
This checklist is designed for an operating company preparing for a Main Board or SME IPO. It does not replace additional requirements applicable to banks, NBFCs, insurers, payment companies, telecom operators, health companies, critical infrastructure operators or entities that are themselves SEBI-registered intermediaries.
As of August 2026, the main regulatory anchors are the SEBI ICDR Regulations, last amended March 21, 2026; the SEBI LODR Regulations, last amended July 14, 2026; CERT-In directions; the Companies Act; and India's evolving data-protection framework. (Securities and Exchange Board of India)
For listed entities to which the SEBI Risk Management Committee provisions apply—currently the top 1,000 listed entities and high-value debt listed entities—the committee's functions must specifically cover cybersecurity. Its risk framework is expected to address information and cyber risks, mitigation controls and business continuity. (Securities and Exchange Board of India)
Evidence: board minutes, committee charter, CISO appointment letter, approved policies, cyber budget, quarterly dashboards.
The Companies Act requires the audit committee to evaluate internal financial controls and risk-management systems. The board-report framework also covers internal financial controls, making technology controls relevant where systems support financial reporting. (India Code)
The DPDP Act and Rules have staggered commencement. Most substantive processing, security and breach-related provisions are scheduled to take effect 18 months after the November 13, 2025 Gazette publication—May 13, 2027—while certain provisions commence earlier.
CERT-In's audit guidance expects audit scope to be derived from an updated asset inventory and to cover infrastructure, applications, APIs, cloud, databases, OT, data security and incident-response capability.
CERT-In's guidance specifically recommends least-privilege controls and secure management of authorized assets.
Evidence: access matrices, quarterly review sign-offs, termination samples, privileged-account inventory, MFA reports.
CERT-In recommends an authorized hardware and software inventory, patch management, secure configurations, removal of default settings and least-privilege access.
CERT-In requires body corporates to report specified incidents within six hours of noticing them, designate a point of contact, synchronize system clocks and retain ICT logs for 180 days within India. Reportable categories include unauthorized access, ransomware, phishing, data breaches, data leaks, cloud attacks, digital-payment incidents and attacks on AI systems.
Under Regulation 30, material events emanating from within the listed entity generally have a 12-hour disclosure timeline; externally emanating events generally have a 24-hour timeline. Listed entities must also disclose details of cyber incidents, breaches or loss of data/documents through the prescribed corporate-governance report. A material cyber incident should therefore be assessed under both the immediate material-event process and the periodic cyber-disclosure requirement.
CERT-In's audit guidance identifies web, mobile, API, code, cloud and supply-chain testing as relevant scope areas and recommends audits after major technology or infrastructure changes.
CERT-In's audit guidelines call for vendor and supply-chain risk assessment to form part of audit scope, including hosted and third-party infrastructure.
SEBI's prescribed Risk Management Committee role expressly includes mitigation processes and a business-continuity plan.
CERT-In's 2025 audit guidelines recommend at least annual cyber audits, broader audits after major changes, complete infrastructure coverage, independent evidence-based assessments and management oversight of remediation. They also state that responsibility for the organization's security remains with management, not the auditor.
Prepare a central data room containing:
Recent Indian IPO filings commonly include tailored risk factors concerning cyberattacks, breaches, data loss and technology dependence, reflecting the need to consider these risks in the offer-document materiality exercise. (Securities and Exchange Board of India)
Adaptive is a Just-in-Time infrastructure access platform that closes the checklist items IPO-bound companies most often fail — the ones that demand system-enforced behavior rather than documentation:
| Checklist area | What diligence teams and auditors ask for | How Adaptive helps |
|---|---|---|
| Identity & access management (Section 4) | MFA on privileged, remote, and database access; least privilege; no shared credentials | SSO and MFA in front of every resource — including databases and legacy systems with no native SAML/OIDC support; users receive ephemeral credentials, so shared admin passwords disappear |
| Access reviews and joiner-mover-leaver | Quarterly reviews of critical systems; prompt deprovisioning | Just-in-Time access with approvals: privileges are granted per-request, scoped to the resource, and expire automatically — departed users hold nothing, and reviews shrink to exceptions |
| Audit & accountability (Section 6, CERT-In) | Logs retained 180 days within India; every action attributable to an individual | Session Recording and Activity Monitoring capture every query and command, attributed to the SSO identity and stored centrally — evidence that is ready for the six-hour reporting drill, auditors, and the IPO data room |
| Developer access to production (Sections 4 and 9) | Segregation of duties; controlled emergency access | Scoped, time-boxed grants with approval workflows and full recording — production access without standing privileges, including break-glass paths that leave an audit trail |
| Data protection (DPDP readiness, Section 2) | Limiting exposure of personal and sensitive data | Data Masking keeps sensitive fields hidden from users and tools that don't need them |
Because Adaptive deploys as an agentless, container-based gateway inside your own network, it strengthens the evidence trail without expanding the assessment boundary — and it typically stands up in days, comfortably inside an IPO preparation timeline.
The company should ordinarily avoid entering the filing stage with:
Applicability caution: SEBI's CSCRF is framed for SEBI Regulated Entities. An ordinary operating company does not become subject to the entire CSCRF merely because it undertakes an IPO; it may apply where the issuer is itself a SEBI-regulated intermediary or other covered entity. (Securities and Exchange Board of India)
This should be validated by Indian securities counsel and sector-specific regulatory advisers before implementation.

