The Indian law that names ISO 27001 — and what changes on 13 May 2027
One Indian rule names IS/ISO/IEC 27001 in its own text and deems an audited implementation compliance with the IT Act. A later Act omits the provisions it was made under.
On this page (6)
One Indian rule names IS/ISO/IEC 27001 in its own text, and deems an audited implementation of it compliance with the security obligation the Information Technology Act imposes. It was made under two provisions of that Act. A later Act omits both, on a date the gazette fixes by formula rather than by calendar.
A certification decision taken this week starts a three-year cycle. The date falls inside it.
Rule 8 says the standard's name
The Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 — G.S.R. 313(E), 11 April 2011 — set the test in Rule 8(1). A body corporate is considered to have complied if it has implemented "a comprehensive documented information security programme and information security policies" whose control measures are "commensurate with the information assets being protected with the nature of business". The same sub-rule adds the part that decides arguments: after a breach the body corporate must "demonstrate, as and when called upon to do so by the agency mandated under the law", that it implemented those measures.
Rule 8(2) then does something almost no other Indian instrument does. It names a standard:
"The international Standard IS/ISO/IEC 27001 on 'Information Technology - Security Techniques - Information Security Management System - Requirements' is one such standard referred to in sub-rule (1)."
Rule 8(4) attaches a consequence, and conditions it twice:
"The body corporate or a person on its behalf who have implemented either IS/ISO/IEC 27001 standard or the codes of best practices for data protection as approved and notified under sub-rule (3) shall be deemed to have complied with reasonable security practices and procedures provided that such standard or the codes of best practices have been certified or audited on a regular basis by entities through independent auditor, duly approved by the Central Government. The audit of reasonable security practices and procedures shall be carried out by an auditor at least once a year or as and when the body corporate or a person on its behalf undertake significant upgradation of its process and computer resource."
Read the proviso rather than the promise. The deeming runs on regular certification or audit by an independent auditor approved by the Central Government, and carries two triggers: the calendar, at least once a year, and a significant upgradation of process or computer resource.
The two provisions it stands on
G.S.R. 313(E) opens by naming its own authority: "In exercise of the powers conferred by clause (ob) of sub-section (2) of section 87 read with section 43A of the Information Technology Act, 2000 (21 of 2000)."
So section 43A is the obligation Rule 8 deems compliance with, and section 87(2)(ob) is the rule-making power the Rules were made under. Section 44(2) of the Digital Personal Data Protection Act, 2023 addresses both:
"(2) The Information Technology Act, 2000 shall be amended in the following manner, namely:— (a) section 43A shall be omitted; (b) in section 81, in the proviso, after the words and figures 'the Patents Act, 1970', the words and figures 'or the Digital Personal Data Protection Act, 2023' shall be inserted; and (c) in section 87, in sub-section (2), clause (ob) shall be omitted."
The date, in the gazette's own words
Commencement notification G.S.R. 843(E), Ministry of Electronics and Information Technology, dated the 13th November, 2025, is made under section 1(2) of the DPDP Act and appoints three dates. Clause (a) commenced the Act's machinery on publication; clause (b) sets one year for section 6(9) and section 27(1)(d). Clause (c) carries the rest:
"eighteen months from the date of publication of this gazette, on which the provision of sections 3 to 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 10, sections 11 to 17, section 27 except clause (d) of sub-section (1) of the said section, sections 28 to 34, 36, 37 and sub-section (2) of section 44 of the said Act shall come into force."
Because the notification fixes the date by formula, two dates circulate. The gazette issue carrying G.S.R. 843(E) is No. 757, headed NEW DELHI, THURSDAY, NOVEMBER 13, 2025. The Controller of Publications' digital signature on the same file is timestamped 14 November 2025 at 10:37 IST, and the e-gazette reference reads CG-DL-E-14112025-267647. Eighteen months from the first is 13 May 2027; from the second, 14 May 2027. Both appear in serious published timetables. Nothing in a certification programme turns on twenty-four hours — plan against the earlier date.
One thing could move it, and only earlier. At a stakeholder consultation on 22 January 2026 the Ministry raised compressing the eighteen-month runway to twelve, which would bring these provisions forward to November 2026, and sought comments by 4 February 2026. The operative date remains the one G.S.R. 843(E) fixes: as at 27 August 2026 that proposal has not been carried into a commencement notification. Worth a watch rather than a re-plan.
What starts on the same morning
Clause (c) is not a single-provision commencement, and the Rules run on the same clock. Rule 1(4) of the DPDP Rules, 2025: "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette." Four things that decide how an Indian organisation evidences information security start together.
| Provision | What it does |
|---|---|
| DPDP Act s.8(5) | "A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach." |
| DPDP Rules, 2025, Rule 6(1) | Sets the minimum content of those safeguards — seven items |
| DPDP Rules, 2025, Rule 13(1) | A Significant Data Fiduciary shall, "once in every period of twelve months", undertake a Data Protection Impact Assessment and an audit; 13(2) requires whoever carries them out to report significant observations to the Board |
| DPDP Act s.33 and the Schedule | Entry 1 — breach of the s.8(5) obligation — carries a penalty that "may extend to two hundred and fifty crore rupees", the largest of the Schedule's seven entries |
Rule 6 is drafted as control categories rather than by reference to a named standard. A Data Fiduciary's safeguards "shall include, at the minimum" encryption or equivalent obfuscation, access control, "visibility on the accessing of such personal data, through appropriate logs, monitoring and review", backups, contractual safeguards binding the Data Processor, and retention of those logs and personal data "for a period of one year, unless compliance with any law for the time being in force requires otherwise".
An ISMS built for ISO/IEC 27001:2022 clause 6.1.3 will already produce most of that. Two of the seven items are fixed numbers rather than risk-based decisions, and are the ones to check against what the ISMS actually does: the one-year retention floor, and Rule 13's twelve-month cycle.
The other Indian instrument that names it runs on a different clock
SEBI's Cybersecurity and Cyber Resilience Framework, master circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 of 20 August 2024, names it too. Section 4.2.1, at page 47:
"It is mandated (as per standard PR.IP.S16) that MIIs and Qualified REs shall obtain ISO 27001 (latest version) certification. Accordingly, all MIIs and Qualified REs shall obtain ISO 27001 within 1 year of issuance of CSCRF. The evidence of certification shall be submitted along with the cyber audit report to the authority(ies) as given below."
The guideline to PR.IP.S16, at page 115, sets the scope: "The scope for ISO 27001 certification shall include (but not limited to) PDC site, DR site, NDR site, SOC, and Colocation facility." MIIs, under Box Item 1, are Stock Exchanges, Depositories, Clearing Corporations, KRAs and QRTAs.
That position was amended a year later, and the two must always be read together. Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 of 28 August 2025 carries paragraph 6.11, headed "Requirement of ISO 27001 certification for Qualified REs". The clarification, in full: "Qualified REs are encouraged and recommended (not mandatory) to obtain ISO 27001 certification." For MIIs the §4.2.1 mandate stands as written. Two extension circulars had moved CSCRF timelines for every RE except MIIs, KRAs and QRTAs — to 30 June 2025, then to 31 August 2025 — and the clarification landed three days before that date.
CSCRF FAQ 58 of 11 June 2025 carries the scope down the supply chain: where any site in the PR.IP.S16 list is outsourced, "it must be ensured that those third-party service providers are also ISO 27001 certified for the services being outsourced to them."
Section 44(2) amends the Information Technology Act. CSCRF is issued under section 11(1) of the SEBI Act, 1992. A regulated entity's ISO 27001 obligation runs on the securities market's timetable, and 13 May 2027 does not appear in it.
The arithmetic on a certificate you are buying now
Under ISO/IEC 17021-1:2015 clause 9.1.3.2, the audit programme runs a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration. Which party produces which document, and who is barred from producing which sets out the rest of the vocabulary.
An organisation reaching a certification decision in 2026 will be in its first surveillance year on 13 May 2027. The certificate outlasts the statutory section that the rule naming the standard was written against. Two things are worth doing before that date rather than after.
Write the scope against the obligation you are answering. The scope statement under ISO/IEC 27001:2022 clause 4.3 and the Statement of Applicability under 6.1.3 d) record what is being certified and why. A certificate obtained for PR.IP.S16 has five named site types to reach and a supply chain behind them. One obtained for a data-protection obligation answers an obligation whose statutory basis changes on a known date, and should be scoped for the state it will be in.
Build the evidence for every cadence at once. Rule 8(4) asks for an audit at least once a year and on significant upgradation. Rule 13(1) will ask a Significant Data Fiduciary for a DPIA and an audit every twelve months, reported to the Board. A surveillance audit is annual too, but it is the certification body's audit of the management system and is neither of those — nor is the clause 9.2 internal audit, which is yours, and which the certification body is barred from performing for you. Four annual obligations drawing on one evidence base are a single programme if scoped together, and four arguments if not.
Security Brigade works the readiness side: scoping, risk assessment and treatment, the Statement of Applicability, control implementation, the clause 9.2 internal audit, and the evidence base a certification body reads — ISO 27001 readiness and internal audit.
Every clause number, quotation and date above was checked against primary gazette or circular text on 27 August 2026.
Continue reading
All articles →Why the firm that prepares you cannot be the firm that certifies you
No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you, it shall not certify you for two years.
Who issues an ISO 27001 certificate, and what every other party produces
An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the Statement of Applicability.
SOC 2 Type 1 and Type 2: one date, one period, and a deadline already given
A Type 1 opinion speaks about one date. A Type 2 speaks about a stretch of time that has already closed by the time anyone reads the report. Most of the cost follows from that.