Back to home
Compliance & Regulations

Regulatory frameworks, decoded for your enterprise

Open Security Alliance is a trusted compliance advisory partner across India and global mandates. Explore the frameworks we implement, audit, and defend — from RBI and SEBI CSCRF to ISO 27001, PCI DSS, HIPAA, GDPR, SOC 2, and NIST CSF 2.0.

Latest
India · Financial

RBI Cyber Security Framework

Reserve Bank of India cyber resilience mandates for banks, NBFCs, payment operators and PAPG-regulated entities.

Updated 2026 · Baseline controls refresh
Learn more
Latest
India · Capital Markets

SEBI Cyber Security & Cyber Resilience Framework

Cyber Security and Cyber Resilience Framework for SEBI-regulated intermediaries — MIIs, brokers, mutual funds, portfolio managers.

Effective April 2026 · CSCRF v2
Learn more
Latest
India · Privacy

Digital Personal Data Protection Act

India's comprehensive personal data protection law governing collection, processing, cross-border transfer, and consent management.

DPDP Rules 2026 notified
Learn more
Latest
Global · Standards

ISO/IEC 27001:2022

International standard for Information Security Management Systems (ISMS) — the de-facto enterprise security certification.

2022 controls (Annex A revision)
Learn more
Latest
India · Incident Response

CERT-In Directions

Indian Computer Emergency Response Team directions on incident reporting, log retention, KYC for VPN/cloud, and cyber hygiene.

6-hour reporting mandate active
Learn more
Latest
Global · Payments

PCI DSS 4.0

Payment Card Industry Data Security Standard — mandatory for organisations that store, process, or transmit cardholder data.

v4.0.1 future-dated controls
Learn more
Latest
Global · Healthcare

HIPAA Security Rule

Health Insurance Portability and Accountability Act — protects electronic Protected Health Information (ePHI).

Security Rule NPRM 2025
Learn more
EU · Privacy

GDPR

EU General Data Protection Regulation — extraterritorial data protection law with strict consent, DPIA and breach obligations.

AI Act interoperability guidance
Learn more
Global · Assurance

SOC 2 Type II

AICPA System and Organization Controls report on Security, Availability, Confidentiality, Processing Integrity, and Privacy.

2022 TSC criteria
Learn more
Latest
Global · Framework

NIST Cybersecurity Framework 2.0

NIST Cybersecurity Framework 2.0 — the industry-standard voluntary framework for managing cyber risk.

CSF 2.0 with Govern function
Learn more

Need a compliance readiness assessment?

Our compliance desk delivers end-to-end programs across all frameworks above — gap analysis, control design, evidence packs, and audit representation.

Talk to our advisory