Cyber security has moved from an IT-team concern to a boardroom risk — accelerated by the Digital Personal Data Protection Act, 2023 (DPDP Act), the CERT-In directions on incident reporting, the RBI cyber-security framework, and customer contracts increasingly requiring ISO 27001, SOC 2 and third-party VAPT attestation. A serious cyber posture is now a condition of doing enterprise business.
The Exim Roof runs an information-security advisory practice that combines regulatory expertise, ISO 27001 lead auditors, penetration testers, cloud-security architects and privacy counsel. We build defensible security programs, close specific gaps against ISO 27001 / SOC 2 / DPDP Act / PCI-DSS, and support you through internal / third-party audits and CERT-In incident response.
Regulatory landscape we help you navigate
- Digital Personal Data Protection Act, 2023 (DPDP Act) — consent, notice, DPO, breach reporting, cross-border transfer, children data.
- CERT-In directions dated 28 April 2022 — 6-hour incident reporting, 180-day log retention, KYC and traceability requirements.
- RBI cyber-security framework for banks, NBFCs, PSOs and PPI issuers.
- SEBI Cyber Security & Resilience Framework (CSCRF) for regulated intermediaries.
- Sector-specific mandates from IRDAI, TRAI, MeitY and DGGI.
Certifications and attestations we deliver
Enterprise contracts and marketplace listings increasingly require independent attestation of your security controls. Our team drives every stage — scoping, gap analysis, remediation, internal audit, stage-1 and stage-2 audit support with an accredited certification body.
- ISO / IEC 27001:2022 Information Security Management System.
- ISO / IEC 27701 Privacy Information Management System.
- ISO / IEC 27017 and 27018 for cloud security and cloud PII.
- SOC 2 Type I and Type II readiness against Trust Service Criteria.
- PCI-DSS v4.0 for payment environments.
- ISO 22301 Business Continuity Management.
Vulnerability assessment and penetration testing (VAPT)
Our red-team practice runs black-box, grey-box and white-box VAPT against web applications, mobile applications, APIs, cloud environments and internal networks. Every engagement produces a CVSS-scored report, a proof-of-concept for every finding, and a retest to close the loop after remediation. We also deliver source-code review, cloud posture assessment (AWS / Azure / GCP CIS benchmark) and container / Kubernetes security review.
DPDP Act 2023 compliance — a full programme
The DPDP Act 2023 imposes obligations on every Data Fiduciary — consent management, notices, purpose limitation, data-principal rights, breach reporting, appointment of a Data Protection Officer for Significant Data Fiduciaries, and lawful cross-border transfer. Non-compliance attracts penalties of up to ₹250 crore per breach category. We build the privacy programme end-to-end — data-flow mapping, ROPA, consent-artefact design, DPIA, DPO-as-a-service, breach-response playbooks and vendor-risk clauses.
How The Exim Roof helps
- Gap assessment against the target framework (ISO 27001 / SOC 2 / DPDP / PCI-DSS).
- ISMS and privacy documentation — policies, procedures, records, ROPA, DPIA templates.
- Technical hardening — cloud posture, endpoint hardening, SIEM tuning, email security.
- VAPT, source-code review and cloud-security assessment with actionable remediation.
- Internal audit, management review and third-party stage-1 / stage-2 audit support.
- CERT-In incident-response playbook and 6-hour breach-reporting readiness.
- DPO-as-a-service and virtual CISO for growing organisations.
Cyber Security Process — Step by Step
- 1
Step 1: Free Consultation
A no-obligation 20-minute call to understand your product, project, market and the exact approvals you need.
- 2
Step 2: Document Preparation
Our specialists prepare, review and vet every document so your application clears the portal in the first submission.
- 3
Step 3: Portal Filing & Fee Payment
We handle the online application, government fee payment and coordinate with test labs / auditors where required.
- 4
Step 4: Department Liaison
Continuous follow-up with the concerned authority, response to queries and any additional information sought.
- 5
Step 5: Certificate / Approval Grant
Once approved, the certificate is delivered to you along with a compliance calendar for renewals and returns.
Documents Required for Cyber Security
- PAN of the applicant / company
- GST registration certificate
- Certificate of Incorporation / partnership deed
- Product details, technical write-up or project report
- Authorised signatory ID proof (Aadhaar / passport)
- Address proof of manufacturing unit or office
- Existing information-security policies and procedures
- System / network / cloud architecture diagrams
- Vendor / sub-processor list and data-flow maps
- Previous audit reports and open observations
- Incident-response and business-continuity plans
Why Choose The Exim Roof for Cyber Security
- ISO 27001 & SOC 2
- VAPT & source-code review
- DPDP Act 2023 gap analysis
- CERT-In advisory
Frequently Asked Questions
- How long does the entire process take?
Most approvals are granted in 30–90 days once documentation is in order. Timelines vary by department, product category and testing requirements — we share a milestone-based plan on day one.
- Do you handle end-to-end filing?
Yes. Our team drafts the application, uploads it on the government portal, pays the fee (against invoice), coordinates with labs / auditors and follows up till the certificate is granted.
- Will you help with renewals and post-approval compliance?
Absolutely. We share a compliance calendar with due dates for renewals, annual returns and periodic filings. You will never miss a deadline.
- Do we need ISO 27001 if we already have SOC 2?
Not necessarily — but many Indian and European enterprise customers still ask for both. We help you scope one programme, prepare a single control set, and run parallel audits so you do not do the same work twice.
- What are the DPDP Act penalties?
The DPDP Act 2023 provides for penalties up to ₹250 crore per breach category, escalating with the severity, duration and consequences of the breach. A structured compliance programme is the only defence.
- How long does ISO 27001 certification take?
From kick-off to stage-2 audit certification, most mid-sized organisations complete in 4–6 months. Larger or geographically distributed organisations may take 6–9 months.
Need more information about Cyber Security?
Fill in the form below and our compliance team will get back to you within one business day.
You may also need
All services →AERB Certification
Atomic Energy Regulatory Board certification support for radiation-generating equipment.
BIS CRS Registration
Compulsory Registration Scheme (CRS) support for electronics and IT products notified by MeitY.
BIS FMCS Certification
End-to-end consultancy for Foreign Manufacturers Certification Scheme (FMCS) under the Bureau of Indian Standards.
BIS Scheme X Certification
Consultancy for the new BIS Scheme X applicable to machinery and electrical equipment safety.

