{"id":159,"date":"2026-04-28T11:16:37","date_gmt":"2026-04-28T11:16:37","guid":{"rendered":"https:\/\/blog.osto.one\/?p=159"},"modified":"2026-05-05T10:13:03","modified_gmt":"2026-05-05T10:13:03","slug":"the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/","title":{"rendered":"The Indian Fintech Compliance Map: What&#8217;s Mandatory, What Kills Your License, and What Your Lawyer Won&#8217;t Tell You"},"content":{"rendered":"<p style=\"font-size:17px;line-height:1.75;color:#333;\">Building a fintech in India means operating under more security and compliance obligations than almost any startup category in the world. RBI, SEBI, IRDAI, NPCI, CERT-In. Each has published cybersecurity frameworks that apply to different types of financial entities.<\/p>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">Some are legally mandatory. Some become mandatory the moment something goes wrong. Some are effectively mandatory the moment you try to partner with a bank or raise institutional capital.<\/p>\n<p><!-- CALLOUT --><\/p>\n<div style=\"background:#FFF8F8;border-left:5px solid #D94040;padding:20px 24px;margin:28px 0;border-radius:2px;\">\n<p style=\"font-size:17px;font-weight:600;color:#D94040;margin:0;line-height:1.65;\">Nobody hands you this map at the start. You usually find out what&#8217;s required the hard way \u2014 during your first RBI interaction, when a sponsor bank questionnaire arrives, or when CERT-In issues a notice about an incident you didn&#8217;t know you had to report.<\/p>\n<\/div>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">What&#8217;s mandatory today and has real teeth<\/h2>\n<p><!-- CERT-IN BLOCK --><\/p>\n<div style=\"background:#EEF1FB;border-left:5px solid #1C267A;padding:20px 24px;margin:20px 0 16px;border-radius:2px;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.15em;text-transform:uppercase;color:#1C267A;margin-bottom:8px;\">CERT-In Mandatory Directions \u00b7 Active since 2023<\/div>\n<p style=\"font-size:15px;color:#333;margin:0;line-height:1.65;\">Applies to every organisation operating in India with an IT infrastructure. No exceptions for size, funding stage, or registration status.<\/p>\n<\/div>\n<div style=\"margin:0 0 28px;display:flex;flex-direction:column;gap:8px;\">\n<div style=\"display:flex;align-items:flex-start;gap:14px;padding:14px 16px;background:#FAFBFF;border:1px solid #EEF1FB;border-radius:2px;\">\n    <span style=\"background:#D94040;color:white;font-size:11px;font-weight:700;padding:3px 8px;border-radius:2px;flex-shrink:0;margin-top:2px;\">6 HRS<\/span><br \/>\n    <span style=\"font-size:15px;color:#333;line-height:1.6;\"><strong>Incident reporting window.<\/strong> Data breach, ransomware, unauthorised account access, phishing, supply chain compromise \u2014 all must be reported to CERT-In within six hours of detection. Not six hours after containment. Six hours after you first know something happened. Most companies are not ready for this.<\/span>\n  <\/div>\n<div style=\"display:flex;align-items:flex-start;gap:14px;padding:14px 16px;background:#FAFBFF;border:1px solid #EEF1FB;border-radius:2px;\">\n    <span style=\"background:#1C267A;color:white;font-size:11px;font-weight:700;padding:3px 8px;border-radius:2px;flex-shrink:0;margin-top:2px;\">180 DAYS<\/span><br \/>\n    <span style=\"font-size:15px;color:#333;line-height:1.6;\"><strong>Log retention.<\/strong> All system logs \u2014 servers, applications, network devices \u2014 must be maintained for 180 days and be available within India or accessible to CERT-In on request.<\/span>\n  <\/div>\n<\/div>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">Meeting the six-hour window requires automated alerting so you know within minutes, a pre-written report template, and a named person who can file it. Companies that find out about a breach from a customer complaint on a Monday morning have already missed the window.<\/p>\n<p><!-- RBI TABLE --><\/p>\n<div style=\"overflow-x:auto;margin:28px 0 16px;\">\n<table style=\"width:100%;border-collapse:collapse;font-size:14px;font-family:inherit;\">\n<thead>\n<tr>\n<th style=\"background:#1C267A;color:white;padding:12px 16px;text-align:left;font-weight:600;font-size:13px;width:30%;\">RBI Master Direction<\/th>\n<th style=\"background:#1C267A;color:white;padding:12px 16px;text-align:left;font-weight:600;font-size:13px;width:40%;\">Who it applies to<\/th>\n<th style=\"background:#1C267A;color:white;padding:12px 16px;text-align:left;font-weight:600;font-size:13px;width:30%;\">Core requirement<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;font-weight:600;color:#1C267A;background:#FAFBFF;\">IT Governance<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;color:#333;background:white;\">NBFCs, payment aggregators, payment gateways, account aggregators, PPI issuers<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;color:#333;background:#F5F7FF;\">Board-approved ISP, named security officer, annual VAPT, IR plan, BCP\/DR tested annually<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;font-weight:600;color:#1C267A;background:#FAFBFF;\">PCI DSS<\/td>\n<td style=\"padding:12px 16px;color:#333;background:white;\">Any product that touches payment card data<\/td>\n<td style=\"padding:12px 16px;color:#333;background:#F5F7FF;\">Annual penetration test \u2014 overlaps with RBI VAPT if scoped correctly<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">What&#8217;s commercially mandatory \u2014 banks will block you otherwise<\/h2>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">There&#8217;s a category of requirements that aren&#8217;t legally mandated but become prerequisites the moment you pursue the partnerships you need to operate.<\/p>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">Every serious sponsor bank in India \u2014 IDFC First, RBL, SBM India, Axis \u2014 has a vendor risk management programme. Before they approve you as a technology partner, they send a security questionnaire asking for: SOC 2 or ISO 27001 attestation, penetration test history and scope, data encryption standards, access control policies, and incident response procedures.<\/p>\n<p><!-- SOC 2 CALLOUT --><\/p>\n<div style=\"background:#EEF1FB;border-left:5px solid #1C267A;padding:20px 24px;margin:24px 0;border-radius:2px;\">\n<p style=\"font-size:16px;font-weight:600;color:#1C267A;margin:0 0 6px;\">SOC 2 is not required by Indian law.<\/p>\n<p style=\"font-size:15px;color:#555;margin:0;line-height:1.6;\">It is commercially required by the bank you need to operate. This distinction matters because it tells you when to prioritise it \u2014 not immediately, but before your first serious bank partnership conversation starts, because the process takes nine to twelve months.<\/p>\n<\/div>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">Some banks will accept a VAPT report plus written policies for early-stage partners, with a committed SOC 2 timeline. Get this in writing if you go that route.<\/p>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">The DPDPA deadline that changes everything<\/h2>\n<p><!-- DPDPA STAT --><\/p>\n<div style=\"background:#1C267A;padding:24px 28px;margin:20px 0 24px;border-radius:2px;display:flex;align-items:center;gap:24px;flex-wrap:wrap;\">\n<div style=\"flex-shrink:0;\">\n<div style=\"font-size:42px;font-weight:700;color:#C8FF00;line-height:1;\">\u20b9250 Cr<\/div>\n<div style=\"font-size:12px;color:rgba(255,255,255,0.6);text-transform:uppercase;letter-spacing:0.1em;margin-top:4px;\">max penalty<\/div>\n<\/p><\/div>\n<div style=\"font-size:15px;color:rgba(255,255,255,0.85);line-height:1.6;\">DPDPA full enforcement expected around May 2027. For a seed-stage fintech, \u20b9250 crore is an existential number.<\/div>\n<\/div>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">For fintechs specifically, the financial data you process \u2014 bank account details, transaction histories, credit records, income information \u2014 is classified as sensitive personal data under the act, with stricter treatment than general personal data.<\/p>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">The obligations that require building infrastructure, not just policy: mandatory security safeguards proportionate to the risk, 72-hour breach notification to the Data Protection Board, explicit consent for non-transactional data processing, and erasure rights for users.<\/p>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">The good news: the security infrastructure that satisfies RBI&#8217;s requirements \u2014 WAF, endpoint protection, continuous monitoring, access controls \u2014 substantially overlaps with DPDPA&#8217;s security safeguard standard. One well-run security programme serves both. The new piece DPDPA adds is consent management and data rights infrastructure, which RBI compliance doesn&#8217;t address.<\/p>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">The practical priority order<\/h2>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">If you&#8217;re a seed-stage Indian fintech figuring out where to start, this sequence minimises existential risk while building toward the complete picture.<\/p>\n<p><!-- PRIORITY SEQUENCE --><\/p>\n<div style=\"margin:20px 0 32px;display:flex;flex-direction:column;gap:2px;\">\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n    <span style=\"background:#1C267A;color:white;font-size:13px;font-weight:700;width:28px;height:28px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;margin-top:1px;\">1<\/span><\/p>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Make CERT-In reporting operational first<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Automated alerting, a template, a named person. This eliminates a live legal exposure that costs almost nothing to address.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n    <span style=\"background:#1C267A;color:white;font-size:13px;font-weight:700;width:28px;height:28px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;margin-top:1px;\">2<\/span><\/p>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Commission a VAPT before production launch<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Satisfies RBI Master Direction, part of PCI DSS, and becomes your primary evidence for sponsor bank vendor reviews.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n    <span style=\"background:#1C267A;color:white;font-size:13px;font-weight:700;width:28px;height:28px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;margin-top:1px;\">3<\/span><\/p>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Document your security policies<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Information Security Policy, Incident Response Plan, BCP\/DR Plan. Board-approved. Three documents. Current. Reflecting reality.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n    <span style=\"background:#1C267A;color:white;font-size:13px;font-weight:700;width:28px;height:28px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;margin-top:1px;\">4<\/span><\/p>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Start your SOC 2 process when the first bank partnership conversation becomes serious<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Give yourself nine to twelve months.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n    <span style=\"background:#1C267A;color:white;font-size:13px;font-weight:700;width:28px;height:28px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;margin-top:1px;\">5<\/span><\/p>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Map your DPDPA obligations now<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">What data do you collect? Where does it go? What third parties touch it? Four to six weeks of work. The foundation of everything DPDPA-related that follows.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p><!-- OVERLAP CALLOUT --><\/p>\n<blockquote style=\"margin:36px 0;padding:24px 28px;background:#EEF1FB;border-left:5px solid #1C267A;border-radius:2px;\">\n<p style=\"font-size:17px;font-style:italic;font-weight:500;color:#1C267A;margin:0;line-height:1.7;\">The overlap between RBI requirements, CERT-In directions, PCI DSS, SOC 2, and DPDPA is significant. One comprehensive security programme satisfies the majority of all five simultaneously. You don&#8217;t need five separate compliance workstreams. You need one programme comprehensive enough to evidence across all five.<\/p>\n<\/blockquote>\n<p><!-- SUBTLE OSTO PLUG --><\/p>\n<p style=\"font-size:15px;line-height:1.75;color:#777;border-top:1px solid #EEF1FB;padding-top:24px;margin-top:40px;font-style:italic;\">This is exactly the problem <a href=\"https:\/\/osto.one\" style=\"color:#1C267A;text-decoration:none;font-weight:500;\">Osto<\/a> is built for \u2014 one platform that runs the security infrastructure and generates the evidence across RBI, CERT-In, PCI DSS, and SOC 2 simultaneously, so Indian fintech teams aren&#8217;t managing five separate workstreams.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Building a fintech in India means operating under more security and compliance obligations than almost any startup category in the\u2026<\/p>\n","protected":false},"author":5,"featured_media":239,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,40],"tags":[],"class_list":["post-159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-fintech"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Indian Fintech Compliance: RBI, CERT-In &amp; DPDPA Guide<\/title>\n<meta name=\"description\" content=\"Navigate India&#039;s fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what&#039;s legally mandatory before your first RBI interaction.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Indian Fintech Compliance: RBI, CERT-In &amp; DPDPA Guide\" \/>\n<meta property=\"og:description\" content=\"Navigate India&#039;s fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what&#039;s legally mandatory before your first RBI interaction.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\" \/>\n<meta property=\"og:site_name\" content=\"Osto\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-28T11:16:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-05T10:13:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ansh Satwani\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ansh Satwani\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\"},\"author\":{\"name\":\"Ansh Satwani\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144\"},\"headline\":\"The Indian Fintech Compliance Map: What&#8217;s Mandatory, What Kills Your License, and What Your Lawyer Won&#8217;t Tell You\",\"datePublished\":\"2026-04-28T11:16:37+00:00\",\"dateModified\":\"2026-05-05T10:13:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\"},\"wordCount\":862,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png\",\"articleSection\":[\"Blog\",\"Fintech\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\",\"url\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\",\"name\":\"Indian Fintech Compliance: RBI, CERT-In & DPDPA Guide\",\"isPartOf\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png\",\"datePublished\":\"2026-04-28T11:16:37+00:00\",\"dateModified\":\"2026-05-05T10:13:03+00:00\",\"description\":\"Navigate India's fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what's legally mandatory before your first RBI interaction.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage\",\"url\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png\",\"contentUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.osto.one\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Indian Fintech Compliance Map: What&#8217;s Mandatory, What Kills Your License, and What Your Lawyer Won&#8217;t Tell You\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.osto.one\/resources\/#website\",\"url\":\"https:\/\/www.osto.one\/resources\/\",\"name\":\"Osto\",\"description\":\"Osto secures apps, networks, and endpoints with an integrated platform built for modern teams.\",\"publisher\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.osto.one\/resources\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\",\"name\":\"Osto\",\"url\":\"https:\/\/www.osto.one\/resources\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png\",\"contentUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png\",\"width\":1144,\"height\":428,\"caption\":\"Osto\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144\",\"name\":\"Ansh Satwani\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g\",\"caption\":\"Ansh Satwani\"},\"url\":\"https:\/\/www.osto.one\/resources\/author\/ansh\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Indian Fintech Compliance: RBI, CERT-In & DPDPA Guide","description":"Navigate India's fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what's legally mandatory before your first RBI interaction.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/","og_locale":"en_US","og_type":"article","og_title":"Indian Fintech Compliance: RBI, CERT-In & DPDPA Guide","og_description":"Navigate India's fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what's legally mandatory before your first RBI interaction.","og_url":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/","og_site_name":"Osto","article_published_time":"2026-04-28T11:16:37+00:00","article_modified_time":"2026-05-05T10:13:03+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png","type":"image\/png"}],"author":"Ansh Satwani","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ansh Satwani","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#article","isPartOf":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/"},"author":{"name":"Ansh Satwani","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144"},"headline":"The Indian Fintech Compliance Map: What&#8217;s Mandatory, What Kills Your License, and What Your Lawyer Won&#8217;t Tell You","datePublished":"2026-04-28T11:16:37+00:00","dateModified":"2026-05-05T10:13:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/"},"wordCount":862,"commentCount":0,"publisher":{"@id":"https:\/\/www.osto.one\/resources\/#organization"},"image":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage"},"thumbnailUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png","articleSection":["Blog","Fintech"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/","url":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/","name":"Indian Fintech Compliance: RBI, CERT-In & DPDPA Guide","isPartOf":{"@id":"https:\/\/www.osto.one\/resources\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage"},"image":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage"},"thumbnailUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png","datePublished":"2026-04-28T11:16:37+00:00","dateModified":"2026-05-05T10:13:03+00:00","description":"Navigate India's fintech compliance landscape \u2014 RBI, SEBI, IRDAI, CERT-In, PCI DSS, and DPDPA requirements explained. Know what's legally mandatory before your first RBI interaction.","breadcrumb":{"@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#primaryimage","url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png","contentUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_14_18-AM.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.osto.one\/resources\/blog\/the-indian-fintech-compliance-map-whats-mandatory-what-kills-your-license-and-what-your-lawyer-wont-tell-you\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.osto.one\/resources\/"},{"@type":"ListItem","position":2,"name":"The Indian Fintech Compliance Map: What&#8217;s Mandatory, What Kills Your License, and What Your Lawyer Won&#8217;t Tell You"}]},{"@type":"WebSite","@id":"https:\/\/www.osto.one\/resources\/#website","url":"https:\/\/www.osto.one\/resources\/","name":"Osto","description":"Osto secures apps, networks, and endpoints with an integrated platform built for modern teams.","publisher":{"@id":"https:\/\/www.osto.one\/resources\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.osto.one\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.osto.one\/resources\/#organization","name":"Osto","url":"https:\/\/www.osto.one\/resources\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/","url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png","contentUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png","width":1144,"height":428,"caption":"Osto"},"image":{"@id":"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144","name":"Ansh Satwani","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g","caption":"Ansh Satwani"},"url":"https:\/\/www.osto.one\/resources\/author\/ansh\/"}]}},"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=159"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/159\/revisions"}],"predecessor-version":[{"id":160,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/159\/revisions\/160"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/239"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}