India is the one country in the region whose law names the standard by title. SPDI Rule 8 deems a certified ISO 27001 implementation ‘reasonable security practices’ under section 43A of the IT Act. The CERT-In 6-hour incident-reporting rule is in force now, and the DPDP Act duties commence on 13 May 2027. A single certified ISMS satisfies Rule 8 and provides the monitoring, logging and incident management the other two require.
Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the SPDI Rules — names IS/ISO/IEC 27001 in its text. An organisation that has implemented the standard, and had that implementation certified or audited, is deemed to have complied with the “reasonable security practices and procedures” required by section 43A of the IT Act 2000.
No other data-protection law in the region names a standard this way. Most require “reasonable security” and leave the definition to be argued after an incident. Certification remains optional in India — section 43A can be met by other means — but Rule 8 identifies the standard the regulator recognises.
The deemed compliance attaches to a certified implementation. A documented alignment to the standard, without certification or audit, does not satisfy Rule 8.
India’s data-protection law is mid-handover. Different obligations apply before and after 13 May 2027, and the sequencing determines what has to be built first.
| Today | From 13 May 2027 | |
|---|---|---|
| Governing law | IT Act 2000 + SPDI Rules 2011 | Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025 |
| Security duty | “Reasonable security practices” under s.43A — certified ISO 27001 deemed compliant (Rule 8) | The Act’s substantive obligations commence |
| Breach notification | CERT-In incident reporting (see below) | Notify the Data Protection Board without delay, detailed report within 72 hours, affected individuals also notified — with no materiality threshold |
| Regulator | MeitY and CERT-In | Data Protection Board of India (established per the 13 November 2025 notification) |
The DPDP Act was passed in 2023 and its Rules were notified on 13 November 2025. Most substantive obligations commence on 13 May 2027. Until that date the SPDI Rules and the CERT-In directions govern, and both are enforceable now.
The CERT-In Cyber Security Directions of 28 April 2022 are in force now, for the incidents on CERT-In’s list, and impose two requirements:
Both are operational requirements. Six-hour reporting depends on monitoring that is already running; a 180-day onshore log store has to exist before the incident it will be used to investigate. Secure60 runs delivery infrastructure in India via Rackcorp, across two datacentres, so collection and retention can sit within Indian jurisdiction on our security platform.
| Indian obligation | Where the ISMS answers it |
|---|---|
| s.43A “reasonable security practices” (SPDI Rule 8) | The certified ISMS itself — the rule names certified ISO 27001 implementation as deemed compliance |
| CERT-In 6-hour incident reporting | Monitoring and incident management tuned so detection-to-report fits inside six hours |
| 180-day log retention in Indian jurisdiction | Logging controls with retention configured, on in-country infrastructure |
| DPDP breach regime (from 13 May 2027) | Incident management extended: Board notified without delay, detailed report within 72 hours, individuals notified |
| RBI / SEBI / IRDAI sectoral data rules | Scope and data location recorded in the ISMS — payment-system data stored in India per the RBI rule in force since 15 October 2018 |
The certification audit — Stage 1 documentation review, Stage 2 interviews and evidence — is performed by a certification body accredited by NABCB, the National Accreditation Board for Certification Bodies under the Quality Council of India. Secure60 does not perform it. Audit fees are set by the certification body and vary with the size and scope of the certified system.
Scope carries legal weight in India, because Rule 8’s deemed compliance attaches to the certificate. Systems that process sensitive personal data have to sit inside the certificate boundary for the section 43A protection to reach them.
13 May 2027 is the commencement date for the DPDP Act’s substantive duties. It defers nothing else. The CERT-In directions have applied since 2022 — six-hour reporting and 180-day onshore log retention are current law — and section 43A with the SPDI Rules governs sensitive personal data today.
The operational work is therefore required before the DPDP deadline rather than after it. Logging, monitoring and incident handling built for CERT-In, and an ISMS certified against Rule 8, are the same components the DPDP’s 72-hour breach regime will run on in 2027.
Secure60 delivers the certification and operates the security behind it. In India that means building the ISMS Rule 8 recognises, then operating what the CERT-In directions require: logging with 180-day retention on Indian infrastructure via Rackcorp, monitoring that makes a six-hour report achievable, and incident management ready for the Data Protection Board’s 72-hour regime in 2027. The certification audit belongs to a NABCB-accredited body; we make sure that what they sample is running. Secure60 is ISO 27001:2022 certified.
Is ISO 27001 legally mandatory in India?
No. Certification is not mandatory. Rule 8 of the SPDI Rules 2011 names IS/ISO/IEC 27001 by title: an organisation that implements the standard and has that implementation certified or audited is deemed to have met the ‘reasonable security practices’ required under section 43A of the IT Act. No other data-protection law in the region names a standard this way.
Is the DPDP Act in force yet?
Partly. The Act was passed in 2023 and the DPDP Rules were notified on 13 November 2025. Most substantive obligations commence on 13 May 2027. Until then, the IT Act 2000 and the SPDI Rules 2011 govern.
What does the CERT-In 6-hour rule require?
The CERT-In Cyber Security Directions of 28 April 2022 require listed cyber incidents to be reported to CERT-In within 6 hours of noticing, and ICT logs to be retained for 180 days within Indian jurisdiction. These directions are in force now, independent of the DPDP commencement date.
Does our data have to stay in India?
The DPDP Act imposes no general localisation rule. Sectoral rules apply: the RBI has required payment-system data to be stored in India since 15 October 2018, and SEBI and IRDAI have similar sectoral rules. The CERT-In directions separately require 180-day log retention within Indian jurisdiction.
Who performs the ISO 27001 certification audit in India?
A certification body accredited by NABCB (the National Accreditation Board for Certification Bodies, under the Quality Council of India). Secure60 does not perform certification audits. Audit fees are set by the certification body and vary with the size and scope of what’s certified.
Can Secure60 deliver in India?
Yes. We have delivery infrastructure in India via Rackcorp, across two datacentres, so log collection and 180-day retention can run within Indian jurisdiction. We have no local offices, and we do not perform the certification audit.