Compliance guides
Plain-English guides to the frameworks that matter
Practical walkthroughs of ISO 27001, PCI DSS, SOC 2, DPDP and VAPT, written by the CERT-In empanelled senior auditors who run these assessments. What the standard actually asks for, what evidence satisfies it, and where teams usually fail.
01 / 07
ISO 27001
The global standard for information security management, the certification enterprise buyers ask for most.
02 / 07
PCI DSS
Payment card data security, mandatory for anyone who stores, processes or transmits cardholder data.
03 / 07
SOC 2
The trust report US and global customers expect from SaaS vendors before they buy.
04 / 07
VAPT / Penetration Testing
Find and fix real vulnerabilities before attackers do, with CERT-In empanelled, senior-auditor-led testing.
05 / 07
DPDP and Data Privacy
India’s Digital Personal Data Protection Act, and the board-level accountability it creates for how you handle personal data.
06 / 07
Regulatory and Strategy
Sector rules, and the build against buy decisions behind a compliance programme that actually holds up.
07 / 07
Not sure where to start?
Begin with a score rather than a proposal.
More resources
Keep going
Talk to us
Want the guide applied to your environment?
A senior assessor will walk your scope, tell you which of these apply and what the realistic path to an audit looks like.
support@threatsys.co.in