
TL;DR — IT company compliance in one minute
• An IT company in India carries four compliance layers: company law (ROC), tax (PAN, TAN, TDS, GST), payroll-linked (EPF, ESI, PT, PoSH), and now data protection (the DPDP Act).
• Most rules trigger by headcount, turnover or state — ESI at 10 employees, PoSH at 10, EPF at 20, GST at ₹20 lakh turnover for services.
• ROC filings (AOC-4 and MGT-7) and DIR-3 KYC are annual and non-negotiable — late fees run at ₹100 per day with no ceiling.
• The DPDP Rules 2025 are now final. Full compliance is due by mid-2027, and a security lapse that leaks personal data can cost up to ₹250 crore.
• Compliance is not a one-time task. Build a calendar, assign owners, and treat it as due-diligence readiness for your next raise.

If you run an IT or SaaS company in India, statutory compliance is not just a legal checklist. It decides whether you can hire cleanly, invoice clients, raise funding and pass due diligence without disruption.
The trouble is timing. Most founders only think about compliance after a notice lands, a deadline slips, or an investor asks for documents. By then it is a fire drill. The smarter path is to know what applies at incorporation, what becomes recurring, and what triggers as you grow.
Broadly, an IT company juggles four layers: company-law compliance, tax compliance, payroll-linked compliance and, since 2023, data-protection compliance. A steady accounting and compliance function keeps all four in sync instead of scrambling one at a time.
Founder tip: Treat compliance as due-diligence readiness, not paperwork. Every clean filing you make today is one less red flag in your next fundraise or acquisition data room.
Here is the core recurring stack most Indian IT companies manage, and what usually triggers each one.
Compliance area | Usually triggers at | Why it matters |
PAN | Incorporation | Tax identity for banking, invoicing and filings |
TAN / TDS | First salary or vendor payment | Deduct, deposit and report tax at source |
GST | ₹20 lakh service turnover | Compliant invoicing and input tax credit |
ROC filings | Every financial year | Keeps the company in good legal standing |
Professional Tax | First salaried employee (state-based) | Employer payroll compliance |
EPF | 20 employees | Employee retirement fund contributions |
ESI | 10 employees (wages up to ₹21,000) | Employee medical insurance cover |
PoSH | 10 employees | Workplace harassment prevention committee |
DPDP Act | You process personal data | Lawful, secure handling of user data |
A PAN (Permanent Account Number) is one of the first essentials. It links the company to its tax profile and runs through banking, vendor onboarding and every filing you make.
A TAN (Tax Deduction Account Number) becomes relevant the moment you must deduct tax at source — usually your first payroll run. Both are foundational, so get them in place before you start billing or paying anyone. You can apply and verify these through the Income Tax Department portal.
TDS is not a one-off entry. It is a monthly rhythm: deduct, deposit, file and reconcile. For IT companies it starts with salaries and quickly extends to contractor fees, consultant payments and certain vendor payouts.
Step | What the company does |
1 | Deduct tax where applicable on salary or vendor payments |
2 | Deposit the tax by the 7th of the following month |
3 | File quarterly TDS statements (Form 24Q / 26Q) |
4 | Issue TDS certificates and reconcile in Form 26AS |
5 | Correct mismatches quickly before they become notices |
Where IT companies slip: paying consultants without checking TDS applicability, missing deductions on founder remuneration, weak vendor PAN capture, and late deposits after deduction. These small gaps are exactly what a clean payroll management process is built to prevent.
Watch out: Deducting TDS but depositing it late attracts 1.5% interest per month, and the expense can be disallowed. Return mismatches are the most common reason IT companies receive tax notices — reconcile every quarter, not once a year.
GST is one of the most operationally important compliances for an IT business because it touches billing, contracts, cash flow and customer experience. For service companies, registration commonly becomes relevant once you cross ₹20 lakh aggregate turnover, though special situations and inter-state rules can change that.
Why it matters more than founders expect: B2B buyers expect compliant GST invoices, broken invoicing hurts once client volume grows, and SaaS, support, implementation and subscription models each raise transaction-specific tax questions.
:info: Export of services: Software exports can qualify as zero-rated supplies under GST, letting you claim refunds or supply under a LUT without charging tax. The conditions are strict — confirm your invoicing meets them on the official GST portal.
Every company registered under the Companies Act, 2013 must file annually with the Registrar of Companies — even in a year with zero revenue. These are the filings you cannot skip.
Filing | What it is | Typical due date (FY 2025-26) |
AOC-4 | Financial statements | Within 30 days of AGM (by 30 Oct 2026) |
MGT-7 | Annual return | Within 60 days of AGM (by 29 Nov 2026) |
DIR-3 KYC | Director KYC | By 30 September 2026 |
AGM | Annual General Meeting | By 30 September 2026 |
Beyond filings, keep your board meetings minuted and statutory registers current — this is the paperwork investors and auditors ask for first. The forms and due dates live on the Ministry of Corporate Affairs portal. Late filing costs ₹100 per day, per form, with no upper limit.
As you hire, a set of payroll-linked registrations switch on automatically. Miss the trigger and you inherit back-dated dues plus interest.

Professional Tax (PT): a state levy with no headcount floor — it usually applies from your first salaried employee, and rules vary by state.
ESI: mandatory once you reach 10 employees, covering staff who earn up to ₹21,000 a month in gross wages.
EPF: mandatory at 20 employees; smaller teams can opt in voluntarily. Deposits are due by the 15th of the following month.
PoSH: at 10 employees you must form an Internal Committee under the PoSH Act and file an annual report.
You can register and manage provident-fund contributions on the EPFO employer portal. Getting these thresholds right is core to clean payroll management.
Founder tip: Map every threshold to a headcount trigger in your HR system now. The day you make your 10th and 20th hire should auto-flag ESI, PoSH and EPF — not surprise you six months later during an audit.
Most states require an office-based business to register under the local Shops and Establishments Act soon after setup. It governs working hours, leave and basic employment conditions, and it is state-specific — a Bengaluru office and a Pune office follow different state rules.
If you operate across multiple states, each location can carry its own PT, Shops and Establishments, and labour registrations. Multi-state growth is where compliance complexity quietly multiplies, so plan registrations ahead of each new office.
For IT companies, data protection is now a statutory duty. The Digital Personal Data Protection (DPDP) Act, 2023, with its final Rules notified in 2025, treats your company as a Data Fiduciary — legally accountable for how you collect, store and process personal data, even when a vendor does the processing.
Three obligations matter most for a growing IT firm:
Itemised consent — blanket consent forms are out. Ask separately for each use of data, so a user can say yes to one and no to another.
72-hour breach reporting — if you lose user data, notify the Data Protection Board and affected users without delay, with a detailed report inside 72 hours.
Data-principal rights — users can access, correct, nominate and request deletion of their data, usually within about 30 days.
The stakes are real: a security failure that leads to a personal-data breach can attract a penalty of up to ₹250 crore, and failing to report a breach up to ₹200 crore. You can read the Act and rules on the MeitY DPDP page.
Watch out: DPDP liability follows you to your vendors. If your cloud host or analytics tool leaks data, you are still the accountable Data Fiduciary. Update processor contracts with security and breach-reporting clauses before mid-2027.
Laws like the DPDP Act say you must be "secure" but do not name the tools. Frameworks fill that gap — they give you a documented, auditable way to prove security. The two you will hear about most are ISO 27001 and the NIST Cybersecurity Framework.

Feature | ISO 27001 | NIST CSF 2.0 |
Primary focus | Process-driven — how you manage security via policies | Outcome-driven — achieving specific security results |
Best for | Global firms needing a certification for B2B sales | US-facing or government-linked firms (free to use) |
Core structure | Clauses 4-10 plus Annex A controls | Six functions: Govern, Identify, Protect, Detect, Respond, Recover |
On top of a framework, regulators increasingly expect a Zero Trust posture — never trust, always verify, with least-privilege access. It limits the damage if a password is stolen and demonstrates you did more than build a weak perimeter.
Compliance load scales with headcount, turnover and geography. Knowing what comes next helps you staff and budget for it.
Stage | Main compliance priority |
0-5 employees | Incorporation, PAN, TAN, GST applicability, basic governance |
5-20 employees | Payroll controls, PT and Shops registrations, recurring filings |
20+ employees | EPF, PoSH committee, tighter payroll, audit readiness |
Multi-state / export | State PT variations, cross-border GST, DPDP maturity |
Reacting to notices instead of running a calendar — the deadline always wins.
Ignoring payroll triggers and inheriting back-dated EPF or ESI dues with interest.
Treating TDS casually, then facing return mismatches and disallowed expenses.
Skipping ROC filings in a dormant or pre-revenue year — the ₹100/day fee still runs.
Postponing DPDP work until an investor or enterprise client demands it.
An annual financial audit is a good moment to catch these gaps before they surface in someone else’s data room.
The fix for most of the above is unglamorous: a shared compliance calendar with owners, due dates and reminders for every filing — monthly TDS and GST, quarterly returns, and annual ROC and DIR-3 KYC. Assign each item to a person, not a vague "finance team".
As your headcount, turnover and data footprint grow, the load crosses tax, law, HR and security at once. That is the point to bring in expert help so nothing slips through the cracks.
An Indian IT company typically manages four layers: company law (ROC filings such as AOC-4, MGT-7 and DIR-3 KYC), tax (PAN, TAN, TDS and GST), payroll-linked compliance (EPF, ESI, professional tax and PoSH) and data protection under the DPDP Act. Which items apply depends on your headcount, turnover and state of operation.
ESI applies once you reach 10 employees, covering staff earning up to Rs 21,000 a month. The PoSH Act requires an Internal Committee at 10 employees. EPF becomes mandatory at 20 employees, though smaller teams can enrol voluntarily. Professional tax has no headcount floor and usually applies from your first salaried employee, depending on the state.
For FY 2025-26, the AGM must be held by 30 September 2026. AOC-4 (financial statements) is due within 30 days of the AGM and MGT-7 (annual return) within 60 days. DIR-3 KYC for directors is due by 30 September 2026. Late filing costs Rs 100 per day, per form, with no maximum limit — even for a dormant company.
Yes, if you process the personal data of individuals in India, you are a Data Fiduciary under the DPDP Act, 2023. You must obtain itemised consent, report data breaches to the Data Protection Board within 72 hours, and honour data-principal rights. Penalties reach up to Rs 250 crore for a security lapse that causes a breach, with full compliance expected by mid-2027.
For service businesses, GST registration is generally required once aggregate turnover crosses Rs 20 lakh. Inter-state supply, certain notified categories and specific business models can make registration necessary earlier. Software exports can qualify as zero-rated supplies, allowing you to supply under a LUT or claim refunds if invoicing conditions are met.
This guide is for general information only and does not constitute tax, legal or financial advice. Statutory thresholds, forms and deadlines change — confirm the current position with a qualified professional before you act.