Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Compliance Testing

DPDP Act Security Testing and VAPT

The DPDP Act requires a Data Fiduciary to protect personal data with reasonable security safeguards, and it names no certificate and no mandatory penetration test. A test is how you evidence that those safeguards actually work, and the penalty schedule reaches 250 crore rupees for failing to take them. SecureRoot runs manual, exploit-driven testing of the systems that hold personal data, so you can show the safeguards hold rather than assert it. This is the security-testing part of DPDP Act readiness; the full programme, consent, notices, data-principal rights and the DPO function, sits on our DPDP Act consultant and compliance pages. SecureRoot is not a CERT-In empanelled auditor, and there is no DPDP Act certification to sell you.

The Law

How the DPDP Act Treats Security Testing

The Digital Personal Data Protection Act, 2023 and its 2025 Rules set duties, not a testing cycle. Testing is how you evidence them.

  • Reasonable security safeguards

    DPDP Act, 2023, Section 8(5)

    What the DPDP Act expects
    A Data Fiduciary must protect the personal data in its possession or control by taking reasonable security safeguards to prevent a personal data breach. The Act does not list the safeguards; it holds you to their effectiveness.
    What the test provides
    We test the systems that hold personal data the way an attacker would, so you can show the safeguards work rather than assert they do.
  • Breach intimation

    DPDP Act Section 8(6) and the DPDP Rules, 2025

    What the DPDP Act expects
    On a personal data breach you must intimate the Data Protection Board and affected Data Principals in the manner the Rules set. Noticing a breach at all depends on detection and logging.
    What the test provides
    We test detection and logging alongside the applications, and can validate that a breach would actually be seen, which is the hard part of the duty.
  • The cost of getting it wrong

    DPDP Act penalty schedule

    What the DPDP Act expects
    The schedule reaches 250 crore rupees for failing to take reasonable security safeguards and 200 crore for failing to notify a breach. The comparison is not a scare tactic; it is why boards fund the work.
    What the test provides
    A focused test is far cheaper than the penalty, the lost deals or the breach it helps you avoid, and it produces the evidence that the safeguards hold.

The DPDP Act names no certificate and no mandatory annual penetration test; testing is evidence the safeguards work, not a compliance certificate. SecureRoot is not a CERT-In empanelled auditing organisation. The full DPDP Act programme, consent, notices, data-principal rights and the DPO function, is on our DPDP Act consultant and compliance pages; this page is the security-testing part.

How It Runs

How a DPDP Security Test Runs

The scope is drawn from where personal data actually flows, and written down with the price before anyone starts.

  1. 01

    Scoping to the Personal Data

    You hear back within one business day. On the call we map where personal data is collected, processed and stored, so the test covers the systems the safeguards duty actually applies to.

  2. 02

    A Written Scope and a Fixed Price

    Targets, test windows, deliverables and the price, in writing, scoped to the systems that hold personal data rather than to everything you run.

  3. 03

    Manual Testing and Detection Checks

    Testing by hand and with intent, including whether a breach would actually be detected and logged. Critical findings reach you within three hours of discovery.

  4. 04

    Remediation, Retest and Evidence

    The tester who found the flaw explains it to your developers. Once fixes land we retest inside the engagement and give you evidence the safeguards hold, dated for your records.

Our Role

Security Testing Is One Part of DPDP Readiness

The DPDP Act is a privacy law, and most of readiness is not testing: data discovery and mapping, consent and notice design, data-principal rights workflows, processor contracts, a tested breach playbook and, for many organisations, a named Data Protection Officer. That programme sits on our DPDP Act consultant and compliance pages, and this page is deliberately the narrower piece: the security testing that evidences the Act's reasonable-security-safeguards duty.

What testing does is turn an assertion into evidence. The Act holds you to the effectiveness of your safeguards, not to a documented list of them, so a report that reproduces a real weakness and then confirms it closed is worth more than a policy that describes controls you have not verified. We also test detection and logging, because the breach-intimation duty depends on noticing a breach in the first place.

SecureRoot is not a CERT-In empanelled auditing organisation, and there is no official DPDP Act certification scheme; anyone selling you a DPDP certificate is overstating what exists. SecureRoot Risk Advisory LLP holds ISO/IEC 27001:2022 (certificate IN60432E), and the same testing serves as evidence for ISO 27001 and SOC 2 programmes as well as for the DPDP Act.

Who It Is For

Who We Test For

Organisations that hold the personal data of people in India and must show their safeguards work.

  • SaaS and Consumer Platforms

    Products collecting personal data at scale, where the application and its APIs are where a breach would happen.

  • Fintech and Lending

    Teams holding financial and identity data, where DPDP sits beside RBI expectations and PCI DSS.

  • Edtech and Health-adjacent

    Services holding children's or sensitive data, where the safeguards duty carries extra weight.

  • Data Processors

    Companies processing personal data for others, whose client's DPDP posture depends on theirs.

  • Enterprises Modernising a Legacy Estate

    Established firms whose older systems hold personal data that has never been tested together.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does the DPDP Act require a penetration test?

No, not explicitly. The Digital Personal Data Protection Act, 2023 does not name penetration testing or set a testing cycle the way PCI DSS does; what it requires, under Section 8(5), is that a Data Fiduciary protect the personal data in its possession or control by taking reasonable security safeguards to prevent a breach. The Act deliberately does not list the safeguards, which means you are held to their effectiveness rather than to a checklist, and that is exactly where testing earns its place: a penetration test is the practical way to show the safeguards actually work rather than merely exist in a policy. There is also no DPDP Act certificate to obtain, so be wary of anyone selling one. In short, a test is not mandatory, but for any organisation holding meaningful amounts of personal data it is the most credible evidence that the reasonable-security-safeguards duty is met, and it is increasingly what enterprise customers and the Data Protection Board's expectations point towards. We scope the test to the systems that actually hold personal data.

What are 'reasonable security safeguards', and how does testing help?

The DPDP Act, in Section 8(5), requires a Data Fiduciary to protect personal data with reasonable security safeguards to prevent a personal data breach, and the 2025 Rules add detail on what good practice looks like, but the Act stops short of a prescriptive list, which is deliberate: what is reasonable for a large platform differs from what is reasonable for a small one. In practice reasonable safeguards include access control, encryption, logging and monitoring, secure configuration, and a tested ability to detect and respond to a breach. Testing helps in two ways. First, a penetration test reproduces how an attacker would actually reach personal data, so it shows whether your safeguards hold under pressure rather than on paper, which is the standard the Act sets. Second, because the breach-intimation duty under Section 8(6) depends on noticing a breach at all, we test detection and logging alongside the applications, so you can show that a breach would be seen in time to report it. The output is dated evidence you can put in front of a board, a customer or the Data Protection Board.

Is there a DPDP Act certification we can get?

No. There is no official DPDP Act certification scheme, no government-backed certificate and no empanelled-auditor sign-off that makes you "DPDP certified", so treat any firm selling a DPDP certificate with caution, because it is overstating what exists. What you can hold instead is demonstrable readiness: evidence that your consent, notices, data-principal rights workflows, security safeguards and breach process meet the Act and the 2025 Rules, assembled so it stands up to an enterprise buyer's due diligence or the Data Protection Board's attention. For the security-safeguards part specifically, that evidence is a penetration test that reproduces real weaknesses and confirms them closed, plus the detection and logging checks that show a breach would be noticed. This is the honest framing we use throughout: the DPDP Act is about being able to show your safeguards and processes work, not about collecting a certificate. If you also need a recognised certification for customer assurance, ISO 27001 is the one that certifies your security management system, and we can run the testing for that at the same time.

How is this different from a DPDP audit or a DPDP consultant engagement?

This page is deliberately the narrow, technical slice; the broader work lives on our DPDP Act consultant and DPDP compliance pages. A DPDP consultant or audit engagement covers the whole programme: data discovery and mapping, applicability and scoping, a gap assessment against the Act and the 2025 Rules, consent and notice design, data-principal rights workflows, processor contracts, a breach playbook and, for many organisations, standing up a Data Protection Officer function. DPDP security testing, which is what this page is about, is the part that evidences one specific duty, the reasonable security safeguards under Section 8(5), by testing the systems that hold personal data and confirming the safeguards hold. Most organisations need both, and they fit together: the consulting defines what good looks like and the testing proves the technical safeguards actually work. If you are not sure which you need first, the honest answer for a team early in its DPDP journey is usually the programme work before the testing, and we will say so on the scoping call rather than sell you a test you are not ready to act on.

Which systems should we test for the DPDP Act?

The ones that hold personal data, and the infrastructure that supports them. The Act's safeguards duty attaches to the personal data in your possession or control, so the test follows the data rather than the org chart: the customer-facing applications that collect it, the APIs that move it, the databases and cloud storage that hold it, and the authentication, administration and logging systems around them. For most organisations that is the product and its backend; for a data processor it is the systems that handle other companies' personal data on their behalf. On the scoping call we map where personal data is collected, processed and stored, because testing the wrong systems produces evidence that does not match the duty, and a system you forgot holds personal data is exactly where a breach and a penalty come from. Where your estate is large or legacy, we help you prioritise the systems that hold the most, or the most sensitive, personal data first, including children's data, which carries extra weight under the Act, rather than trying to test everything at once.

When do the DPDP Act's duties apply, and when should we test?

Read the dates as a sequence. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, bringing the Data Protection Board into force; Consent Manager provisions apply from 13 November 2026; and most duties for Data Fiduciaries, including security safeguards, breach intimation and data-principal rights, apply from 13 May 2027. The security-safeguards duty is one of those that bites at the last date, so the work in front of it is not paperwork: finding and fixing the weaknesses in the systems that hold personal data takes time, and remediation of real findings runs at your development speed, not ours. The sensible sequence is to get the programme work moving, map your data and close the obvious gaps, then test the safeguards with enough runway to fix and retest what the test finds before the duty applies, rather than discovering exploitable weaknesses the month the deadline lands. On the scoping call we help you place the test in that timeline so the evidence is ready when it matters.

Is SecureRoot CERT-In empanelled?

No. SecureRoot Risk Advisory LLP is not a CERT-In empanelled information security auditing organisation, and we will not blur that line. CERT-In empanelment is an Indian scheme that matters where a regulator or a tender specifically requires the formal VAPT report to be signed by an empanelled auditor; it is separate from the DPDP Act, which names neither empanelment nor a certificate. For DPDP Act security testing, what you need is credible evidence that your reasonable security safeguards work, and that is what we provide: manual, exploit-driven testing of the systems that hold personal data, with a proof of concept for every finding, a fix, and a retest that confirms closure, plus the detection and logging checks that support the breach-intimation duty. Where your situation separately requires an empanelled auditor's signature for some other obligation, that is a different party, and we will tell you so on the scoping call rather than after the work. SecureRoot does hold ISO/IEC 27001:2022, certificate IN60432E, if certification-backed assurance is also useful to you.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.