25 security obligations on Indian IT & SaaS firms, and where each comes from
Indian law and regulators, what your regulated clients push down to you, what buyers demand, and foreign law that reaches you. Every card carries its source and the date we checked it.
- 25obligations, in four groups
- 7carry a reporting clock
- 21dated milestones, 2025–2027
- 11read from the primary text
The deadlines still ahead
From today, in order. Everything already in force is folded underneath. Click one to open its card.
Already in force — 16 milestones since 17 Jan 2025
Showing 25 of 25
Indian law & regulators
9What binds every Indian firm in this industry, or every firm doing a particular kind of work.
CERT-In Directions under section 70B(6), 28 April 2022
6 hoursAlways. The Directions bind every “body corporate”, which is every Indian IT, ITES and software company.
CERT-In Directions under section 70B(6), 28 April 2022
6 hoursAlways. The Directions bind every “body corporate”, which is every Indian IT, ITES and software company.
Who it reaches
Status
What it requires
- Report any of 20 listed incident types — ransomware, data breach, cloud and identity attacks among them — within six hours of noticing it.
- Keep logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand.
- Synchronise clocks to NIC or NPL NTP, or a source traceable to them.
- Register a point of contact with CERT-In.
The clock
What people get wrong
The duty cannot be handed to your client by contract. CERT-In's own FAQ: “Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with.” And logs may sit outside India, provided they can be produced in reasonable time (FAQ Q35).
The controls it drives
CERT-In (MeitY). Source: CERT-In Directions and FAQ (May 2022). Read from the primary text, verified 2026-10-05.
Digital Personal Data Protection Act 2023 and DPDP Rules 2025
72 hoursAlways — you are a Data Fiduciary for your own employees’ data even where you are only a processor for clients. A SaaS firm is a fiduciary for its own account holders and usually a processor for what customers load into the product.
Digital Personal Data Protection Act 2023 and DPDP Rules 2025
72 hoursAlways — you are a Data Fiduciary for your own employees’ data even where you are only a processor for clients. A SaaS firm is a fiduciary for its own account holders and usually a processor for what customers load into the product.
Who it reaches
Status
What it requires
- Reasonable security safeguards: encryption, masking or tokenisation; access control; logging and review of access to personal data; backups (Rule 6).
- Keep logs of processing for at least one year — longer than CERT-In’s 180 days — including processing done by a Data Processor (Rules 6 and 8).
- Tell the Board without delay, with a detailed report within 72 hours; tell affected people without delay (Rule 7).
- Bind every processor by a contract that carries security safeguards (section 8, Rule 6).
The clock
What people get wrong
Penalties — up to ₹250 crore for failing to keep safeguards — fall on the Data Fiduciary, not the processor; processors are bound through the contract. Offshore delivery has a carve-out: section 17(1)(d) disapplies most of the Act when an Indian firm processes non-residents’ data under a foreign contract, but the section 8(5) duty to keep reasonable security safeguards still applies.
The controls it drives
Parliament; Rules by MeitY. Source: DPDP Rules 2025, G.S.R. 846(E). Read from the primary text, verified 2026-10-05.
IT Act section 43A and the SPDI Rules 2011
Always, until the DPDP Act replaces it.
IT Act section 43A and the SPDI Rules 2011
Always, until the DPDP Act replaces it.
Who it reaches
Status
What it requires
- A documented information-security programme; ISO/IEC 27001 is the standard the Rules name as recognised.
The controls it drives
MeitY. Source: DPDP commencement, G.S.R. 843(E) (via ICAI and taxmann). Two or more reputable secondary sources, verified 2026-10-05.
Companies (Accounts) Rules 2014 — electronic books of account
Always — every Indian company.
Companies (Accounts) Rules 2014 — electronic books of account
Always — every Indian company.
Who it reaches
Status
What it requires
- Back up electronic books of account daily, on servers physically located in India.
- Disclose the cloud or service provider’s name and location to the Registrar annually.
The controls it drives
Ministry of Corporate Affairs. Source: Companies (Accounts) Amendment Rules 2022 (via AZB, Grant Thornton). Two or more reputable secondary sources, verified 2026-10-05.
CERT-In Comprehensive Cyber Security Audit Policy Guidelines v1.0
When a regulator, a government contract or a client asks for a CERT-In-empanelled audit — which regulated clients increasingly do.
CERT-In Comprehensive Cyber Security Audit Policy Guidelines v1.0
When a regulator, a government contract or a client asks for a CERT-In-empanelled audit — which regulated clients increasingly do.
Who it reaches
Status
What it requires
- A comprehensive audit of all ICT systems at least once a year, by a CERT-In-empanelled auditor.
- Vulnerability assessment and penetration testing in scope, and third-party and supply-chain risk.
What people get wrong
Not a statutory mandate for every private company — don’t let anyone sell it to you as one.
The controls it drives
CERT-In. Source: CERT-In audit guidelines, 25 July 2025. Read from the primary text, verified 2026-10-05.
CERT-In technical guidelines on SBOM, CBOM, AIBOM and HBOM v2.0
ProductIf you build software — guidance aimed squarely at software-export and software-services organisations.
CERT-In technical guidelines on SBOM, CBOM, AIBOM and HBOM v2.0
ProductIf you build software — guidance aimed squarely at software-export and software-services organisations.
Who it reaches
Status
What it requires
- A software bill of materials for what you ship; a cryptographic BOM for post-quantum readiness; an AI BOM for model provenance.
What people get wrong
Advisory, not mandatory, on its own. Your SEBI-regulated customers will still ask for the SBOM.
The controls it drives
CERT-In. Source: CERT-In BOM guidelines (via Khaitan, AZB). Two or more reputable secondary sources, verified 2026-10-05.
DoT Other Service Provider guidelines (2020, revised 2021)
ServicesVoice-based BPOs and contact centres only. Non-voice ITES left the regime in 2020.
DoT Other Service Provider guidelines (2020, revised 2021)
ServicesVoice-based BPOs and contact centres only. Non-voice ITES left the regime in 2020.
Who it reaches
Status
What it requires
- Keep call-detail records, usage data and system logs for voice traffic for one year — with a copy in India where the EPABX sits abroad.
- Keep remote-agent activity logs for one year.
What people get wrong
OSP registration no longer exists. Anyone asking you for an OSP certificate is working from 2019.
The controls it drives
Department of Telecommunications. Source: PIB, 23 June 2021. Read from the primary text, verified 2026-10-05.
SEZ Rules 2006, Rule 43A — work from home for IT/ITES units
ServicesIT/ITES units in a Special Economic Zone letting staff work from home.
SEZ Rules 2006, Rule 43A — work from home for IT/ITES units
ServicesIT/ITES units in a Special Economic Zone letting staff work from home.
Who it reaches
Status
What it requires
- “SEZ Units will provide equipment and secured connectivity for the purpose of WFH to an employee.”
The controls it drives
Department of Commerce. Source: SEZ (Amendment) Rules 2022 (via EY, AZB). Two or more reputable secondary sources, verified 2026-10-05.
MeitY cloud empanelment and Guidelines for Procurement of Cloud Services
ProductIf you sell SaaS to Indian government departments (or resell cloud to them as an MSP or SI).
MeitY cloud empanelment and Guidelines for Procurement of Cloud Services
ProductIf you sell SaaS to Indian government departments (or resell cloud to them as an MSP or SI).
Who it reaches
Status
What it requires
- Offer the service only from STQC-audited data centres, with all data processing inside India.
- Encryption at rest, in transit and in processing; data-loss prevention; directory integration and role-based access; ISO/IEC 27018.
The controls it drives
MeitY. Source: MeitY Guidelines for Procurement of Cloud Services. Read from the primary text, verified 2026-10-05.
Via your regulated clients
4Rules that bind your bank, insurer or market client — and reach you through the contract they must sign with you.
RBI Managing Risks in Outsourcing Directions 2025
6 hoursIf a bank or NBFC is your client. It replaced the 2023 IT-outsourcing Master Direction on 28 November 2025, issued separately for each type of regulated entity.
RBI Managing Risks in Outsourcing Directions 2025
6 hoursIf a bank or NBFC is your client. It replaced the 2023 IT-outsourcing Master Direction on 28 November 2025, issued separately for each type of regulated entity.
Who it reaches
Status
What it requires
- Report cyber incidents to the bank without undue delay, so the bank can report to the RBI within six hours of detection by you (para 56).
- Accept audit and inspection — by the bank and by the RBI — of you and your subcontractors (para 69).
- Keep the bank’s data separated and isolated, accessible only to people the bank authorises (para 65).
- Store data only in India where regulation requires it; for an outsourced SOC, the bank keeps ownership of rules, logs and analytics (para 90).
The clock
What people get wrong
Most vendor contracts still cite the April 2023 Master Direction. It has been repealed — the 2025 Directions are the ones your client is now inspected against.
The controls it drives
Reserve Bank of India. Source: RBI (Commercial Banks – Managing Risks in Outsourcing) Directions 2025. Read from the primary text, verified 2026-10-05.
RBI Master Direction: Storage of Payment System Data
If you process for a payment system operator — as a vendor, gateway or SaaS.
RBI Master Direction: Storage of Payment System Data
If you process for a payment system operator — as a vendor, gateway or SaaS.
Who it reaches
Status
What it requires
- Store the entire data relating to payment systems only in India — this explicitly covers third-party vendors.
- A system audit report by a CERT-In-empanelled auditor.
The controls it drives
Reserve Bank of India. Source: RBI Master Direction RBI/2017-18/153. Read from the primary text, verified 2026-10-05.
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)
If a broker, AMC, depository, exchange or other SEBI-regulated entity is your client or customer.
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)
If a broker, AMC, depository, exchange or other SEBI-regulated entity is your client or customer.
Who it reaches
Status
What it requires
- Follow “similar or higher” security standards to your regulated client (FAQ 40).
- ISO/IEC 27001 certification if you run their outsourced data centre, DR or SOC (FAQ 58).
- An SBOM for any software used in core or critical activities (FAQs 35–37).
- Encryption keys and key management kept inside India (FAQ 26); VAPT closure timelines in the SLA.
The controls it drives
SEBI. Source: SEBI CSCRF FAQs, June 2025. Read from the primary text, verified 2026-10-05.
IRDAI Information and Cybersecurity Guidelines 2026
If an insurer, broker or TPA is your client — claims and policy-servicing BPOs especially, and insurtech SaaS.
IRDAI Information and Cybersecurity Guidelines 2026
If an insurer, broker or TPA is your client — claims and policy-servicing BPOs especially, and insurtech SaaS.
Who it reaches
Status
What it requires
- The 2023 edition required reporting cyber incidents to IRDAI within six hours, ICT logs and critical data kept in India for intermediaries, and audit, access and exit rights over outsourced vendors.
- Expect the same or stricter in your insurer client’s contract — and confirm against the 2026 Guidelines before relying on any detail.
What people get wrong
Contracts drafted before April 2026 cite the 2023 Guidelines, which have been replaced.
The controls it drives
IRDAI. Source: IRDAI Guidelines, 6 April 2026. Two or more reputable secondary sources, verified 2026-10-05.
What buyers demand
5Certifications and agreements that are not law, but without which the deal does not close.
ISO/IEC 27001:2022
Practically always — the baseline ask in nearly every RFP, from either side of the industry.
ISO/IEC 27001:2022
Practically always — the baseline ask in nearly every RFP, from either side of the industry.
Who it reaches
Status
What it requires
- An information-security management system, with the evidence an external auditor can test.
What people get wrong
If your certificate still says 27001:2013, you are not certified — the auditor treats you as a new client.
The controls it drives
ISO/IEC. Source: IAF MD 26 transition (via certification bodies). Two or more reputable secondary sources, verified 2026-10-05.
SOC 2 Type I and Type II
If you sell to US companies. For a SaaS firm it is the de facto enterprise sales gate; MSPs and BPOs with US clients get asked too.
SOC 2 Type I and Type II
If you sell to US companies. For a SaaS firm it is the de facto enterprise sales gate; MSPs and BPOs with US clients get asked too.
Who it reaches
Status
What it requires
- Controls over access, change, logging and monitoring, vendors, incident response and backup — tested over time for Type II.
The controls it drives
AICPA. Source: AICPA Trust Services Criteria. Two or more reputable secondary sources, verified 2026-10-05.
PCI DSS v4.0.1
If you take, see or store card data — voice-payment BPOs, service providers to merchants, payments SaaS.
PCI DSS v4.0.1
If you take, see or store card data — voice-payment BPOs, service providers to merchants, payments SaaS.
Who it reaches
Status
What it requires
- Multi-factor authentication for all access into the cardholder data environment.
- Integrity monitoring of scripts on payment pages (6.4.3, 11.6.1).
- Authenticated internal vulnerability scanning; DTMF masking or pause-and-resume for card details taken by phone.
The controls it drives
PCI Security Standards Council. Source: PCI DSS v4.0.1 (via QSAs). Two or more reputable secondary sources, verified 2026-10-05.
HIPAA Business Associate obligations
≤ 60 daysIf you handle US patient data — medical coding, revenue-cycle management, transcription, health SaaS. You are a business associate, bound by the agreement and directly by the Security Rule.
HIPAA Business Associate obligations
≤ 60 daysIf you handle US patient data — medical coding, revenue-cycle management, transcription, health SaaS. You are a business associate, bound by the agreement and directly by the Security Rule.
Who it reaches
Status
What it requires
- Security Rule safeguards: risk analysis, access control, audit controls, integrity and transmission security.
- Notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days after discovery.
The clock
The controls it drives
US HHS. Source: 45 CFR 164.410. Read from the primary text, verified 2026-10-05.
ISO/IEC 42001:2023 — AI management system
If you ship AI features or deliver AI work for clients, especially into the EU.
ISO/IEC 42001:2023 — AI management system
If you ship AI features or deliver AI work for clients, especially into the EU.
Who it reaches
Status
What it requires
- A management system for how you develop, provide and use AI — risk, data, oversight, monitoring.
The controls it drives
ISO/IEC. Source: ISO/IEC 42001:2023. Two or more reputable secondary sources, verified 2026-10-05.
Foreign law that reaches you
7EU, UK and US rules that apply to Indian firms through the clients or customers they serve there.
EU GDPR (Articles 28, 32, 33) and UK GDPR
Without undue delayIf you process EU or UK personal data — as a processor for clients, or as a controller offering services to people there.
EU GDPR (Articles 28, 32, 33) and UK GDPR
Without undue delayIf you process EU or UK personal data — as a processor for clients, or as a controller offering services to people there.
Who it reaches
Status
What it requires
- Processor contract terms: documented instructions, Article 32 security, sub-processor approval, audits.
- As a processor, notify the controller of a breach without undue delay; the controller has 72 hours to tell the authority.
The clock
The controls it drives
EU; UK. Source: Regulation (EU) 2016/679; Decision (EU) 2021/914. Two or more reputable secondary sources, verified 2026-10-05.
EU NIS2 Directive (2022/2555)
24 hoursThrough your EU clients’ supply-chain duties — and directly if you are a managed service, managed security or cloud provider serving the EU, which may need an EU representative (Article 26(3)).
EU NIS2 Directive (2022/2555)
24 hoursThrough your EU clients’ supply-chain duties — and directly if you are a managed service, managed security or cloud provider serving the EU, which may need an EU representative (Article 26(3)).
Who it reaches
Status
What it requires
- Supply-chain security clauses, questionnaires and audits from in-scope EU clients (Article 21(2)(d)).
- For in-scope entities: a 24-hour early warning, a 72-hour notification and a one-month final report.
The clock
The controls it drives
European Union. Source: Directive (EU) 2022/2555. Two or more reputable secondary sources, verified 2026-10-05.
EU Digital Operational Resilience Act (DORA)
ServicesIf an EU bank, insurer or investment firm is your client.
EU Digital Operational Resilience Act (DORA)
ServicesIf an EU bank, insurer or investment firm is your client.
Who it reaches
Status
What it requires
- Article 30 contract terms: audit and access rights, incident assistance, exit plans, and taking part in threat-led penetration testing.
The controls it drives
European Union. Source: Regulation (EU) 2022/2554; EBA press release, 18 Nov 2025. Two or more reputable secondary sources, verified 2026-10-05.
EU Cyber Resilience Act (2024/2847)
Product24 hoursIf you sell installable software — desktop, on-premise, mobile apps, agents — in the EU. Pure SaaS is generally outside it (NIS2 covers that).
EU Cyber Resilience Act (2024/2847)
Product24 hoursIf you sell installable software — desktop, on-premise, mobile apps, agents — in the EU. Pure SaaS is generally outside it (NIS2 covers that).
Who it reaches
Status
What it requires
- Report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification, then a final report.
- From December 2027: an SBOM, vulnerability handling for the support period, and security by design.
The clock
What people get wrong
The headline date most people quote is 2027. The reporting clock started in September 2026.
The controls it drives
European Union. Source: European Commission — CRA reporting. Read from the primary text, verified 2026-10-05.
EU AI Act, as amended by the Digital Omnibus on AI
ProductIf you place AI systems on the EU market, or build them for EU clients.
EU AI Act, as amended by the Digital Omnibus on AI
ProductIf you place AI systems on the EU market, or build them for EU clients.
Who it reaches
Status
What it requires
- AI governance, logging and human oversight; labelling of AI-generated content.
The controls it drives
European Union. Source: Digital Omnibus agreement (via Gibson Dunn). Two or more reputable secondary sources, verified 2026-10-05.
US federal secure-software attestation (OMB M-26-05)
ProductIf you sell software to US federal agencies or their prime contractors.
US federal secure-software attestation (OMB M-26-05)
ProductIf you sell software to US federal agencies or their prime contractors.
Who it reaches
Status
What it requires
- Whatever the agency asks for — often an SBOM or the (now optional) secure-development attestation.
What people get wrong
Do not let a consultant sell you the attestation as mandatory. It has not been since January 2026.
The controls it drives
US Office of Management and Budget. Source: OMB M-26-05. Read from the primary text, verified 2026-10-05.
US DoD CMMC 2.0
ServicesIf you do engineering or IT work in the US defence supply chain and handle controlled unclassified information.
US DoD CMMC 2.0
ServicesIf you do engineering or IT work in the US defence supply chain and handle controlled unclassified information.
Who it reaches
Status
What it requires
- The NIST SP 800-171 controls, assessed by an accredited third party at Level 2.
The controls it drives
US Department of Defense. Source: DFARS CMMC final rule (via GRF CPA). Two or more reputable secondary sources, verified 2026-10-05.
14 things the market gets wrong
Each of these circulates in vendor decks, contracts or commentary. Each was checked against the source.
- “Your client reports the incident, not you.”CERT-In says whoever notices it reports it, and the duty cannot be contracted away.
- “DPDP is in force now.”Only the Board is. The operational duties start on 13 May 2027; a proposal to bring that forward has not been notified.
- “Processors face DPDP penalties directly.”The penalty schedule targets Data Fiduciaries. Processors are bound through the contract.
- “CERT-In logs must physically stay in India.”CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time. RBI, IRDAI and SEBI clients can be stricter.
- “Our contracts follow the RBI’s 2023 IT-outsourcing Master Direction.”It was repealed on 28 November 2025. The Managing Risks in Outsourcing Directions 2025 replaced it.
- “Our insurer clients follow IRDAI’s 2023 cyber guidelines.”IRDAI reissued them on 6 April 2026, replacing the 2023 edition.
- “The EU Cyber Resilience Act starts in 2027.”Its reporting clock started on 11 September 2026. 2027 is full application.
- “CRA covers our SaaS.”Pure SaaS is generally outside the CRA; NIS2 is the law that reaches it.
- “The US secure-software attestation is mandatory.”OMB rescinded the mandate on 23 January 2026.
- “We still need OSP registration.”Abolished on 5 November 2020. Voice BPOs keep one-year call-record and remote-agent log duties.
- “STPI units have their own cyber rules.”We found no STPI-specific cybersecurity mandate.
- “CERT-In’s SBOM guidelines are mandatory.”They are advisory. SEBI’s CSCRF is what makes an SBOM mandatory for regulated buyers.
- “Our ISO 27001:2013 certificate is fine.”The 2013 edition’s transition ended on 31 October 2025.
- “The Digital India Act is coming into force.”No draft bill has been published. It is not law.
Compiled and verified by TechBag research. General information, not legal advice — confirm applicability and current status with your counsel. If we have read something wrongly, write to info@thetechbag.com.
IT & ITES obligations, answered
Short answers, each backed by the sources on this page.
Which obligations bind every Indian IT and ITES company?
The CERT-In Directions (report incidents within six hours, keep 180 days of logs, sync clocks to NIC or NPL time); the DPDP Act, whose operational duties apply from 13 May 2027; IT Act section 43A until then; and the Companies Act rule to back up electronic books daily to servers in India.
Has the RBI's 2023 IT outsourcing Master Direction been replaced?
Yes. The Managing Risks in Outsourcing Directions 2025 replaced it on 28 November 2025, issued separately for each type of regulated entity. Existing agreements had to comply at renewal or by 10 April 2026, and a vendor must report incidents so the bank can tell the RBI within six hours of the vendor's detection.
Do voice BPOs still need OSP registration?
No. OSP registration was abolished on 5 November 2020 and the regime liberalised again on 23 June 2021; non-voice ITES left it in 2020. No restatement under the Telecommunications Act 2023 has been published.
Is a CERT-In-empanelled security audit mandatory for IT companies?
Not by law. CERT-In's audit policy guidelines of 25 July 2025 are guidance: they take force when a regulator, a government contract or a client requires them, which regulated clients increasingly do. They ask for a comprehensive audit of all ICT systems at least once a year.
Does DORA apply to Indian IT companies?
Through EU financial clients. DORA has applied since 17 January 2025, and EU banks, insurers and investment firms must write audit, exit and testing terms into their ICT contracts. The EU's first list of critical ICT third-party providers, of 18 November 2025, includes Tata Consultancy Services.
Is the US secure-software attestation still mandatory?
No. The mandatory attestation was rescinded on 23 January 2026. US agencies now set their own requirements and may still ask for an SBOM.