Become a Certified GRC Professional (GRCP)
GRCP is a flagship certification by FCRF designed to equip professionals with the strategic, technical, and regulatory expertise required to master Governance, Risk, and Compliance (GRC) within the specific Indian context. This intensive program focuses on navigating India’s complex regulatory mandates, including key directives from RBI, SEBI, IRDAI, and CERT-In , foundational laws like the Digital Personal Data Protection (DPDP) Act, 2023 , and the modern technical frameworks such as Zero Trust Architecture (ZTA) and MITRE ATT&CK that are essential to excel as a GRC leader.
The Indian GRC Landscape
A dedicated program to explore the full spectrum of Governance, Risk, and Compliance in India. This includes deep dives into financial sector GRC for Banking (RBI) and Capital Markets (SEBI) , as well as Insurance (IRDAI). Hands-on exposure to building a hybrid Risk Management Framework (RMF) , using MITRE ATT&CK for gap analysis , and governing emerging tech like the RBI ‘FREE-AI’ framework prepares you for real-world risk management and compliance challenges.
Live Classes By Expert
Renowned GRC leaders, principal risk consultants, and compliance experts will guide you through the complexities of India’s specific regulatory mandates from RBI, SEBI, IRDAI, and CERT-In. You’ll master foundational laws like the DPDP Act, 2023 , and learn to implement technical frameworks like Zero Trust Architecture (ZTA) and MITRE ATT&CK. You’ll learn how to build and manage a GRC program that satisfies regulatory audits and protects the organization in practice.
Career-Defining Certification
Position yourself as a Certified Indian GRC Professional (GRCP) and open pathways into risk management, compliance leadership, GRC strategy, internal audit, and Third-Party Risk Management (TPRM). Gain solid technical and strategic skills from both operational (like SOC Governance and Incident Response ) and strategic (like ZTA implementation and communicating risk to the Board ) perspectives, making you the indispensable resource who can translate between technical, legal, and business units.
10th Jan, 2026
Starting Date
4 Weeks Duration
Sat & Sun, 11:00 AM
- 1:00 PM
Live Sessions
Recordings will be Provided
16 Modules
Curriculum
Snapshots from Our CCMP Program with CERT-In
Organised in collaboration with CERT-In, FCRF’s Certified Cyber Crisis Management Professional (CCMP) program was attended by over 500 top officials from civil services, defence, cybersecurity, and regulatory bodies. These glimpses capture our commitment to high-impact, nationally recognised training.
India Needs GRC Professionals - Will You Be One?
✅ Master the IT Act, 2000 & CERT-In Directives – 6-hour reporting , 180-day log retention , and mandatory annual audits.
✅ Understand the Digital Personal Data Protection Act, 2023 – Fiduciary obligations & breach notifications.
✅ Navigate the RBI’s Cyber Security Framework – IT Governance, TPRM, and digital payment controls.
✅ Apply the SEBI Cloud Adoption Framework – data localization , MeitY-empanelled CSPs , and technical controls.
✅ Implement the IRDAI Cyber Security Guidelines, 2023 – the 24 security domains & mandated NIST framework use.
✅ Learn Zero Trust Architecture (ZTA) and its strategic GRC implications for managing cloud and vendor risk.
✅ Explore advanced risk assessment using MITRE ATT&CK for threat-informed defense and gap analysis.
✅ Gain hands-on expertise in SOC Governance (SIEM) and automating incident response with SOAR.
✅ Tackle new-age challenges like governing AI using the RBI ‘FREE-AI’ Framework and auditing for algorithmic bias.
Discover Why GRC is The Perfect Program for GRCP & Compliance Leaders
An expert-crafted program to help you master India's specific GRC mandates, technical risk frameworks, and launch a career in Governance, Risk, and Compliance
- 16 modules aligned with India's key regulators (RBI, SEBI, IRDAI) , the DPDP Act, 2023 , and CERT-In Directives.
- Learn key domains like technical GRC strategy (ZTA) , advanced risk assessment (MITRE ATT&CK) , financial GRC , and Third-Party Risk Management.
- Now is the best time to build your expertise as India enforces new mandates for data protection and sectoral compliance.
- Designed to address real-world use cases across India's key financial (RBI, SEBI) , insurance (IRDAI), and corporate regulatory sectors.
- Practical frameworks (NIST, ISO) and capstone exercises bridging technical, legal, and business perspectives.
- Strong technical and governance foundations to help you step confidently into your role as a Certified Indian GRC Professional.
Who Can Join The GRCP Program?
The program is open to professionals, students, and leaders across IT, risk, governance, compliance, and audit domains—especially those preparing for roles in strategic GRC, risk management, internal audit, and regulatory compliance in the Indian context.
Course Module
Comprehensive modules covering essential governance concepts, practical risk strategies, and real-world case studies for driving principled performance.
GRC Principles & International Frameworks
Core concepts: Governance, Risk, and Compliance
The strategic value of an integrated GRC model
Key international standards: ISO 27001/27005 and the NIST Cybersecurity Framework (CSF)
The Indian GRC Ecosystem: Regulators & Laws
Mapping key regulators: RBI, SEBI, IRDAI, PFRDA, NABARD
Overview of national laws: Digital Personal Data Protection (DPDP) Act 2023, IT Act 2000
Nodal agencies: CERT-In, MHA I4C, DoT
Understanding the “Stacked Compliance” model
The DPDP Act, 2023 – Part 1: Foundations
Origins: Justice K.S. Puttaswamy (Retd.) v. Union of India
Scope and key definitions: Data Principal, Data Fiduciary, Data Processor
Grounds for lawful processing: Consent vs. “Legitimate Uses”
Rights and duties of Data Principals
The DPDP Act, 2023 – Part 2: Fiduciary Obligations
Key obligations: “Reasonable security safeguards,” purpose limitation
Privacy notice requirements (multilingual mandates)
Mandatory Personal Data Breach Notification to the Data Protection Board (DPB)
The IT Act (2000) & CERT-In Directives
Overview of the IT Act, 2000 and IT Rules, 2021 (Intermediary Guidelines)
CERT-In Directives: 6-hour incident reporting
CERT-In Directives: 180-day log retention
New mandates: Mandatory annual third-party audits and Software Bill of Materials (SBOM)
GRC for Banking (RBI)
RBI’s Cyber Security Framework
Consolidation of Master Directions: IT Governance, Outsourcing, and Digital Payments
Intensive focus on Third-Party Risk Management (TPRM) and vendor due diligence
GRC for Capital Markets (SEBI)
Obligations for intermediaries: Code of Conduct, AML, Internal Compliance
Deep dive: SEBI Cloud Adoption Framework (2023)
Mandated controls: Data localization, MeitY-empanelled CSPs
Technical requirements: Hardware Security Modules (HSM), BYOK/BYOE (Bring-Your-Own-Key/Encryption)
GRC for Insurance (IRDAI) & Pension (PFRDA)
IRDAI (Information and Cyber Security) Guidelines, 2023
The 24 Security Domains for insurance
Regulatory convergence: Mandated NIST framework implementation and dual 6-hour reporting (IRDAI & CERT-In)
PFRDA framework: Protecting subscriber interests and fraud prevention
Modern Defense – Zero Trust Architecture (ZTA)
Core philosophy: “Never Trust, Always Verify”
Key tenets: Assume Breach, least privilege access, micro-segmentation
ZTA as a GRC strategy for managing cloud, WFH, and vendor risk
Advanced Risk Assessment – MITRE ATT&CK
Moving from traditional risk registers to threat-informed defense
Using MITRE ATT&CK (Adversarial Tactics, Techniques, and Procedures)
Practical application: Gap analysis, prioritizing security controls, and threat modeling
Governing Emerging Tech – The RBI ‘FREE-AI’ Framework
RBI’s ‘FREE-AI’ (Framework for Responsible and Ethical Enablement of AI)
The “7 Sutras” (Guiding Principles), including ‘Understandable by Design’ (Explainability)
New GRC domains: Auditing for model risk, data risk, and algorithmic bias
National Cyber Coordination – MHA I4C & DoT Sanchaar Saathi
MHA I4C: Nodal point for coordinating with Law Enforcement Agencies (LEAs)
DoT Sanchaar Saathi portal: Citizen-centric fraud reporting
Using “Chakshu” reports as a public threat intelligence source for brand protection
The GRC Hub – Security Operations Center (SOC) Governance
The SOC as the central command for monitoring, detection, and response
Core technology: SIEM (Security Information and Event Management)
Using SIEM to generate evidence for CERT-In’s 180-day log retention mandate
Operationalizing Incident Response – SOAR, DFIR & Playbooks
Incident Response (IR) Playbooks as the core GRC document
Key technologies: DFIR (Digital Forensics) and SOAR (Security Orchestration, Automation, Response)
SOAR as the automation engine to meet the 6-hour CERT-In reporting deadline
Risk Management Frameworks in Practice
Building a hybrid Risk Management Framework (RMF)
Synthesizing frameworks: Using NIST RMF as the “chassis”
Integrating DPDP data mapping, MITRE TTPs, and ZTA controls into a single unified risk register
Capstone – The Certified GRC Professional in Practice
Managing the new mandatory annual CERT-In cybersecurity audits
The GRC professional as a “translator” between technical, legal, and business units
Critical skill: Communicating risk to the Board and justifying budgets, as required by RBI, SEBI, and IRDAI



FCRF's Pioneering Role In Ensuring A Cyber-Safe India
Future Crime Research Foundation (FCRF) is an IIT Kanpur’s AIIIDE–CoE incubated start-up (Non-Profit NGO) specializing in research in Cyber Security, Digital Crime, Fraud Risk Management, Cyber Laws, and Cyber Forensics. FCRF is also the host of India’s largest conference on tech-enabled crime and cyber threats, the FutureCrime Summit. It is registered under Section 8 of the Companies Act, 2013, and Sections 12A and 80G of the Income Tax Act, 1961. FCRF strives to make India future-ready by increasing digital awareness and building an ecosystem for a cyber-safe India.
Govern with Vision . Manage Risk . Lead in Integrated GRC .
Learn From the Leading Instructors & Mentors Behind FCRF Academy










FCRF’s Esteemed Speakers at the FutureCrime Summit





What Our Learners Say About Us
From senior officers to first-time professionals, our participants consistently praise the real-world relevance, expert-led delivery, and practical focus of our programs.
Well-organised sessions, very good speakers, and nicely structured content.
Well-structured and not too heavy, perfect for working professionals.
Content planning, pace of course. From scratch, so that all are on the same platform.
Informative sessions delivered with clarity and precision.
What I liked most about the CCMP Cyber Crisis course was how it explained tough topics in a simple way using real-life examples.
Case studies and introduction to professionals who could articulate towards today's situation.
All the speakers in the course are from very well reputed organisation having deep understanding in cybersecurity, really learnt a lot.
The course was well organised, and lecture by the industry experts was superb, Covered advanced topics like XDR, SIEM, and threat intelligence in depth.
From LinkedIn Feed


















Inside the FCRF Academy LMS
Every live session’s recording is made available on the LMS within 3 hours, along with the session’s PDF handouts, so you never miss a moment of learning.
Group Enrollments & Institutional Payments
We offer exclusive group discounts for departments, organisations, and corporate teams. Participants can also be manually enrolled on behalf of their organisation, with a consolidated invoice issued for institutional payment.
To avail group access or inquire further, Contact Us:
FCRF & NIELIT (MeitY) Sign MoU in Presence of Union Minister Ashwini Vaishnaw
In a major boost to India's cybersecurity ecosystem, FCRF and NIELIT (MeitY) have joined forces to co-develop advanced training and certification programs. The MoU was signed on October 2nd in New Delhi, with Hon'ble Union Minister Shri Ashwini Vaishnaw presiding over the event.
FCRF x GT BHARAT
FCRF and Grant Thornton Jointly Published Landmark Report on Cybercrime Investigations, Unveiled at FutureCrime Summit 2025.
Have any questions? Find answers here!
Find answers to common questions below. For more queries, contact: research@futurecrime.org
Should I use my laptop, tablet, or phone to access this course?
While the course is accessible on all devices, we recommend using a laptop for the best learning experience—especially for live sessions, practical labs, and assignments.
However, you can also download the FCRF Academy app from the Google Play Store and log in with your credentials to access sessions on your phone or tablet. The FCRF Academy app for iOS (App Store) will be live by mid-October.
What is the total duration of the course?
The course runs for 4 weeks, with live sessions every Saturday and Sunday from 11:00 AM to 1:00 PM IST.
Will this be live or pre-recorded?
The course is conducted live by expert instructors, with recordings made available after each session for revision and convenience.
I made the payment but didn’t receive any email
If you’ve made the payment but haven’t received confirmation, please check your spam folder. If not found, email us at research@futurecrime.org with your payment details.
Are the sessions interactive? Can I ask questions?
Absolutely. All sessions are live and interactive, and learners are encouraged to ask questions during and after class.
Is a refund available after payment and registration?
Kindly go through the syllabus and curriculum of the course carefully. No refund is possible once the payment is made. Though, we highly recommend all to enroll in this program.
Will I get lifetime access to course content?
You’ll receive lifetime access to session recordings, downloadable resources, and reading materials provided during the course.
Will I be added to a WhatsApp or Telegram group?
Yes, you’ll be added to the official GRCP WhatsApp group for updates, resources, and peer discussions. We’ll send the invite link via email and WhatsApp after registration. The link will also be available on the LMS for easy access.
If you don’t receive it, feel free to reach out at research@futurecrime.org at the earliest.


















