Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
India · Central · Cyber & Technology

CERT-In · Incident reporting and log retention

CERT-In Directions under s.70B(6) of the Information Technology Act, 2000 · 28 April 2022

Open in Studio
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · All ICT systems in India
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Ongoing · per incident

Requirement coverage · compliance position: gaps to close

3
requirements
  • Covered 00%
  • Partially covered 3100%
  • Evidence unavailable 00%
Controls
3
1 failed testing
Evidence approved
5/8
current cycle
Open findings (gaps)
1
1 high
Open actions
1
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
Dir. (ii)Report cyber incidents within 6 hoursApplicableIncidents, including supplier incidents, are assessed and reportedVEN-03LOG-01Partially covered
Dir. (iv)Retain ICT system logs for 180 days within IndiaApplicableSecurity events are logged, retained and monitoredLOG-01LOG-02Partially covered
Dir. (i)Synchronise system clocks to NIC or NPL NTP serversApplicableSecurity events are logged, retained and monitoredLOG-01LOG-02Partially covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
VEN-03Supplier security incidents are assessed for impact and trackedPayGate Payment Gateway, Meridian Customer PortalFail2 / 41
LOG-01Security events are centrally logged and monitored 24x7Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass3 / 40
LOG-02Audit logs retained 180 days online and 5 years archived, tamper-protectedAmazon Web Services (ap-south-1), SAP S/4HANANot tested0 / 00

Open actions

ActionIssueOwnerDueStatus
REM-F-RBI-03Payment provider incident — incomplete credential rotationDeepa Menon10 Oct 2026In Progress

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.