Compliance Contact हिन्दी

Compliance

Registrations and compliance.

The current status of each registration and certification, including those still in progress.

Eligibility and certifications

Registrations and certifications

Several are in progress. This page shows the current status of each.

  • GeM Seller ID registration in progress Required to receive and bid on Government e-Marketplace tenders.
  • MSME / Udyam awaiting Udyam number Carries tender fee and EMD exemptions, and purchase preference under the Public Procurement Policy.
  • DPIIT / Startup India application pending Recognition under G.S.R. 108(E) of 4 February 2026: within ten years of incorporation and turnover under ₹200 crore, or twenty years and ₹300 crore as a Deep Tech Startup. The prior-turnover and prior-experience relaxations quoted alongside it come from procurement orders and the General Financial Rules, not from the notification itself.
  • NSIC registration planned Single-point registration for government supply.
  • MeitY empanelment target FY 2026-27 Empanelment for government IT and cloud services engagements.
  • STQC certification target FY 2026-27 Standardisation Testing and Quality Certification, expected for citizen-facing systems.
  • ISO/IEC 27001 audit scheduled Information security management. Commonly a mandatory eligibility clause.
  • ISO 9001 audit scheduled Quality management systems.
  • CMMI appraisal not yet appraised Maturity level for software delivery. Frequently scored in technical evaluation.
  • CERT-In empanelled audit engaging an empanelled auditor Independent security audit by a CERT-In empanelled organisation, required before most government go-lives.
  • WCAG 2.1 AA / GIGW 3.0 self-assessed This website is built to GIGW 3.0 and WCAG 2.1 AA. Independent audit to follow, see the accessibility statement.

Security and data protection

How we handle data and security

  • Data residency

    All departmental data stays within India. We deploy to NIC, MeghRaj, a state data centre or an empanelled Indian cloud region, as the contract requires. No departmental data leaves the country, including for support or diagnostics.

  • DPDP Act, 2023 position

    In department engagements Padmanex acts as Data Processor; the department remains Data Fiduciary. Purpose limitation, retention windows and breach notification timelines are set in the contract and built into the system.

  • Independent security audit

    Systems are built to pass audit by a CERT-In empanelled auditor before go-live, and re-audit after material change. Remediation is budgeted in the engagement.

  • Access and logging

    Role- and jurisdiction-based access control, with administrative actions logged and the log retained for the period the department is answerable for.

  • Source and handover

    Source code, build pipeline, infrastructure definitions, documentation and runbooks are contract deliverables with dates. Credentials are held by the department.

  • Accessibility of what we build

    Citizen-facing interfaces are built to GIGW 3.0 and WCAG 2.1 AA, verified by keyboard-only and screen-reader testing as well as automated checks.

Documents available on request

Certificates, registration proofs, audited financials, board resolutions and a signed no-blacklisting declaration are provided on request in the format your tender specifies. Email info@padmanex.com with the tender number.