Skip to main content
Trust · Compliance

Findings map to controls. Certificates come from elsewhere

Nine frameworks, and one rule that governs every one of them. An engagement produces evidence against the controls a framework names. Certification and attestation are issued by certification bodies and auditors appointed for that purpose, which is separate work from testing and is not work we do.

The nine

Each framework, and what it asks for

9 of the nine have a page of their own, each citing the instrument it rests on and the date that instrument was read. The rest are named here because the set matters even before every page exists.

FrameworkWhat an engagement produces against it
CERT-In Security Brigade has been empanelled since 2008. Where an instrument requires empanelled delivery it is the testing that has to be empanelled, which makes it a delivery-model decision.
SEBI CSCRF Four cadences the framework keeps separate — VAPT, cyber audit, red teaming and threat hunting. Conflating them is the most frequent error made against it.
RBI Directions, 2026 Vulnerability assessment six-monthly and penetration testing twelve-monthly under paragraph 151, plus the lifecycle triggers that sit outside the calendar.
DPDP Rules notified 14 November 2025, phasing over eighteen months. Testing is evidence about the safeguards around personal data rather than about the obligation itself.
PCI DSS External and internal penetration testing on a twelve-month cycle and after significant change, plus review of bespoke software before release.
ISO 27001 Evidence for the technical-vulnerability and secure-development controls in Annex A. Security Brigade is certified; the certificate is issued by a certification body, not by us.
SOC 2 Evidence an auditor can use against the Trust Services Criteria. This page is about your report rather than about ours.
GDPR Article 32(1)(d) asks for a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.
HIPAA The Security Rule in force asks for a risk analysis and a periodic evaluation. A proposed update would name testing explicitly — the page says exactly where that stands.

CERT-In

What an engagement produces against it
Security Brigade has been empanelled since 2008. Where an instrument requires empanelled delivery it is the testing that has to be empanelled, which makes it a delivery-model decision.

SEBI CSCRF

What an engagement produces against it
Four cadences the framework keeps separate — VAPT, cyber audit, red teaming and threat hunting. Conflating them is the most frequent error made against it.

RBI Directions, 2026

What an engagement produces against it
Vulnerability assessment six-monthly and penetration testing twelve-monthly under paragraph 151, plus the lifecycle triggers that sit outside the calendar.

DPDP

What an engagement produces against it
Rules notified 14 November 2025, phasing over eighteen months. Testing is evidence about the safeguards around personal data rather than about the obligation itself.

PCI DSS

What an engagement produces against it
External and internal penetration testing on a twelve-month cycle and after significant change, plus review of bespoke software before release.

ISO 27001

What an engagement produces against it
Evidence for the technical-vulnerability and secure-development controls in Annex A. Security Brigade is certified; the certificate is issued by a certification body, not by us.

SOC 2

What an engagement produces against it
Evidence an auditor can use against the Trust Services Criteria. This page is about your report rather than about ours.

GDPR

What an engagement produces against it
Article 32(1)(d) asks for a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.

HIPAA

What an engagement produces against it
The Security Rule in force asks for a risk analysis and a periodic evaluation. A proposed update would name testing explicitly — the page says exactly where that stands.

The delivery decision

Which model you buy decides where the report can go

Coverage is identical across the three delivery models. What differs is whose signature the report carries — and where a report leaves your organisation for a regulator or an assessor, that is the whole question.

Two of the three put a senior Security Brigade auditor inside the engagement. Start from the expert-verified model where the output is going into a filing, and read the CERT-In page for what empanelled delivery actually attaches to.

Tell us which instrument you file under, and we will scope to it

Which framework applies to your entity is a determination for you and your advisers. What the engagement has to cover, and which delivery model produces output you can file, is a short conversation.