📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
Cybersecurity GRC & Compliance in India | ISO 27001, SEBI CSCRF, DPDPA — SIRI Law LLP
GRC as a Legal Service · Hyderabad, India

Cybersecurity GRC & compliance in India — compliance that holds up in court. GRC backed by legal authority.

Any consulting firm can run a gap assessment. Only a law firm can make your compliance legally defensible, attorney-client privileged, and court-admissible. Nine frameworks, one law firm — with legal enforceability attached to every output.

₹250 CrMaximum DPDPA penalty for security safeguard failures
9+Frameworks covered under one privileged engagement
30 Jun 2026SEBI CSCRF first-audit deadline for Qualified/Mid-size entities
100%Of GRC work delivered as privileged legal advice
The compliance deadline clock
Live tracking · scroll to see every relevant deadline
Issued
20 AUG 2024
SEBI issues CSCRF, replacing legacy cyber circulars — the most comprehensive cybersecurity regulation from an Indian financial regulator to date.
Extended twice
31 AUG 2025
CSCRF's implementation deadline, after two extensions from an original 31 March 2025 target — now passed, with no further blanket extension issued.
Live deadline
30 JUN 2026
SEBI CSCRF first-audit deadline for Qualified and mid-size regulated entities — daily penalties of ₹1,500–5,000 for non-compliance plus NSE/BSE action.
Layered on
5 MAY 2026
SEBI's AI Vulnerability Detection Advisory adds 10 Annexure-A directives on top of the existing CSCRF framework.
Notified
14 NOV 2025
DPDP Rules 2025 notified — not merely "expected," as some compliance content still states. Data Protection Board already staffed and active.
Real deadline
13 MAY 2027
Operative DPDP Rules compliance deadline for most substantive obligations — a genuine transition window, not an immediate cliff.

Getting the deadlines right, not just listing frameworks

SEBI CSCRF isn't "mandatory from Jan 2025" anymore. It's already through two deadline extensions and into its recurring audit cycle.

Some GRC compliance content still frames SEBI's Cybersecurity and Cyber Resilience Framework as "mandatory for all SEBI-regulated entities from Jan 2025." That's stale. CSCRF was actually issued on 20 August 2024, and its implementation timeline moved twice — from an original 31 March 2025 target, extended to 30 June 2025, then extended again to 31 August 2025 for most regulated entities (Market Infrastructure Institutions, KRAs, and QRTAs followed an earlier schedule). That final extended deadline has now passed with no further blanket extension, which means CSCRF is currently in its live, recurring obligation phase: Qualified and mid-size regulated entities face a 30 June 2026 deadline for their first cyber audit, with real daily penalties of roughly ₹1,500 to ₹5,000 for non-compliance, plus regulatory action from NSE and BSE.

What's genuinely new, and missing from most GRC service pages, is SEBI's 5 May 2026 AI Vulnerability Detection Advisory, which layers ten additional Annexure-A directives onto the existing CSCRF requirements specifically addressing AI-related risk — a reminder that CSCRF isn't a document you implement once and file away, but a framework that continues to expand as new risk categories emerge.

DPDP Rules: notified, not "expected"
Similarly, some content still describes DPDPA Rules as "expected Q2 2025." They were actually notified on 14 November 2025 — a firm, dated fact, not a forecast — with the operative compliance deadline for most substantive obligations set at 13 May 2027. That's a genuine transition window, not an emergency, but the Data Protection Board is already staffed and active, and organisations building consent architecture, breach protocols, and a Data Processing Agreement register now do so at materially lower cost than a compressed effort closer to the deadline.

The practical lesson across both frameworks is the same: compliance dates in India move, extend, and layer new requirements on top of existing ones far more often than a static compliance calendar suggests. A GRC programme built around a snapshot of "the current deadlines" goes stale within months — which is exactly why ongoing legal advisory, not a one-time gap assessment, is what actually keeps an organisation compliant as the ground shifts under it.

Frameworks we cover

Nine frameworks. One law firm.

Most GRC consultants cover one or two frameworks. SIRI delivers all nine, with legal enforceability attached to every output.

01 / ISO

ISO 27001

Internationally recognised ISMS standard. SIRI handles legal implementation, policy drafting, and audit-ready documentation, not just gap assessment.

02 / SOC 2

SOC 2 Type I & II

Readiness for SaaS companies selling to US enterprises. Trust Service Criteria mapped to Indian regulatory context.

03 / DPDPA

Digital Personal Data Protection Act 2023

India's primary privacy law. Compliance programme with legal defensibility — consent architecture, DPIA, breach protocols, and DPA register, mapped to the 13 May 2027 deadline.

04 / CERT-IN

CERT-In Directions & Amendments

6-hour breach notification, 180-day log retention, VAPT compliance for critical infrastructure. Mandatory for all ICT service providers.

05 / SEBI

SEBI CSCRF

Full compliance lifecycle for the recurring audit cycle, including the 30 June 2026 first-audit deadline and the May 2026 AI Vulnerability Detection Advisory.

06 / RBI

RBI IT Framework

IS Policy, cyber risk appetite, board-level reporting, and BCP/DR requirements for banks, NBFCs, and payment system operators.

07 / PCI DSS

PCI DSS v4.0

Readiness for fintechs and payment companies. Scoping, gap assessment, remediation, and QSA engagement managed by SIRI.

08 / HIPAA

HIPAA

PHI data handling for Indian HealthTech companies serving US markets. Security Rule and Privacy Rule compliance with legal overlay.

09 / NIST

NIST CSF 2.0

Risk-based framework adoption. SIRI maps NIST CSF to Indian regulatory requirements — CERT-In, SEBI, RBI — in a single integrated programme.

Evidence, not guesswork

SEBI CSCRF's actual timeline — not the flat "Jan 2025" some content still cites

Two extensions, then a recurring audit cycle. Here's the real sequence.

Date Event Status today
20 Aug 2024 CSCRF issued, replacing legacy cyber circulars Foundational framework document
28 Mar 2025 Deadline extended from 31 Mar 2025 to 30 Jun 2025 First of two extensions
30 Jun 2025 Deadline extended again to 31 Aug 2025 Second and final extension for most REs
31 Aug 2025 Implementation deadline for most regulated entities Passed — no further blanket extension issued
30 Jun 2026 First-audit deadline, Qualified/Mid-size REs Live, upcoming — recurring annual/half-yearly cycle thereafter
5 May 2026 AI Vulnerability Detection Advisory issued Additional Annexure-A directives now in effect

Sources: SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 Aug 2024); subsequent SEBI extension circulars (Mar, Jun 2025); SEBI AI Vulnerability Detection Advisory, circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 (5 May 2026). Entity classification and applicable cycle vary by tier — confirm your specific obligations with counsel before relying on this general timeline.

What the numbers actually mean

Four figures that frame GRC risk today

₹250 Cr
Max DPDPA penalty

For security safeguard failures — can compound per instance, alongside separate penalty tiers for breach notification and children's data.

₹1,500–5,000
Daily SEBI CSCRF penalty

For entities missing the audit deadline — compounds daily, alongside potential NSE/BSE trading-related consequences.

180 days
CERT-In log retention

Minimum in-country retention for ICT system logs — VPN, email, and cloud logs included, verified during any audit.

18 weeks
Our fastest dual certification

ISO 27001 + SEBI CSCRF achieved simultaneously with zero regulatory findings — see the case study below.

Why a law firm for GRC

Consulting firms audit. Law firms defend.

The difference isn't just expertise — it's the legal weight behind every finding, every report, and every recommendation.

Deliverable GRC consulting firm SIRI Law LLP — GRC as a legal service
Gap assessment A document. No legal standing. Cannot be used as a defence in regulatory proceedings. Legally privileged. Your vulnerabilities cannot be disclosed or used against you.
Policies Generic templates, not specifically adapted to Indian law or sector obligations. Drafted as legal instruments — enforceable, statute-compliant, regulator-ready.
Certification support Focused on passing the audit, not on what happens when a regulator later reviews your practices. ISMS policies, internal audit procedures, and legal controls built to survive external scrutiny.
Work product privilege Discoverable — your own audit findings can be used against you in litigation. Full attorney-client privilege — incident reports, audit findings, DD responses all protected.
Incident response Referred out — no legal capacity, meaning a new team and lost time when a breach happens. Same team that built your compliance programme responds — zero ramp-up time.
Board reporting PowerPoint decks — no legal basis, no regulatory defensibility. Formal legal opinions on cyber risk for board minutes, Companies Act-grade reporting.

Our process

Five steps to audit-ready, legally defensible compliance

Every GRC engagement follows a proven methodology — delivering not just a certificate, but a compliance programme that actually holds up.

01

Gap Assessment

Legal + technical assessment of your current posture against applicable frameworks. Privileged report maps every gap with regulatory risk scoring.

Weeks 1–2
02

Roadmap

Prioritised remediation plan with legal deadlines mapped to CERT-In, SEBI, DPDPA, and RBI timelines. Board-ready presentation included.

Week 3
03

Implementation

Policy drafting, technical controls advisory, vendor DPA review, employee training, and ISMS documentation, all legally privileged.

Weeks 4–12
04

Audit Readiness

Internal audit simulation. Evidence pack preparation. Regulatory inquiry response preparation. Management review documentation for ISO/SOC 2.

Weeks 13–16
05

Certification

Certification audit support with legal counsel on standby. Ongoing retainer for annual surveillance, regulatory updates, and incident response coverage.

Ongoing

Compliance calendar

Key Indian regulatory deadlines you cannot miss

Missing a regulatory deadline isn't just a fine — it can be a criminal offence under several Indian statutes. SIRI monitors these for all retainer clients.

Deadline Obligation Priority
Ongoing CERT-In 6-Hour — breach notification within 6 hours of discovery. Mandatory for all ICT service providers, data centres, and corporates. Immediate
30 Jun 2026 SEBI CSCRF — first-audit deadline for Qualified/Mid-size regulated entities; recurring annual or half-yearly cycle thereafter. High
13 May 2027 DPDP Rules — operative compliance deadline for most substantive data fiduciary obligations, consent manager framework, and significant data fiduciary classification. High
Ongoing RBI IT Framework — annual IT risk assessment, board cyber risk reporting, and BCP testing for scheduled banks, NBFCs above threshold, and payment operators. Medium
Rolling ISO 27001 Surveillance — annual surveillance audits required to maintain certification. Medium
180 days CERT-In Log Retention — all entities must maintain ICT system logs for a minimum of 180 days within Indian jurisdiction. VPN, email, and cloud logs included. High

GRC case studies

Two mandates. Measurable outcomes.

Listed NBFC · SEBI CSCRF Mandate

ISO 27001 + SEBI CSCRF dual certification in 18 weeks, zero findings

A listed NBFC came to SIRI after its previous consultant failed the SEBI CSCRF internal assessment, and also needed ISO 27001 certification to satisfy a key institutional investor requirement. SIRI ran both programmes simultaneously, leveraging control overlaps and drafting all legal instruments — board resolutions, ISMS policies, vendor DPAs, incident response procedures — under legal privilege.

18 wksDual certification achieved
0SEBI regulatory findings
2-in-1ISO 27001 + CSCRF simultaneously
SEBI CSCRF ISO 27001 NBFC
HealthTech Startup · DPDPA + HIPAA

DPDPA compliance built in 10 weeks, enabling a hospital contract

A HealthTech startup processing patient data was blocked from signing its first enterprise hospital contract by a data privacy compliance requirement. SIRI built the full compliance programme — consent architecture, data processing register, DPA template, DPDPA notice, internal breach procedures — in 10 weeks. HIPAA mapping was added for a US investor's diligence requirement in the same engagement.

10 wksFull programme delivered
₹2.4 CrContract value unlocked
2DPDPA + HIPAA dual coverage
DPDPA HIPAA HealthTech

Our certified engineers hold

Credentials boards and regulators expect

CCSP CEH CPENT CISM CIPP/E OSCP CISSP GPEN eCPPT

Frequently asked

Cybersecurity GRC, answered directly

What's the actual current status of SEBI CSCRF compliance deadlines?

CSCRF was issued in August 2024 and went through multiple deadline extensions — from an original 31 March 2025 target, pushed to 30 June 2025, then to 31 August 2025 for most regulated entities. That deadline has now passed with no further blanket extension, and CSCRF is in its recurring audit cycle: Qualified and mid-size regulated entities face a 30 June 2026 deadline for their first cyber audit, with daily penalties of roughly ₹1,500 to ₹5,000 for non-compliance plus regulatory action from NSE and BSE. SEBI has also layered a 5 May 2026 AI Vulnerability Detection Advisory onto the framework, adding specific directives for AI-related risk. Confirm your entity's specific tier and current cycle date before assuming any single deadline applies uniformly.

When are the DPDP Rules actually due, and has India's deadline already passed?

The DPDP Rules 2025 were notified on 14 November 2025, not merely "expected" as some compliance content still states. The operative compliance deadline for most substantive obligations is 13 May 2027, giving organisations a genuine transition window rather than an immediate cliff, but the Data Protection Board is already staffed and active, and building consent architecture, breach protocols, and a Data Processing Agreement register now is materially cheaper than a compressed effort closer to the deadline.

Why does a law firm handle GRC differently than a consulting firm?

A consulting firm's gap assessment is a document with no legal standing — it cannot be used as a defence in regulatory proceedings, and the work product is generally discoverable, meaning your own audit findings can be used against you in litigation. SIRI's GRC engagements are conducted as legal advisory from the outset, so findings, policies, and audit reports are protected by attorney-client privilege, and the policies themselves are drafted as enforceable legal instruments rather than generic templates.

How long does a typical GRC engagement take, from gap assessment to certification?

Our standard five-phase methodology runs gap assessment in weeks 1–2, roadmap development in week 3, implementation across weeks 4–12, audit readiness in weeks 13–16, and certification support on an ongoing basis. Actual timelines vary by framework and organisational complexity — our fastest dual-framework certification (ISO 27001 and SEBI CSCRF simultaneously) was completed in 18 weeks with zero regulatory findings.

Can one engagement cover multiple frameworks at once?

Yes, and it's frequently more efficient to do so. Many frameworks share overlapping controls — access management, logging, incident response, vendor risk — so a well-scoped engagement can build the documentation and technical controls that satisfy ISO 27001, SEBI CSCRF, and DPDPA simultaneously, as demonstrated in our NBFC case study above.

What happens if we miss a compliance deadline?

Consequences vary by framework — CSCRF non-compliance carries daily penalties plus potential NSE/BSE action; DPDPA violations can reach ₹250 crore for security safeguard failures; CERT-In reporting failures carry their own regulatory consequences. In every case, documented remediation efforts and a credible compliance trajectory materially affect how a regulator responds to a missed deadline, which is why continuous monitoring matters more than a single point-in-time assessment.

Ready when you are

Compliance without legal backing is just paperwork. SIRI makes it enforceable.

Start with a free GRC scoping call — we'll identify your most urgent regulatory obligations and map the fastest path to compliance.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes only and does not constitute legal advice. Compliance frameworks and certification requirements vary by sector, jurisdiction, and specific organisational context. References to SEBI CSCRF deadlines, DPDP Rules dates, and related penalty figures reflect publicly available information as of publication and remain subject to further regulatory change; confirm current requirements before relying on any specific deadline. Case study details are described generically to protect client confidentiality. No lawyer-client relationship is formed by viewing this page. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top