NIRMATA Cybersecurity Guides

Practical, question-by-question guidance for Indian businesses doing a NIRMATA self-assessment. Written for real organisations with real constraints.

191
Question guides
12
Pillars covered
Free
No login required
1

Find your question

Each guide matches exactly one question in the NIRMATA self-assessment. Use the code (e.g. GL-01) to find yours.

2

Understand your level

Read what each maturity level looks like in practice. Find where your organisation honestly sits today.

3

Improve and evidence

Follow the step-by-step actions. Collect the evidence listed so you're ready for auditors and reviewers.

All 12 NIRMATA Pillars

Click any question code to open its guide. Pillar weights show contribution to your overall maturity score.

🏛️
GL · P1
Governance & Leadership
10% of OML score

Board-level oversight, security ownership, policies, and strategic direction for cybersecurity and data protection.

12 questions
⚖️
RC · P2
Risk & Compliance
20% of OML score

Risk management frameworks, regulatory compliance with DPDP Act, CERT-In, IT Act, and audit posture.

15 questions
💻
AD · P3
Application & Product Security
6% of OML score

Secure SDLC, DevSecOps, vulnerability management, SAST/DAST, and secure coding standards.

20 questions
🗄️
IAM · P4
Asset & Data Management
8% of OML score

Asset inventory, data classification, data lifecycle management, and retention policies.

15 questions
🔐
IS · P5
Identity & Access
8% of OML score

Identity management, MFA, privileged access controls, and zero-trust principles.

24 questions
🌐
APS · P6
Infrastructure Security
12% of OML score

Network security, endpoint protection, cloud security, and physical infrastructure controls.

15 questions
🔗
SCS · P7
Supply-Chain Security
8% of OML score

Third-party risk management, vendor assessments, and software supply-chain controls.

15 questions
🚨
IR · P8
Incident Readiness
4% of OML score

Incident response plans, playbooks, CERT-In reporting obligations, and breach response drills.

15 questions
🔄
BCR · P9
Business Continuity & Resilience
4% of OML score

BCP/DR plans, RTO/RPO objectives, backup testing, and crisis management.

15 questions
🔒
PDP · P10
Privacy & Data Protection
6% of OML score

DPDP Act 2023 alignment, personal data protection, data subject rights, and PII handling.

15 questions
🎓
CTA · P11
Culture, Training & Awareness
8% of OML score

Security awareness programmes, training cadence, phishing simulations, and building a security-first culture.

15 questions
📡
MD · P12
Monitoring & Detection
6% of OML score

SIEM, log management, SOC capabilities, threat detection, and incident alerting.

15 questions