India and international
The framework your business needs —
implemented, not just filed.
The first group below is our own work, implemented end to end. The second we will tell you whether you are in scope for — no charge, and no pretence that we implement it. The right scope depends on your geography, sector, and who your customers are. Not sure what applies? A 30-minute scoping call will tell you.
International pricing
Fixed-fee, scoped per engagement — Starter, Standard, and Complete tiers.
Implementation included — not advisory hours.
We implement these end to end
Our own work — assessed, implemented, tested and documented, with the evidence to show for it.
CERT-In Directions 2022
Ministry of Electronics & IT / CERT-InDetails →Binding on service providers, intermediaries, data centres, body corporates and Government organisations — in practice, every company operating in India. Report incidents within six hours of noticing them, or of being brought to notice. Retain ICT logs for a rolling 180 days within Indian jurisdiction. Synchronise clocks to NIC or NPL time servers, and designate a Point of Contact with CERT-In.
DPDP Act 2023
Digital Personal Data Protection Act 2023Details →India's comprehensive data privacy law. Self-certified. Requires lawful basis, consent architecture, data principal rights (access, correction, erasure), grievance officer, breach response, and DPAs with all data processors. The DPDP Rules 2025 were notified on 14 November 2025 — phased compliance runs to May 2027.
Medical Device & IVD Cybersecurity (CE / MDR / IVDR)
EU MDR 2017/745 · IVDR 2017/746 · MDCG 2019-16 · EN IEC 81001-5-1Details →The cybersecurity evidence a medical device or IVD needs for its CE technical file: security architecture and threat model, gap assessment against MDCG 2019-16 and EN IEC 81001-5-1, security risk management linked to ISO 14971, SBOM, security testing, and a Notified Body readiness assessment. MDCG 2019-16 is the joint MDR/IVDR guidance — the same evidence set applies to both. Readiness delivered — we prepare the cybersecurity evidence; the Notified Body issues the mark. FDA §524B premarket cybersecurity on request.
FDA Premarket Cybersecurity (§524B)
FD&C Act §524B (21 U.S.C. §360n-2) · FDA premarket cybersecurity guidance, February 2026Details →The cybersecurity evidence a US premarket submission is expected to carry: threat model and security risk assessment feeding the ISO 14971 risk file, the four security architecture views, security controls across eight categories shown to be implemented and tested, a software bill of materials, a coordinated vulnerability disclosure policy, and security testing. §524B requires an SBOM and specifies no format; a machine-readable one against the NTIA baseline is what FDA's guidance recommends. Documentation scales with the device's risk and connectivity. Evidence delivered — we prepare it; FDA reviews the submission.
We tell you whether these apply
Your free regulatory profile covers these — what reaches your business, what does not, and what would trigger it. We do not implement them; that is your team's work or a specialist's, and we will say so rather than stretch to reach it.
ISO 27001
ISO/IEC 27001:2022The internationally recognised information security management standard. Required by large enterprise and government clients across India, EU, UK, Singapore, and the Middle East. Certification requires an accredited third-party audit.
PCI DSS v4
Payment Card Industry Data Security StandardApplies to organisations that store, process or transmit cardholder data. Using a compliant hosted gateway so card data never reaches your systems reduces what you have to do — how far depends on your integration, which we confirm during scoping rather than assume.
GDPR / UK GDPR
EU General Data Protection Regulation + UK DPA 2018Applies to organisations processing personal data of EU or UK residents, wherever the company is based — including Indian companies serving EU customers. Lawful basis, privacy notices, data-subject rights, processor agreements and breach response.
Cyber Essentials
NCSC Cyber Essentials / Cyber Essentials PlusThe UK NCSC's baseline scheme for suppliers, covering a defined set of technical controls. The Plus variant adds independent verification. Increasingly asked for by enterprise UK buyers beyond government.
SOC 2 Type II
AICPA Trust Services CriteriaThe security attestation US enterprise buyers most often ask B2B SaaS companies for, reported against the AICPA Trust Services Criteria. A Type II report covers an observation period rather than a point in time, which is why buyers ask for it specifically; the length of that period is set with your audit firm. The Criteria are copyrighted, so we do not restate them — your auditor scopes which apply.
CCPA / CPRA
California Consumer Privacy Act + Privacy Rights ActCalifornia's data privacy law — the closest US equivalent to GDPR. Gives California residents rights to know, delete and opt out of the sale of personal data; CPRA added correction rights and limits on sensitive-data use.
FTC Safeguards Rule
FTC Standards for Safeguarding Customer InformationRequires a written information security programme with a designated responsible individual, risk assessments, and defined technical controls, for financial institutions in scope of the Rule.
HIPAA
Health Insurance Portability and Accountability ActOn requestApplies to US covered entities and their business associates. Administrative, physical and technical safeguards for protected health information, and written agreements with business associates. HIPAA engagements are available on request — contact us to discuss your situation before scoping.
PDPA (Singapore)
Personal Data Protection Act 2012 (amended 2021)Singapore's data protection law, enforced by the PDPC. Consent and purpose limitation, data-protection officer designation, protection and retention obligations, and notifiable data-breach reporting.
MAS TRM Guidelines
MAS Technology Risk Management GuidelinesMAS Guidelines setting supervisory expectations for technology risk governance, IT controls, cyber resilience and third-party risk at MAS-regulated financial institutions. Vendors supplying those institutions face the expectations indirectly.
Not sure what applies to you?
30 minutes. We ask the right questions, map your regulatory exposure, and tell you exactly what your business needs to do — and what it doesn't.
Book a free scoping call →