
Evidence that can be re-run — not a report that gets filed
Threat models, risk registers and applicability assessments are generated by our own engine — traceable to the rule that produced them, and reproducible on demand. Fixed-fee engagements across two practices: India regulatory (CERT-In, DPDP Act) and medical device & IVD cybersecurity (EU MDR, IVDR, FDA §524B).
Why the evidence holds
A reviewer — a Notified Body, an auditor, an enterprise security team — is not assessing whether the work was done. They are assessing whether the evidence supports the claim. Reproducibility is what separates the two.
Reproducible.
The threat model, the risk register and the applicability assessment are generated, not written. Run them again against the same system and you get the same result, in the same order — so two revisions of a device can be diffed rather than re-argued.
Traceable.
Every threat records the rule that produced it and the component it fired on. “Why is this in my report?” always has a mechanical answer, and the scores are engine output rather than a view we formed.
Judgement stays yours.
Clinical severity and residual-risk acceptability are decisions only you can make, under ISO 14971. We propose; you conclude. The assistant that drafts the documents cannot add, remove or re-score anything — the numbers in the document are the numbers in the register.
The engine is built, deployed and covered by its own test suite. It is new — we would rather say that than imply a track record we have not yet earned.
Compliance isn't optional — it's just badly served
The regulations are real. The problem is most businesses don't know which ones apply to them — or where to start.
You don't know what applies to you.
New regulations, older ones you've never heard of — the landscape is genuinely complex. Most businesses aren't non-compliant on purpose. They simply haven't had a clear map of what their specific business actually needs to do.
You've been told to do everything.
Most compliance advice starts with a list of every possible risk. Nobody tells you what's mandatory now, what can wait, and what will never apply to you. Kaitara Security starts there.
You're paying for advice, not outcomes.
A report is not compliance. Consent flows need to be built. Policies need to be written. Security gaps need to be fixed. We do the work — not just the writing.
Cybersecurity is now part of CE marking and US submissions
A medical device or IVD that contains software or connects to anything must carry cybersecurity evidence — in its CE technical file under MDCG 2019-16, and in a US premarket submission under FD&C Act §524B. It is reviewed as its own section, and it is a specialist discipline, distinct from the regulatory and quality-system work your partner leads.
We cover that slice for either market, or both at once — largely the same evidence core, presented for a different reviewer. We prepare and validate it; the Notified Body issues the mark, and FDA reviews the submission.
What goes into the submission
- →Threat model and security risk file, linked to your ISO 14971 process
- →Gap assessment against MDCG 2019-16, EN IEC 81001-5-1 and FDA’s premarket guidance
- →Security architecture views, SBOM, security testing and a clean retest
- →The submission cybersecurity section, and a readiness assessment
EU MDR 2017/745 · IVDR 2017/746 · MDCG 2019-16 · EN IEC 81001-5-1 · ISO 14971 with AAMI TIR57 · FD&C Act §524B and FDA’s premarket cybersecurity guidance.
Fixed-fee packages. No surprises.
We don't hand you a report and walk away. We map what applies, implement it, test it, and verify it — then give you a clear roadmap for what comes next.
Not sure what applies to you yet? Get your regulatory profile free — no engagement required.
Starter
We map what applies. We implement it.
Fixed-fee — scoped to you
- ✓Everything in your free regulatory profile — implemented
- ✓CERT-In Directions 2022 — implemented
- ✓DPDP Act 2023 — implemented end to end
- ✓Data inventory built, privacy notice written
- ✓Consent flows reviewed and set up
- ✓Grievance mechanism in place
Standard
Security and compliance. Fully implemented.
Fixed-fee — scoped to you
- ✓Everything in Starter
- ✓Application & infrastructure security tested
- ✓Security gaps found, fixed, and verified
- ✓WhatsApp Business security & TRAI TCCCPR compliance
- ✓Security monitoring and log retention implemented
- ✓5 core security policies written and adopted
- ✓Roadmap for ISO 27001, SOC 2, PCI DSS — when triggered
Complete
Implemented, monitored, and maintained.
Fixed-fee — scoped to you
- ✓Everything in Standard
- ✓Trigger roadmap — ISO 27001 / SOC 2 / PCI DSS, mapped to the events that would require them
- ✓Quarterly compliance retainer
- ✓Regulatory changes tracked and applied
- ✓Incident response — supported, not just documented
- ✓Ongoing engagement as your business scales
India regulations, and the international frameworks your customers ask for
CERT-In and the DPDP Act are the India baseline, and we implement them end to end — as we do medical-device cybersecurity for CE marking. Sell into the US, EU, UK or Singapore and more frameworks reach you; we will tell you which ones do, and which do not, before anyone spends money on them.
We implement these end to end
Our own work — assessed, implemented, tested and documented.
CERT-In Directions 2022
Ministry of Electronics & IT / CERT-In
DPDP Act 2023
Digital Personal Data Protection Act 2023
Medical Device & IVD Cybersecurity (CE / MDR / IVDR)
EU MDR 2017/745 · IVDR 2017/746 · MDCG 2019-16 · EN IEC 81001-5-1
FDA Premarket Cybersecurity (§524B)
FD&C Act §524B (21 U.S.C. §360n-2) · FDA premarket cybersecurity guidance, February 2026
We tell you whether these apply
We tell you what reaches your business and what would trigger it. Implementing these is your team's work or a specialist's, and we will say so rather than stretch to reach it.
ISO 27001
ISO/IEC 27001:2022
PCI DSS v4
Payment Card Industry Data Security Standard
GDPR / UK GDPR
EU General Data Protection Regulation + UK DPA 2018
SOC 2 Type II
AICPA Trust Services Criteria
HIPAA
Health Insurance Portability and Accountability Act
Keeping watch afterwards — Kaitara Monitor
Fixing gaps and reaching compliance is the foundation; staying compliant means someone has to be watching. We have built a monitoring stack from permissively-licensed parts so it runs in your own cloud account or on your own hardware, rather than shipping your telemetry to a vendor. It is in pilot — we stand it up per engagement, and there is no shared service to sign up for.
See what Kaitara Monitor coversWhat this covers
- Threat detection across your endpoints, servers and cloud
- Cloud security posture — misconfigurations surfaced before they are exploited
- 180-day log retention within Indian jurisdiction, per CERT-In Direction 20(3)/2022
Specialist security tools — deployed as part of your engagement
We partner with specialist security vendors, stand their technology up in your environment, and fold the findings into your compliance engagement — one point of contact for the whole programme.
How it works
A structured 4–6 week engagement. Everything sequenced so mandatory work happens first, optional work only when triggered.
Understand your business first
We start by mapping what actually applies to you — not a generic checklist. Your sector, data, customers, and licences determine your obligations. Most businesses are over-worried about things that don't apply and under-prepared for things that do.
Get the mandatory baseline in place
Businesses operating in India carry non-negotiable legal obligations, with no size threshold. We get these in place first, quickly, before anything else. No surprises later.
Data privacy, done properly
We work through your data flows with you and implement what the law requires — notices, consent, individual rights, breach response, vendor agreements. Written for your business, not copied from a template.
Security testing
We test your application and infrastructure for vulnerabilities using industry-standard methods. You get a clear findings report, we work with your team to fix what matters, and we verify the fixes before closing.
Policies and a clear roadmap
Core security policies that your team will actually use. Then an honest map of what to do next — ISO 27001, SOC 2, PCI DSS — and critically, only when your business actually needs them.
Staying watched afterwards — Kaitara Monitor, in pilot
Once your compliance foundation is in place, the question becomes who is watching. Kaitara Monitor is a monitoring stack we stand up per engagement — in your own cloud account or on your own hardware — covering threat detection, file-integrity monitoring, and the 180-day India-resident log retention CERT-In requires. It is in pilot today, so it gets scoped with you rather than switched on.
Start free. Pay only when you implement.
You don't have to talk to us to find out where you stand. Create an account and get your regulatory profile at no cost — the engagement only begins when you ask for the work to be done.
Run a free scan
Website or public repo, about two minutes. No account needed.
Create a free account
Work email on your company domain. We activate it within 24 hours.
Get your regulatory profile
Which regulations apply to you, which don't. Free, in seconds.
From there, a fixed-fee engagement turns the profile into implemented compliance — your document pack, a prioritised checklist with evidence tracking, and a live dashboard.
India fintech — CERT-In & DPDP compliance in 4 weeks
A fintech needed to get compliant before an enterprise sales push. Starting from zero, we mapped their obligations, implemented data privacy requirements, tested and cleared their security posture, and delivered a full compliance foundation in four weeks.
Read the full case studyOutcomes
- ✓Legal baseline in place within 2 weeks
- ✓DPDP Act compliance implemented end to end
- ✓Security vulnerabilities found, fixed, and verified
- ✓5 security policies adopted by the team
- ✓Clear roadmap — what to do next, and when
Common questions
Start with a free scoping call
30 minutes. We'll map your regulatory exposure and tell you exactly what applies to your business. No obligation.
Book a free scoping callOpens your email client — or write directly to security@kaitara.com
By submitting you consent to Kaitara Security contacting you about your enquiry. Privacy Policy.