Regulatory Traceability Matrix
Every Regulation 2–17 clause, plus the First and Second Schedules, mapped to a NXT GRID module and its coverage type — no orphan requirement (Section 14).
10Software
14Software + External
5Software + Infrastructure
1Software Record Only
30 of 30
| Regulation | Requirement Coverage | NXT GRID Module | Coverage Type |
|---|---|---|---|
| 2 | Applicability by entity/type/capacity; vendor applicability | Applicability Engine | Implemented |
| 4(3) | Comply with CSIRT-Power directions/guidelines | Regulatory Update Center | External Dependency |
| 5(1)-(8) | CISO/Alternate designation, reporting, tenure, public contacts, training | Org/CISO Module | External Dependency |
| 5(9) | 24x7 India Information Security Division, staffing/certification/training/tenure | ISD Workforce Module | External Dependency |
| 5(10)-(11) | Cyber Security Policy + CCMP approval/review/vetting | Policy Studio / CCMP | External Dependency |
| 5(12)-(15) | CII separation, perimeter controls, web/app security devices and audit clearance | Network/Web Security Governance | Evidence Valid |
| 5(16)-(17) | Critical classification and remote access | Asset Register / Remote Access | Implemented |
| 5(18) | Six-monthly awareness/exercises | Training & Exercises | External Dependency |
| 5(19) | India-resident encrypted sensitive data | Data Governance | External Dependency |
| 5(20) | Vendor SLA/NDA/personnel risk/breach action | Vendor Compliance | Implemented |
| 5(21) | Online/offline critical backups | Backup Governance | Evidence Valid |
| 5(22)-(24) | Annual cyber audit, IT procurement compliance, ISO/TCC | Audit & Certification | External Dependency |
| 5(25)-(26) | Asset register; cyber risk assessment/mitigation | Asset / Risk | Implemented |
| 5(27)-(31) | Pre-commissioning audit/VAPT; CSIRT info; NCIIPC/Protected; non-discoverability; FAT/SAT | Commissioning / Audit / CII / FAT-SAT | External Dependency |
| 5(32)-(39) | Time sync, training, physical/logical separation, IR plan, monitoring, logs, annual perimeter review, trusted source | Time/Training/Network/IR/SecOps/Vendor | Evidence Valid |
| 5(40)-(42) | IT Act obligations, vulnerability disclosure, incident register | Regulatory / Vulnerability / Incident | External Dependency |
| 6(1)-(9) | OT isolation, perimeter controls, dedicated channels, remote ops, compliant/trusted OT equipment, segmentation, inter-entity channel security | OT Network & Remote Operation | Evidence Valid |
| 7(1)-(3) | CISO qualifications/functions, reporting, reviews, threat intel, retention, patches, IPs, random tests, policies/registers/time sync | CISO Workspace | External Dependency |
| 8(1)-(33) | All required Cyber Security Policy contents/procedures | Policy Studio linked to modules | Implemented |
| 9 | CCMP detailed SOP, crisis criteria/scenarios, roles/comms, mitigation/recovery | CCMP | Implemented |
| 10 | Crisis communications, annual tests, post-crisis report/share/update | Crisis Exercise & After Action | External Dependency |
| 11(1)-(7) | Vendor recovery, signed/authenticated patches, integration requirements, EOL, BOM, hardening, vulnerability process | Vendor Portal | External Dependency |
| 12(1)-(3) | DGR vendor India data residency, secure mutual auth/encryption, trusted-source info | DGR Vendor Compliance | Evidence Valid |
| 13(1)-(3) | Audit scope, prior finding closure, 6-week report and remediation deadlines | Audit Workspace | External Dependency |
| 14(1)-(2) | CISO audit review, closure report, board reporting, third-party verification readiness | Audit Workspace | External Dependency |
| 15 | Annual self-audit, closure before next audit, verification readiness | Self Audit | Implemented |
| 16 | Potential statutory proceedings | Regulatory record/notice register | Not Applicable |
| 17 | Relaxation orders | Regulatory exception/waiver register | Implemented |
| First Schedule | Retention of 12 categories of documents/information | Evidence Vault | Implemented |
| Second Schedule | Prior-audit software update criteria | Change/Patch Classifier | Implemented |