# IT & ITES security compliance in India — the TechBag guide

> For Indian IT services, ITES/BPM, MSP/MSSP, engineering R&D, global capability centres (GCCs), and SaaS and software-product companies. Every obligation carries its source and the date it was verified. Last reviewed 2026-10-05. General information, not legal advice.

Web version: https://www.thetechbag.com/industries/it-ites · Obligations: https://www.thetechbag.com/industries/it-ites/obligations · Controls: https://www.thetechbag.com/industries/it-ites/controls

## The core point: whoever notices the incident owns the clock

- **CERT-In FAQ, Q13** (on the Directions of 28 April 2022): "Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with." An IT vendor cannot contract its six-hour duty away to its client, and the same duty binds a SaaS platform.
- **RBI Managing Risks in Outsourcing Directions 2025, para 56:** incidents are reported to the bank by the service provider "so that an incident is reported by the bank to the RBI within six hours of detection by the service provider". The vendor's detection starts the bank client's regulatory clock.
- **EU Cyber Resilience Act, Article 14:** for installable software, apps and agents sold in the EU, a 24-hour early warning for actively exploited vulnerabilities and severe incidents, from 11 September 2026 (full application 11 December 2027). Pure SaaS is generally outside it.

### The reporting clocks one incident can start

- **CERT-In** — 6 hours from the moment you notice it, to CERT-In.
- **RBI outsourcing** — 6 hours from detection by you, the service provider, to the RBI, via your bank client.
- **NIS2** — 24 hours from becoming aware of a significant incident, to the national CSIRT (early warning).
- **EU CRA** — 24 hours from becoming aware of an actively exploited vulnerability, to ENISA’s single reporting platform.
- **DPDP** — 72 hours from a personal-data breach (from May 2027), to the Data Protection Board.
- **HIPAA** — ≤ 60 days from discovery of the breach, to your covered-entity client.
- **GDPR** — Without undue delay from becoming aware (processor → controller), to your client, the controller.

## The industry

FY2026E: $315bn revenue, ~78% exported, 59.5 lakh employees. Services: $149bn IT services; $63bn Engineering R&D; $59bn BPM; 2,117 GCCs, 2.36 million staff. Product: $23bn Software products; ~1,600 SaaS firms funded, 2017–22 (Bain); $12–13bn Indian SaaS ARR, 2022 (Bain). Sources: NASSCOM Strategic Review 2026 as reported by PTI; NASSCOM–Zinnov India GCC Landscape 2026; Bain India SaaS Report 2022 (the latest with a public method); DSCI Indian Cybersecurity Product Landscape 3.0.

## Deadlines (2025–2027)

- 2025-01-17 — DORA applies (DORA)
- 2025-03-31 — Future-dated requirements mandatory (PCI DSS)
- 2025-07-09 — SBOM/CBOM/AIBOM guidelines v2.0 (CERT-In SBOM)
- 2025-07-25 — Audit policy guidelines issued (CERT-In audit)
- 2025-08-31 — CSCRF compliance deadline (SEBI CSCRF)
- 2025-10-31 — 2013 certificates lapse (ISO 27001)
- 2025-11-10 — CMMC rule takes effect (CMMC)
- 2025-11-13 — DPDP Rules notified (DPDP)
- 2025-11-18 — First critical-provider list (DORA)
- 2025-11-28 — Outsourcing Directions issued (RBI outsourcing)
- 2026-01-23 — Federal attestation rescinded (US attestation)
- 2026-02-05 — UK transfer test in force (GDPR)
- 2026-04-06 — Guidelines reissued (IRDAI)
- 2026-04-10 — Existing contracts must comply (RBI outsourcing)
- 2026-08-02 — Transparency duties (EU AI Act)
- 2026-09-11 — Reporting obligations live (EU CRA)
- 2026-11-10 — Third-party Level 2 assessments (CMMC)
- 2026-11-13 — Consent Managers begin (DPDP)
- 2027-05-13 — Operational duties apply (DPDP)
- 2027-12-02 — High-risk obligations (EU AI Act)
- 2027-12-11 — Full application (EU CRA)

## The 25 obligations

### Indian law & regulators

What binds every Indian firm in this industry, or every firm doing a particular kind of work.

#### CERT-In Directions under section 70B(6), 28 April 2022

- **Issuer:** CERT-In (MeitY) · **Force:** Regulator · **For:** Both
- **Who it reaches:** Always. The Directions bind every “body corporate”, which is every Indian IT, ITES and software company.
- **Status:** In force since June 2022 (September 2022 for MSMEs).
- **What it requires:**
  - Report any of 20 listed incident types — ransomware, data breach, cloud and identity attacks among them — within six hours of noticing it.
  - Keep logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand.
  - Synchronise clocks to NIC or NPL NTP, or a source traceable to them.
  - Register a point of contact with CERT-In.
- **Reporting clock:** 6 hours from the moment you notice it, to CERT-In.
- **What people get wrong:** The duty cannot be handed to your client by contract. CERT-In's own FAQ: “Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with.” And logs may sit outside India, provided they can be produced in reasonable time (FAQ Q35).
- **Source:** [CERT-In Directions and FAQ (May 2022)](https://www.cert-in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#cert-in-directions

#### Digital Personal Data Protection Act 2023 and DPDP Rules 2025

- **Issuer:** Parliament; Rules by MeitY · **Force:** Law · **For:** Both
- **Who it reaches:** Always — you are a Data Fiduciary for your own employees’ data even where you are only a processor for clients. A SaaS firm is a fiduciary for its own account holders and usually a processor for what customers load into the product.
- **Status:** Rules notified 13 November 2025. Data Protection Board live; Consent Managers from November 2026; the operational duties from 13 May 2027. A proposal to bring that forward was consulted on in early 2026 but has not been notified.
- **What it requires:**
  - Reasonable security safeguards: encryption, masking or tokenisation; access control; logging and review of access to personal data; backups (Rule 6).
  - Keep logs of processing for at least one year — longer than CERT-In’s 180 days — including processing done by a Data Processor (Rules 6 and 8).
  - Tell the Board without delay, with a detailed report within 72 hours; tell affected people without delay (Rule 7).
  - Bind every processor by a contract that carries security safeguards (section 8, Rule 6).
- **Reporting clock:** 72 hours from a personal-data breach (from May 2027), to the Data Protection Board.
- **What people get wrong:** Penalties — up to ₹250 crore for failing to keep safeguards — fall on the Data Fiduciary, not the processor; processors are bound through the contract. Offshore delivery has a carve-out: section 17(1)(d) disapplies most of the Act when an Indian firm processes non-residents’ data under a foreign contract, but the section 8(5) duty to keep reasonable security safeguards still applies.
- **Source:** [DPDP Rules 2025, G.S.R. 846(E)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#dpdp

#### IT Act section 43A and the SPDI Rules 2011

- **Issuer:** MeitY · **Force:** Law · **For:** Both
- **Who it reaches:** Always, until the DPDP Act replaces it.
- **Status:** Still in force. The DPDP Act omits section 43A, but that provision only commences with the operational duties on 13 May 2027.
- **What it requires:**
  - A documented information-security programme; ISO/IEC 27001 is the standard the Rules name as recognised.
- **Source:** [DPDP commencement, G.S.R. 843(E) (via ICAI and taxmann)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#it-act-43a

#### Companies (Accounts) Rules 2014 — electronic books of account

- **Issuer:** Ministry of Corporate Affairs · **Force:** Law · **For:** Both
- **Who it reaches:** Always — every Indian company.
- **Status:** Daily-backup amendment in force since 5 August 2022.
- **What it requires:**
  - Back up electronic books of account daily, on servers physically located in India.
  - Disclose the cloud or service provider’s name and location to the Registrar annually.
- **Source:** [Companies (Accounts) Amendment Rules 2022 (via AZB, Grant Thornton)](https://www.mca.gov.in/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#companies-accounts

#### CERT-In Comprehensive Cyber Security Audit Policy Guidelines v1.0

- **Issuer:** CERT-In · **Force:** Regulator · **For:** Both
- **Who it reaches:** When a regulator, a government contract or a client asks for a CERT-In-empanelled audit — which regulated clients increasingly do.
- **Status:** Issued 25 July 2025. A guideline: its force comes from whoever requires it.
- **What it requires:**
  - A comprehensive audit of all ICT systems at least once a year, by a CERT-In-empanelled auditor.
  - Vulnerability assessment and penetration testing in scope, and third-party and supply-chain risk.
- **What people get wrong:** Not a statutory mandate for every private company — don’t let anyone sell it to you as one.
- **Source:** [CERT-In audit guidelines, 25 July 2025](https://it.delhi.gov.in/sites/default/files/IT/generic_multiple_files/comprehensive.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#cert-in-audit

#### CERT-In technical guidelines on SBOM, CBOM, AIBOM and HBOM v2.0

- **Issuer:** CERT-In · **Force:** Regulator · **For:** Product firms
- **Who it reaches:** If you build software — guidance aimed squarely at software-export and software-services organisations.
- **Status:** v1.0 October 2024; v2.0 9 July 2025. Advisory — sectoral rules (SEBI’s CSCRF) make SBOMs mandatory for regulated buyers.
- **What it requires:**
  - A software bill of materials for what you ship; a cryptographic BOM for post-quantum readiness; an AI BOM for model provenance.
- **What people get wrong:** Advisory, not mandatory, on its own. Your SEBI-regulated customers will still ask for the SBOM.
- **Source:** [CERT-In BOM guidelines (via Khaitan, AZB)](https://www.cert-in.org.in/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#cert-in-sbom

#### DoT Other Service Provider guidelines (2020, revised 2021)

- **Issuer:** Department of Telecommunications · **Force:** Regulator · **For:** Services firms
- **Who it reaches:** Voice-based BPOs and contact centres only. Non-voice ITES left the regime in 2020.
- **Status:** Registration abolished 5 November 2020; liberalised again 23 June 2021. No restatement under the Telecommunications Act 2023 has been published.
- **What it requires:**
  - Keep call-detail records, usage data and system logs for voice traffic for one year — with a copy in India where the EPABX sits abroad.
  - Keep remote-agent activity logs for one year.
- **What people get wrong:** OSP registration no longer exists. Anyone asking you for an OSP certificate is working from 2019.
- **Source:** [PIB, 23 June 2021](https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1729725) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#dot-osp

#### SEZ Rules 2006, Rule 43A — work from home for IT/ITES units

- **Issuer:** Department of Commerce · **Force:** Law · **For:** Services firms
- **Who it reaches:** IT/ITES units in a Special Economic Zone letting staff work from home.
- **Status:** Inserted 14 July 2022. Up to 50% of employees, contract staff included, with one-year approvals.
- **What it requires:**
  - “SEZ Units will provide equipment and secured connectivity for the purpose of WFH to an employee.”
- **Source:** [SEZ (Amendment) Rules 2022 (via EY, AZB)](https://www.ey.com/en_in/technical/alerts-hub/2022/07/amendments-to-special-economic-zone-rules-2006-work-from-home-permitted-it-ites-sez-units) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#sez-43a

#### MeitY cloud empanelment and Guidelines for Procurement of Cloud Services

- **Issuer:** MeitY · **Force:** Regulator · **For:** Product firms
- **Who it reaches:** If you sell SaaS to Indian government departments (or resell cloud to them as an MSP or SI).
- **Status:** Current guidelines dated March 2026.
- **What it requires:**
  - Offer the service only from STQC-audited data centres, with all data processing inside India.
  - Encryption at rest, in transit and in processing; data-loss prevention; directory integration and role-based access; ISO/IEC 27018.
- **Source:** [MeitY Guidelines for Procurement of Cloud Services](https://www.meity.gov.in/static/uploads/2026/03/fea54ec9e544c77abbdb48d0f1da6264.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#meity-cloud

### Via your regulated clients

Rules that bind your bank, insurer or market client — and reach you through the contract they must sign with you.

#### RBI Managing Risks in Outsourcing Directions 2025

- **Issuer:** Reserve Bank of India · **Force:** Via your client · **For:** Both
- **Who it reaches:** If a bank or NBFC is your client. It replaced the 2023 IT-outsourcing Master Direction on 28 November 2025, issued separately for each type of regulated entity.
- **Status:** In force. Existing agreements had to comply at renewal or by 10 April 2026, whichever came first.
- **What it requires:**
  - Report cyber incidents to the bank without undue delay, so the bank can report to the RBI within six hours of detection by you (para 56).
  - Accept audit and inspection — by the bank and by the RBI — of you and your subcontractors (para 69).
  - Keep the bank’s data separated and isolated, accessible only to people the bank authorises (para 65).
  - Store data only in India where regulation requires it; for an outsourced SOC, the bank keeps ownership of rules, logs and analytics (para 90).
- **Reporting clock:** 6 hours from detection by you, the service provider, to the RBI, via your bank client.
- **What people get wrong:** Most vendor contracts still cite the April 2023 Master Direction. It has been repealed — the 2025 Directions are the ones your client is now inspected against.
- **Source:** [RBI (Commercial Banks – Managing Risks in Outsourcing) Directions 2025](https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13139) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#rbi-outsourcing

#### RBI Master Direction: Storage of Payment System Data

- **Issuer:** Reserve Bank of India · **Force:** Via your client · **For:** Both
- **Who it reaches:** If you process for a payment system operator — as a vendor, gateway or SaaS.
- **Status:** RBI/2017-18/153, 6 April 2018 — still listed by the RBI as a current Master Direction.
- **What it requires:**
  - Store the entire data relating to payment systems only in India — this explicitly covers third-party vendors.
  - A system audit report by a CERT-In-empanelled auditor.
- **Source:** [RBI Master Direction RBI/2017-18/153](https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11244) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#rbi-payment-data

#### SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)

- **Issuer:** SEBI · **Force:** Via your client · **For:** Both
- **Who it reaches:** If a broker, AMC, depository, exchange or other SEBI-regulated entity is your client or customer.
- **Status:** Circular 20 August 2024; compliance extended to 31 August 2025 for most entities. Data localisation still under consultation.
- **What it requires:**
  - Follow “similar or higher” security standards to your regulated client (FAQ 40).
  - ISO/IEC 27001 certification if you run their outsourced data centre, DR or SOC (FAQ 58).
  - An SBOM for any software used in core or critical activities (FAQs 35–37).
  - Encryption keys and key management kept inside India (FAQ 26); VAPT closure timelines in the SLA.
- **Source:** [SEBI CSCRF FAQs, June 2025](https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#sebi-cscrf

#### IRDAI Information and Cybersecurity Guidelines 2026

- **Issuer:** IRDAI · **Force:** Via your client · **For:** Both
- **Who it reaches:** If an insurer, broker or TPA is your client — claims and policy-servicing BPOs especially, and insurtech SaaS.
- **Status:** Reissued on 6 April 2026, replacing the 2023 edition. We have not been able to read the 2026 text itself, so what follows is the 2023 edition’s floor, not the full list.
- **What it requires:**
  - The 2023 edition required reporting cyber incidents to IRDAI within six hours, ICT logs and critical data kept in India for intermediaries, and audit, access and exit rights over outsourced vendors.
  - Expect the same or stricter in your insurer client’s contract — and confirm against the 2026 Guidelines before relying on any detail.
- **What people get wrong:** Contracts drafted before April 2026 cite the 2023 Guidelines, which have been replaced.
- **Source:** [IRDAI Guidelines, 6 April 2026](https://irdai.gov.in/en/document-detail?documentId=9189223) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#irdai

### What buyers demand

Certifications and agreements that are not law, but without which the deal does not close.

#### ISO/IEC 27001:2022

- **Issuer:** ISO/IEC · **Force:** Buyers demand it · **For:** Both
- **Who it reaches:** Practically always — the baseline ask in nearly every RFP, from either side of the industry.
- **Status:** The transition from the 2013 edition ended on 31 October 2025. A 2013 certificate has lapsed.
- **What it requires:**
  - An information-security management system, with the evidence an external auditor can test.
- **What people get wrong:** If your certificate still says 27001:2013, you are not certified — the auditor treats you as a new client.
- **Source:** [IAF MD 26 transition (via certification bodies)](https://www.iso.org/standard/27001) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#iso-27001

#### SOC 2 Type I and Type II

- **Issuer:** AICPA · **Force:** Buyers demand it · **For:** Both
- **Who it reaches:** If you sell to US companies. For a SaaS firm it is the de facto enterprise sales gate; MSPs and BPOs with US clients get asked too.
- **Status:** 2017 Trust Services Criteria, points of focus revised 2022. Type II covers a period, usually 6–12 months.
- **What it requires:**
  - Controls over access, change, logging and monitoring, vendors, incident response and backup — tested over time for Type II.
- **Source:** [AICPA Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#soc-2

#### PCI DSS v4.0.1

- **Issuer:** PCI Security Standards Council · **Force:** Buyers demand it · **For:** Both
- **Who it reaches:** If you take, see or store card data — voice-payment BPOs, service providers to merchants, payments SaaS.
- **Status:** v4.0.1 published June 2024. The 51 future-dated requirements became mandatory on 31 March 2025.
- **What it requires:**
  - Multi-factor authentication for all access into the cardholder data environment.
  - Integrity monitoring of scripts on payment pages (6.4.3, 11.6.1).
  - Authenticated internal vulnerability scanning; DTMF masking or pause-and-resume for card details taken by phone.
- **Source:** [PCI DSS v4.0.1 (via QSAs)](https://www.pcisecuritystandards.org/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#pci-dss

#### HIPAA Business Associate obligations

- **Issuer:** US HHS · **Force:** Via your client · **For:** Both
- **Who it reaches:** If you handle US patient data — medical coding, revenue-cycle management, transcription, health SaaS. You are a business associate, bound by the agreement and directly by the Security Rule.
- **Status:** In force. The proposed Security Rule overhaul (January 2025) has not been finalised.
- **What it requires:**
  - Security Rule safeguards: risk analysis, access control, audit controls, integrity and transmission security.
  - Notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days after discovery.
- **Reporting clock:** ≤ 60 days from discovery of the breach, to your covered-entity client.
- **Source:** [45 CFR 164.410](https://www.law.cornell.edu/cfr/text/45/164.410) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#hipaa

#### ISO/IEC 42001:2023 — AI management system

- **Issuer:** ISO/IEC · **Force:** Buyers demand it · **For:** Both
- **Who it reaches:** If you ship AI features or deliver AI work for clients, especially into the EU.
- **Status:** Published 18 December 2023. The evidence layer most buyers accept for AI governance.
- **What it requires:**
  - A management system for how you develop, provide and use AI — risk, data, oversight, monitoring.
- **Source:** [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#iso-42001

### Foreign law that reaches you

EU, UK and US rules that apply to Indian firms through the clients or customers they serve there.

#### EU GDPR (Articles 28, 32, 33) and UK GDPR

- **Issuer:** EU; UK · **Force:** Law · **For:** Both
- **Who it reaches:** If you process EU or UK personal data — as a processor for clients, or as a controller offering services to people there.
- **Status:** In force. India has no EU adequacy decision, so transfers run on the 2021 Standard Contractual Clauses; the UK’s new transfer test applies from 5 February 2026.
- **What it requires:**
  - Processor contract terms: documented instructions, Article 32 security, sub-processor approval, audits.
  - As a processor, notify the controller of a breach without undue delay; the controller has 72 hours to tell the authority.
- **Reporting clock:** Without undue delay from becoming aware (processor → controller), to your client, the controller.
- **Source:** [Regulation (EU) 2016/679; Decision (EU) 2021/914](https://eur-lex.europa.eu/eli/reg/2016/679/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#gdpr

#### EU NIS2 Directive (2022/2555)

- **Issuer:** European Union · **Force:** Law · **For:** Both
- **Who it reaches:** Through your EU clients’ supply-chain duties — and directly if you are a managed service, managed security or cloud provider serving the EU, which may need an EU representative (Article 26(3)).
- **Status:** Transposition deadline 17 October 2024; national laws still being completed in some member states.
- **What it requires:**
  - Supply-chain security clauses, questionnaires and audits from in-scope EU clients (Article 21(2)(d)).
  - For in-scope entities: a 24-hour early warning, a 72-hour notification and a one-month final report.
- **Reporting clock:** 24 hours from becoming aware of a significant incident, to the national CSIRT (early warning).
- **Source:** [Directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#nis2

#### EU Digital Operational Resilience Act (DORA)

- **Issuer:** European Union · **Force:** Via your client · **For:** Services firms
- **Who it reaches:** If an EU bank, insurer or investment firm is your client.
- **Status:** Applies from 17 January 2025. The first list of critical ICT third-party providers (18 November 2025) includes Tata Consultancy Services.
- **What it requires:**
  - Article 30 contract terms: audit and access rights, incident assistance, exit plans, and taking part in threat-led penetration testing.
- **Source:** [Regulation (EU) 2022/2554; EBA press release, 18 Nov 2025](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#dora

#### EU Cyber Resilience Act (2024/2847)

- **Issuer:** European Union · **Force:** Law · **For:** Product firms
- **Who it reaches:** If you sell installable software — desktop, on-premise, mobile apps, agents — in the EU. Pure SaaS is generally outside it (NIS2 covers that).
- **Status:** Reporting obligations live since 11 September 2026. Full application, including SBOM and CE marking, from 11 December 2027.
- **What it requires:**
  - Report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification, then a final report.
  - From December 2027: an SBOM, vulnerability handling for the support period, and security by design.
- **Reporting clock:** 24 hours from becoming aware of an actively exploited vulnerability, to ENISA’s single reporting platform.
- **What people get wrong:** The headline date most people quote is 2027. The reporting clock started in September 2026.
- **Source:** [European Commission — CRA reporting](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#eu-cra

#### EU AI Act, as amended by the Digital Omnibus on AI

- **Issuer:** European Union · **Force:** Law · **For:** Product firms
- **Who it reaches:** If you place AI systems on the EU market, or build them for EU clients.
- **Status:** Transparency duties from 2 August 2026. High-risk obligations — recruitment, credit scoring and education among them — deferred to 2 December 2027.
- **What it requires:**
  - AI governance, logging and human oversight; labelling of AI-generated content.
- **Source:** [Digital Omnibus agreement (via Gibson Dunn)](https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#eu-ai-act

#### US federal secure-software attestation (OMB M-26-05)

- **Issuer:** US Office of Management and Budget · **Force:** Regulator · **For:** Product firms
- **Who it reaches:** If you sell software to US federal agencies or their prime contractors.
- **Status:** The mandatory attestation was rescinded on 23 January 2026. Agencies now set their own requirements and may still ask for an SBOM.
- **What it requires:**
  - Whatever the agency asks for — often an SBOM or the (now optional) secure-development attestation.
- **What people get wrong:** Do not let a consultant sell you the attestation as mandatory. It has not been since January 2026.
- **Source:** [OMB M-26-05](https://www.whitehouse.gov/wp-content/uploads/2026/01/M-26-05-Adopting-a-Risk-based-Approach-to-Software-and-Hardware-Security.pdf) — read from the primary text, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#us-secure-software

#### US DoD CMMC 2.0

- **Issuer:** US Department of Defense · **Force:** Via your client · **For:** Services firms
- **Who it reaches:** If you do engineering or IT work in the US defence supply chain and handle controlled unclassified information.
- **Status:** Rule effective 10 November 2025; third-party Level 2 assessments in new contracts from 10 November 2026.
- **What it requires:**
  - The NIST SP 800-171 controls, assessed by an accredited third party at Level 2.
- **Source:** [DFARS CMMC final rule (via GRF CPA)](https://www.grfcpa.com/resource/dfars-publishes-final-rule-on-cmmc-effective-november-10/) — two or more reputable secondary sources, verified 2026-10-05.
- **Card:** https://www.thetechbag.com/industries/it-ites/obligations#cmmc

## The 29 controls, and what answers each

### Shared by both halves

Every firm in the industry needs these, whichever half it is in.

#### Detect and respond inside six hours

- **What it is:** Endpoint detection and response, or a managed service that watches it 24×7.
- **Why it matters here:** Every Indian clock on this page starts at detection — CERT-In’s, and a bank client’s. You cannot report in six hours what you find in six days. CircleCI’s 2022 breach began with malware that antivirus missed on one engineer’s laptop.
- **What a client or auditor asks to see:** Coverage across every endpoint and server, 24×7 monitoring (in-house or MDR), and a dated record of detection-to-report times from your last incidents or drills.
- **Required by:** CERT-In, RBI outsourcing, IRDAI, NIS2
- **What answers it:** [Endpoint protection guide](https://www.thetechbag.com/browse/security/endpoint-protection), [Managed detection & response guide](https://www.thetechbag.com/browse/security/managed-detection-response)

#### Logs kept, and producible

- **What it is:** Central log management or SIEM with retention set to the longest clock you owe.
- **Why it matters here:** CERT-In wants 180 days of logs from every ICT system; the DPDP Rules want at least a year for personal-data processing — including processing you do as someone else’s processor. Voice BPOs owe a year of call records under the OSP rules.
- **What a client or auditor asks to see:** Retention settings per log source, NTP synchronisation to an NIC/NPL-traceable source, and a test retrieval of a six-month-old log.
- **Required by:** CERT-In, DPDP, DoT OSP, RBI outsourcing, IRDAI, SOC 2, HIPAA, CMMC
- **What answers it:** [SIEM & log management guide](https://www.thetechbag.com/browse/security/siem-log-management)

#### Phishing-resistant sign-in

- **What it is:** Single sign-on everywhere, with FIDO2 or passkey MFA that a phone call cannot reset.
- **Why it matters here:** Help-desk impersonation and stolen sessions are how firms in this industry get breached. The Snowflake intrusions of 2024 succeeded on accounts with no MFA at all; CISA’s guidance on the help-desk attackers is phishing-resistant MFA.
- **What a client or auditor asks to see:** MFA coverage across workforce and admin accounts, which methods are allowed, and how a lost authenticator is replaced.
- **Required by:** DPDP, PCI DSS, HIPAA, CMMC
- **What answers it:** [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa)

#### Access that ends when the job does

- **What it is:** Identity governance: automated joiner-mover-leaver, contractors included, with access reviews.
- **Why it matters here:** Attrition runs at 13–15% at the largest firms, and contract staff are a large share of delivery. KiranaPro’s servers and code were wiped in 2025 through a former employee’s access that was never revoked.
- **What a client or auditor asks to see:** Time from exit to access removal, quarterly access reviews signed off by owners, and how contractor accounts expire.
- **Required by:** SOC 2
- **What answers it:** [Identity governance guide](https://www.thetechbag.com/browse/identity-access/identity-governance)

#### Managed devices only

- **What it is:** Unified endpoint management, so work happens only on devices you can see, patch and wipe.
- **Why it matters here:** Mandiant traced the Snowflake intrusions to infostealers on contractor laptops also used for gaming and pirated software. SEZ units must provide the equipment for work from home.
- **What a client or auditor asks to see:** Device inventory against headcount, encryption and patch compliance, and the policy for personal devices.
- **Required by:** SEZ 43A
- **What answers it:** [UEM & MDM guide](https://www.thetechbag.com/browse/endpoint-management/uem-mdm)

#### Email security and phishing training

- **What it is:** A secure email gateway or API-based protection, with awareness training that tests people.
- **Why it matters here:** Phishing — including voice and SMS — is the most common way in for Indian breaches (IBM, 2026). Wipro’s 2019 intrusion began with a phished employee.
- **What a client or auditor asks to see:** Phishing simulation results over time, DMARC enforcement, and training completion.
- **What answers it:** [Email security guide](https://www.thetechbag.com/browse/security/email-security), [Proofpoint Security Awareness](https://www.thetechbag.com/proofpoint/proofpoint-awareness-training), [Mimecast Engage](https://www.thetechbag.com/mimecast/mimecast-engage), [Arctic Wolf Security Awareness](https://www.thetechbag.com/arcticwolf/arcticwolf-security-awareness-training), [TitanHQ SAT](https://www.thetechbag.com/titanhq/titanhq-sat)

#### Backups the attacker cannot reach

- **What it is:** Immutable or air-gapped backup, including Microsoft 365 and Google Workspace, with tested restores.
- **Why it matters here:** Ransomware is the incident that stops delivery. Your books of account must be backed up daily in India, and DPDP lists backups among the required safeguards.
- **What a client or auditor asks to see:** Immutability settings, an India copy for books of account, and the date and duration of the last full restore test.
- **Required by:** DPDP, Companies Act, NIS2, DORA
- **What answers it:** [Backup & recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/backup-recovery), [SaaS backup guide](https://www.thetechbag.com/browse/backup-cyber-resilience/saas-backup), [Cyber recovery guide](https://www.thetechbag.com/browse/backup-cyber-resilience/cyber-recovery)

#### Vulnerability management and VAPT

- **What it is:** Continuous scanning and exposure management, plus annual penetration testing.
- **Why it matters here:** Kaseya, MOVEit and SimpleHelp were all internet-facing tools exploited at scale. Regulated clients increasingly ask for an annual audit by a CERT-In-empanelled auditor.
- **What a client or auditor asks to see:** Scan coverage, time to fix critical findings, and the last VAPT report with closure evidence.
- **Required by:** CERT-In audit, RBI payment data, SEBI CSCRF, PCI DSS, DORA
- **What answers it:** [Vulnerability management guide](https://www.thetechbag.com/browse/security/vulnerability-management)
- **Catalogue coverage:** The two VAPT services in our catalogue are not CERT-In-empanelled. If a client needs an empanelled auditor, that is a separate engagement.

#### Audit evidence: ISO 27001, SOC 2

- **What it is:** A GRC or compliance-automation platform that collects evidence continuously instead of before the audit.
- **Why it matters here:** ISO 27001 is the first line of nearly every RFP, and SOC 2 is the gate to US enterprise customers. Every 2013-edition certificate lapsed on 31 October 2025.
- **What a client or auditor asks to see:** A current certificate or report, the scope statement, and how evidence is collected between audits.
- **Required by:** IT Act 43A, CERT-In audit, SEBI CSCRF, ISO 27001, SOC 2, CMMC
- **What answers it:** [OneTrust Tech Risk & Compliance](https://www.thetechbag.com/onetrust/onetrust-tech-risk-compliance), [Mitigata Compliance & GRC](https://www.thetechbag.com/mitigata/mitigata-compliance-grc), [Iru Compliance Automation](https://www.thetechbag.com/iru/iru-compliance-automation), [MetricStream Cyber GRC](https://www.thetechbag.com/metricstream/metricstream-cyber-grc), [Optro Compliance](https://www.thetechbag.com/optro/optro-compliance)
- **Catalogue coverage:** Only three of these automate SOC 2 / ISO 27001 evidence collection; the others are enterprise GRC platforms.

#### Privacy operations for DPDP

- **What it is:** Consent, notices, data-principal requests and a record of processing.
- **Why it matters here:** From May 2027 every firm here is a Data Fiduciary at least for its own employees, and SaaS firms for their users. Grievances must be resolved within 90 days.
- **What a client or auditor asks to see:** A data map, the consent and notice flows, and request-handling times.
- **Required by:** DPDP, GDPR
- **What answers it:** [OneTrust Privacy Automation](https://www.thetechbag.com/onetrust/onetrust-privacy-automation), [OneTrust Consent & Preferences](https://www.thetechbag.com/onetrust/onetrust-consent-preferences), [Securiti Data Privacy](https://www.thetechbag.com/securiti/securiti-data-privacy), [Mitigata Dranta](https://www.thetechbag.com/mitigata/mitigata-dranta), [Seqrite Data Privacy](https://www.thetechbag.com/seqrite/seqrite-data-privacy)

#### Your own suppliers, managed

- **What it is:** Third-party risk management: who your subcontractors are, what they can reach, and what they have promised.
- **Why it matters here:** The RBI can now inspect your subcontractors, DORA and NIS2 push supply-chain clauses down to you, and the 2024 C-Edge outage reportedly began at a partner’s misconfigured build server.
- **What a client or auditor asks to see:** A register of subcontractors and SaaS tools with their access, back-to-back contract clauses, and periodic reviews.
- **Required by:** DPDP, CERT-In audit, RBI outsourcing, IRDAI, SOC 2, GDPR, NIS2, DORA
- **What answers it:** [OneTrust Third-Party Management](https://www.thetechbag.com/onetrust/onetrust-third-party-management), [Optro IT & Cyber Risk](https://www.thetechbag.com/optro/optro-it-cyber-risk)
- **Catalogue coverage:** Thin: two products in our catalogue. Most firms this size run supplier risk in their GRC platform.

#### Client and customer data, encrypted and found

- **What it is:** Data discovery and posture management, encryption with keys you control, tokenisation where it fits.
- **Why it matters here:** DPDP names encryption, masking and tokenisation; SEBI wants keys managed in India; GDPR transfers to India rely on safeguards because there is no adequacy decision.
- **What a client or auditor asks to see:** Where sensitive data lives, how it is encrypted, who holds the keys, and where.
- **Required by:** DPDP, MeitY cloud, RBI payment data, SEBI CSCRF, HIPAA, GDPR
- **What answers it:** [DSPM & data discovery guide](https://www.thetechbag.com/browse/data-security-privacy/dspm), [Encryption & rights management guide](https://www.thetechbag.com/browse/data-security-privacy/encryption-rights)

### Services firms

For firms that work inside their clients’ environments.

#### Privileged access into client environments

- **What it is:** Privileged access management with vaulted credentials, just-in-time access and session recording.
- **Why it matters here:** Your engineers hold the keys to someone else’s estate. Cloud Hopper went through service providers’ jump servers into their clients; the RBI requires that only people the bank authorises can reach its data.
- **What a client or auditor asks to see:** Who can reach which client, through what, with recordings of privileged sessions and per-client separation.
- **Required by:** RBI outsourcing
- **What answers it:** [Privileged access management guide](https://www.thetechbag.com/browse/identity-access/privileged-access-management)

#### Zero-trust access for distributed delivery

- **What it is:** ZTNA or SASE in place of the flat VPN, so a home laptop reaches one client’s apps and nothing else.
- **Why it matters here:** Hybrid delivery is the norm and SEZ units must provide “secured connectivity” for work from home. A VPN that drops a laptop onto the whole network is how one infection becomes a client incident.
- **What a client or auditor asks to see:** Per-application access policies, device-posture checks, and the absence of standing network-level access.
- **Required by:** SEZ 43A
- **What answers it:** [Zero-trust access guide](https://www.thetechbag.com/browse/network-security-sase/zero-trust-access), [SASE & SSE guide](https://www.thetechbag.com/browse/network-security-sase/sase-sse)

#### Leakage and insider risk on delivery floors

- **What it is:** Data-loss prevention and insider-risk monitoring sized for support and operations teams.
- **Why it matters here:** In 2025 Coinbase disclosed that overseas support agents were bribed to pull customer data; Reuters reported an Indore BPO employee photographing her screen. Coinbase put its costs at $180–400 million.
- **What a client or auditor asks to see:** Masking of customer data in support tools, DLP policies by role, and how anomalous access is investigated.
- **Required by:** MeitY cloud
- **What answers it:** [DLP & insider risk guide](https://www.thetechbag.com/browse/data-security-privacy/dlp-insider-risk)

#### Isolated client workspaces

- **What it is:** Virtual desktops or a secure enterprise browser, so client data and code never land on the laptop.
- **Why it matters here:** HCLTech’s 2023 ransomware incident stayed inside one project’s isolated cloud environment. Isolation per client is what keeps one engagement’s incident from becoming every client’s.
- **What a client or auditor asks to see:** How each client’s environment is separated, and whether data can be copied out of it.
- **Required by:** RBI outsourcing
- **What answers it:** [Citrix DaaS](https://www.thetechbag.com/citrix/citrix-daas), [Citrix SecurSpaces](https://www.thetechbag.com/citrix/citrix-securspaces), [Prisma Access Browser](https://www.thetechbag.com/palo-alto/prisma-access-browser), [Menlo Secure Enterprise Browser](https://www.thetechbag.com/menlo-security/menlo-security-secure-enterprise-browser), [Akamai Guardicore Segmentation](https://www.thetechbag.com/akamai/akamai-guardicore-segmentation)
- **Catalogue coverage:** Virtual desktops in our catalogue are Citrix only.

#### Your remote-management tools, locked down

- **What it is:** RMM, PSA and remote support — kept off the open internet, patched, and behind MFA.
- **Why it matters here:** Kaseya VSA reached about 1,500 downstream businesses through fewer than 60 MSPs in 2021; CISA warned in 2025 of attackers using an unpatched RMM to reach a provider’s customers. Your tools are their tools.
- **What a client or auditor asks to see:** An inventory of every remote-access tool in use, how consoles are exposed, and MFA on technician accounts.
- **Required by:** NIS2
- **What answers it:** [RMM & patch guide](https://www.thetechbag.com/browse/endpoint-management/rmm-patch), [Remote access & support guide](https://www.thetechbag.com/browse/endpoint-management/remote-access)

#### Contact-centre and BPO operations

- **What it is:** The contact-centre, workforce-management and quality stack — with call records kept and card details masked.
- **Why it matters here:** Voice BPOs owe a year of call records under the OSP rules, and any centre taking card payments must keep card numbers out of recordings under PCI DSS.
- **What a client or auditor asks to see:** Call-record retention, how card details are captured, and agent access to customer data.
- **Required by:** DoT OSP, PCI DSS
- **What answers it:** [Zendesk Contact Center](https://www.thetechbag.com/zendesk/zendesk-contact-center), [Zoom Contact Center](https://www.thetechbag.com/zoom/zoom-contact-center), [Zendesk WFM](https://www.thetechbag.com/zendesk/zendesk-wfm), [Zendesk QA](https://www.thetechbag.com/zendesk/zendesk-qa), [Freshdesk](https://www.thetechbag.com/freshworks/freshdesk), [Zoho Desk](https://www.thetechbag.com/zoho/zoho-desk)
- **Catalogue coverage:** Thin: our contact-centre coverage is Zendesk and Zoom, and nothing we list does DTMF masking for card payments.

### Product firms

For firms that ship software other people run.

#### Source code and the build pipeline

- **What it is:** A hardened Git platform and CI/CD: SSO on every account, protected branches, isolated runners, nothing internet-facing that need not be.
- **Why it matters here:** Codecov’s tampered uploader sent customers’ CI secrets to an attacker; the 2024 C-Edge outage that hit about 300 small banks reportedly began at a partner’s misconfigured Jenkins server; the 2025 Salesloft Drift token theft started in Salesloft’s GitHub account.
- **What a client or auditor asks to see:** Branch protection, who can approve and deploy, how runners are isolated, and SSO and MFA on the code platform.
- **Required by:** EU CRA
- **What answers it:** [Developer tools guide](https://www.thetechbag.com/browse/devops/developer-tools)

#### Dependencies you can account for

- **What it is:** Software composition analysis, an SBOM per release, and a repository firewall in front of npm and PyPI.
- **Why it matters here:** The xz-utils backdoor (2024) and the Shai-Hulud npm worm (2025) came in through dependencies, and a ManageEngine flaw exploited in the wild came from an outdated third-party library. The EU CRA, SEBI’s buyers and US agencies now ask for the SBOM.
- **What a client or auditor asks to see:** An SBOM per release, the policy for new and vulnerable dependencies, and time to patch a disclosed vulnerability.
- **Required by:** CERT-In SBOM, SEBI CSCRF, EU CRA, US attestation
- **What answers it:** [Developer tools guide](https://www.thetechbag.com/browse/devops/developer-tools), [Sonatype Repository Firewall](https://www.thetechbag.com/sonatype/sonatype-repository-firewall), [JFrog Xray](https://www.thetechbag.com/jfrog/jfrog-xray), [JFrog Curation](https://www.thetechbag.com/jfrog/jfrog-curation), [SonarQube Advanced Security](https://www.thetechbag.com/sonar/sonarqube-advanced-security)

#### Secrets and signing keys out of the code

- **What it is:** A secrets vault with short-lived credentials, secret scanning in commits, and protected code-signing keys.
- **Why it matters here:** 29 million new hardcoded secrets reached public GitHub in 2025 (GitGuardian). CircleCI told every customer to rotate every secret after one stolen session.
- **What a client or auditor asks to see:** Where secrets are stored, how long they live, scanning results, and who can sign a release.
- **Required by:** EU CRA
- **What answers it:** [Encryption & rights management guide](https://www.thetechbag.com/browse/data-security-privacy/encryption-rights), [HashiCorp Vault](https://www.thetechbag.com/hashicorp/hashicorp-vault), [CyberArk Secrets Manager](https://www.thetechbag.com/cyberark/cyberark-secrets-manager), [Delinea DevOps Secrets Vault](https://www.thetechbag.com/delinea/delinea-devops-secrets-vault), [CyberArk Machine Identity Security](https://www.thetechbag.com/cyberark/cyberark-machine-identity-security)
- **Catalogue coverage:** Code signing is thin: one dedicated product, plus PKI from Entrust and eMudhra.

#### Cloud posture and workloads

- **What it is:** Cloud-native application protection: misconfiguration, identities and entitlements, and runtime threats.
- **Why it matters here:** Your product runs in the cloud and a customer’s security review will ask how you know it is configured safely. KiranaPro’s attacker replaced MFA on the AWS root account.
- **What a client or auditor asks to see:** Posture findings over time, root and admin account protection, and least-privilege cloud roles.
- **Required by:** MeitY cloud
- **What answers it:** [Cloud & workload security guide](https://www.thetechbag.com/browse/security/cloud-workload-security)

#### Application and API protection

- **What it is:** WAF and API security, bot and DDoS defence, and payment-page script monitoring.
- **Why it matters here:** MOVEit was an internet-facing application exploited at 2,773 organisations. If you take card payments, PCI DSS now requires integrity monitoring of payment-page scripts.
- **What a client or auditor asks to see:** WAF and API inventory coverage, DDoS protection, and script monitoring on payment pages.
- **Required by:** PCI DSS
- **What answers it:** [Akamai App & API Protector](https://www.thetechbag.com/akamai/akamai-app-api-protector), [Cloudflare Application Security](https://www.thetechbag.com/cloudflare/cloudflare-application-security), [F5 Distributed Cloud WAAP](https://www.thetechbag.com/f5/f5-distributed-cloud-waap), [Akamai API Security](https://www.thetechbag.com/akamai/akamai-api-security), [Levo](https://www.thetechbag.com/product/levo), [Akamai Bot Manager](https://www.thetechbag.com/akamai/akamai-bot-manager), [Akamai Prolexic](https://www.thetechbag.com/akamai/akamai-prolexic), [Akamai Client-Side Protection](https://www.thetechbag.com/akamai/akamai-client-side-protection)

#### Customer identity and account protection

- **What it is:** Sign-in, MFA and account-takeover defence for your own customers.
- **Why it matters here:** Credential stuffing and session theft against your users become your incident and, under DPDP, your notification.
- **What a client or auditor asks to see:** MFA options offered to customers, account-takeover detection, and session lifetimes.
- **What answers it:** [IAM, SSO & MFA guide](https://www.thetechbag.com/browse/identity-access/iam-sso-mfa), [Okta Customer Identity](https://www.thetechbag.com/okta/okta-customer-identity), [miniOrange CIAM](https://www.thetechbag.com/miniorange/miniorange-ciam), [Akamai Account Protector](https://www.thetechbag.com/akamai/akamai-account-protector)
- **Catalogue coverage:** Thin: three products in our catalogue.

#### AI features, secured and governed

- **What it is:** Guardrails and firewalls for the AI you ship, and governance that maps to ISO 42001 and the EU AI Act.
- **Why it matters here:** EU transparency duties apply from August 2026, high-risk duties from December 2027 — and AI used in recruitment, credit scoring or education is classed high-risk.
- **What a client or auditor asks to see:** An inventory of models and AI features, guardrail policies, and how AI-generated content is labelled.
- **Required by:** ISO 42001, EU AI Act
- **What answers it:** [Prisma AIRS](https://www.thetechbag.com/palo-alto/prisma-airs), [F5 AI Guardrails](https://www.thetechbag.com/f5/f5-ai-guardrails), [Akamai Firewall for AI](https://www.thetechbag.com/akamai/akamai-firewall-for-ai), [Trend Micro AI Security](https://www.thetechbag.com/trendmicro/trendmicro-ai-security), [Kong AI Gateway](https://www.thetechbag.com/kong/kong-ai-gateway), [OneTrust AI Governance](https://www.thetechbag.com/onetrust/onetrust-ai-governance)

### What no software answers

Procedure, hiring, a runbook and a contract — where the 2023–25 attacks got in.

#### Verifying the caller before a reset

- **What it is:** A help-desk procedure that proves who is asking before any password or MFA reset.
- **Why it matters here:** This is the attack of 2023–25. Clorox alleges in its lawsuit that Cognizant’s help desk reset credentials without verification; Co-op’s attackers called its help desk; the UK’s NCSC told firms to review reset processes.
- **What a client or auditor asks to see:** The written reset procedure, call-back or manager-approval records, and alerts on resets of privileged accounts.
- **Not answered by software:** A procedure and a culture: call back on a number already on record, require manager approval for privileged accounts, and use phishing-resistant MFA so a reset alone is not enough. We list no product that verifies callers.

#### Knowing who you hired

- **What it is:** Identity and background verification at offer and onboarding, with in-person or verified-video steps for privileged roles.
- **Why it matters here:** AuthBridge found discrepancies in 9.46% of IT/ITES candidates it checked (2024–25). The US Justice Department found North Korean IT workers inside more than 100 US companies in 2025.
- **What a client or auditor asks to see:** Verification at offer, liveness checks for remote hires, and least-privilege access in the first weeks.
- **Required by:** IRDAI
- **Not answered by software:** Background-verification firms and a hiring process. We list no employee-verification product — the KYC tools in our catalogue verify customers, not candidates.

#### The six-hour runbook

- **What it is:** Who calls CERT-In, who calls each client, in what order, with what.
- **Why it matters here:** One incident can start several clocks to several recipients — and filing one does not discharge another.
- **What a client or auditor asks to see:** A runbook naming owners and recipients per client, and the date of the last drill.
- **Required by:** CERT-In, EU CRA
- **Not answered by software:** A document, a contact list and a rehearsal. Software can collect the evidence; it cannot make the calls.

#### The clauses you sign

- **What it is:** Audit rights, data location, subcontractor flow-down and incident terms — in your client contracts and your customers’ DPAs.
- **Why it matters here:** Most of what binds a services firm arrives in a client’s contract; most of what binds a SaaS firm arrives in a customer’s data-processing agreement.
- **What a client or auditor asks to see:** A clause register across client contracts, mapped to what you can actually deliver.
- **Required by:** RBI outsourcing, GDPR, DORA
- **Not answered by software:** Legal and commercial work. Contract tools can store the clauses; only you can negotiate them.

## How firms like yours actually get breached

### The help desk resets the attacker’s password (Services firms)

A caller impersonates an employee, the service desk resets the password and MFA, and the attacker walks in with valid credentials. Path: Caller poses as staff → Desk resets password + MFA → Attacker signs in.

- **Clorox v. Cognizant** (2023 incident; suit filed July 2025): Clorox alleges its outsourced help desk reset passwords and MFA for callers without verifying them, and is seeking $380 million. Cognizant: it was hired for “a narrow scope of help desk services which Cognizant reasonably performed” and “did not manage cybersecurity for Clorox”. These are allegations in litigation. Source: [The Record](https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor)
- **Co-op (UK)** (April 2025): Attackers called the IT help desk impersonating employees to obtain password resets; data on all 6.5 million members was taken. Source: [LBC, citing BleepingComputer](https://www.lbc.co.uk/article/co-op-marks-spencer-cyberattackers-tricked-it-workers-5Hjd6LG_2/)
- **CISA advisory AA23-320A** (Revised July 2025): The group behind these attacks “targets large companies and their contracted information technology (IT) help desks”. Source: [CISA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a)
- **Stops it:** Verifying the caller before a reset, Phishing-resistant sign-in, Privileged access into client environments

### Your remote tool becomes their remote tool (Services firms)

The software you use to manage clients — RMM, remote support, jump servers — is exploited or abused to reach every client at once. Path: Remote tool exposed → Console taken over → Pushed to every client.

- **Kaseya VSA** (July 2021): A zero-day in the RMM tool MSPs use pushed ransomware through fewer than 60 MSPs to fewer than 1,500 downstream businesses. Source: [The Record](https://therecord.media/kaseya-more-than-1500-downstream-businesses-impacted-by-ransomware-attack)
- **Wipro** (2019): KrebsOnSecurity reported that phished employee accounts were used to target customers, with a remote-access tool seeded on more than 100 endpoints. Wipro: “We detected a potentially abnormal activity in a few employee accounts on our network due to an advanced phishing campaign.” Source: [KrebsOnSecurity](https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/)
- **CISA advisory AA25-163A** (June 2025): Ransomware actors used an unpatched SimpleHelp RMM at a software provider to reach that provider’s downstream customers. Source: [CISA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a)
- **Stops it:** Your remote-management tools, locked down, Vulnerability management and VAPT, Privileged access into client environments, Zero-trust access for distributed delivery, Email security and phishing training

### The insider is paid (Services firms)

Support or operations staff with broad access to customer records are bribed to copy them out. Path: Agent is bribed → Records copied out → Data sold on.

- **Coinbase** (Disclosed May 2025): Coinbase disclosed that support agents outside the US were bribed to pull customer data, and put its costs at $180–400 million. Reuters reported an India-based TaskUs employee photographing her screen. Source: [The Register](https://www.theregister.com/2025/05/15/coinbase_extorted_for_20m_support/)
- **Stops it:** Leakage and insider risk on delivery floors, Isolated client workspaces, Client and customer data, encrypted and found

### The build pipeline ships the breach (Product firms)

An attacker who reaches your CI/CD or code platform reaches every secret in it — and every customer downstream. Path: CI server reached → Secrets harvested → Customers hit downstream.

- **Codecov** (2021): A tampered uploader script sent customers’ CI environment variables — tokens and keys — to the attacker for two months. Source: [Codecov](https://about.codecov.io/security-update/)
- **C-Edge Technologies** (July 2024): Ransomware at the banking-technology provider disrupted payments at about 300 small Indian banks; analysts reported it began at a misconfigured Jenkins server at a partner. Source: [CSO Online](https://www.csoonline.com/article/3480250/over-300-indian-banks-suffer-payment-disruption-from-ransomware-attack.html)
- **CircleCI** (December 2022): Malware that antivirus missed stole an engineer’s MFA-backed session; every customer was told to rotate every secret. Source: [CircleCI incident report](https://circleci.com/blog/jan-4-2023-incident-report)
- **Stops it:** Source code and the build pipeline, Secrets and signing keys out of the code, Detect and respond inside six hours

### The code you didn’t write (Product firms)

A dependency is backdoored, hijacked or simply outdated, and your product ships the attacker’s code. Path: Dependency backdoored → Pulled into your build → Shipped to customers.

- **xz-utils** (March 2024): A maintainer persona built trust over years, then hid a backdoor targeting SSH authentication; it was caught just before wide distribution. Source: [Tarlogic](https://www.tarlogic.com/blog/cve-2024-3094-backdoor-xz-utils-library/)
- **Shai-Hulud npm worm** (September and November 2025): A self-replicating worm compromised hundreds of npm packages and stole developer and cloud credentials; CISA told developers to require phishing-resistant MFA on GitHub and npm. Source: [CISA](https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem)
- **Zoho ManageEngine (CVE-2022-47966)** (Disclosed January 2023): A bundled Apache Santuario library about a decade old left many on-premise ManageEngine products open to unauthenticated code execution; it was exploited in the wild. Source: [Flashpoint](https://flashpoint.io/blog/manageengine-apache-santuario-cve-2022-47966)
- **Stops it:** Dependencies you can account for, Source code and the build pipeline, Vulnerability management and VAPT

### The token in the integration (Product firms)

Long-lived keys and OAuth tokens — in code, in CI, in a SaaS integration — are found and replayed. Path: Long-lived token found → Replayed via integration → Customer data pulled.

- **Salesloft Drift** (August 2025): Stolen OAuth tokens for the Drift integration were used to pull data from Salesforce instances at 700+ organisations; the intrusion began in Salesloft’s GitHub account months earlier. Source: [SecurityWeek](https://www.securityweek.com/salesloft-github-account-compromised-months-before-salesforce-attack/)
- **GitGuardian, State of Secrets Sprawl** (2026 report): 29 million new hardcoded secrets reached public GitHub in 2025, up 34% — the largest jump recorded. Source: [GitGuardian](https://gitguardian.com/state-of-secrets-sprawl-report-2026)
- **Stops it:** Secrets and signing keys out of the code, Source code and the build pipeline, Customer identity and account protection

### The contractor’s laptop is the way in (Both)

Malware on an unmanaged or personally used device steals the passwords and sessions that open client and production systems. Path: Personal use, work device → Infostealer takes sessions → Signs in to clients.

- **Snowflake customer tenants** (2024): About 165 organisations were hit with stolen credentials on accounts without MFA. Mandiant: the infostealers ran “on contractor systems that were also used for personal activities, including gaming and downloads of pirated software”. Source: [Google Cloud (Mandiant)](https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion)
- **Okta / Sitel** (January 2022): A support contractor’s workstation was taken over through remote desktop; Okta’s final finding was 25 minutes of control and two customer tenants accessed. Source: [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/okta-just-two-customers-lapsus/)
- **Stops it:** Managed devices only, Phishing-resistant sign-in, Detect and respond inside six hours, Isolated client workspaces

### The hire isn’t who they say — or the leaver never left (Both)

A fake candidate is onboarded with real access, or a former employee’s access is never removed. Path: Fake or stale identity → Gets real access → Data or systems taken.

- **North Korean IT workers** (June 2025): The US Justice Department found North Korean IT workers had obtained jobs at more than 100 US companies using stolen identities. Source: [US Department of Justice](https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote)
- **KiranaPro** (May 2025): Servers and code were wiped through a former employee’s access that had never been revoked. Source: [Outlook Business](https://www.outlookbusiness.com/start-up/explainers/kiranapro-crisis-explained-ex-employees-revenge-move-that-paralysed-the-app)
- **Stops it:** Knowing who you hired, Access that ends when the job does, Managed devices only

## What a breach costs here

- **₹35.7 cr** — Average cost of a breach in India’s technology sector — second only to financial services ([IBM Cost of a Data Breach, India 2026](https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026))
- **15%** — Share of Indian breaches that began with a supply-chain compromise ([IBM Cost of a Data Breach, India 2026](https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026))
- **$17.5M** — Infosys McCamish’s class-action settlement after 6.08 million people were notified, agreed without admission of liability ([BankInfoSecurity](https://www.bankinfosecurity.com/infosys-settles-data-breach-class-action-lawsuits-for-175m-a-27746))
- **$50–70M** — Revenue Cognizant expected to lose from 2020 ransomware — some clients disconnected from it as a precaution ([The Week](https://www.theweek.in/news/biz-tech/2020/04/21/cognizant-revenue-to-be-hit-by-maze-ransomware-attack.amp.html))
- **$2bn+** — Market value Okta lost in the days after disclosing that its support system had been breached (October 2023) ([NBC / CNBC](https://www.nbcwashington.com/news/national-international/okta-cybersecurity-breach-wipes-out-more-than-2-billion-in-market-cap/3451258/))
- **144** — Class actions MOVEit’s maker, Progress Software, faced by mid-2024 — plus letters from 38 customers, some seeking indemnification ([Cybersecurity Dive](https://www.cybersecuritydive.com/news/progress-moveit-legal-liabilities/720988/))

## What the market gets wrong

- "Your client reports the incident, not you." — CERT-In says whoever notices it reports it, and the duty cannot be contracted away.
- "DPDP is in force now." — Only the Board is. The operational duties start on 13 May 2027; a proposal to bring that forward has not been notified.
- "Processors face DPDP penalties directly." — The penalty schedule targets Data Fiduciaries. Processors are bound through the contract.
- "CERT-In logs must physically stay in India." — CERT-In’s FAQ allows storage abroad if logs can be produced in reasonable time. RBI, IRDAI and SEBI clients can be stricter.
- "Our contracts follow the RBI’s 2023 IT-outsourcing Master Direction." — It was repealed on 28 November 2025. The Managing Risks in Outsourcing Directions 2025 replaced it.
- "Our insurer clients follow IRDAI’s 2023 cyber guidelines." — IRDAI reissued them on 6 April 2026, replacing the 2023 edition.
- "The EU Cyber Resilience Act starts in 2027." — Its reporting clock started on 11 September 2026. 2027 is full application.
- "CRA covers our SaaS." — Pure SaaS is generally outside the CRA; NIS2 is the law that reaches it.
- "The US secure-software attestation is mandatory." — OMB rescinded the mandate on 23 January 2026.
- "We still need OSP registration." — Abolished on 5 November 2020. Voice BPOs keep one-year call-record and remote-agent log duties.
- "STPI units have their own cyber rules." — We found no STPI-specific cybersecurity mandate.
- "CERT-In’s SBOM guidelines are mandatory." — They are advisory. SEBI’s CSCRF is what makes an SBOM mandatory for regulated buyers.
- "Our ISO 27001:2013 certificate is fine." — The 2013 edition’s transition ended on 31 October 2025.
- "The Digital India Act is coming into force." — No draft bill has been published. It is not law.

## Frequently asked questions

### If an IT services vendor detects a cyber incident in a client's environment, who reports it to CERT-In?

Whoever notices it. CERT-In's FAQ on its 2022 Directions says any entity which notices the incident shall report it within six hours, and that the obligation is neither transferable nor indemnifiable by contract.

### When does a bank's six-hour RBI reporting clock start if its IT vendor detects the incident?

At the vendor's detection. The RBI's Managing Risks in Outsourcing Directions 2025 require the service provider to report to the bank without undue delay so that the bank reports to the RBI within six hours of detection by the service provider.

### Do CERT-In's reporting rules apply to Indian SaaS companies?

Yes. CERT-In's 2022 Directions bind every body corporate, so an incident on a SaaS platform must be reported within six hours of noticing it, and logs kept for 180 days. Under DPDP, a SaaS company is also a Data Fiduciary for its own users' data, with the operational duties applying from 13 May 2027.

### What does CERT-In require for log retention?

Logs of all ICT systems for a rolling 180 days, producible to CERT-In on demand. CERT-In's FAQ allows them to be stored outside India if they can be produced in reasonable time. The DPDP Rules add at least one year for logs of personal-data processing.

### Are IT services firms Data Fiduciaries or Data Processors under the DPDP Act?

Usually processors for their clients' data, bound through the contract — the penalties fall on the Data Fiduciary. But every firm is a Data Fiduciary for its own employees' data. The operational duties apply from 13 May 2027.

### Is ISO 27001:2013 still valid for Indian IT and SaaS companies?

No. The transition to ISO/IEC 27001:2022 ended on 31 October 2025, so a 2013-edition certificate has lapsed. ISO 27001 is not law, but it is the baseline ask in nearly every client RFP.

### Does the EU Cyber Resilience Act apply to Indian software companies?

If they sell installable software, apps or agents in the EU, yes. Its reporting obligations — a 24-hour early warning for actively exploited vulnerabilities and severe incidents — apply from 11 September 2026, with full application from 11 December 2027. Pure SaaS is generally outside it.

## Questions about the obligations

### Which obligations bind every Indian IT and ITES company?

The CERT-In Directions (report incidents within six hours, keep 180 days of logs, sync clocks to NIC or NPL time); the DPDP Act, whose operational duties apply from 13 May 2027; IT Act section 43A until then; and the Companies Act rule to back up electronic books daily to servers in India.

### Has the RBI's 2023 IT outsourcing Master Direction been replaced?

Yes. The Managing Risks in Outsourcing Directions 2025 replaced it on 28 November 2025, issued separately for each type of regulated entity. Existing agreements had to comply at renewal or by 10 April 2026, and a vendor must report incidents so the bank can tell the RBI within six hours of the vendor's detection.

### Do voice BPOs still need OSP registration?

No. OSP registration was abolished on 5 November 2020 and the regime liberalised again on 23 June 2021; non-voice ITES left it in 2020. No restatement under the Telecommunications Act 2023 has been published.

### Is a CERT-In-empanelled security audit mandatory for IT companies?

Not by law. CERT-In's audit policy guidelines of 25 July 2025 are guidance: they take force when a regulator, a government contract or a client requires them, which regulated clients increasingly do. They ask for a comprehensive audit of all ICT systems at least once a year.

### Does DORA apply to Indian IT companies?

Through EU financial clients. DORA has applied since 17 January 2025, and EU banks, insurers and investment firms must write audit, exit and testing terms into their ICT contracts. The EU's first list of critical ICT third-party providers, of 18 November 2025, includes Tata Consultancy Services.

### Is the US secure-software attestation still mandatory?

No. The mandatory attestation was rescinded on 23 January 2026. US agencies now set their own requirements and may still ask for an SBOM.

## Questions about the controls

### Which security controls should an Indian IT company start with?

Those every obligation leans on, whichever half you are in: Detect and respond inside six hours; Logs kept, and producible; Phishing-resistant sign-in; Access that ends when the job does; Managed devices only; Email security and phishing training; Backups the attacker cannot reach; Vulnerability management and VAPT; Audit evidence: ISO 27001, SOC 2; Privacy operations for DPDP; Your own suppliers, managed; Client and customer data, encrypted and found.

### What security controls do IT services firms need that product firms don't?

The ones for working inside clients' environments: Privileged access into client environments; Zero-trust access for distributed delivery; Leakage and insider risk on delivery floors; Isolated client workspaces; Your remote-management tools, locked down; Contact-centre and BPO operations.

### What security controls do SaaS and software-product companies need?

Beyond the shared baseline, the ones for shipping software other people run: Source code and the build pipeline; Dependencies you can account for; Secrets and signing keys out of the code; Cloud posture and workloads; Application and API protection; Customer identity and account protection; AI features, secured and governed.

### Which security controls can't be bought as software?

Verifying the caller before a reset; Knowing who you hired; The six-hour runbook; The clauses you sign. Each is a procedure, a hiring check, a runbook or a contract: the places the 2023 to 2025 attacks on IT firms got in.

---

TechBag — software discovery for Indian businesses. Talk to us: https://www.thetechbag.com/discovery-call?ref=it-ites
