Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
India · Central · Cyber & Technology
CERT-In · Incident reporting and log retention
CERT-In Directions under s.70B(6) of the Information Technology Act, 2000 · 28 April 2022
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · All ICT systems in India
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Ongoing · per incident
Requirement coverage · compliance position: gaps to close
3
requirements
- Covered 00%
- Partially covered 3100%
- Evidence unavailable 00%
Controls
3
1 failed testing
Evidence approved
5/8
current cycle
Open findings (gaps)
1
1 high
Open actions
1
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| Dir. (ii) | Report cyber incidents within 6 hours | Applicable | Incidents, including supplier incidents, are assessed and reported | VEN-03LOG-01 | Partially covered |
| Dir. (iv) | Retain ICT system logs for 180 days within India | Applicable | Security events are logged, retained and monitored | LOG-01LOG-02 | Partially covered |
| Dir. (i) | Synchronise system clocks to NIC or NPL NTP servers | Applicable | Security events are logged, retained and monitored | LOG-01LOG-02 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| VEN-03 | Supplier security incidents are assessed for impact and tracked | PayGate Payment Gateway, Meridian Customer Portal | Fail | 2 / 4 | 1 |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Pass | 3 / 4 | 0 |
| LOG-02 | Audit logs retained 180 days online and 5 years archived, tamper-protected | Amazon Web Services (ap-south-1), SAP S/4HANA | Not tested | 0 / 0 | 0 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-RBI-03 | Payment provider incident — incomplete credential rotation | Deepa Menon | 10 Oct 2026 | In Progress |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.