Skip to main content

India and international

The framework your business needs —
implemented, not just filed.

The first group below is our own work, implemented end to end. The second we will tell you whether you are in scope for — no charge, and no pretence that we implement it. The right scope depends on your geography, sector, and who your customers are. Not sure what applies? A 30-minute scoping call will tell you.

International pricing

Fixed-fee, scoped per engagement — Starter, Standard, and Complete tiers.

Implementation included — not advisory hours.

Get a quote →

We implement these end to end

Our own work — assessed, implemented, tested and documented, with the evidence to show for it.

India

CERT-In Directions 2022

Ministry of Electronics & IT / CERT-InDetails →

Binding on service providers, intermediaries, data centres, body corporates and Government organisations — in practice, every company operating in India. Report incidents within six hours of noticing them, or of being brought to notice. Retain ICT logs for a rolling 180 days within Indian jurisdiction. Synchronise clocks to NIC or NPL time servers, and designate a Point of Contact with CERT-In.

Trigger: Service providers, intermediaries, data centres, body corporates and Government organisations — no size thresholdPenalty: Punitive action under s.70B(7) of the IT Act 2000
India

DPDP Act 2023

Digital Personal Data Protection Act 2023Details →

India's comprehensive data privacy law. Self-certified. Requires lawful basis, consent architecture, data principal rights (access, correction, erasure), grievance officer, breach response, and DPAs with all data processors. The DPDP Rules 2025 were notified on 14 November 2025 — phased compliance runs to May 2027.

Trigger: Always — any processing of personal data of Indian residentsPenalty: Graded by the obligation breached, up to ₹250 crore
EU

Medical Device & IVD Cybersecurity (CE / MDR / IVDR)

EU MDR 2017/745 · IVDR 2017/746 · MDCG 2019-16 · EN IEC 81001-5-1Details →

The cybersecurity evidence a medical device or IVD needs for its CE technical file: security architecture and threat model, gap assessment against MDCG 2019-16 and EN IEC 81001-5-1, security risk management linked to ISO 14971, SBOM, security testing, and a Notified Body readiness assessment. MDCG 2019-16 is the joint MDR/IVDR guidance — the same evidence set applies to both. Readiness delivered — we prepare the cybersecurity evidence; the Notified Body issues the mark. FDA §524B premarket cybersecurity on request.

Trigger: CE marking a medical device or IVD that contains software or connectivityPenalty: CE submission delayed or rejected; market access blocked
US

FDA Premarket Cybersecurity (§524B)

FD&C Act §524B (21 U.S.C. §360n-2) · FDA premarket cybersecurity guidance, February 2026Details →

The cybersecurity evidence a US premarket submission is expected to carry: threat model and security risk assessment feeding the ISO 14971 risk file, the four security architecture views, security controls across eight categories shown to be implemented and tested, a software bill of materials, a coordinated vulnerability disclosure policy, and security testing. §524B requires an SBOM and specifies no format; a machine-readable one against the NTIA baseline is what FDA's guidance recommends. Documentation scales with the device's risk and connectivity. Evidence delivered — we prepare it; FDA reviews the submission.

Trigger: A US premarket submission — 510(k), De Novo, PMA, PDP or HDE — for a device that contains software and has the ability to connectPenalty: An incomplete cybersecurity section puts an eSTAR submission on Technical Screening hold — not a rejection, but calendar time

We tell you whether these apply

Your free regulatory profile covers these — what reaches your business, what does not, and what would trigger it. We do not implement them; that is your team's work or a specialist's, and we will say so rather than stretch to reach it.

Global

ISO 27001

ISO/IEC 27001:2022

The internationally recognised information security management standard. Required by large enterprise and government clients across India, EU, UK, Singapore, and the Middle East. Certification requires an accredited third-party audit.

Trigger: Enterprise or government client requests it in procurementPenalty: Lost enterprise contracts
Global

PCI DSS v4

Payment Card Industry Data Security Standard

Applies to organisations that store, process or transmit cardholder data. Using a compliant hosted gateway so card data never reaches your systems reduces what you have to do — how far depends on your integration, which we confirm during scoping rather than assume.

Trigger: Accepting card payments. A validated gateway reduces scope rather than removing itPenalty: Card brand fines, processing termination
EU / UK

GDPR / UK GDPR

EU General Data Protection Regulation + UK DPA 2018

Applies to organisations processing personal data of EU or UK residents, wherever the company is based — including Indian companies serving EU customers. Lawful basis, privacy notices, data-subject rights, processor agreements and breach response.

Trigger: Processing personal data of EU or UK residents
UK

Cyber Essentials

NCSC Cyber Essentials / Cyber Essentials Plus

The UK NCSC's baseline scheme for suppliers, covering a defined set of technical controls. The Plus variant adds independent verification. Increasingly asked for by enterprise UK buyers beyond government.

Trigger: UK government contracts, NHS supply chainPenalty: Lost government and enterprise contracts
US

SOC 2 Type II

AICPA Trust Services Criteria

The security attestation US enterprise buyers most often ask B2B SaaS companies for, reported against the AICPA Trust Services Criteria. A Type II report covers an observation period rather than a point in time, which is why buyers ask for it specifically; the length of that period is set with your audit firm. The Criteria are copyrighted, so we do not restate them — your auditor scopes which apply.

Trigger: US enterprise client asks for it during procurementPenalty: Lost deals, failed procurement
US

CCPA / CPRA

California Consumer Privacy Act + Privacy Rights Act

California's data privacy law — the closest US equivalent to GDPR. Gives California residents rights to know, delete and opt out of the sale of personal data; CPRA added correction rights and limits on sensitive-data use.

Trigger: Serving California consumers, above the Act's applicability thresholds
US

FTC Safeguards Rule

FTC Standards for Safeguarding Customer Information

Requires a written information security programme with a designated responsible individual, risk assessments, and defined technical controls, for financial institutions in scope of the Rule.

Trigger: US financial institutions, fintechs, tax preparers, mortgage brokersPenalty: FTC enforcement action, fines
US

HIPAA

Health Insurance Portability and Accountability ActOn request

Applies to US covered entities and their business associates. Administrative, physical and technical safeguards for protected health information, and written agreements with business associates. HIPAA engagements are available on request — contact us to discuss your situation before scoping.

Trigger: Handling protected health information (PHI) for US patients
Singapore

PDPA (Singapore)

Personal Data Protection Act 2012 (amended 2021)

Singapore's data protection law, enforced by the PDPC. Consent and purpose limitation, data-protection officer designation, protection and retention obligations, and notifiable data-breach reporting.

Trigger: Collecting or processing personal data of Singapore residents
Singapore

MAS TRM Guidelines

MAS Technology Risk Management Guidelines

MAS Guidelines setting supervisory expectations for technology risk governance, IT controls, cyber resilience and third-party risk at MAS-regulated financial institutions. Vendors supplying those institutions face the expectations indirectly.

Trigger: MAS-regulated financial institutions and their technology service providersPenalty: Supervisory action by MAS

Not sure what applies to you?

30 minutes. We ask the right questions, map your regulatory exposure, and tell you exactly what your business needs to do — and what it doesn't.

Book a free scoping call →