Know which rules apply — and meet them with evidence.
Regulators expect controls you can prove. Use the Compliance Finder for an indicative answer, then dive into each framework in plain English.
| Framework | Who it applies to | What TrustNet does |
|---|---|---|
| RBIRBI cyber security directions → | Scheduled commercial banks and small finance banks; Urban and state co-operative banks (as applicable) | Gap assessment against the RBI directions that apply to your entity; VAPT of banking, payment and lending channels |
| SEBI CSCRFSEBI CSCRF → | Market infrastructure institutions (MIIs); Qualified regulated entities | Category check to confirm which obligations apply; Gap assessment against CSCRF requirements |
| CERT-InCERT-In Directions (2022) → | Service providers and intermediaries; Data centres | 6-hour reporting playbook with templates and roles; 180-day log retention design and review |
| IRDAIIRDAI Information and Cyber Security Guidelines → | Life, general and health insurers; Reinsurers | Gap assessment against the IRDAI guidelines; Audit preparation and support |
| PCI DSSPCI DSS v4.x → | Merchants that accept card payments; Payment aggregators and gateways | Scoping and data-flow mapping; Gap assessment against PCI DSS v4.x |
| DPDPDPDP Act 2023 and Rules → | Any organisation processing digital personal data in India; Organisations outside India offering goods or services to people in India | Data mapping and inventory; Consent and notice review |
| ISO 27001ISO/IEC 27001:2022, SOC 2 and NIST CSF 2.0 → | Any organisation that wants a recognised security management system; SaaS and IT companies selling to enterprise customers | ISO 27001 readiness and gap assessment; ISMS policy suite and risk register |
| HIPAA · ABDMHIPAA, ABDM and NABH → | Hospitals, clinics and diagnostic labs; Health-tech and telemedicine platforms | Safeguards assessment against HIPAA, ABDM and NABH expectations; Access control review for clinical systems |
Regulatory references indicate the frameworks we help clients align with — aligned with, not endorsed by any regulator. Always confirm requirements against the latest official circulars.
Which rules likely apply to you?
Three quick questions. Indicative only — your obligations depend on your licence, category and circulars in force.
How we follow guidelines — and keep you current
- We monitor regulator circulars daily — RBI, SEBI, CERT-In and IRDAI.
- Our checklists are updated when rules change.
- Clients get alerts on changes that affect them.
- Quarterly re-assessment under our Maintenance Plans.
Where to start
- Compliance & Risk Advisory — Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
- VAPT — Find and fix weaknesses in apps, APIs, networks and cloud before attackers exploit them.
- Security Audit — Independent review of your systems, controls and architecture against the rules you must follow.
- vCISO, Governance & Third-Party Risk — Senior security leadership, policies and vendor risk management without a full-time CISO.
Book a gap assessment
We map your controls and evidence to the frameworks that apply, and give you a prioritised plan to close the gaps.
support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438
Under attack right now? Go to emergency help →