway or SaaS.

Who it reaches

If you process for a payment system operator — as a vendor, gateway or SaaS.

Status

RBI/2017-18/153, 6 April 2018 — still listed by the RBI as a current Master Direction.

What it requires

  • Store the entire data relating to payment systems only in India — this explicitly covers third-party vendors.
  • A system audit report by a CERT-In-empanelled auditor.
Your client’s side of thisThe RBI side of the picture, in our BFSI guide

Reserve Bank of India. Source: RBI Master Direction RBI/2017-18/153. Read from the primary text, verified 2026-10-05.

SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)

If a broker, AMC, depository, exchange or other SEBI-regulated entity is your client or customer.

Who it reaches

If a broker, AMC, depository, exchange or other SEBI-regulated entity is your client or customer.

Status

Circular 20 August 2024; compliance extended to 31 August 2025 for most entities. Data localisation still under consultation.

What it requires

  • Follow “similar or higher” security standards to your regulated client (FAQ 40).
  • ISO/IEC 27001 certification if you run their outsourced data centre, DR or SOC (FAQ 58).
  • An SBOM for any software used in core or critical activities (FAQs 35–37).
  • Encryption keys and key management kept inside India (FAQ 26); VAPT closure timelines in the SLA.
Your client’s side of thisYour SEBI-regulated client’s CSCRF, in our BFSI guide

SEBI. Source: SEBI CSCRF FAQs, June 2025. Read from the primary text, verified 2026-10-05.

IRDAI Information and Cybersecurity Guidelines 2026

If an insurer, broker or TPA is your client — claims and policy-servicing BPOs especially, and insurtech SaaS.

Who it reaches

If an insurer, broker or TPA is your client — claims and policy-servicing BPOs especially, and insurtech SaaS.

Status

Reissued on 6 April 2026, replacing the 2023 edition. We have not been able to read the 2026 text itself, so what follows is the 2023 edition’s floor, not the full list.

What it requires

  • The 2023 edition required reporting cyber incidents to IRDAI within six hours, ICT logs and critical data kept in India for intermediaries, and audit, access and exit rights over outsourced vendors.
  • Expect the same or stricter in your insurer client’s contract — and confirm against the 2026 Guidelines before relying on any detail.

What people get wrong

Contracts drafted before April 2026 cite the 2023 Guidelines, which have been replaced.

Your client’s side of thisYour insurer client’s guidelines, in our BFSI guide

IRDAI. Source: IRDAI Guidelines, 6 April 2026. Two or more reputable secondary sources, verified 2026-10-05.

What buyers demand

5

Certifications and agreements that are not law, but without which the deal does not close.

ISO/IEC 27001:2022

Practically always — the baseline ask in nearly every RFP, from either side of the industry.

Who it reaches

Practically always — the baseline ask in nearly every RFP, from either side of the industry.

Status

The transition from the 2013 edition ended on 31 October 2025. A 2013 certificate has lapsed.

What it requires

  • An information-security management system, with the evidence an external auditor can test.

What people get wrong

If your certificate still says 27001:2013, you are not certified — the auditor treats you as a new client.

The controls it drives

ISO/IEC. Source: IAF MD 26 transition (via certification bodies). Two or more reputable secondary sources, verified 2026-10-05.

SOC 2 Type I and Type II

If you sell to US companies. For a SaaS firm it is the de facto enterprise sales gate; MSPs and BPOs with US clients get asked too.

Who it reaches

If you sell to US companies. For a SaaS firm it is the de facto enterprise sales gate; MSPs and BPOs with US clients get asked too.

Status

2017 Trust Services Criteria, points of focus revised 2022. Type II covers a period, usually 6–12 months.

What it requires

  • Controls over access, change, logging and monitoring, vendors, incident response and backup — tested over time for Type II.

AICPA. Source: AICPA Trust Services Criteria. Two or more reputable secondary sources, verified 2026-10-05.

PCI DSS v4.0.1

If you take, see or store card data — voice-payment BPOs, service providers to merchants, payments SaaS.

Who it reaches

If you take, see or store card data — voice-payment BPOs, service providers to merchants, payments SaaS.

Status

v4.0.1 published June 2024. The 51 future-dated requirements became mandatory on 31 March 2025.

What it requires

  • Multi-factor authentication for all access into the cardholder data environment.
  • Integrity monitoring of scripts on payment pages (6.4.3, 11.6.1).
  • Authenticated internal vulnerability scanning; DTMF masking or pause-and-resume for card details taken by phone.

PCI Security Standards Council. Source: PCI DSS v4.0.1 (via QSAs). Two or more reputable secondary sources, verified 2026-10-05.

HIPAA Business Associate obligations

≤ 60 days

If you handle US patient data — medical coding, revenue-cycle management, transcription, health SaaS. You are a business associate, bound by the agreement and directly by the Security Rule.

Who it reaches

If you handle US patient data — medical coding, revenue-cycle management, transcription, health SaaS. You are a business associate, bound by the agreement and directly by the Security Rule.

Status

In force. The proposed Security Rule overhaul (January 2025) has not been finalised.

What it requires

  • Security Rule safeguards: risk analysis, access control, audit controls, integrity and transmission security.
  • Notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days after discovery.

The clock

≤ 60 days from discovery of the breach, to your covered-entity client.

US HHS. Source: 45 CFR 164.410. Read from the primary text, verified 2026-10-05.

ISO/IEC 42001:2023 — AI management system

If you ship AI features or deliver AI work for clients, especially into the EU.

Who it reaches

If you ship AI features or deliver AI work for clients, especially into the EU.

Status

Published 18 December 2023. The evidence layer most buyers accept for AI governance.

What it requires

  • A management system for how you develop, provide and use AI — risk, data, oversight, monitoring.

The controls it drives

ISO/IEC. Source: ISO/IEC 42001:2023. Two or more reputable secondary sources, verified 2026-10-05.

Foreign law that reaches you

7

EU, UK and US rules that apply to Indian firms through the clients or customers they serve there.

EU GDPR (Articles 28, 32, 33) and UK GDPR

Without undue delay

If you process EU or UK personal data — as a processor for clients, or as a controller offering services to people there.

Who it reaches

If you process EU or UK personal data — as a processor for clients, or as a controller offering services to people there.

Status

In force. India has no EU adequacy decision, so transfers run on the 2021 Standard Contractual Clauses; the UK’s new transfer test applies from 5 February 2026.

What it requires

  • Processor contract terms: documented instructions, Article 32 security, sub-processor approval, audits.
  • As a processor, notify the controller of a breach without undue delay; the controller has 72 hours to tell the authority.

The clock

Without undue delay from becoming aware (processor → controller), to your client, the controller.

EU; UK. Source: Regulation (EU) 2016/679; Decision (EU) 2021/914. Two or more reputable secondary sources, verified 2026-10-05.

EU NIS2 Directive (2022/2555)

24 hours

Through your EU clients’ supply-chain duties — and directly if you are a managed service, managed security or cloud provider serving the EU, which may need an EU representative (Article 26(3)).

Who it reaches

Through your EU clients’ supply-chain duties — and directly if you are a managed service, managed security or cloud provider serving the EU, which may need an EU representative (Article 26(3)).

Status

Transposition deadline 17 October 2024; national laws still being completed in some member states.

What it requires

  • Supply-chain security clauses, questionnaires and audits from in-scope EU clients (Article 21(2)(d)).
  • For in-scope entities: a 24-hour early warning, a 72-hour notification and a one-month final report.

The clock

24 hours from becoming aware of a significant incident, to the national CSIRT (early warning).

European Union. Source: Directive (EU) 2022/2555. Two or more reputable secondary sources, verified 2026-10-05.

EU Digital Operational Resilience Act (DORA)

Services

If an EU bank, insurer or investment firm is your client.

Who it reaches

If an EU bank, insurer or investment firm is your client.

Status

Applies from 17 January 2025. The first list of critical ICT third-party providers (18 November 2025) includes Tata Consultancy Services.

What it requires

  • Article 30 contract terms: audit and access rights, incident assistance, exit plans, and taking part in threat-led penetration testing.

European Union. Source: Regulation (EU) 2022/2554; EBA press release, 18 Nov 2025. Two or more reputable secondary sources, verified 2026-10-05.

EU Cyber Resilience Act (2024/2847)

Product24 hours

If you sell installable software — desktop, on-premise, mobile apps, agents — in the EU. Pure SaaS is generally outside it (NIS2 covers that).

Who it reaches

If you sell installable software — desktop, on-premise, mobile apps, agents — in the EU. Pure SaaS is generally outside it (NIS2 covers that).

Status

Reporting obligations live since 11 September 2026. Full application, including SBOM and CE marking, from 11 December 2027.

What it requires

  • Report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification, then a final report.
  • From December 2027: an SBOM, vulnerability handling for the support period, and security by design.

The clock

24 hours from becoming aware of an actively exploited vulnerability, to ENISA’s single reporting platform.

What people get wrong

The headline date most people quote is 2027. The reporting clock started in September 2026.

European Union. Source: European Commission — CRA reporting. Read from the primary text, verified 2026-10-05.

EU AI Act, as amended by the Digital Omnibus on AI

Product

If you place AI systems on the EU market, or build them for EU clients.

Who it reaches

If you place AI systems on the EU market, or build them for EU clients.

Status

Transparency duties from 2 August 2026. High-risk obligations — recruitment, credit scoring and education among them — deferred to 2 December 2027.

What it requires

  • AI governance, logging and human oversight; labelling of AI-generated content.

The controls it drives

European Union. Source: Digital Omnibus agreement (via Gibson Dunn). Two or more reputable secondary sources, verified 2026-10-05.

US federal secure-software attestation (OMB M-26-05)

Product

If you sell software to US federal agencies or their prime contractors.

Who it reaches

If you sell software to US federal agencies or their prime contractors.

Status

The mandatory attestation was rescinded on 23 January 2026. Agencies now set their own requirements and may still ask for an SBOM.

What it requires

  • Whatever the agency asks for — often an SBOM or the (now optional) secure-development attestation.

What people get wrong

Do not let a consultant sell you the attestation as mandatory. It has not been since January 2026.

The controls it drives

US Office of Management and Budget. Source: OMB M-26-05. Read from the primary text, verified 2026-10-05.

US DoD CMMC 2.0

Services

If you do engineering or IT work in the US defence supply chain and handle controlled unclassified information.

Who it reaches

If you do engineering or IT work in the US defence supply chain and handle controlled unclassified information.

Status

Rule effective 10 November 2025; third-party Level 2 assessments in new contracts from 10 November 2026.

What it requires

  • The NIST SP 800-171 controls, assessed by an accredited third party at Level 2.

US Department of Defense. Source: DFARS CMMC final rule (via GRF CPA). Two or more reputable secondary sources, verified 2026-10-05.

14 things the market gets wrong

Each of these circulates in vendor decks, contracts or commentary. Each was checked against the source.

  • “Your client reports the incident, not you.”CERT-In says whoever notices it reports it, and the duty cannot be contracted away.
  • “DPDP is in force now.”Only the Board is. The operational duties start on 13 May 2027; a proposal to bring that forward has not been notified.
  • “Processors face DPDP penalties directly.”The penalty schedule targets Data Fiduciaries. Processors are bound through the contract.
  • “CERT-In logs must physically stay in India.”CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time. RBI, IRDAI and SEBI clients can be stricter.
  • “Our contracts follow the RBI’s 2023 IT-outsourcing Master Direction.”It was repealed on 28 November 2025. The Managing Risks in Outsourcing Directions 2025 replaced it.
  • “Our insurer clients follow IRDAI’s 2023 cyber guidelines.”IRDAI reissued them on 6 April 2026, replacing the 2023 edition.
  • “The EU Cyber Resilience Act starts in 2027.”Its reporting clock started on 11 September 2026. 2027 is full application.
  • “CRA covers our SaaS.”Pure SaaS is generally outside the CRA; NIS2 is the law that reaches it.
  • “The US secure-software attestation is mandatory.”OMB rescinded the mandate on 23 January 2026.
  • “We still need OSP registration.”Abolished on 5 November 2020. Voice BPOs keep one-year call-record and remote-agent log duties.
  • “STPI units have their own cyber rules.”We found no STPI-specific cybersecurity mandate.
  • “CERT-In’s SBOM guidelines are mandatory.”They are advisory. SEBI’s CSCRF is what makes an SBOM mandatory for regulated buyers.
  • “Our ISO 27001:2013 certificate is fine.”The 2013 edition’s transition ended on 31 October 2025.
  • “The Digital India Act is coming into force.”No draft bill has been published. It is not law.

Compiled and verified by TechBag research. General information, not legal advice — confirm applicability and current status with your counsel. If we have read something wrongly, write to info@thetechbag.com.

Questions people ask

IT & ITES obligations, answered

Short answers, each backed by the sources on this page.

Which obligations bind every Indian IT and ITES company?

The CERT-In Directions (report incidents within six hours, keep 180 days of logs, sync clocks to NIC or NPL time); the DPDP Act, whose operational duties apply from 13 May 2027; IT Act section 43A until then; and the Companies Act rule to back up electronic books daily to servers in India.

Has the RBI's 2023 IT outsourcing Master Direction been replaced?

Yes. The Managing Risks in Outsourcing Directions 2025 replaced it on 28 November 2025, issued separately for each type of regulated entity. Existing agreements had to comply at renewal or by 10 April 2026, and a vendor must report incidents so the bank can tell the RBI within six hours of the vendor's detection.

Do voice BPOs still need OSP registration?

No. OSP registration was abolished on 5 November 2020 and the regime liberalised again on 23 June 2021; non-voice ITES left it in 2020. No restatement under the Telecommunications Act 2023 has been published.

Is a CERT-In-empanelled security audit mandatory for IT companies?

Not by law. CERT-In's audit policy guidelines of 25 July 2025 are guidance: they take force when a regulator, a government contract or a client requires them, which regulated clients increasingly do. They ask for a comprehensive audit of all ICT systems at least once a year.

Does DORA apply to Indian IT companies?

Through EU financial clients. DORA has applied since 17 January 2025, and EU banks, insurers and investment firms must write audit, exit and testing terms into their ICT contracts. The EU's first list of critical ICT third-party providers, of 18 November 2025, includes Tata Consultancy Services.

Is the US secure-software attestation still mandatory?

No. The mandatory attestation was rescinded on 23 January 2026. US agencies now set their own requirements and may still ask for an SBOM.