NIST, ISO 27001, SOC 2, DORA: what binds you in India
NIST CSF, ISO 27001, SOC 2, PCI DSS and DORA are frameworks, not laws — what each is for, and how it maps onto RBI, SEBI, IRDAI and CERT-In rules in India.
A framework, a standard and a law are three different claims
A vendor questionnaire or a board pack will happily use “framework” to cover NIST CSF, ISO 27001, SOC 2, PCI DSS and the RBI’s own Directions in the same sentence. They are not the same kind of thing, and the difference decides what each one can actually discharge.
- Voluntary guidance organises a programme and cannot be failed — the NIST Cybersecurity Framework and the CIS Controls sit here.
- A certifiable standard sets requirements an independent body audits against, for a scope the certificate names — ISO/IEC 27001 is the reference case.
- An attestation reports what an auditor examined, over a stated period — a SOC 2 report.
- A contractual or industry requirement binds through a scheme or an agreement rather than through statute — PCI DSS, and the flow-down clauses covered in NIS2, DORA and SEC Reg S-P.
- Law. The RBI’s Directions, SEBI’s CSCRF, IRDAI’s Guidelines, CERT-In’s Directions and the DPDP Rules create an enforceable duty whether or not an organisation has adopted anything else on this list.
Only the last category binds an Indian entity by itself. Everything above it can be genuinely useful and still leave the legal obligation open — which is the confusion this page exists to close.
Thirteen names, five kinds of claim
Most of what circulates as “the major frameworks” reduces to the same thirteen names, each doing one of the five jobs above.
| Name | Kind of claim | Who it typically reaches |
|---|---|---|
| NIST CSF 2.0 | Voluntary framework | Any sector, as an organising structure |
| ISO/IEC 27001:2022 | Certifiable standard | SaaS, cloud, financial services, government suppliers |
| CIS Controls v8.1 | Voluntary framework | Any size, as a prioritised baseline |
| SOC 2 | Attestation | SaaS, cloud, fintech, managed service providers |
| COBIT 2019 | Governance framework | Large enterprises, regulated organisations |
| PCI DSS 4.0.1 | Industry requirement | Anyone storing, processing or transmitting card data |
| CMMC | Contractual requirement | US defence contractors and subcontractors |
| NERC CIP | Mandatory reliability standard | US and Canadian Bulk Electric System entities |
| HIPAA Security Rule | Law | US covered entities and their business associates |
| FISMA / NIST RMF | Law | US federal agencies and their contractors |
| GDPR | Law | EU controllers and processors, and anyone serving EU residents |
| DORA | Law | EU financial entities and their ICT providers |
| NIS2 | Law (via national transposition) | Essential and important entities across 18 EU sectors |
None of these thirteen were written with India in view, and none of them names an Indian regulator. That is the gap the rest of this page is about.
NIST CSF, ISO 27001 and SOC 2 — the three an Indian buyer meets most
Three names dominate real vendor conversations in India, for three different reasons.
- NIST CSF 2.0 organises a programme around six functions — Govern, Identify, Protect, Detect, Respond, Recover. It prescribes no specific control and carries no certification, so “we follow NIST CSF” is a statement about structure, not about evidence.
- ISO/IEC 27001:2022 certifies that an Information Security Management System operates within a defined scope. The scope is the entire value of the claim — a certificate covering one business unit says nothing about the service actually being bought from a different one.
- SOC 2 reports what an independent CPA firm examined against the AICPA Trust Services Criteria, over a stated period for a Type II report. It is the report Indian SaaS and BPO vendors are asked for most often by overseas customers, and it answers a narrower question than a certificate does: what was tested, for whom, and when.
DORA, NIS2, PCI DSS and GDPR — the ones that reach you by contract
None of these four name Indian entities, and almost no Indian firm falls directly inside any of them. That has little bearing on whether they reach you.
DORA and NIS2 push obligations down the chain contractually — a European bank subject to DORA has to place specified terms in its ICT contracts, and if an Indian firm sits in that chain, the terms arrive at renewal rather than from a regulator. What each regime actually demands of third parties covers the detail; the pattern is the same one PCI DSS uses domestically — a payment gateway or processor is drawn in through the card networks’ own compliance programme, not through Indian statute.
GDPR is the one exception that binds directly rather than by contract: an Indian company offering goods or services to people in the EU, or monitoring their behaviour there, is in scope on its own terms, independent of where the company is incorporated. Holding data about an EU resident is not by itself enough to trigger it — the offering or monitoring test is what does.
What each maps to under Indian law
This is the table a global framework does not draw, because it was not written to. For an Indian entity, each name above sits beside a domestic instrument that keeps applying regardless of what the global framework says.
| Global name | What it does not cover in India | What still binds |
|---|---|---|
| NIST CSF, CIS Controls | No compliance date, no audit, no reporting duty | Every sector-specific instrument that applies to the entity |
| ISO/IEC 27001 | No VAPT cadence, no board reporting format, no incident clock | SEBI’s CSCRF, the RBI’s 2026 Directions or IRDAI’s 2026 Guidelines, as applicable — plus IFSCA’s certification date for GIFT City MIIs, the one place ISO 27001 itself is written into a compliance deadline |
| SOC 2 | No CERT-In notification, no DPDP breach duty | CERT-In’s six-hour rule and, for personal data, the DPDP Rules’ own clocks |
| PCI DSS | No RBI oversight of the entity itself | RBI directions applicable to the payment system participant, if regulated as one |
| GDPR | No DPDP compliance, even where scope overlaps | The DPDP Rules, for any personal data of an Indian Data Principal |
| DORA, NIS2 | No Indian regulator satisfied by EU compliance | Whichever domestic instrument binds the entity by sector, unaffected |
Read the other direction, the same table answers the more common question: an Indian entity compliant with CSCRF, the RBI’s Directions or IRDAI’s Guidelines has met none of the global names by doing so, and typically has to run the two in parallel rather than fold one into the other.
Where to start, if you are choosing one
For an Indian entity, the domestic instrument is never optional — it is set by sector and by law, and which one applies is a fact, not a choice. The global framework layered on top is a choice, and it is worth making deliberately rather than by whichever name a customer mentioned first.
- Selling to Indian regulated entities. The domestic instrument already sets the controls and the cadence. A voluntary framework adds structure on top; it does not change what has to be evidenced or by when.
- Selling to global enterprise or SaaS buyers. SOC 2 Type II is the report asked for most often, because it is what a buyer’s own procurement process expects to see.
- Selling into regulated supply chains — banking, insurance, critical infrastructure. ISO/IEC 27001 travels further, because it is the one a customer’s own auditor can map against a control catalogue rather than take on trust.
- Building the programme itself, with no external report due yet. NIST CSF or the CIS Controls give a working structure without the cost of certification, and either maps cleanly onto ISO 27001 later if a certificate becomes necessary.
A certificate is a point-in-time claim
Every name on this page — voluntary, certifiable, attested or statutory — shares one limit. A certificate describes a scope at a point in time, or over a stated period that has already ended. Assets, vendors, exposures and configurations keep changing after the auditor leaves, and the framework that produced the certificate has no mechanism for saying so.
Continuous, externally observed measurement is the artefact that sits underneath all of them without expiring on the audit date — the same argument made against the annual questionnaire applies here. It does not replace certification, an ISMS or a regulator’s own audit cycle; it is the evidence that what any of them found on the day still holds true today.
Background reading: Bitsight’s guide to the thirteen frameworks, the NIST Cybersecurity Framework, and the ISO/IEC 27001:2022 and PCI DSS standards pages. Indian instruments are read from the issuing regulator’s own notification and tracked in the India cyber regulation register. This page is a summary for orientation and is not legal advice; confirm scope and applicability with counsel. Continuous external measurement referenced here is a Bitsight capability; BitScore Cybertech LLP is an authorised Bitsight partner.
Questions this page answers
- Does an ISO 27001 certificate satisfy RBI, SEBI or IRDAI cyber security requirements in India?
- No. None of the Indian instruments accept a certificate in place of their own obligations. The RBI’s 2026 Directions, SEBI’s CSCRF and IRDAI’s 2026 Guidelines each mandate specific, dated artefacts — a VAPT cadence, board-approved policies, category-based audits, CERT-In’s six-hour incident report — that an ISMS certified under ISO 27001 can support but cannot substitute for.
- What is the difference between a cybersecurity framework, a standard and a regulation?
- A framework such as NIST CSF or the CIS Controls is voluntary guidance for organising a security programme; it cannot be failed. A standard such as ISO/IEC 27001 sets requirements an independent body certifies against, for a defined scope. An attestation such as SOC 2 reports what an auditor examined over a period. A law or regulation — the RBI’s Directions, SEBI’s CSCRF, IRDAI’s Guidelines, CERT-In’s Directions, the DPDP Rules — creates an enforceable duty regardless of what any of the others say.
- Which global standard does an Indian regulator actually write into a binding instrument?
- ISO/IEC 27001. IFSCA’s 2026 Guidelines for Market Infrastructure Institutions in GIFT City require ISO 27001 certification within two years of the Guidelines’ issuance — the one place in the Indian cyber regulation register a certifiable global standard is named as a compliance date rather than left to a firm’s own choice.
- We hold a SOC 2 report — does that cover our CERT-In or DPDP obligations?
- No. A SOC 2 report examines a defined system boundary against the Trust Services Criteria for a stated period; it says nothing about CERT-In’s six-hour reporting clock or the DPDP Rules’ breach-notification duties, both of which run on their own trigger regardless of what any attestation states.