Certifications & Compliance
Evidence requirements by vendor type. Requested automatically in the vendor portal and monitored for expiry.
| Certification | Applies to | Requirement | Validity | Reminder | Document | Issuer | Origin | Status | Actions |
|---|---|---|---|---|---|---|---|---|---|
ISO/IEC 27001 Information security management certification. | Data ProcessorCloud Service ProviderIT Service ProviderPayment Processor | Mandatory | 36 months | 90 days before | Required | Accredited certification body | System | Updated 2026-08-01 · System | |
SOC 2 Type II Independent attestation of trust services criteria. | SaaS ProviderCloud Service ProviderData ProcessorAnalytics Provider | Mandatory | 12 months | 60 days before | Required | CPA firm | System | Updated 2026-08-01 · System | |
ISO/IEC 27701 Privacy information management extension. | HR / Payroll ProviderData Processor | Optional | 36 months | 90 days before | Required | Accredited certification body | System | Updated 2026-08-01 · System | |
PCI DSS Payment card industry data security standard. | Payment Processor | Mandatory | 12 months | 60 days before | Required | QSA | System | Updated 2026-08-01 · System | |
Penetration Test Report Annual third-party penetration test. | Cloud Service ProviderSaaS Provider | Mandatory | 12 months | 45 days before | Required | Independent security firm | System | Updated 2026-08-01 · System | |
CERT-In Compliance Evidence Evidence of CERT-In directions compliance (logs, reporting). | Cloud Service ProviderIT Service Provider | Optional | 12 months | 30 days before | Required | Self-attested | Organization | Updated 2026-08-01 · System | |
Privacy Programme Attestation DPDP privacy programme self-attestation. | Marketing AgencyData Processor | Optional | 12 months | 30 days before | Not required | Self-attested | Organization | Updated 2026-08-01 · System |
