Compliance frameworks, explained by the people who implement them.
Most compliance content online summarises the statute. These guides cover what applicability actually looks like, what evidence a regulator or auditor actually wants, and where frameworks that sound similar genuinely diverge — DPDP, GDPR, DORA, NIS2, DESC ISR, SOC 2, ISO 27001, RBI, and SEBI.
DORA · NIS2 · DESC ISR
Operational resilience for EU financial ICT, critical-infrastructure cybersecurity across 18 sectors, and Dubai government supply-chain security.
DPDP Act 2023
India's Digital Personal Data Protection Act — consent, data principal rights, RoPA, and breach notification for any organisation processing Indian residents' data.
GDPR
The world's most consequential data protection regulation — extraterritorial reach, six lawful bases, and 72-hour breach notification.
SOC 2 · ISO 27001
The two security certifications enterprise deals are most commonly blocked on — which one your RFP actually needs, and the full path to get there.
RBI · SEBI
Cybersecurity and IT governance for Indian banks, NBFCs, payment operators, stock exchanges, brokers, and asset managers.
Compliance is an operating capability, not a policy document
Every framework above shares underlying work — data discovery, access governance, incident response, evidence collection — even where the framework-specific layer on top genuinely diverges. SG2 builds the shared foundation once and maps it to whichever frameworks actually apply, through Compliance & Tools,Data Governance, and theMetaSight andDPDP Compliance platforms.
Not sure if your compliance programme applies to your organisation?
Our compliance team scopes applicability in a 30-minute call — no charge.