Why India Is a Leading Location for Cybersecurity GCCs
Setting up a cybersecurity or SOC GCC in India means complying with CERT-In's Directions of 28 April 2022 under section 70B(6) of the Information Technology Act, 2000, which took effect 60 days after issue and require service providers, intermediaries, data centres, body corporate and government organisations — a GCC subsidiary is a body corporate — to report the incidents listed in Annexure I within six hours of noticing them. That is among the strictest reporting timelines anywhere, and far tighter than the EU's 72-hour GDPR window.
India's attraction for security work is the combination of a large engineering labour market, an established GCC operating model and English-language 24/7 coverage. What follows is a practical guide to the regulatory obligations, the entity structure and the staffing model of a security operations centre run out of India. It deliberately does not print salary or cost bands: there is no published Indian benchmark for security roles or SOC tooling that we would stand behind, and the spreads move too fast by city, seniority and licensing model for a planning band to be worth budgeting on. Price the specific roles and platforms you need against live quotes.
Setting up a cybersecurity GCC in India is not simply a hiring exercise: it also requires understanding the Digital Personal Data Protection Act (DPDP Act) and structuring the entity correctly for cross-border data flows under FEMA regulations.

Understanding India's Cybersecurity Regulatory Landscape
India's cybersecurity regulatory framework has undergone a fundamental transformation since CERT-In issued its landmark Directions in April 2022, with significant updates in 2025 that affect every GCC operating in the country.
CERT-In Directions: The 6-Hour Reporting Mandate
The Indian Computer Emergency Response Team (CERT-In) mandates that all organisations — including GCCs — report cybersecurity incidents within six hours of detection. This is among the strictest reporting timelines globally, significantly tighter than the EU's GDPR 72-hour window. Reportable incidents include:
- Unauthorised access to systems or data
- Malware and ransomware attacks
- DDoS and denial-of-service events
- Data breaches and exfiltration
- Identity theft and spoofing attacks
- Supply chain compromises
- Attacks on web applications, APIs, and databases
- Attacks on operational technology (OT) and industrial control systems (ICS)
Cyber Security Audits and the CERT-In Guidance Stack
CERT-In issued its Comprehensive Cyber Security Audit Policy Guidelines (CISG-2025-02) on 25 July 2025 and 15 Elemental Cyber Defense Controls for Micro, Small and Medium Enterprises (CISG-2025-03) on 1 September 2025. Treat both for what they are: CERT-In guidelines, issued under its section 70B(4)(e) power to publish guidelines and advisories, not a statute creating a standalone annual-audit offence. The 15 elemental controls are addressed to MSMEs; a multinational's Indian GCC is not an MSME, and should be measuring itself against its group standard and any sectoral audit mandate that applies to it (the RBI, SEBI and IRDAI audit regimes bind their own regulated entities, and government departments have their own rules). Using a CERT-In empanelled auditor remains the sensible default because CERT-In's own guidance and most sectoral regulators point there.
The real enforcement hook is narrower and sharper. Under section 70B(7) of the IT Act, 2000, a service provider, intermediary, data centre, body corporate or person who fails to provide information called for, or to comply with a direction given, under section 70B(6) is punishable with imprisonment of up to one year, or a fine of up to INR 1 crore, or both — the fine having been raised from INR 1 lakh by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023. A court can take cognizance only on a complaint by an officer authorised by CERT-In (section 70B(8)).
180-Day Log Retention Requirement
Direction (iv) requires logs of all ICT systems to be enabled, maintained securely for a rolling period of 180 days, and maintained within the Indian jurisdiction, to be produced to CERT-In with any incident report or on direction. For a cybersecurity GCC processing threat intelligence and security event data from global operations, this means dedicated log infrastructure hosted in India. Direction (i) separately requires clock synchronisation across all ICT systems to the NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or to servers traceable to them; an entity with infrastructure spanning multiple geographies may use another accurate standard time source provided it does not deviate from NIC and NPL.
The DPDP Act and Rules 2025
The Digital Personal Data Protection Act 2023, operationalised through the DPDP Rules, 2025 (G.S.R. 846(E), notified 13 November 2025), adds another compliance layer. GCCs processing personal data must implement encryption, masking, and obfuscation techniques, intimate affected Data Principals without delay, intimate the Data Protection Board without delay with an initial description, and furnish the Board's detailed report within 72 hours of becoming aware (or within such longer period as the Board may allow on a written request) under rule 7 of the DPDP Rules, 2025. Penalties for non-compliance reach up to INR 250 crore. Full compliance obligations — including breach notification, consent mechanisms, and Significant Data Fiduciary duties — become binding by May 13, 2027.

Setting Up a Cybersecurity SOC in India: Entity and Infrastructure
The most common entity structure for a cybersecurity GCC is a wholly-owned subsidiary incorporated as a private limited company under the Companies Act 2013. This structure provides 100% ownership for the parent, limited liability, and the legal standing required for CERT-In registration and compliance.
Entity Registration Process
Registration follows the standard FDI route. IT and cybersecurity services fall under the automatic route with 100% FDI permitted, meaning no prior government approval is required. The process involves:
- Obtain Digital Signature Certificates (DSC) for directors from a licensed Certifying Authority
- Apply for Director Identification Numbers (DIN)
- File SPICe+ form with the MCA for incorporation; processing time depends on the ROC and on whether the form is returned for resubmission
- Open a bank account and receive initial share capital from the parent
- File FC-GPR with the RBI within 30 days of share allotment
- Obtain GST registration — essential for service delivery
Infrastructure Requirements for a SOC
A Security Operations Center requires specialised infrastructure beyond standard office space:
| Component | Specification |
|---|---|
| SOC floor space (30-50 seats) | 1,500-3,000 sq ft, access-controlled |
| SIEM platform | Splunk, QRadar, or Sentinel |
| Threat intelligence feeds | Commercial + open-source |
| Network monitoring tools | IDS/IPS, NDR solutions |
| Endpoint detection & response | CrowdStrike, SentinelOne, etc. |
| Secure connectivity | MPLS, SD-WAN, encrypted VPN |
| Log storage (180-day retention) | On-prem or cloud, India-hosted |
We do not attach a cost to these line items. There is no published benchmark for them that we could cite, and the two that dominate the bill — the SIEM and the log estate — are priced on data volume ingested and retention depth rather than on seat count, so a band drawn from someone else's build tells you very little about yours. Scope your own daily ingest volume and 180-day retention footprint first, then take quotes against those numbers.
Location Strategy: Bengaluru vs Hyderabad vs Pune
The three cities most often shortlisted for a security GCC trade off against each other along the same three axes — depth of the security talent market, cost of salaries and real estate, and attrition. Bengaluru has the largest pool of experienced security engineers and the widest choice of lateral hires, and prices accordingly. Hyderabad's planned IT corridors (Gachibowli, HITEC City) and its data centre build-out make it the usual cost-efficient alternative. Pune draws on a large engineering university base and is typically pitched on cost and retention rather than seniority. Rather than rely on published city premiums, price the specific roles you need in each city during the shortlisting exercise — the spreads move quickly and differ sharply by seniority band.

Building the Cybersecurity Talent Pipeline
India's cybersecurity talent market presents a paradox: a very large supply of entry-level engineers alongside a persistent shortage of experienced security practitioners. The practical consequence for a new GCC is that L1 and L2 analyst roles fill quickly while L3, incident response and architecture roles do not. Plan hiring on that asymmetry rather than on a single headline shortage number.
How SOC Roles Are Priced
A SOC staffs into a standard ladder: L1 analysts on triage, L2 on investigation, L3 leads and senior analysts above them, with threat intelligence, incident response management and security architecture alongside, and a head of security at the top. Compensation climbs steeply up that ladder, and the steepness is the planning point — the L1 and L2 rungs are inexpensive and fill quickly, while every rung above them is priced by a national shortage.
We do not print salary bands for these roles. There is no citable published survey of Indian security compensation that we would stand behind, the figures that circulate are largely recycled between vendor reports, and the real spread moves with city, sector and the certification or clearance profile of the role. Get live compensation data for your target cities and seniority bands before modelling headcount cost. What does hold generally is that a GCC has to price above Indian IT services firms for the same role to win lateral hires; measure that gap in your own target market rather than applying a fixed percentage.
Talent Acquisition Strategy
A sustainable cybersecurity talent pipeline requires a multi-pronged approach:
- Hire-and-train model: Recruit B.Tech graduates from Tier 1 and Tier 2 engineering colleges and run intensive 3-6 month SOC training programmes, either in-house or through a specialist security training provider
- Lateral hiring: Target experienced analysts from Indian IT services firms, where cybersecurity teams are well-established but salaries are lower than GCC market rates
- University partnerships: Establish internship and placement programmes with the IITs, NITs and IIITs, several of which run dedicated security research groups
- Certification sponsorship: Fund CISSP, CEH, OSCP, and GIAC certifications for employees — this is both a retention tool and a quality differentiator
Retention Challenges
Retention is the binding constraint on most security GCCs: analysts trained at your cost become attractive lateral hires elsewhere, and a SOC that loses its L2 bench has to rebuild its detection quality from scratch. Budget for meaningful annual attrition and build against it — competitive ESOPs, clear career progression paths, rotation opportunities to global SOC locations, and investment in continuous learning. For structuring equity compensation plans, see our guide on ESOPs for India subsidiary employees.

CERT-In Compliance: Implementation Roadmap for GCCs
Meeting CERT-In requirements is not optional — it is a legal obligation with criminal penalties. Here is a practical implementation roadmap for a cybersecurity GCC:
Phase 1: Baseline Assessment (Weeks 1-4)
- Engage a CERT-In empanelled auditor to conduct a gap assessment against the CERT-In Directions of 28 April 2022 and any sectoral audit standard that binds you
- Map your current controls against your group security baseline; CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (CISG-2025-02) are the reference for how the audit itself should be scoped and governed
- Identify log retention gaps — are all ICT system, network and application logs enabled and retained for a rolling 180 days within Indian jurisdiction?
- Establish an incident reporting process that can meet the 6-hour deadline for Annexure I incidents
Phase 2: Control Implementation (Weeks 5-12)
- Deploy or upgrade SIEM to centralise logging and ensure 180-day retention on India-hosted infrastructure
- Implement NTP synchronisation across all assets to NIC or NPL servers (or sources traceable to them)
- Establish a formal incident response plan with documented escalation procedures and CERT-In reporting templates
- Deploy multi-factor authentication, endpoint detection, and network segmentation controls
- If you operate as a data centre, VPS, cloud service or VPN service provider, set up the subscriber registration records that direction (v) requires you to hold for five years after cancellation or withdrawal of the registration
Phase 3: Ongoing Compliance (Continuous)
- Schedule periodic cyber security audits by CERT-In empanelled auditors, at the frequency your sectoral regulator or group policy requires
- Conduct quarterly tabletop exercises to test 6-hour incident reporting capability
- Maintain documentation of all security controls, changes, and audit findings
- Stay current with CERT-In advisories and update controls accordingly
Audit cost and duration vary widely with scope and organisational complexity; get scoped quotes from two or three empanelled auditors rather than budgeting from a rule of thumb.

Cross-Border Data Flow and FEMA Considerations
A cybersecurity GCC inherently processes data that flows across borders — threat intelligence from the parent company's global infrastructure, security event logs from international endpoints, and incident response data that may contain personally identifiable information.
FEMA and Data Transfer
The Foreign Exchange Management Act governs the financial aspects of the GCC's operations. Key compliance requirements include:
- Filing FLA Returns annually by July 15
- Transfer pricing documentation for inter-company service charges — the GCC's service fees to the parent must be at arm's length
- Forms 145 and 146 (formerly Forms 15CA and 15CB) for outward remittances including dividend payments, royalties, and management fees
- Withholding tax compliance on cross-border payments, with rates varying based on applicable DTAA treaties
Data Localisation Requirements
While India does not yet mandate complete data localisation for cybersecurity data, the CERT-In 180-day log retention rule effectively requires security logs to be stored on Indian infrastructure. Additionally, the DPDP Act restricts transfer of personal data to countries not approved by the central government. GCCs should design their data architecture with clear segregation between personal data (subject to DPDP Act restrictions) and security operational data (subject to CERT-In retention requirements).
What Drives the Cost of Running a Cybersecurity SOC GCC in India
The annual operating cost of a mid-sized SOC of 40-50 professionals falls into six buckets. They are worth modelling separately because each scales on a different driver:
- Employee costs (salary and benefits) — by far the largest line, scaling with headcount and, more sharply, with the seniority mix
- Office and SOC infrastructure — floor space, access control and the secure-room build-out
- Security tools and platforms — SIEM, EDR, threat intelligence and network monitoring, priced mostly on data volume or endpoint count rather than on headcount
- Compliance and audit — empanelled-auditor engagements plus the India-specific work created by the CERT-In directions and the DPDP Rules
- Training and certifications — the hire-and-train pipeline and certification sponsorship
- Statutory compliance — ROC filings, GST, transfer pricing documentation and tax
We do not publish a total. Any figure we printed would be a planning band from our own engagements rather than a benchmark you could verify, and the two heaviest lines — compensation and platform licensing — are precisely the two that vary most between builds. Model each bucket from live quotes against your own seniority mix and ingest volume. The margin against an equivalent US or UK SOC is the reason most of these builds get approved; model it against your own current fully-loaded cost per analyst rather than a headline percentage, and include the India-specific compliance overhead above. For a comprehensive understanding of compliance cost structures, see our guide on hidden costs of running a company in India.
24/7 SOC Operations: Leveraging India's Time-Zone Advantage
One of the most compelling strategic reasons for establishing a cybersecurity SOC in India is the time-zone advantage. India (IST, UTC+5:30) provides natural coverage for off-hours in the US (9.5 to 13.5 hours ahead of US Eastern and Pacific time, depending on daylight saving) and partial overlap with European business hours. This enables a follow-the-sun SOC model where the India team handles overnight monitoring for US operations and morning coverage for European operations.
Shift Structure for a 24/7 SOC
| Shift | IST Hours | Coverage Provided |
|---|---|---|
| Day Shift | 08:00-16:00 | APAC business hours, US late night |
| Evening Shift | 16:00-00:00 | Europe business hours, US morning |
| Night Shift | 00:00-08:00 | US business hours, Europe evening |
Size each shift against the alert volume it actually carries rather than against a fixed ratio: for a parent whose main estate sits in the United States, the IST night shift covers the busiest hours and usually needs the deepest bench, which is the opposite of how SOC rosters are often drafted.
Night shift operations carry a shift premium and must comply with the state Shops and Establishments Act where the office sits — these state statutes and the conditions attached to state night-shift exemptions are where obligations such as transport for employees working at night, and rest intervals between shifts, actually come from, and they differ materially between Karnataka, Telangana and Maharashtra. The Occupational Safety, Health and Working Conditions Code, 2020 came into force on 21 November 2025 and governs daily and weekly hours, overtime and the conditions for employing women at night; the state rules under it are still being notified, so check the position in your state before fixing shift rosters. For a complete overview of labour law obligations, see our guide on India new labour codes for foreign employers.
Key Takeaways
- CERT-In compliance is non-negotiable — the 6-hour incident reporting mandate and the 180-day in-India log retention rule come from binding directions under section 70B(6), and failing to comply with a direction or an information request is punishable under section 70B(7) with up to one year's imprisonment, a fine of up to INR 1 crore, or both
- Experienced security talent is the scarce input, not headcount — combine hire-and-train models with lateral hiring and university partnerships rather than relying solely on experienced hires
- Compensation dominates the operating cost of a 40-50 person SOC, with SIEM and log-retention licensing next — build the business case from live salary and platform quotes for your target cities and ingest volume, not from a published planning band
- Structure as a wholly-owned subsidiary under the automatic FDI route — no government approval needed for 100% foreign ownership in IT and cybersecurity services
- Design data architecture for dual compliance — CERT-In log retention within India and DPDP Act personal data transfer restrictions require careful data segregation from day one
For assistance with registering your cybersecurity GCC as a foreign subsidiary in India or navigating FEMA and RBI compliance, contact our team for a tailored advisory engagement.
Need help with GCC Operations? Our team handles it.
India Entry StrategyFrequently Asked Questions
What is the CERT-In 6-hour incident reporting requirement for GCCs?
CERT-In's Directions of 28 April 2022, issued under section 70B(6) of the IT Act, 2000, require service providers, intermediaries, data centres, body corporate and government organisations — which includes a GCC incorporated in India — to report the cyber incidents listed in Annexure I to the Directions within 6 hours of noticing them or being told about them. Reportable incidents include unauthorised access, malware and ransomware attacks, DDoS events, data breaches, identity theft and supply chain compromises. Failing to comply with a CERT-In direction or information request is punishable under section 70B(7) with imprisonment of up to one year, a fine of up to INR 1 crore, or both.
How much does it cost to set up a cybersecurity SOC GCC in India?
There is no citable benchmark we would stand behind, so we do not publish a figure. The annual cost of a mid-sized SOC of 40-50 professionals is dominated by compensation, followed by security tooling licensed on data volume or endpoint count; office and SOC infrastructure, compliance and audit, training and certification, and statutory compliance make up the remainder. Compensation and platform licensing are also the two lines that vary most between builds, so model both from live quotes for your target cities and your own ingest volume before building a business case.
What cybersecurity certifications are most valued for SOC roles in India?
The most valued certifications for SOC professionals in India include CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical Hacker), OSCP (Offensive Security Certified Professional), and GIAC certifications. Sponsoring these certifications for employees serves as both a quality differentiator and a retention tool in a competitive talent market.
Is 100% FDI allowed for cybersecurity GCCs in India?
Yes. IT and cybersecurity services fall under the automatic route for FDI in India, permitting 100% foreign ownership without prior government approval. The most common structure is a wholly-owned subsidiary incorporated as a private limited company under the Companies Act 2013.
What are the DPDP Act compliance requirements for cybersecurity GCCs?
The DPDP Act 2023 and the DPDP Rules, 2025 require GCCs processing personal data to implement reasonable security safeguards, intimate affected Data Principals without delay following a personal data breach, intimate the Data Protection Board without delay with an initial description, and furnish the Board's detailed report within 72 hours of becoming aware (or within such longer period as the Board may allow on a written request) under rule 7. A Significant Data Fiduciary must additionally undertake a Data Protection Impact Assessment and an audit once in every twelve months under rule 13(1). Penalties under the Schedule to the Act reach INR 250 crore for failure to take reasonable security safeguards. The substantive obligations come into force on 13 May 2027.
Which Indian cities are best for setting up a cybersecurity SOC GCC?
Bengaluru, Hyderabad and Pune are the usual shortlist. Bengaluru offers the deepest pool of experienced security engineers and the widest choice of lateral hires, at the highest cost. Hyderabad's planned IT corridors and data centre build-out make it the standard cost-efficient alternative. Pune draws on a large engineering university base and is typically pitched on cost and retention. Price the specific roles you need in each city during shortlisting rather than relying on published city premiums.