Compliance

The accessibility and security standards we help you meet, in India and around the world.

India

Indian accessibility law and standards

Since the Supreme Court recognised digital access as part of the right to life in 2025, regulators have set firm accessibility requirements.

SEBI digital accessibility circulars

SEBI requires regulated entities to audit their websites and apps with an IAAP-certified professional, fix the findings and submit annual compliance reports.

Applies to: Stock brokers, depositories, mutual funds, investment advisers, research analysts and other SEBI-regulated entities

Rights of Persons with Disabilities Act, 2016

India's disability rights law, which makes accessible information and communication technology a legal duty.

Applies to: Government bodies, establishments and service providers

GIGW (Guidelines for Indian Government Websites)

The government's standard for website quality, including accessibility, usability and security.

Applies to: Government websites and their technology vendors

IS 17802

The Bureau of Indian Standards' accessibility requirements for ICT products and services, aligned with WCAG.

Applies to: Organisations referenced by SEBI and other regulators, and public procurement

International

Global accessibility standards

WCAG 2.2 Level AA

The Web Content Accessibility Guidelines from the W3C. The benchmark behind almost every accessibility law worldwide.

Applies to: Every organisation that wants an accessible website

Americans with Disabilities Act (ADA)

US law, with a 2024 rule setting WCAG 2.1 AA as the standard for state and local government websites.

Applies to: Indian companies serving US customers or US public-sector clients

European Accessibility Act (EAA)

EU law in force since June 2025 covering e-commerce, banking, transport and other digital services.

Applies to: Indian companies selling products or services to EU customers

Section 508 and VPAT

US federal procurement standard. A VPAT/ACR documents how your product conforms.

Applies to: SaaS companies selling to US government and enterprise buyers

Security

Security frameworks

OWASP Top 10 and ASVS

The most widely used lists of web application risks and security verification requirements. Our testing methodology is built on them.

Applies to: Every web application

ISO 27001 and SOC 2

Information security certifications that expect regular penetration testing. Our reports are written to support your audit.

Applies to: SaaS, fintech and companies handling customer data

Digital Personal Data Protection Act, 2023

India's privacy law requires reasonable security safeguards to prevent personal data breaches.

Applies to: Organisations processing personal data of people in India

PCI DSS

Payment card security standard that requires penetration testing of systems handling card data.

Applies to: Businesses that store, process or transmit card payments

This page is general information, not legal advice. Please consult a legal adviser about your specific obligations.

Facing a compliance deadline?

Tell us which regulation applies to you and when your deadline is. We'll plan an audit and remediation schedule that fits.