Regulation

NIST, ISO 27001, SOC 2, DORA: what binds you in India

NIST CSF, ISO 27001, SOC 2, PCI DSS and DORA are frameworks, not laws — what each is for, and how it maps onto RBI, SEBI, IRDAI and CERT-In rules in India.

In short
NIST CSF, ISO/IEC 27001, SOC 2, PCI DSS, DORA and NIS2 describe global expectations for managing cyber risk, but are not interchangeable with each other or with Indian law — some are voluntary, some certifiable, some contractual, some statutory. None discharges an Indian entity’s own duties under the RBI, SEBI’s CSCRF, IRDAI’s 2026 Guidelines, CERT-In’s six-hour rule or the DPDP Rules; a firm operating in India typically needs both.

A framework, a standard and a law are three different claims

A vendor questionnaire or a board pack will happily use “framework” to cover NIST CSF, ISO 27001, SOC 2, PCI DSS and the RBI’s own Directions in the same sentence. They are not the same kind of thing, and the difference decides what each one can actually discharge.

  • Voluntary guidance organises a programme and cannot be failed — the NIST Cybersecurity Framework and the CIS Controls sit here.
  • A certifiable standard sets requirements an independent body audits against, for a scope the certificate names — ISO/IEC 27001 is the reference case.
  • An attestation reports what an auditor examined, over a stated period — a SOC 2 report.
  • A contractual or industry requirement binds through a scheme or an agreement rather than through statute — PCI DSS, and the flow-down clauses covered in NIS2, DORA and SEC Reg S-P.
  • Law. The RBI’s Directions, SEBI’s CSCRF, IRDAI’s Guidelines, CERT-In’s Directions and the DPDP Rules create an enforceable duty whether or not an organisation has adopted anything else on this list.

Only the last category binds an Indian entity by itself. Everything above it can be genuinely useful and still leave the legal obligation open — which is the confusion this page exists to close.

Thirteen names, five kinds of claim

Most of what circulates as “the major frameworks” reduces to the same thirteen names, each doing one of the five jobs above.

NameKind of claimWho it typically reaches
NIST CSF 2.0Voluntary frameworkAny sector, as an organising structure
ISO/IEC 27001:2022Certifiable standardSaaS, cloud, financial services, government suppliers
CIS Controls v8.1Voluntary frameworkAny size, as a prioritised baseline
SOC 2AttestationSaaS, cloud, fintech, managed service providers
COBIT 2019Governance frameworkLarge enterprises, regulated organisations
PCI DSS 4.0.1Industry requirementAnyone storing, processing or transmitting card data
CMMCContractual requirementUS defence contractors and subcontractors
NERC CIPMandatory reliability standardUS and Canadian Bulk Electric System entities
HIPAA Security RuleLawUS covered entities and their business associates
FISMA / NIST RMFLawUS federal agencies and their contractors
GDPRLawEU controllers and processors, and anyone serving EU residents
DORALawEU financial entities and their ICT providers
NIS2Law (via national transposition)Essential and important entities across 18 EU sectors
Global frameworks, standards and laws most often cited in a security programme or a vendor questionnaire.

None of these thirteen were written with India in view, and none of them names an Indian regulator. That is the gap the rest of this page is about.

NIST CSF, ISO 27001 and SOC 2 — the three an Indian buyer meets most

Three names dominate real vendor conversations in India, for three different reasons.

  • NIST CSF 2.0 organises a programme around six functions — Govern, Identify, Protect, Detect, Respond, Recover. It prescribes no specific control and carries no certification, so “we follow NIST CSF” is a statement about structure, not about evidence.
  • ISO/IEC 27001:2022 certifies that an Information Security Management System operates within a defined scope. The scope is the entire value of the claim — a certificate covering one business unit says nothing about the service actually being bought from a different one.
  • SOC 2 reports what an independent CPA firm examined against the AICPA Trust Services Criteria, over a stated period for a Type II report. It is the report Indian SaaS and BPO vendors are asked for most often by overseas customers, and it answers a narrower question than a certificate does: what was tested, for whom, and when.

DORA, NIS2, PCI DSS and GDPR — the ones that reach you by contract

None of these four name Indian entities, and almost no Indian firm falls directly inside any of them. That has little bearing on whether they reach you.

DORA and NIS2 push obligations down the chain contractually — a European bank subject to DORA has to place specified terms in its ICT contracts, and if an Indian firm sits in that chain, the terms arrive at renewal rather than from a regulator. What each regime actually demands of third parties covers the detail; the pattern is the same one PCI DSS uses domestically — a payment gateway or processor is drawn in through the card networks’ own compliance programme, not through Indian statute.

GDPR is the one exception that binds directly rather than by contract: an Indian company offering goods or services to people in the EU, or monitoring their behaviour there, is in scope on its own terms, independent of where the company is incorporated. Holding data about an EU resident is not by itself enough to trigger it — the offering or monitoring test is what does.

What each maps to under Indian law

This is the table a global framework does not draw, because it was not written to. For an Indian entity, each name above sits beside a domestic instrument that keeps applying regardless of what the global framework says.

Global nameWhat it does not cover in IndiaWhat still binds
NIST CSF, CIS ControlsNo compliance date, no audit, no reporting dutyEvery sector-specific instrument that applies to the entity
ISO/IEC 27001No VAPT cadence, no board reporting format, no incident clockSEBI’s CSCRF, the RBI’s 2026 Directions or IRDAI’s 2026 Guidelines, as applicable — plus IFSCA’s certification date for GIFT City MIIs, the one place ISO 27001 itself is written into a compliance deadline
SOC 2No CERT-In notification, no DPDP breach dutyCERT-In’s six-hour rule and, for personal data, the DPDP Rules’ own clocks
PCI DSSNo RBI oversight of the entity itselfRBI directions applicable to the payment system participant, if regulated as one
GDPRNo DPDP compliance, even where scope overlapsThe DPDP Rules, for any personal data of an Indian Data Principal
DORA, NIS2No Indian regulator satisfied by EU complianceWhichever domestic instrument binds the entity by sector, unaffected
What continues to bind an Indian entity alongside each global framework, standard or law.

Read the other direction, the same table answers the more common question: an Indian entity compliant with CSCRF, the RBI’s Directions or IRDAI’s Guidelines has met none of the global names by doing so, and typically has to run the two in parallel rather than fold one into the other.

Where to start, if you are choosing one

For an Indian entity, the domestic instrument is never optional — it is set by sector and by law, and which one applies is a fact, not a choice. The global framework layered on top is a choice, and it is worth making deliberately rather than by whichever name a customer mentioned first.

  • Selling to Indian regulated entities. The domestic instrument already sets the controls and the cadence. A voluntary framework adds structure on top; it does not change what has to be evidenced or by when.
  • Selling to global enterprise or SaaS buyers. SOC 2 Type II is the report asked for most often, because it is what a buyer’s own procurement process expects to see.
  • Selling into regulated supply chains — banking, insurance, critical infrastructure. ISO/IEC 27001 travels further, because it is the one a customer’s own auditor can map against a control catalogue rather than take on trust.
  • Building the programme itself, with no external report due yet. NIST CSF or the CIS Controls give a working structure without the cost of certification, and either maps cleanly onto ISO 27001 later if a certificate becomes necessary.

A certificate is a point-in-time claim

Every name on this page — voluntary, certifiable, attested or statutory — shares one limit. A certificate describes a scope at a point in time, or over a stated period that has already ended. Assets, vendors, exposures and configurations keep changing after the auditor leaves, and the framework that produced the certificate has no mechanism for saying so.

Continuous, externally observed measurement is the artefact that sits underneath all of them without expiring on the audit date — the same argument made against the annual questionnaire applies here. It does not replace certification, an ISMS or a regulator’s own audit cycle; it is the evidence that what any of them found on the day still holds true today.

Background reading: Bitsight’s guide to the thirteen frameworks, the NIST Cybersecurity Framework, and the ISO/IEC 27001:2022 and PCI DSS standards pages. Indian instruments are read from the issuing regulator’s own notification and tracked in the India cyber regulation register. This page is a summary for orientation and is not legal advice; confirm scope and applicability with counsel. Continuous external measurement referenced here is a Bitsight capability; BitScore Cybertech LLP is an authorised Bitsight partner.

Questions this page answers

Does an ISO 27001 certificate satisfy RBI, SEBI or IRDAI cyber security requirements in India?
No. None of the Indian instruments accept a certificate in place of their own obligations. The RBI’s 2026 Directions, SEBI’s CSCRF and IRDAI’s 2026 Guidelines each mandate specific, dated artefacts — a VAPT cadence, board-approved policies, category-based audits, CERT-In’s six-hour incident report — that an ISMS certified under ISO 27001 can support but cannot substitute for.
What is the difference between a cybersecurity framework, a standard and a regulation?
A framework such as NIST CSF or the CIS Controls is voluntary guidance for organising a security programme; it cannot be failed. A standard such as ISO/IEC 27001 sets requirements an independent body certifies against, for a defined scope. An attestation such as SOC 2 reports what an auditor examined over a period. A law or regulation — the RBI’s Directions, SEBI’s CSCRF, IRDAI’s Guidelines, CERT-In’s Directions, the DPDP Rules — creates an enforceable duty regardless of what any of the others say.
Which global standard does an Indian regulator actually write into a binding instrument?
ISO/IEC 27001. IFSCA’s 2026 Guidelines for Market Infrastructure Institutions in GIFT City require ISO 27001 certification within two years of the Guidelines’ issuance — the one place in the Indian cyber regulation register a certifiable global standard is named as a compliance date rather than left to a firm’s own choice.
We hold a SOC 2 report — does that cover our CERT-In or DPDP obligations?
No. A SOC 2 report examines a defined system boundary against the Trust Services Criteria for a stated period; it says nothing about CERT-In’s six-hour reporting clock or the DPDP Rules’ breach-notification duties, both of which run on their own trigger regardless of what any attestation states.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Work out which Indian instruments bind you