India is the one country where the law names the standard: SPDI Rule 8 deems a certified ISO 27001 implementation ‘reasonable security practices’ under section 43A of the IT Act. Add the CERT-In 6-hour incident-reporting rule in force now, and the DPDP Act duties arriving from 13 May 2027, and certification is the obvious anchor.
Most privacy laws say “reasonable security” and leave you to argue about what that means. India answers the question in the text of the rules. Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the SPDI Rules — expressly names IS/ISO/IEC 27001: an organisation that has implemented the standard, and had that implementation certified or audited, is deemed to have complied with the “reasonable security practices and procedures” that section 43A of the IT Act 2000 requires.
That’s the strongest legal hook ISO 27001 has anywhere in the region. Certification isn’t mandatory — you can meet section 43A other ways — but the law has already told you which standard it recognises. Note the wording carefully: the deemed compliance attaches to a certified implementation, not to a policy folder that “aligns with” the standard.
India’s data-protection law is mid-handover, and getting the sequencing right matters more here than anywhere else on this hub.
| Today | From 13 May 2027 | |
|---|---|---|
| Governing law | IT Act 2000 + SPDI Rules 2011 | Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025 |
| Security duty | “Reasonable security practices” under s.43A — certified ISO 27001 deemed compliant (Rule 8) | The Act’s substantive obligations phase in |
| Breach notification | CERT-In incident reporting (see below) | Notify the Data Protection Board without delay, detailed report within 72 hours, affected individuals also notified — with no materiality threshold |
| Regulator | MeitY and CERT-In | Data Protection Board of India (established per the 13 November 2025 notification) |
The DPDP Act was passed in 2023 and its Rules were notified on 13 November 2025, but most substantive obligations arrive on 13 May 2027. Don’t treat the DPDP regime as fully in force today, and don’t treat the gap as empty either — the SPDI Rules govern right now, and so does CERT-In.
The CERT-In Cyber Security Directions of 28 April 2022 apply now, to the incidents on CERT-In’s list, with two teeth:
Both requirements are operational, not documentary. A six-hour window is unusable without monitoring already watching; a 180-day onshore log store has to exist before the incident, not after. Secure60 runs delivery infrastructure in India via Rackcorp, with 2 datacentres, so collection and retention can sit within Indian jurisdiction on our security platform.
| Indian obligation | Where the ISMS answers it |
|---|---|
| s.43A “reasonable security practices” (SPDI Rule 8) | The certified ISMS itself — the rule names certified ISO 27001 implementation as deemed compliance |
| CERT-In 6-hour incident reporting | Monitoring and incident management tuned so detection-to-report fits inside six hours |
| 180-day log retention in Indian jurisdiction | Logging controls with retention configured, on in-country infrastructure |
| DPDP breach regime (from 13 May 2027) | Incident management extended: Board notified without delay, detailed report within 72 hours, individuals notified |
| RBI / SEBI / IRDAI sectoral data rules | Scope and data location recorded in the ISMS — payment-system data stored in India per the RBI rule in force since 15 October 2018 |
The certification audit — Stage 1 documentation review, Stage 2 interviews and evidence — is performed by a certification body accredited by NABCB, the National Accreditation Board for Certification Bodies under the Quality Council of India. Never by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system, so fix the scope first. Because Rule 8’s deemed compliance attaches to the certificate, scope decisions in India carry legal weight: the systems processing sensitive personal data need to sit inside the certificate boundary, not beside it.
The May 2027 date gets read as a grace period for everything. It isn’t. The DPDP Act’s substantive duties arrive on 13 May 2027, but the CERT-In directions have applied since 2022 — six-hour reporting and 180-day onshore logs are today’s law — and section 43A with the SPDI Rules governs sensitive personal data today.
So the common plan — “we’ll build security when DPDP bites” — has the sequence backwards. The operational pieces are required now. Build the logging, monitoring and incident handling for CERT-In, certify the ISMS that Rule 8 already rewards, and the DPDP’s 72-hour breach regime lands on infrastructure that has been running for two years.
Tools hand you a to-do list. We do the list — and run the security behind it. For India that means building the ISMS to the shape Rule 8 rewards, then operating what the CERT-In directions actually demand: logging with 180-day retention on Indian infrastructure via Rackcorp, monitoring that makes a six-hour report achievable, and incident management ready for the Board’s 72-hour regime when it arrives. The certification audit belongs to a NABCB-accredited body; we make sure what they sample is running. We’re ISO 27001:2022 certified ourselves.
Is ISO 27001 legally mandatory in India?
No — but India comes closer than anywhere else in the region. Rule 8 of the SPDI Rules 2011 expressly names IS/ISO/IEC 27001: implement it and have that implementation certified, and you’re deemed to have met the ‘reasonable security practices’ required under section 43A of the IT Act.
Is the DPDP Act in force yet?
Partly. The Act was passed in 2023 and the DPDP Rules were notified on 13 November 2025, but most substantive obligations phase in from 13 May 2027. Until then, the IT Act 2000 and the SPDI Rules 2011 govern.
What does the CERT-In 6-hour rule require?
The CERT-In Cyber Security Directions of 28 April 2022 require listed cyber incidents to be reported to CERT-In within 6 hours of noticing, and ICT logs to be retained for 180 days within Indian jurisdiction. This applies now — it doesn’t wait for the DPDP timeline.
Does our data have to stay in India?
The DPDP Act imposes no general localisation rule. Sectoral rules do exist: the RBI has required payment-system data to be stored in India since 15 October 2018, and SEBI and IRDAI have similar sectoral rules. The CERT-In directions also require 180-day log retention within Indian jurisdiction.
Who performs the ISO 27001 certification audit in India?
A certification body accredited by NABCB (the National Accreditation Board for Certification Bodies, under the Quality Council of India) — not Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s certified.
Can Secure60 deliver in India?
Yes — we have delivery infrastructure in India via Rackcorp, with 2 datacentres, so log collection and 180-day retention can run within Indian jurisdiction. We don’t have local offices, and we never perform the certification audit.