Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP

  • Home
  • Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP
Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP
Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP
Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP
Cyber Compliance Services in India — ISO 27001, PCI DSS and DPDP

A buyer’s guide · Operating since 2002

Cyber complianceWhich framework applies, what a gap assessment finds, and the evidence an auditor will actually accept

Most organisations that fail an audit are not insecure. They have the control, they turned it on, and they cannot produce dated proof that it operated every month of the period under review. Compliance is an evidence problem far more often than a security problem.

This page sets out which frameworks concern whom, what separates a written policy from a passed audit, what genuinely drives the cost, and the questions worth asking any provider — us included.

Read the instrument, not the summary. Sectoral applicability turns on how your entity is classified, and classifications are specific. Everything below is a map to orient yourself, not advice on your obligations — including the table. Where a duty is stated we name the instrument so you can check it yourself, and regulatory positions change: verify against the current notification before building a plan around anything here.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The gap

Why organisations with good security fail audits

Five stages sit between a written policy and a satisfied auditor. Most organisations reach the second and reasonably believe they are done.

From policy to a passed audit1Policy writtenA document exists2Control implementedIt is actually turned on3Operating consistentlyEvery time, not just in March4Evidence retainedProof it operated, dated5Auditor satisfiedEvidence they will acceptmost stop herethe audit is decided here“We have a policy for that” is stage one. An auditor asks for stage four.Compliance is evidence that a control operated.Not the existence of the control, and certainly not the policy describing it.Which is why gap assessments find so much more than anyone expects.

What an auditor actually tests

Not whether the control exists. Whether it operated, consistently, throughout the period under review — and whether you can produce dated artefacts proving it. Access review records with a reviewer and a date. Change approvals. Patch reports. Backup restores that were actually performed.

None of that can be manufactured retrospectively, which is why the timeline for certification is driven by evidence accrual rather than by how quickly documents can be written.

Why gap assessments surprise people

Because most are performed against documentation, and documentation describes intent. An assessment performed against evidence asks a harder question: show me this happening, for each month, for the last year.

The gap between those two answers is where audits are lost, and it is almost always wider than the organisation expects — particularly for controls that depend on somebody remembering to do something quarterly.

The landscape

What each framework is, and what it is not

Six frameworks that get discussed as though they are alternatives. They are not — they have different subjects, different authorities and different consequences, and several apply simultaneously.

Four questions settle which framework appliesMore than one usually applies. That is the argument for mapping controls once.Do you take card payments?Scope is whatever touches card data. Shrinking it is the cheapest control.PCI DSSDo you sell to enterprises abroad?They will ask for one, and the buyer usually names which.SOC 2 or ISO 27001Do you hold personal data of Indians?Applies regardless of sector or size. Newest, and rarely scoped.DPDP ActAre you regulated — bank, insurer, broker?SEBI, RBI or IRDAI direction outranks any voluntary framework.Sector rules firstMap the control once, report it four ways. Running four programmes is how compliance becomes the cost people complain about.

Most organisations answer yes to more than one of these, which is the entire argument for mapping a control once and reporting it several ways.

Scroll the table sideways →

Framework Who it concerns What it is about What it is not
ISO/IEC 27001:2022 Voluntary. Any organisation. An information security management system — risk assessment, control selection, and the management process around both. Not a security guarantee, and not a fixed control set. You choose the scope, so a certificate means nothing until you have read the scope statement behind it.
PCI DSS Anyone storing, processing or transmitting payment card data. Prescriptive technical and operational controls around the cardholder data environment. Not a general security standard. It is deliberately scoped to card data, and reducing that scope is usually cheaper than securing it.
CERT-In Directions20(3)/2022 Organisations operating in India, broadly drawn. Incident reporting duties, and retention of ICT logs for a rolling 180 days, maintained within India. Not a certification — a legal direction. There is nothing to be certified against and no auditor to satisfy, only a duty to comply.
SEBI CSCRF SEBI-regulated entities. A cyber security and cyber resilience framework consolidating earlier circulars. Applicability and timelines differ by entity category. Read the circular for your classification rather than a summary of it — including ours.
RBI frameworks Banks and NBFCs, per the applicable circulars. Baseline cyber security controls and expectations around security operations. Requirements are not uniform between banks and NBFCs, and have been issued across multiple instruments over time.
DPDP Act 2023 and Rules Anyone processing digital personal data in India. Obligations on how personal data is collected, used, secured, retained and erased. Commencement is phased and several obligations are not yet in force. Verify the current position against the notification before building a plan around a date.

The reporting deadlines that sit across several of these are a subject of their own, and we keep them on a separate page rather than summarising them here where they would go stale: cyber incident reporting in India, with the instrument and date behind every deadline.

Money

What actually drives compliance cost

We publish the drivers rather than a figure, because a number without a scope is meaningless — and because scope is the variable you control.

The two invoices

Consultancy covers gap assessment, the management system, policy work, control implementation and audit preparation. It scales with the scope you choose, the number of sites and people, and how much already exists.

The certification body is separate, charges by audit day, and recurs — surveillance audits annually and recertification on its own cycle. A quote covering only the first is not a budget.

Ask any provider for the three-year total. That is the actual commitment, and the gap between it and the first invoice is where budgets break.

The lever nobody pulls

Scope. It is chosen, not given, and it is the single largest determinant of cost in almost every framework.

  • Which legal entities, sites and systems are in
  • How many people fall inside the boundary
  • Whether a system holds regulated data at all — or could stop
  • How much control overlap can be evidenced once and mapped to several frameworks
  • Whether evidence collection is automated or someone’s calendar reminder

The clearest case is PCI DSS, where removing card data from a system removes the system from scope entirely. The logic generalises: the cheapest control is frequently not holding the data.

Straight answers

What buyers get wrong about compliance

Fact

Compliance is evidence, not controls

The control existing is stage two of five. What an auditor tests is whether it operated consistently and whether you can prove it, dated, for the period under review. This is why organisations with genuinely good security still fail audits, and why gap assessments find far more than anyone expects.

Ask

“We are ISO 27001 certified” — to what scope?

The scope is chosen by the organisation being certified. A certificate can legitimately cover a single office, a single product, or one data centre. Asking for the scope statement is not rude and it is the only way the certificate means anything. Ask it of us too.

Fact

A framework is not a security strategy

Frameworks describe a floor built from what was common practice when they were written. Meeting one is worth doing, frequently contractually necessary, and entirely compatible with being compromised through something the framework does not address.

Ask

“Which of these actually applies to us?”

Sectoral applicability turns on entity classification, and classifications are specific. The right answer is a reading of the instrument against your registration, not a table on a vendor’s website — including the table above, which is a map rather than advice.

Fact

Reducing scope usually beats securing it

This is most obvious with PCI DSS, where removing card data from a system removes the system from scope entirely. The same logic applies more widely: the cheapest control is frequently not holding the data at all.

Ask

“What does year two cost?”

Certification is a beginning. Surveillance audits recur, scope drifts as the business changes, and the person who owned the evidence collection leaves. Programmes rarely fail at certification; they lapse quietly afterwards.

Before you sign

Ten questions for any compliance provider

Use these on us as readily as on anyone else. Question ten is the one that tells you whether you are being assessed or sold to.

Scope

What is the scope statement, and who decides it?

For ISO 27001 the scope is chosen, not given. A certificate covering one office and one product line is a real certificate and may be irrelevant to what your client is asking about. This is the first question to ask of any supplier’s certificate, including ours.

Gap

Does the engagement start with a gap assessment against evidence, or against policy?

Assessing documentation tells you what you have written down. Assessing evidence tells you what is actually operating. Only the second predicts an audit outcome.

Evidence

Who produces the evidence, and where does it live?

Compliance work fails at collection far more often than at control design. Agree early what evidence each control generates, who retains it and for how long.

Cost

What is the total cost, including the certification body?

Consultancy and certification are separate invoices. Surveillance audits recur annually and recertification periodically. A quote covering only the first is not a budget.

Overlap

How much of this maps across frameworks?

Control overlap between ISO 27001, sectoral requirements and internal policy is substantial. A provider treating each as a fresh project is selling the same work more than once.

Tooling

Are we buying a platform, a service, or both?

Compliance automation platforms are useful and are not compliance. Ask what the licence covers, what remains manual, and what happens to your evidence if you stop paying.

People

Who writes the policies — us or you?

Templates delivered as a policy set produce documents nobody follows and auditors recognise instantly. Ask how much comes from your actual practice.

Audit

Will you be present for the audit?

There is a large difference between a provider who prepares you and one who sits in the room when the auditor asks a question nobody rehearsed.

Maintenance

What happens in month thirteen?

Certification is a beginning. Surveillance audits, control changes, staff turnover and scope creep all arrive later, and the second year is where most programmes quietly lapse.

Honesty

What would you tell us not to bother with?

A provider who recommends every framework they sell has not assessed anything. The useful answer names something you do not need yet.

Working with us

How we run this

We hold ISO/IEC 27001:2022 ourselves and we operate the controls we help others evidence. That means we are describing work we do rather than work we have read about — and it means our own certificate is fair game for the scope question.

Assessed against evidence

Gap assessment looks at what operated, not at what the policy says should happen. It is a harder conversation early and a much easier one at audit.

Mapped once

Control overlap between frameworks is substantial. We map once and evidence once rather than running each framework as a separate project.

Policies from your practice

Written from how your organisation actually works. Template policy sets describing somebody else’s company are recognised instantly by auditors.

Evidence that generates itself

Where a control can produce its own dated artefact from systems we already run for you, we set it up that way. Evidence depending on a calendar reminder is evidence you will be missing.

Present at the audit

Not just preparation. Someone in the room when a question arrives that nobody rehearsed.

We will tell you to skip things

If a framework does not apply to you yet, or a control is disproportionate at your size, we say so. A provider recommending everything they sell has assessed nothing.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

Cyber compliance, answered

Which cyber compliance framework applies to us?

It depends on what you do and how you are registered, not on your size. Handling payment card data brings PCI DSS. Operating in India brings the CERT-In Directions regardless of sector. Regulated financial entities have sectoral frameworks whose applicability turns on their specific classification. Processing personal data brings DPDP obligations. ISO 27001 is voluntary but frequently required by customers in contract. The table above is a map to orient yourself; the answer for your organisation comes from reading the instruments against your registration.

What does ISO 27001 certification cost?

There are two separate costs and quotes often show only the first. Consultancy covers gap assessment, the management system, policy work, control implementation and audit preparation, and scales with the scope you choose, the number of sites, headcount and how much already exists. Certification body fees are separate, are charged per audit day, and recur — surveillance audits annually and recertification periodically. Ask any provider for the total across three years rather than the first invoice, because that is the actual commitment.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 certifies a management system against an international standard, issued by an accredited certification body, and is the certification most commonly asked for outside the United States. SOC 2 is an attestation report produced by a licensed CPA firm under the AICPA framework, describing whether controls were suitably designed and, for Type II, operating over a period. US buyers usually ask for SOC 2 by name; buyers elsewhere usually ask for ISO 27001. They overlap substantially in underlying control work, which is why organisations pursuing both should map once and evidence once.

What is a compliance gap assessment?

A structured comparison of what a framework requires against what your organisation actually does — ideally assessed against evidence rather than against documentation. The output is a prioritised remediation plan with owners and effort estimates. Assessing policies tells you what you have written down; assessing evidence tells you what is operating, and only the second predicts an audit outcome.

What are the CERT-In log retention requirements?

CERT-In Direction 20(3) of 2022 requires organisations to maintain logs of their ICT systems for a rolling period of 180 days, and to maintain them within India. In practice that is a configuration and architecture decision affecting your SIEM, your cloud regions and your retention tiers rather than a policy question. Incident reporting duties sit alongside it — the deadlines across the various Indian regulators are set out on our cyber incident reporting page, which is kept current.

What does DPDP compliance involve?

Broadly: knowing what personal data you hold and why, having a lawful basis and notice, honouring the rights the Act gives individuals, securing the data, retaining it no longer than needed, and being able to demonstrate all of that. Commencement is phased and several obligations are not yet in force, so the practical answer is to build the data inventory and the retention position now — those take longest and are useful regardless — and verify current commencement before committing to a date-driven plan.

Is PCI DSS relevant if we use a payment gateway?

Usually yes, but at dramatically reduced scope. If card data never touches your systems, most requirements fall away and your obligation becomes largely about validating that separation and completing the appropriate self-assessment. This is the clearest example of a general principle: reducing scope is nearly always cheaper than securing it.

Do we need a consultant, or can we do this internally?

Internally is entirely possible and is cheaper if you have someone who has done it before and can protect the time. What consultants genuinely add is pattern recognition — knowing which evidence auditors actually ask for, which controls fail in practice, and where a scope decision will cost you later. What they should not add is a set of template policies describing an organisation that is not yours.

How long does ISO 27001 certification take?

From a standing start, typically several months rather than weeks, and the constraint is almost never writing the documents. Certification requires evidence that the management system has been operating — internal audits performed, a management review held, risks assessed and treated, incidents handled. That evidence accrues over time and cannot be manufactured retrospectively, which is the single most common reason timelines slip.

Will a certificate satisfy our customer’s security questionnaire?

Partly, and it depends entirely on scope. A questionnaire usually asks about the systems handling that customer’s data. If those systems sit inside your certified scope, the certificate answers a great deal. If they do not, it answers very little and the mismatch is discovered at exactly the wrong moment. Check the scope statement before relying on it.

Can you help with more than one framework at once?

Yes, and it is usually the sensible order. Control overlap between ISO 27001, sectoral requirements and internal policy is substantial, so the efficient approach is to map controls once, implement once, and evidence once against multiple frameworks. Treating each as an independent project means paying repeatedly for the same work.

What evidence do auditors actually ask for?

Dated artefacts showing a control operated during the period under review: access review records with the reviewer and date, change approvals, patch reports, incident tickets with timelines, backup restore tests, training completion, supplier reviews, internal audit reports and management review minutes. Not policies. The policy explains what should happen; the evidence shows it did.

What happens after certification?

Surveillance audits recur, and recertification comes round on its own cycle. Meanwhile the business changes, scope drifts, and whoever was collecting the evidence moves on. Programmes rarely fail at certification — they lapse in year two. Deciding who owns evidence collection as a standing responsibility is the single most useful thing to settle before you certify.

Do you provide the certification itself?

No, and nobody providing consultancy can. Certification is issued by an accredited certification body, and that separation is deliberate — the same organisation cannot both build your management system and independently certify it. We prepare you, we can be present for the audit, and the certificate comes from an accredited body you appoint.

Next step

Start with the scope conversation

Tell us which framework you are being asked for and by whom — a customer, a regulator, a board. Scope is the largest cost lever in every framework and it is decided at the start, usually without anyone realising a decision was made. We will help you draw it deliberately, then assess honestly against evidence.

sanjay@pjnetworks.com