Skip to content Skip to footer

Become a Certified GRC Professional (GRCP)

GRCP is a flagship certification by FCRF designed to equip professionals with the strategic, technical, and regulatory expertise required to master Governance, Risk, and Compliance (GRC) within the specific Indian context. This intensive program focuses on navigating India’s complex regulatory mandates, including key directives from RBI, SEBI, IRDAI, and CERT-In , foundational laws like the Digital Personal Data Protection (DPDP) Act, 2023 , and the modern technical frameworks such as Zero Trust Architecture (ZTA) and MITRE ATT&CK that are essential to excel as a GRC leader.

Law Enforcement & Government Officials and Cybersecurity Professionals Trained
11600 +
Awareness Programs, Technical Workshops & Sessions Conducted
320 +
National & International Speakers, Instructors, and Subject Matter Experts
200 +
Satisfaction Rate of Learners
80 %

The Indian GRC Landscape

A dedicated program to explore the full spectrum of Governance, Risk, and Compliance in India. This includes deep dives into financial sector GRC for Banking (RBI) and Capital Markets (SEBI) , as well as Insurance (IRDAI). Hands-on exposure to building a hybrid Risk Management Framework (RMF) , using MITRE ATT&CK for gap analysis , and governing emerging tech like the RBI ‘FREE-AI’ framework prepares you for real-world risk management and compliance challenges.

Live Classes By Expert

Renowned GRC leaders, principal risk consultants, and compliance experts will guide you through the complexities of India’s specific regulatory mandates from RBI, SEBI, IRDAI, and CERT-In. You’ll master foundational laws like the DPDP Act, 2023 , and learn to implement technical frameworks like Zero Trust Architecture (ZTA) and MITRE ATT&CK. You’ll learn how to build and manage a GRC program that satisfies regulatory audits and protects the organization in practice.

Career-Defining Certification

Position yourself as a Certified Indian GRC Professional (GRCP) and open pathways into risk management, compliance leadership, GRC strategy, internal audit, and Third-Party Risk Management (TPRM). Gain solid technical and strategic skills from both operational (like SOC Governance and Incident Response ) and strategic (like ZTA implementation and communicating risk to the Board ) perspectives, making you the indispensable resource who can translate between technical, legal, and business units.

10th Jan, 2026

Starting Date

4 Weeks Duration

Sat & Sun, 11:00 AM
- 1:00 PM

Live Sessions

Recordings will be Provided

16 Modules

Curriculum

Snapshots from Our CCMP Program with CERT-In

Organised in collaboration with CERT-In, FCRF’s Certified Cyber Crisis Management Professional (CCMP) program was attended by over 500 top officials from civil services, defence, cybersecurity, and regulatory bodies. These glimpses capture our commitment to high-impact, nationally recognised training.

India Needs GRC Professionals - Will You Be One?

✅ Master the IT Act, 2000 & CERT-In Directives – 6-hour reporting , 180-day log retention , and mandatory annual audits.

✅ Understand the Digital Personal Data Protection Act, 2023 – Fiduciary obligations & breach notifications.

✅ Navigate the RBI’s Cyber Security Framework – IT Governance, TPRM, and digital payment controls.

✅ Apply the SEBI Cloud Adoption Framework – data localization , MeitY-empanelled CSPs , and technical controls.

✅ Implement the IRDAI Cyber Security Guidelines, 2023 – the 24 security domains & mandated NIST framework use.

✅ Learn Zero Trust Architecture (ZTA) and its strategic GRC implications for managing cloud and vendor risk.

✅ Explore advanced risk assessment using MITRE ATT&CK for threat-informed defense and gap analysis.

✅ Gain hands-on expertise in SOC Governance (SIEM) and automating incident response with SOAR.

✅ Tackle new-age challenges like governing AI using the RBI ‘FREE-AI’ Framework and auditing for algorithmic bias.

Objective Of GRCP

Discover Why GRC is The Perfect Program for GRCP & Compliance Leaders

An expert-crafted program to help you master India's specific GRC mandates, technical risk frameworks, and launch a career in Governance, Risk, and Compliance

Course Module

Comprehensive modules covering essential governance concepts, practical risk strategies, and real-world case studies for driving principled performance.

  • Core concepts: Governance, Risk, and Compliance

  • The strategic value of an integrated GRC model

  • Key international standards: ISO 27001/27005 and the NIST Cybersecurity Framework (CSF)

  • Mapping key regulators: RBI, SEBI, IRDAI, PFRDA, NABARD

  • Overview of national laws: Digital Personal Data Protection (DPDP) Act 2023, IT Act 2000

  • Nodal agencies: CERT-In, MHA I4C, DoT

  • Understanding the “Stacked Compliance” model

  • Origins: Justice K.S. Puttaswamy (Retd.) v. Union of India

  • Scope and key definitions: Data Principal, Data Fiduciary, Data Processor

  • Grounds for lawful processing: Consent vs. “Legitimate Uses”

  • Rights and duties of Data Principals

  • Key obligations: “Reasonable security safeguards,” purpose limitation

  • Privacy notice requirements (multilingual mandates)

  • Mandatory Personal Data Breach Notification to the Data Protection Board (DPB)

  • Overview of the IT Act, 2000 and IT Rules, 2021 (Intermediary Guidelines)

  • CERT-In Directives: 6-hour incident reporting

  • CERT-In Directives: 180-day log retention

  • New mandates: Mandatory annual third-party audits and Software Bill of Materials (SBOM)

  • RBI’s Cyber Security Framework

  • Consolidation of Master Directions: IT Governance, Outsourcing, and Digital Payments

  • Intensive focus on Third-Party Risk Management (TPRM) and vendor due diligence

  • Obligations for intermediaries: Code of Conduct, AML, Internal Compliance

  • Deep dive: SEBI Cloud Adoption Framework (2023)

  • Mandated controls: Data localization, MeitY-empanelled CSPs

  • Technical requirements: Hardware Security Modules (HSM), BYOK/BYOE (Bring-Your-Own-Key/Encryption)

  • IRDAI (Information and Cyber Security) Guidelines, 2023

  • The 24 Security Domains for insurance

  • Regulatory convergence: Mandated NIST framework implementation and dual 6-hour reporting (IRDAI & CERT-In)

  • PFRDA framework: Protecting subscriber interests and fraud prevention

  • Core philosophy: “Never Trust, Always Verify”

  • Key tenets: Assume Breach, least privilege access, micro-segmentation

  • ZTA as a GRC strategy for managing cloud, WFH, and vendor risk

  • Moving from traditional risk registers to threat-informed defense

  • Using MITRE ATT&CK (Adversarial Tactics, Techniques, and Procedures)

  • Practical application: Gap analysis, prioritizing security controls, and threat modeling

  • RBI’s ‘FREE-AI’ (Framework for Responsible and Ethical Enablement of AI)

  • The “7 Sutras” (Guiding Principles), including ‘Understandable by Design’ (Explainability)

  • New GRC domains: Auditing for model risk, data risk, and algorithmic bias

  • MHA I4C: Nodal point for coordinating with Law Enforcement Agencies (LEAs)

  • DoT Sanchaar Saathi portal: Citizen-centric fraud reporting

  • Using “Chakshu” reports as a public threat intelligence source for brand protection

  • The SOC as the central command for monitoring, detection, and response

  • Core technology: SIEM (Security Information and Event Management)

  • Using SIEM to generate evidence for CERT-In’s 180-day log retention mandate

  • Incident Response (IR) Playbooks as the core GRC document

  • Key technologies: DFIR (Digital Forensics) and SOAR (Security Orchestration, Automation, Response)

  • SOAR as the automation engine to meet the 6-hour CERT-In reporting deadline

  • Building a hybrid Risk Management Framework (RMF)

  • Synthesizing frameworks: Using NIST RMF as the “chassis”

  • Integrating DPDP data mapping, MITRE TTPs, and ZTA controls into a single unified risk register

  • Managing the new mandatory annual CERT-In cybersecurity audits

  • The GRC professional as a “translator” between technical, legal, and business units

  • Critical skill: Communicating risk to the Board and justifying budgets, as required by RBI, SEBI, and IRDAI

About Us

FCRF's Pioneering Role In Ensuring
A Cyber-Safe India

Future Crime Research Foundation (FCRF) is an IIT Kanpur’s AIIIDE–CoE incubated start-up (Non-Profit NGO) specializing in research in Cyber Security, Digital Crime, Fraud Risk Management, Cyber Laws, and Cyber Forensics. FCRF is also the host of India’s largest conference on tech-enabled crime and cyber threats, the FutureCrime Summit. It is registered under Section 8 of the Companies Act, 2013, and Sections 12A and 80G of the Income Tax Act, 1961. FCRF strives to make India future-ready by increasing digital awareness and building an ecosystem for a cyber-safe India.

Govern with Vision . Manage Risk . Lead in Integrated GRC .

Learn From the Leading Instructors & Mentors Behind FCRF Academy

FCRF’s partner Institutions & Organizations over the years.

FCRF’s Esteemed Speakers at the FutureCrime Summit

What Our Learners Say About Us

From senior officers to first-time professionals, our participants consistently praise the real-world relevance, expert-led delivery, and practical focus of our programs.

Manoranjan SP, CBI

Well-organised sessions, very good speakers, and nicely structured content.

Nitin Kawathekar GM, thyssenkrupp Uhde

Well-structured and not too heavy, perfect for working professionals.

Col. Sooraj S Assam Rifles

Content planning, pace of course. From scratch, so that all are on the same platform.

Rohini R. S. Nair Sr. Security Engineer, Kerela IT Mission

Informative sessions delivered with clarity and precision.

Srikakulapu Balaji Engineer, IFTAS (RBI)

What I liked most about the CCMP Cyber Crisis course was how it explained tough topics in a simple way using real-life examples.

Srivathsan Sridharan Manager, PwC

Case studies and introduction to professionals who could articulate towards today's situation.

Manjyot Singh SOC analyst, PwC

All the speakers in the course are from very well reputed organisation having deep understanding in cybersecurity, really learnt a lot.

Gaurav Raj Manager, Bank of Baroda

The course was well organised, and lecture by the industry experts was superb, Covered advanced topics like XDR, SIEM, and threat intelligence in depth.

From LinkedIn Feed

Inside the FCRF Academy LMS

Every live session’s recording is made available on the LMS within 3 hours, along with the session’s PDF handouts, so you never miss a moment of learning.

Group Enrollments & Institutional Payments

We offer exclusive group discounts for departments, organisations, and corporate teams. Participants can also be manually enrolled on behalf of their organisation, with a consolidated invoice issued for institutional payment.

To avail group access or inquire further, Contact Us:


FCRF & NIELIT (MeitY) Sign MoU in Presence of Union Minister Ashwini Vaishnaw

In a major boost to India's cybersecurity ecosystem, FCRF and NIELIT (MeitY) have joined forces to co-develop advanced training and certification programs. The MoU was signed on October 2nd in New Delhi, with Hon'ble Union Minister Shri Ashwini Vaishnaw presiding over the event.


FCRF x GT BHARAT

FCRF and Grant Thornton Jointly Published Landmark Report on Cybercrime Investigations, Unveiled at FutureCrime Summit 2025.

Have any questions?
Find answers here!

Find answers to common questions below. For more queries, contact: research@futurecrime.org

While the course is accessible on all devices, we recommend using a laptop for the best learning experience—especially for live sessions, practical labs, and assignments.

However, you can also download the FCRF Academy app from the Google Play Store and log in with your credentials to access sessions on your phone or tablet. The FCRF Academy app for iOS (App Store) will be live by mid-October.

The course runs for 4 weeks, with live sessions every Saturday and Sunday from 11:00 AM to 1:00 PM IST.

The course is conducted live by expert instructors, with recordings made available after each session for revision and convenience.

If you’ve made the payment but haven’t received confirmation, please check your spam folder. If not found, email us at research@futurecrime.org with your payment details.

Absolutely. All sessions are live and interactive, and learners are encouraged to ask questions during and after class.

Kindly go through the syllabus and curriculum of the course carefully. No refund is possible once the payment is made. Though, we highly recommend all to enroll in this program.

You’ll receive lifetime access to session recordings, downloadable resources, and reading materials provided during the course.

Yes, you’ll be added to the official GRCP WhatsApp group for updates, resources, and peer discussions. We’ll send the invite link via email and WhatsApp after registration. The link will also be available on the LMS for easy access.

If you don’t receive it, feel free to reach out at research@futurecrime.org at the earliest.