- July 22, 2026
- Gaurav Vashistha
- 0
Table of Content
- 1. What Is the Right Legal Structure for Cybersecurity Company Setup in India?
- 2. What Do the CERT-In 2022 Directions Require for a Cybersecurity Company in India?
- 3. What Did the July 2025 CERT-In Guidelines Add for Cybersecurity Companies?
- 4. What Licensing Requirements Apply to Cybersecurity Company Setup India?
- 5.What Are the DPDPA and Transfer Pricing Obligations for Cybersecurity Companies?
- 6. Conclusion
Demand for cybersecurity services in India is growing rapidly. Businesses are investing more in cyber resilience, the government’s digital infrastructure initiatives are gathering pace, and organisations are looking for specialist support with services such as vulnerability assessments, penetration testing, managed security, and incident response. For foreign cybersecurity companies, India offers access to both a large customer base and a skilled talent pool.
Cybersecurity company setup India, however, has a compliance layer that most other technology sectors do not. The CERT-In (Indian Computer Emergency Response Team) Directions of 2022 apply to every entity operating digital infrastructure in India. The July 2025 cybersecurity audit mandate introduced annual third-party audits aligned to ISO/IEC 27001 for public and private enterprises that are covered under the guidelines. The DPDPA 2023 applies where thecompany processes personal data of Indian users.Defence-adjacent cybersecurity services carry additional licensing requirements which are beyond thestandard FDI and Companies Act framework.
This guide covers what cybersecurity company setup India actually requires across all of these layers.
What Is the Right Legal Structure for Cybersecurity Company Setup in India?
A Private Limited Company incorporated as a Wholly Owned Subsidiary is the most suitable structure for cybersecurity company setup inIndia. In most cases,100% FDI is permitted under the Automatic Route for cybersecurity services. No prior government approval is required. The company must be registered as a body corporate under Indian law to satisfy the CERT-In obligation of having a designated Point of Contact within India.
A private limited company as WOS requires at least two shareholders, two directors (including at least one resident director), and there is no statutory minimum paid-up capital requirement. The standard SPICe+ incorporation process on the MCA portal applies. The MoA objects clause must specifically cover cybersecurity activities: vulnerability assessment and penetration testing (VAPT), managed security services, security operations centre (SOC) services, incident response, security consulting, and any other service the company intends to offer.
One point that matters specifically for cybersecurity: the CERT-In Directions issued under Section 70B(6) of the IT Act apply to body corporates and other covered entities specified in the Directions in India. Having the Indian entity incorporated correctly, with a designated Point of Contact for CERT-In registered before the first client engagement begins, is a compliance prerequisite, not an afterthought.
What Do the CERT-In 2022 Directions Require for a Cybersecurity Company in India?
The CERT-In Directions, which came into effect on June 28, 2022, introduced several mandatory obligations for body corporates and other covered entities specified in the Directions andoperating in India. Organisations must report specified cyber incidents within six hours of incident or its detection, retain security logs in India for 180 days, synchronise system clocks with trusted NTP servers, and designate a Point of Contact for CERT-In. VPN providers, cloud service providers, and data centres are also required to retain subscriber information for atleast five years.
The Directions mandate 6-hour cybersecurity incident reporting to CERT-In, 180-day log retention within Indian jurisdiction, NTP clock synchronisation, and atleast 5-year subscriber data retention for VPN and cloud providers.
For a cybersecurity company setup in India, these obligations are not background compliance. The company is in the business of handling client security data, incident data, and potentially sensitive infrastructure information. The CERT-In framework applies to the company’s own operations and potentially to the services it delivers to clients.
Key CERT-In obligations for cybersecurity companies:
| Obligation | Requirement | Penalty for Non-Compliance |
| Incident reporting | Report to CERT-In within 6 hours of detection | Imprisonment up to 1 year and/or fine up to INR 1 crore as per Jan Vishwas amendment) |
| Log retention | Maintain ICT security logs within India for 180 days | Same as above |
| NTP synchronisation | System clocks synced with trusted NTP servers | Same as above |
| Point of Contact | Designate a POC to interface with CERT-In | Same as above |
| Subscriber data (VPN/cloud) | Retain subscriber names, email, IP, address for atleast 5 years | Same as above |
The original rules prescribed 10 reportable incident types; the 2022 Directions expanded this to 20 incident types that must be reported. For a cybersecurity company whose own systems may be targeted specifically because of the sensitive client data they hold, this reporting obligation must be operationalised from day one, not built retrospectively.
What Did the July 2025 CERT-In Guidelines Add for Cybersecurity Companies?
CERT-In Guideline CIGU-2025-0002/ CISG-2025-02, effective July 25, 2025, mandates annual third-party cybersecurity audits for public and private enterprise in India that are covered under CERT -IN Audit guidelines, with audit scope aligned to ISO/IEC 27001 with other recognised standards and findings required to be visible at board level. For cybersecurity companies, this means the company must itself undergo the same annual audit it may be delivering to clients.
Organisations subject to the CERT-In Cyber Security Audit Guidelines should undergo annual third-party cybersecurity audits. These are not surface-level compliance checks. The scope must align with ISO/IEC 27001 with other recognised standards and reflect the actual business risk. Audit outcomes now need to be board-visible.
The 2025 guidelines also expanded the Bill of Materials (BOM) policy beyond traditional SBOMs, now requiring documentation of any third-party touching regulated networks, and extended CERT-In mandates to vendor and supply chain security. For a cybersecurity company setup in India providing managed security services or SOC services, the vendor security obligation means the company’s own supply chain — third-party tools, threat intelligence feeds, cloud infrastructure — must now be documented and audited against the same standard.
This is the compliance update that most cybersecurity companies setting up in India in 2025 and 2026 are not yet fully accounting for. The 2022 Directions created the incident reporting and log retention framework. The July 2025 guidelines added the annual audit and board-level accountability layer on top.
What Licensing Requirements Apply to Cybersecurity Company Setup India?
There is no single cybersecurity-specific licence for commercial cybersecurity services in India. However, companies offering penetration testing, vulnerability assessment, or security audit services to government entities or critical information infrastructure must comply with CERT-In empanelment requirements. Companies in the defence-adjacent cybersecurity space face additional licensing under the MoD and DRDO frameworks.
CERT-In maintains an empanelled information security auditing organisations list. Government organisations and many regulated private sector entities (banking, telecom, insurance) require their security auditors and VAPT vendors to be CERT-In empanelled. For a cybersecurity company setup in India targeting enterprise and government clients, CERT-In empanelment is effectively a commercial prerequisite even though it is not a legal one.
The empanelment process requires:
- A relevant experience and technical capability, in information security (or evidence of the foreign parent’s equivalent experience)
- A qualified team with relevant certifications such as CISA, CISSP, CEH, or equivalent
- Proof of previous audit work
- Submission of application to CERT-In with supporting documentation
For defence-adjacent cybersecurity services, including cyber defence for defence contractors, military systems security, or work with DRDO or the National Security Council, additional approvals under the defence industrial licensing framework apply. FDI in defence above 74% requires Government Route approval regardless of the broader FDI policy.
What Are the DPDPA and Transfer Pricing Obligations for Cybersecurity Companies?
The Digital Personal Data Protection Act 2023 applies to any cybersecurity company in India processing personal data of Indian users, including data encountered during incident response, forensic analysis, or managed detection and response services. Transfer pricing obligations apply to all intercompany transactions with the foreign parent, including technical service fees, software licence fees, and shared services charges.
CERT-In compliance India requires maintaining 180 days of logs. Those logs frequently contain personal data. The DPDPA’s consent, security safeguard, and breach notification obligations apply to that personal data the moment it is collected or processed. For a cybersecurity company handling client incident data, forensic artefacts, or threat intelligence that includes personal identifiers, the intersection of CERT-In log retention and DPDPA data minimisation principles needs to be designed carefully before the first engagement begins.
Transfer pricing for cybersecurity company setup in India follows the same framework as any other IT company. Intercompany transactions above Rs. 1 crore require annual Transfer Pricing documentation and Form 3CEB. Cost-plus methodology is most commonly used for Indian entities providing managed services or SOC services to a foreign parent, with margins benchmarked against comparable Indian managed security services companies. Companies licensing threat intelligence platforms or proprietary security tools from the foreign parent may have royalty payments subject to TDS under Section 195 (393 under new Income Tax Act) and reverse charge GST at 18%.
Conclusion
Cybersecurity company setup India is operationally straightforward at the entity level. The Private Limited Company structure, 100% FDI, and standard SPICe+ incorporation apply as they do for any IT company. What makes cybersecurity different is the CERT-In compliance layer that begins operating the moment the entity is incorporated, the July 2025 annual audit mandate that adds board-level accountability on top, and the CERT-In empanelment requirement that determines whether government and regulated enterprise clients will engage the company at all.
Corporate Legit Consulting LLP advises foreign cybersecurity companies on the full setup and compliance framework for cybersecurity company setup India, covering MCA incorporation, FEMA compliance, CERT-In compliance India obligations, empanelment advisory, DPDPA compliance, transfer pricing documentation, and ongoing corporate and tax compliance. Reach out to Corporate Legit before the first client engagement begins.
Frequently Asked Questions
Yes. 100% FDI is permitted under the Automatic Route for cybersecurity services. No prior government approval is required. After share allotment to the foreign investor, Form FC-GPR must be filed with RBI within 30 days. Defence-adjacent cybersecurity services above 74% FDI require Government Route approval under the defence industrial licensing framework.
Every body corporate in India must report cyber incidents to CERT-In within 6 hours of incident or its detection, maintain ICT security logs within Indian jurisdiction for 180 days, synchronise system clocks with trusted NTP sources, and designate a Point of Contact for CERT-In. VPN providers and cloud service providers must additionally retain subscriber information for atleast 5 years. Non-compliance carries imprisonment up to 1 year or a fine currently up to INR 1 crore as per Jan Vishwas latest amendment.
CERT-In empanelment is a voluntary accreditation for information security auditing organisations, maintained by CERT-In under MeitY. It is not legally mandatory for commercial cybersecurity operations, but most government organisations and regulated private sector entities (banking, insurance, telecom) require their VAPT and security audit vendors to be CERT-In empanelled. For cybersecurity companies targeting enterprise and public sector clients, empanelment is effectively a commercial necessity.
CERT-In Guideline CISG-2025-02/ CIGU-2025-0002, effective July 25, 2025, mandates annual third-party cybersecurity audits for public and private enterprises in India covered under CERT-IN audit guidelines, with scope aligned to ISO/IEC 27001 with other recognised standardsand audit findings required to be visible at board level. It also expanded Bill of Materials requirements and extended CERT-In obligations to vendor and supply chain security. Every cybersecurity company operating in India must now itself undergo the same annual audit standard it may be delivering to clients.
Yes. The Digital Personal Data Protection Act 2023 applies to any cybersecurity company processing personal data of Indian users, including personal data encountered during incident response, forensic analysis, log review, or managed detection and response services. The intersection of CERT-In’s 180-day log retention requirement and DPDPA’s data minimisation and security safeguard obligations requires deliberate design before the first client engagement, not after.