Know which rules apply
We read your licenses, card flows and contracts, and list each obligation next to the reader who checks it.
Fintech and banking security compliance in India
For banks, NBFCs, payment and lending apps. We help you build and secure the product, and we work out which rules really apply: RBI or SEBI through your license, PCI DSS v4.0.1 through card data, SOC 2 through a bank customer's contract. Each wants different evidence, so we settle that before you buy any assessment.
What we do
Three kinds of help for financial companies. Start with any one, or book a call and we'll suggest the smallest piece of work that answers your question.
We read your licenses, card flows and contracts, and list each obligation next to the reader who checks it.
We build payment, lending and banking apps for web and mobile, and review the design and code for security before launch.
We find what is exposed, confirm each finding by hand, rank the fixes by risk and check that each fix held.
Need someone to own security and compliance with you over time? See vCISO services and managed security and compliance.
Before any assessment
Regulators and customers do not ask the same questions.
Take a payment company with an RBI authorization, a checkout that touches card numbers, and a product sold to banks. It has several readers. RBI reads against its directions. Your acquirer, the bank that processes your card payments, reads against PCI DSS v4.0.1. A bank customer's vendor-risk team reads against its contract. None of them has to accept evidence written for another.
So order matters. A rule binds you when its applicability line describes your company, not when someone quotes it at you. Buy a vulnerability assessment report before that is settled, and it answers whichever reader happened to ask first. A SOC 2 report has no legal force in India, so it cannot stand in for a regulator's demand.
Find the right help
Most requests start with a rule or a customer's question. Here is the piece of work that answers each one.
Deciding what applies
Every step reads your own documents. You can start on your own, or we can work through it with you.
List each RBI or SEBI authorization and the entity type it names. That type, not your product category, decides which directions address you.
Trace where a card number goes after a customer enters it, including recordings and support tickets. Whether it reaches your servers sets your share of PCI DSS v4.0.1.
Collect security clauses, questionnaires and partner agreements. Note what each one names: a report type, a covered period, a test, or a regulator's expectations passed on to you.
Next to each item, write who reads the evidence: RBI, SEBI, your acquirer, a bank customer or a partner. Choose assessments against that list. Anything without a reader is optional.
What each one asks
Compare the rows that apply to you.
| Rulebook | What it asks for | Worth knowing |
|---|---|---|
| RBI Cybersecurity Directions, 2026 | Separate vulnerability assessment and testing minimums on critical systems | Also before and after go-live, and after major change |
| RBI Payment Aggregator Directions, 2025 | A PCI DSS report with both the Attestation of Compliance (AOC) and the Report on Compliance (ROC) | Where payment data is stored is tied to RBI's 6 April 2018 circular |
| SEBI CSCRF Version 1.0 | Assessment and testing findings in separate report sections | Annexure-A is filed by you, not your tester |
| PCI DSS v4.0.1 | A signed Attestation of Compliance | PCI SSC issues no compliance certificate |
| SOC 2 Type 2 report | Controls shown operating across a stated period | A Type 1 does not count as coverage |
Who signs is not up to us. No rulebook here lets whoever prepared the evidence choose whose name goes on it. SecWiz is not a QSA company, an Approved Scanning Vendor, a CPA firm or a CERT-In empanelled auditor, so any document that needs one of those signers has to come from them. Ask every provider which of these documents it will sign, and for card data, start with how PCI DSS draws its scope.
FAQ
Rulebooks, report formats and who signs what. For anything else, ask us directly.
Only for the entities its rules name. RBI's cybersecurity directions of 31 July 2026 come as separate sets by entity type, and they fix vulnerability assessment and testing minimums for commercial banks, small finance banks, payments banks, NBFCs from the Middle Layer up, credit information companies and all-India financial institutions. We cover the vulnerability assessment side. Part of the required testing is work SecWiz does not perform, so that part needs another provider. Payment aggregators face similar testing demands under separate 2025 directions, and other fintechs can inherit them through a partner bank's contract.
Yes, for a SEBI-regulated entity. CSCRF Version 1.0, as modified by SEBI's Technical Clarifications circular of 28 August 2025, keeps vulnerability assessment findings and testing findings in separate report sections, and wants every tool listed by name, marked open source or commercial, with how it was run. The Annexure-A summary is filed with SEBI by the entity.
For an aggregator, PCI DSS sits inside RBI's rules as well as the card brands'. RBI's Payment Aggregator Directions, 2025 make it responsible for its merchants' infrastructure being compliant and expect a PCI DSS report carrying both the Attestation of Compliance and the Report on Compliance. Where payment data is stored falls under RBI's circular of 6 April 2018.
Some bank customers ask for one, but the requirement comes from their contract, not from a law or regulator, so the customer's clause decides which report and which period it accepts. A SOC 2 report is an opinion issued by an independent licensed CPA firm, and no SOC 2 certificate exists.
Not as a single document. The work can overlap, but each reader expects its own evidence. RBI's aggregator directions want a Report on Compliance beside the Attestation of Compliance, and only a QSA or an Internal Security Assessor signs that report. SEBI's format keeps assessment and testing findings apart. Settle who reads what before agreeing any scope.
No. SecWiz is not a CERT-In empanelled auditing organization, a PCI SSC qualified QSA Company, an Approved Scanning Vendor or a CPA firm, and it holds no approval from RBI or SEBI. Where a rulebook names one of those signers, that document has to come from them.
Let's talk
Send what you know about them. We'll point out which rulebooks apply and which documents need another signer. Project work is delivered remotely from India during business hours. We reply within one working day.