Cybersecurity GRC & compliance in India — compliance that holds up in court. GRC backed by legal authority.
Any consulting firm can run a gap assessment. Only a law firm can make your compliance legally defensible, attorney-client privileged, and court-admissible. Nine frameworks, one law firm — with legal enforceability attached to every output.
Getting the deadlines right, not just listing frameworks
SEBI CSCRF isn't "mandatory from Jan 2025" anymore. It's already through two deadline extensions and into its recurring audit cycle.
Some GRC compliance content still frames SEBI's Cybersecurity and Cyber Resilience Framework as "mandatory for all SEBI-regulated entities from Jan 2025." That's stale. CSCRF was actually issued on 20 August 2024, and its implementation timeline moved twice — from an original 31 March 2025 target, extended to 30 June 2025, then extended again to 31 August 2025 for most regulated entities (Market Infrastructure Institutions, KRAs, and QRTAs followed an earlier schedule). That final extended deadline has now passed with no further blanket extension, which means CSCRF is currently in its live, recurring obligation phase: Qualified and mid-size regulated entities face a 30 June 2026 deadline for their first cyber audit, with real daily penalties of roughly ₹1,500 to ₹5,000 for non-compliance, plus regulatory action from NSE and BSE.
What's genuinely new, and missing from most GRC service pages, is SEBI's 5 May 2026 AI Vulnerability Detection Advisory, which layers ten additional Annexure-A directives onto the existing CSCRF requirements specifically addressing AI-related risk — a reminder that CSCRF isn't a document you implement once and file away, but a framework that continues to expand as new risk categories emerge.
The practical lesson across both frameworks is the same: compliance dates in India move, extend, and layer new requirements on top of existing ones far more often than a static compliance calendar suggests. A GRC programme built around a snapshot of "the current deadlines" goes stale within months — which is exactly why ongoing legal advisory, not a one-time gap assessment, is what actually keeps an organisation compliant as the ground shifts under it.
Frameworks we cover
Nine frameworks. One law firm.
Most GRC consultants cover one or two frameworks. SIRI delivers all nine, with legal enforceability attached to every output.
ISO 27001
Internationally recognised ISMS standard. SIRI handles legal implementation, policy drafting, and audit-ready documentation, not just gap assessment.
SOC 2 Type I & II
Readiness for SaaS companies selling to US enterprises. Trust Service Criteria mapped to Indian regulatory context.
Digital Personal Data Protection Act 2023
India's primary privacy law. Compliance programme with legal defensibility — consent architecture, DPIA, breach protocols, and DPA register, mapped to the 13 May 2027 deadline.
CERT-In Directions & Amendments
6-hour breach notification, 180-day log retention, VAPT compliance for critical infrastructure. Mandatory for all ICT service providers.
SEBI CSCRF
Full compliance lifecycle for the recurring audit cycle, including the 30 June 2026 first-audit deadline and the May 2026 AI Vulnerability Detection Advisory.
RBI IT Framework
IS Policy, cyber risk appetite, board-level reporting, and BCP/DR requirements for banks, NBFCs, and payment system operators.
PCI DSS v4.0
Readiness for fintechs and payment companies. Scoping, gap assessment, remediation, and QSA engagement managed by SIRI.
HIPAA
PHI data handling for Indian HealthTech companies serving US markets. Security Rule and Privacy Rule compliance with legal overlay.
NIST CSF 2.0
Risk-based framework adoption. SIRI maps NIST CSF to Indian regulatory requirements — CERT-In, SEBI, RBI — in a single integrated programme.
Evidence, not guesswork
SEBI CSCRF's actual timeline — not the flat "Jan 2025" some content still cites
Two extensions, then a recurring audit cycle. Here's the real sequence.
| Date | Event | Status today |
|---|---|---|
| 20 Aug 2024 | CSCRF issued, replacing legacy cyber circulars | Foundational framework document |
| 28 Mar 2025 | Deadline extended from 31 Mar 2025 to 30 Jun 2025 | First of two extensions |
| 30 Jun 2025 | Deadline extended again to 31 Aug 2025 | Second and final extension for most REs |
| 31 Aug 2025 | Implementation deadline for most regulated entities | Passed — no further blanket extension issued |
| 30 Jun 2026 | First-audit deadline, Qualified/Mid-size REs | Live, upcoming — recurring annual/half-yearly cycle thereafter |
| 5 May 2026 | AI Vulnerability Detection Advisory issued | Additional Annexure-A directives now in effect |
Sources: SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 Aug 2024); subsequent SEBI extension circulars (Mar, Jun 2025); SEBI AI Vulnerability Detection Advisory, circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 (5 May 2026). Entity classification and applicable cycle vary by tier — confirm your specific obligations with counsel before relying on this general timeline.
What the numbers actually mean
Four figures that frame GRC risk today
For security safeguard failures — can compound per instance, alongside separate penalty tiers for breach notification and children's data.
For entities missing the audit deadline — compounds daily, alongside potential NSE/BSE trading-related consequences.
Minimum in-country retention for ICT system logs — VPN, email, and cloud logs included, verified during any audit.
ISO 27001 + SEBI CSCRF achieved simultaneously with zero regulatory findings — see the case study below.
Why a law firm for GRC
Consulting firms audit. Law firms defend.
The difference isn't just expertise — it's the legal weight behind every finding, every report, and every recommendation.
| Deliverable | GRC consulting firm | SIRI Law LLP — GRC as a legal service |
|---|---|---|
| Gap assessment | A document. No legal standing. Cannot be used as a defence in regulatory proceedings. | Legally privileged. Your vulnerabilities cannot be disclosed or used against you. |
| Policies | Generic templates, not specifically adapted to Indian law or sector obligations. | Drafted as legal instruments — enforceable, statute-compliant, regulator-ready. |
| Certification support | Focused on passing the audit, not on what happens when a regulator later reviews your practices. | ISMS policies, internal audit procedures, and legal controls built to survive external scrutiny. |
| Work product privilege | Discoverable — your own audit findings can be used against you in litigation. | Full attorney-client privilege — incident reports, audit findings, DD responses all protected. |
| Incident response | Referred out — no legal capacity, meaning a new team and lost time when a breach happens. | Same team that built your compliance programme responds — zero ramp-up time. |
| Board reporting | PowerPoint decks — no legal basis, no regulatory defensibility. | Formal legal opinions on cyber risk for board minutes, Companies Act-grade reporting. |
Our process
Five steps to audit-ready, legally defensible compliance
Every GRC engagement follows a proven methodology — delivering not just a certificate, but a compliance programme that actually holds up.
Gap Assessment
Legal + technical assessment of your current posture against applicable frameworks. Privileged report maps every gap with regulatory risk scoring.
Weeks 1–2Roadmap
Prioritised remediation plan with legal deadlines mapped to CERT-In, SEBI, DPDPA, and RBI timelines. Board-ready presentation included.
Week 3Implementation
Policy drafting, technical controls advisory, vendor DPA review, employee training, and ISMS documentation, all legally privileged.
Weeks 4–12Audit Readiness
Internal audit simulation. Evidence pack preparation. Regulatory inquiry response preparation. Management review documentation for ISO/SOC 2.
Weeks 13–16Certification
Certification audit support with legal counsel on standby. Ongoing retainer for annual surveillance, regulatory updates, and incident response coverage.
OngoingCompliance calendar
Key Indian regulatory deadlines you cannot miss
Missing a regulatory deadline isn't just a fine — it can be a criminal offence under several Indian statutes. SIRI monitors these for all retainer clients.
| Deadline | Obligation | Priority |
|---|---|---|
| Ongoing | CERT-In 6-Hour — breach notification within 6 hours of discovery. Mandatory for all ICT service providers, data centres, and corporates. | Immediate |
| 30 Jun 2026 | SEBI CSCRF — first-audit deadline for Qualified/Mid-size regulated entities; recurring annual or half-yearly cycle thereafter. | High |
| 13 May 2027 | DPDP Rules — operative compliance deadline for most substantive data fiduciary obligations, consent manager framework, and significant data fiduciary classification. | High |
| Ongoing | RBI IT Framework — annual IT risk assessment, board cyber risk reporting, and BCP testing for scheduled banks, NBFCs above threshold, and payment operators. | Medium |
| Rolling | ISO 27001 Surveillance — annual surveillance audits required to maintain certification. | Medium |
| 180 days | CERT-In Log Retention — all entities must maintain ICT system logs for a minimum of 180 days within Indian jurisdiction. VPN, email, and cloud logs included. | High |
GRC case studies
Two mandates. Measurable outcomes.
ISO 27001 + SEBI CSCRF dual certification in 18 weeks, zero findings
A listed NBFC came to SIRI after its previous consultant failed the SEBI CSCRF internal assessment, and also needed ISO 27001 certification to satisfy a key institutional investor requirement. SIRI ran both programmes simultaneously, leveraging control overlaps and drafting all legal instruments — board resolutions, ISMS policies, vendor DPAs, incident response procedures — under legal privilege.
DPDPA compliance built in 10 weeks, enabling a hospital contract
A HealthTech startup processing patient data was blocked from signing its first enterprise hospital contract by a data privacy compliance requirement. SIRI built the full compliance programme — consent architecture, data processing register, DPA template, DPDPA notice, internal breach procedures — in 10 weeks. HIPAA mapping was added for a US investor's diligence requirement in the same engagement.
Framework-specific services
Deep dives into each compliance programme
DPDPA 2023 Implementation & Privileged Audit
Consent architecture, DPIA, breach protocols, and DPA registers mapped to the 13 May 2027 deadline.
SOC 2 Compliance & Audit Readiness
Type I and II readiness for SaaS companies selling into US enterprise markets.
NIST Compliance Services
NIST CSF 2.0 adoption mapped to CERT-In, SEBI, and RBI requirements.
PCI DSS Compliance & Audit Readiness
v4.0 readiness, scoping, and QSA engagement for fintechs and payment companies.
Privacy Compliance
Cross-framework privacy advisory beyond DPDPA, including GDPR where applicable.
HIPAA / HITRUST Compliance
PHI handling for Indian HealthTech companies serving US markets.
Our certified engineers hold
Credentials boards and regulators expect
Frequently asked
Cybersecurity GRC, answered directly
What's the actual current status of SEBI CSCRF compliance deadlines?
CSCRF was issued in August 2024 and went through multiple deadline extensions — from an original 31 March 2025 target, pushed to 30 June 2025, then to 31 August 2025 for most regulated entities. That deadline has now passed with no further blanket extension, and CSCRF is in its recurring audit cycle: Qualified and mid-size regulated entities face a 30 June 2026 deadline for their first cyber audit, with daily penalties of roughly ₹1,500 to ₹5,000 for non-compliance plus regulatory action from NSE and BSE. SEBI has also layered a 5 May 2026 AI Vulnerability Detection Advisory onto the framework, adding specific directives for AI-related risk. Confirm your entity's specific tier and current cycle date before assuming any single deadline applies uniformly.
When are the DPDP Rules actually due, and has India's deadline already passed?
The DPDP Rules 2025 were notified on 14 November 2025, not merely "expected" as some compliance content still states. The operative compliance deadline for most substantive obligations is 13 May 2027, giving organisations a genuine transition window rather than an immediate cliff, but the Data Protection Board is already staffed and active, and building consent architecture, breach protocols, and a Data Processing Agreement register now is materially cheaper than a compressed effort closer to the deadline.
Why does a law firm handle GRC differently than a consulting firm?
A consulting firm's gap assessment is a document with no legal standing — it cannot be used as a defence in regulatory proceedings, and the work product is generally discoverable, meaning your own audit findings can be used against you in litigation. SIRI's GRC engagements are conducted as legal advisory from the outset, so findings, policies, and audit reports are protected by attorney-client privilege, and the policies themselves are drafted as enforceable legal instruments rather than generic templates.
How long does a typical GRC engagement take, from gap assessment to certification?
Our standard five-phase methodology runs gap assessment in weeks 1–2, roadmap development in week 3, implementation across weeks 4–12, audit readiness in weeks 13–16, and certification support on an ongoing basis. Actual timelines vary by framework and organisational complexity — our fastest dual-framework certification (ISO 27001 and SEBI CSCRF simultaneously) was completed in 18 weeks with zero regulatory findings.
Can one engagement cover multiple frameworks at once?
Yes, and it's frequently more efficient to do so. Many frameworks share overlapping controls — access management, logging, incident response, vendor risk — so a well-scoped engagement can build the documentation and technical controls that satisfy ISO 27001, SEBI CSCRF, and DPDPA simultaneously, as demonstrated in our NBFC case study above.
What happens if we miss a compliance deadline?
Consequences vary by framework — CSCRF non-compliance carries daily penalties plus potential NSE/BSE action; DPDPA violations can reach ₹250 crore for security safeguard failures; CERT-In reporting failures carry their own regulatory consequences. In every case, documented remediation efforts and a credible compliance trajectory materially affect how a regulator responds to a missed deadline, which is why continuous monitoring matters more than a single point-in-time assessment.
Ready when you are
Compliance without legal backing is just paperwork. SIRI makes it enforceable.
Start with a free GRC scoping call — we'll identify your most urgent regulatory obligations and map the fastest path to compliance.
Related services
Other ways SIRI Law LLP supports your compliance posture
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

