09
Industry Specific Laws
FSSAI, factory licences, pollution consent, RBI authorisations, trade licences and commercial standards - mapped and tracked.
8
Industries mapped
68+
Licences catalogued
0
Things you do
What this covers
Every company in India has the same baseline: company law, GST, income tax, payroll. Any competent firm handles that layer, and most founders assume it is the whole picture.
It is not. Underneath it sits a second layer that depends entirely on what your business does, where it operates and who it serves - a food licence, a pollution consent, a factory registration, an RBI authorisation, a trade licence from a municipal corporation, a fire NOC, a state excise permit. These are not exotic. They are the licences that let you legally operate at all, and they are the ones that get sealed, suspended or fined.
Almost nobody maps this layer. Your company secretary handles the MCA. Your accountant handles tax. Neither of them is watching whether your FSSAI licence expires in March or whether crossing into a second state just triggered a new Shops and Establishments registration.
We map it. Completely, for your specific business, across all three levels of government - and then we track every renewal date on the same calendar as everything else.
How this is priced
Visibility is included. Execution is quoted.
In your monthly fee
- The complete map of what applies to your business
- Applicability reassessed when you change state, product, headcount or turnover
- Every licence and renewal date on your compliance calendar
- Alerts before expiry, not after
- Notification when a law that affects you changes
- Flagging of anything you are operating without
Quoted separately, always before we start
- Obtaining a new licence or registration
- Renewals and periodic returns under those licences
- Audits, inspections and certifications
- Responding to a notice or a sealing order
- Coordination with an empanelled specialist where one is required
We tell you what applies and when it is due at no extra cost, because knowing is the hard part. Getting each licence is one-off work with a real cost attached, and we quote it before we do it.
The stack
Three layers, three governments.
Applies wherever you operate in India.
- FSSAI
- RBI authorisations
- BIS certification
- Legal Metrology
- EPR under plastic and e-waste rules
- CERT-In directions
- Drugs and Cosmetics
- DPIIT recognition
Changes the moment you cross a border.
- Shops and Establishments
- Factories Act licence
- Pollution Control Board consent
- Clinical Establishments Act
- State excise
- Professional tax
- Labour Welfare Fund
- RERA
Changes street to street, and nobody warns you.
- Trade licence
- Health or eating-house licence
- Fire NOC
- Signage and advertisement permission
- Building occupancy certificate
- Local pollution and waste clearances
A single-city company usually holds between four and twelve of these. Most founders can name two.
Applicability
What applies to you.
| What it is | Issued by | When | Applies if | Level |
|---|---|---|---|---|
| CERT-In directions | CERT-In | Incident reporting within the prescribed window; logs retained 180 days | Every body corporate operating IT systems in India | CENTRAL |
| IT Act intermediary rules | MeitY | Continuous | Platforms hosting third-party content | CENTRAL |
| Shops and Establishments | State labour department | On opening | Every office | STATE |
| Trade licence | Municipal corporation | Annual | Commercial premises | LOCAL |
| STPI or SEZ registration | STPI / SEZ authority | On registration, then periodic returns | Software exporters claiming benefits | CENTRAL |
| Softex filing | RBI via STPI | Per invoice | Software exported without physical shipment | CENTRAL |
| DPIIT startup recognition | DPIIT | One-time, then compliance | Startups claiming exemptions | CENTRAL |
| SOC 2 Type II | Independent auditor | Annual | Not law - required by enterprise customers | STANDARD |
| ISO 27001 | Accredited certification body | 3-year cycle with surveillance | Not law - required by enterprise and EU customers | STANDARD |
| GDPR | EU supervisory authorities | Continuous | If you process data of people in the EU | STANDARD |
| HIPAA | US HHS | Continuous | If you touch US protected health information | STANDARD |
CERT-In directions
CENTRALIssued by · CERT-In
When · Incident reporting within the prescribed window; logs retained 180 days
Every body corporate operating IT systems in India
IT Act intermediary rules
CENTRALIssued by · MeitY
When · Continuous
Platforms hosting third-party content
Shops and Establishments
STATEIssued by · State labour department
When · On opening
Every office
Trade licence
LOCALIssued by · Municipal corporation
When · Annual
Commercial premises
STPI or SEZ registration
CENTRALIssued by · STPI / SEZ authority
When · On registration, then periodic returns
Software exporters claiming benefits
Softex filing
CENTRALIssued by · RBI via STPI
When · Per invoice
Software exported without physical shipment
DPIIT startup recognition
CENTRALIssued by · DPIIT
When · One-time, then compliance
Startups claiming exemptions
SOC 2 Type II
STANDARDIssued by · Independent auditor
When · Annual
Not law - required by enterprise customers
ISO 27001
STANDARDIssued by · Accredited certification body
When · 3-year cycle with surveillance
Not law - required by enterprise and EU customers
GDPR
STANDARDIssued by · EU supervisory authorities
When · Continuous
If you process data of people in the EU
HIPAA
STANDARDIssued by · US HHS
When · Continuous
If you touch US protected health information
This is indicative, not your map. Applicability turns on your turnover, headcount, premises, product, states of operation and customers. We build the actual list for your business - and it is almost never the list you expected.
Data protection obligations are covered separately under DPDP.
Our side
What we do.
- Build the complete map of central, state, municipal and contractual obligations for your specific business
- Determine applicability against your real turnover, headcount, premises, products and states
- Identify anything you are currently operating without
- Put every licence, renewal and periodic return on your compliance calendar alongside your MCA and GST dates
- Reassess the whole map whenever you open a location, enter a state, launch a product line, cross a headcount threshold or change what you sell
- Track amendments to the laws that apply to you and tell you when something changes
- Obtain licences and registrations on a quoted, one-off basis
- Manage renewals and periodic returns on a quoted basis
- Coordinate audits and certifications through empanelled specialists
- Respond to inspections, notices and sealing orders
If you miss it
Industry licences do not fine you quietly the way a late MCA form does. They stop you trading. A lapsed FSSAI licence means the premises can be sealed. An expired pollution consent means the unit can be shut. A missing trade licence means an inspector can close the shop the same afternoon. Central regulators are stricter still - operating an unregistered lending business or breaching CERT-In directions carries consequences well beyond a fee. The second cost is commercial. An expired licence surfaces in diligence, and a buyer or investor treats an unlicensed operation as an unpriceable risk.
FSS Act 2006 · Water Act 1974 · Air Act 1981 · Factories Act 1948 · IT Act Section 70B · municipal legislation varies by corporation
Process
How it runs.
- 01
We interview the business, not the entity
What you make, where you make it, who you sell to, which states you operate in, how many people, what your premises look like. Fifteen questions, most of which nobody has asked you before.
- 02
We build your map
Every central, state, municipal and contractual obligation that applies, with the issuing authority and the renewal cycle. You will usually find something you are operating without.
- 03
We track it forever
It goes on the same calendar as your MCA and GST dates. When you open a second location or cross a threshold, the map rebuilds itself and we tell you what just became applicable.
Questions founders ask
The visibility is - the map, the applicability, the calendar, the alerts and the reassessment are all in your monthly fee. What is not included is obtaining and renewing each licence, because that is genuinely one-off work with real cost that varies enormously. A trade licence and an NBFC registration are not the same job. We quote each one before we start, and you decide.
That is normal and not a criticism. A company secretary's mandate is the Companies Act and the MCA. Industry licensing sits with different authorities, in different departments, often at municipal level, with no central register. It falls between everyone's brief, which is precisely why it goes unwatched.
No, and we will never tell you it is. SOC 2, ISO 27001 and most certifications are contractual - your enterprise customers require them. We track them alongside statutory obligations because they fail the same way: a lapsed certification loses you a contract as surely as a lapsed licence closes a shop.
It multiplies the state and municipal layers, not the central one. Shops and Establishments, professional tax, labour welfare fund, trade licences and pollution consents are all per state or per premises. This is the single most common thing companies get wrong when they expand.
You probably are - most companies we onboard are. It is almost always fixable, usually with a late fee rather than a penalty, and it is far cheaper to find now than during diligence. The health check will tell you.
We maintain a curated rule base per state and per major corporation, updated weekly, and we work with local specialists where a corporation's process demands physical presence. Where we do not have depth in a city, we will say so rather than guess.
Related
Compliance you do not have to think about.
Tell us your CIN and what you are worried about. We will tell you exactly what applies to your company.
Every filing under this service is reviewed and signed by a practising Company Secretary or Chartered Accountant engaged on your account.
