Understand all eight requirements at a glance.
| Requirement | Who it applies to | What you end up holding | Typical | Link |
|---|---|---|---|---|
| DPDP Compliance | Anyone processing personal data in India | Consent architecture, retention schedule, breach playbook | 8–14 weeks | |
| Managed SOC / MDR | Too many alerts and no one to manage them | Experienced analysts, clear response times, and monthly management reports | Retained | |
| VAPT | Web, mobile, network, cloud and application estates | Ranked findings, remediation plan and a retest | 3–6 weeks | |
| ISO 27001 | Tender prerequisites and enterprise customers | Statement of Applicability and a certified ISMS | 12–20 weeks | |
| GDPR | Organisations processing EU personal data | Records of processing, DPIAs and transfer mechanisms | 8–14 weeks | |
| SOC 2 | SaaS and IT services selling into enterprises | A Type I report, then Type II over the observation window | 12–24 weeks | |
| SEBI CSCRF | Market intermediaries and market infrastructure | Gap closure and board-level reporting pack | 8–16 weeks |
Confused about the requirements? We can help you narrow them down.
Let’s Understand Your Security Needs
Talk to a cybersecurity expert, not just a salesperson. In 30 minutes, understand what you actually need before starting the project.
Or reach the incident line directly on +91 9147712576, monitored 24×7 from Kolkata.