| RBI cyber security framework | The external asset inventory, the continuous-monitoring record, per-finding remediation timestamps measured against your own window, third-party exposure, and the action log showing who changed what. | RBI evidence guide |
| Applicability is not stated, and no supervisory reading of any obligation is offered. The rows map evidence to artefacts; whether that evidence answers a supervisor is assessment work, and it sits with Security Brigade. |
| SEBI CSCRF | The same evidence rows, plus a validation row marked in the cell as evidence the framework does not ask for. Tier and classification are absent by design — they are not ours to state. | SEBI CSCRF evidence guide |
| Written against the technical clarifications of 28 August 2025, which made Breach and Attack Simulation and Continuous Automated Red-Teaming recommendatory rather than mandatory. Any matrix still presenting Continuous Automated Red-Teaming as a CSCRF requirement is out of date — the band below sets out what changed. |
| IRDAI cyber-security guidelines | Rows for the estate an insurer answers for but does not operate: intermediary and distribution properties, policyholder credential exposure, and look-alike quote and payment pages. | IRDAI monitoring guide |
| These rows carry the longest boundary column in the matrix. An intermediary property is somebody else’s asset and your exposure at the same time, and an outside-in method reaches only what is reachable from outside it. |
| DPDP Act | What external monitoring can establish about personal data already outside your control — where it was observed, when it was first seen, and what it is attributable to. | DPDP exposure guide |
| Nothing in these rows determines whether a personal data breach has occurred, or what follows from one if it has. That determination is legal, and it is not a monitoring vendor’s to make. |
| DORA | Outside-in monitoring evidence on the ICT third-party providers you nominate, with the boundary column stating plainly what that evidence never reaches. | DORA exposure guide |
| Provider-side findings are an input to a third-party risk assessment. They are not the assessment, they designate nothing, and no outside-in method sees anything behind a provider’s perimeter. The rows cite no article number. |
| NIS2 | Supplier-side external findings scored with the same categories, the same arithmetic and the same bands used on your own estate, so an internal target and a supplier threshold are directly comparable. | NIS2 supply-chain guide |
| The NIS2 rows describe what the monitoring record holds, not what the directive obliges — no article, no scope threshold, no entity classification. Which entities are in scope, and under whose national law, is a question for your own counsel. |
| ISO 27001:2022 | The monitoring, logging and supplier rows an ISMS audit expects to see operating rather than documented: dated, scoped, and attributable to a named person and a specific asset. | Covered in the matrix only |
| No control identifiers. A published Annex A mapping is a claim about what the standard requires of your ISMS, it depends on your own scope and control set, and it is certification work rather than product documentation. |
| SOC 2 | The artefacts a service auditor asks for on monitoring, change and vendor oversight, expressed as dated records covering a period rather than a state on the day someone looked. | Covered in the matrix only |
| A SOC 2 report is an opinion issued by a licensed service auditor about your controls over a period. Nothing in the matrix is that opinion, and no artefact in it substitutes for the examination that produces one. |