ISO 27001 · India

ISO 27001 in India: The Standard Named in the SPDI Rules

The Short Answer

India is the one country in the region whose law names the standard by title. SPDI Rule 8 deems a certified ISO 27001 implementation ‘reasonable security practices’ under section 43A of the IT Act. The CERT-In 6-hour incident-reporting rule is in force now, and the DPDP Act duties commence on 13 May 2027. A single certified ISMS satisfies Rule 8 and provides the monitoring, logging and incident management the other two require.

Where Indian law names ISO 27001

Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — the SPDI Rules — names IS/ISO/IEC 27001 in its text. An organisation that has implemented the standard, and had that implementation certified or audited, is deemed to have complied with the “reasonable security practices and procedures” required by section 43A of the IT Act 2000.

No other data-protection law in the region names a standard this way. Most require “reasonable security” and leave the definition to be argued after an incident. Certification remains optional in India — section 43A can be met by other means — but Rule 8 identifies the standard the regulator recognises.

The deemed compliance attaches to a certified implementation. A documented alignment to the standard, without certification or audit, does not satisfy Rule 8.

The two regimes and the 13 May 2027 handover

India’s data-protection law is mid-handover. Different obligations apply before and after 13 May 2027, and the sequencing determines what has to be built first.

Today From 13 May 2027
Governing law IT Act 2000 + SPDI Rules 2011 Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025
Security duty “Reasonable security practices” under s.43A — certified ISO 27001 deemed compliant (Rule 8) The Act’s substantive obligations commence
Breach notification CERT-In incident reporting (see below) Notify the Data Protection Board without delay, detailed report within 72 hours, affected individuals also notified — with no materiality threshold
Regulator MeitY and CERT-In Data Protection Board of India (established per the 13 November 2025 notification)

The DPDP Act was passed in 2023 and its Rules were notified on 13 November 2025. Most substantive obligations commence on 13 May 2027. Until that date the SPDI Rules and the CERT-In directions govern, and both are enforceable now.

The 6-hour clock and the 180-day logs

The CERT-In Cyber Security Directions of 28 April 2022 are in force now, for the incidents on CERT-In’s list, and impose two requirements:

  • Report within 6 hours of noticing the incident. The clock starts at detection, not at the conclusion of the investigation. Six hours has to cover detection, an initial assessment and the report itself.
  • Retain ICT logs for 180 days, within Indian jurisdiction. This is a residency requirement for logs, independent of where the rest of the estate is hosted, and it is commonly scoped to the wrong data set. A detection-tuned SIEM does not satisfy CERT-In’s 180-day rule, because it filters most of the estate out before storage.

Both are operational requirements. Six-hour reporting depends on monitoring that is already running; a 180-day onshore log store has to exist before the incident it will be used to investigate. Secure60 runs delivery infrastructure in India via Rackcorp, across two datacentres, so collection and retention can sit within Indian jurisdiction on our security platform.

Indian obligation Where the ISMS answers it
s.43A “reasonable security practices” (SPDI Rule 8) The certified ISMS itself — the rule names certified ISO 27001 implementation as deemed compliance
CERT-In 6-hour incident reporting Monitoring and incident management tuned so detection-to-report fits inside six hours
180-day log retention in Indian jurisdiction Logging controls with retention configured, on in-country infrastructure
DPDP breach regime (from 13 May 2027) Incident management extended: Board notified without delay, detailed report within 72 hours, individuals notified
RBI / SEBI / IRDAI sectoral data rules Scope and data location recorded in the ISMS — payment-system data stored in India per the RBI rule in force since 15 October 2018

Certification: NABCB and scope

The certification audit — Stage 1 documentation review, Stage 2 interviews and evidence — is performed by a certification body accredited by NABCB, the National Accreditation Board for Certification Bodies under the Quality Council of India. Secure60 does not perform it. Audit fees are set by the certification body and vary with the size and scope of the certified system.

Scope carries legal weight in India, because Rule 8’s deemed compliance attaches to the certificate. Systems that process sensitive personal data have to sit inside the certificate boundary for the section 43A protection to reach them.

What 13 May 2027 does not defer

13 May 2027 is the commencement date for the DPDP Act’s substantive duties. It defers nothing else. The CERT-In directions have applied since 2022 — six-hour reporting and 180-day onshore log retention are current law — and section 43A with the SPDI Rules governs sensitive personal data today.

The operational work is therefore required before the DPDP deadline rather than after it. Logging, monitoring and incident handling built for CERT-In, and an ISMS certified against Rule 8, are the same components the DPDP’s 72-hour breach regime will run on in 2027.

How Secure60 handles this

Secure60 delivers the certification and operates the security behind it. In India that means building the ISMS Rule 8 recognises, then operating what the CERT-In directions require: logging with 180-day retention on Indian infrastructure via Rackcorp, monitoring that makes a six-hour report achievable, and incident management ready for the Data Protection Board’s 72-hour regime in 2027. The certification audit belongs to a NABCB-accredited body; we make sure that what they sample is running. Secure60 is ISO 27001:2022 certified.

Frequently Asked Questions

Is ISO 27001 legally mandatory in India?

No. Certification is not mandatory. Rule 8 of the SPDI Rules 2011 names IS/ISO/IEC 27001 by title: an organisation that implements the standard and has that implementation certified or audited is deemed to have met the ‘reasonable security practices’ required under section 43A of the IT Act. No other data-protection law in the region names a standard this way.

Is the DPDP Act in force yet?

Partly. The Act was passed in 2023 and the DPDP Rules were notified on 13 November 2025. Most substantive obligations commence on 13 May 2027. Until then, the IT Act 2000 and the SPDI Rules 2011 govern.

What does the CERT-In 6-hour rule require?

The CERT-In Cyber Security Directions of 28 April 2022 require listed cyber incidents to be reported to CERT-In within 6 hours of noticing, and ICT logs to be retained for 180 days within Indian jurisdiction. These directions are in force now, independent of the DPDP commencement date.

Does our data have to stay in India?

The DPDP Act imposes no general localisation rule. Sectoral rules apply: the RBI has required payment-system data to be stored in India since 15 October 2018, and SEBI and IRDAI have similar sectoral rules. The CERT-In directions separately require 180-day log retention within Indian jurisdiction.

Who performs the ISO 27001 certification audit in India?

A certification body accredited by NABCB (the National Accreditation Board for Certification Bodies, under the Quality Council of India). Secure60 does not perform certification audits. Audit fees are set by the certification body and vary with the size and scope of what’s certified.

Can Secure60 deliver in India?

Yes. We have delivery infrastructure in India via Rackcorp, across two datacentres, so log collection and 180-day retention can run within Indian jurisdiction. We have no local offices, and we do not perform the certification audit.

India SPDI, CERT-In and DPDP Readiness

A readiness call maps the SPDI Rules, the CERT-In directions and the incoming DPDP duties against the environment and scopes the ISMS.

30 days, every feature switched on. No credit card.