Logo

About Us

Industries

Taxation & Compliance

Statutory Compliance for Indian IT Companies: The Checklist

AC

Aditya Chokhra

10 mins
Blog Cover

TL;DR — IT company compliance in one minute
• An IT company in India carries four compliance layers: company law (ROC), tax (PAN, TAN, TDS, GST), payroll-linked (EPF, ESI, PT, PoSH), and now data protection (the DPDP Act).
• Most rules trigger by headcount, turnover or state — ESI at 10 employees, PoSH at 10, EPF at 20, GST at ₹20 lakh turnover for services.
• ROC filings (AOC-4 and MGT-7) and DIR-3 KYC are annual and non-negotiable — late fees run at ₹100 per day with no ceiling.
• The DPDP Rules 2025 are now final. Full compliance is due by mid-2027, and a security lapse that leaks personal data can cost up to ₹250 crore.
• Compliance is not a one-time task. Build a calendar, assign owners, and treat it as due-diligence readiness for your next raise.

The four pillars of statutory compliance for Indian IT companies — company law, tax, payroll and data privacy, in EaseUp navy and green

What statutory compliance means for an IT company

If you run an IT or SaaS company in India, statutory compliance is not just a legal checklist. It decides whether you can hire cleanly, invoice clients, raise funding and pass due diligence without disruption.

The trouble is timing. Most founders only think about compliance after a notice lands, a deadline slips, or an investor asks for documents. By then it is a fire drill. The smarter path is to know what applies at incorporation, what becomes recurring, and what triggers as you grow.

Broadly, an IT company juggles four layers: company-law compliance, tax compliance, payroll-linked compliance and, since 2023, data-protection compliance. A steady accounting and compliance function keeps all four in sync instead of scrambling one at a time.

bulb emoji Founder tip: Treat compliance as due-diligence readiness, not paperwork. Every clean filing you make today is one less red flag in your next fundraise or acquisition data room.

The compliance stack at a glance

Here is the core recurring stack most Indian IT companies manage, and what usually triggers each one.

Compliance area

Usually triggers at

Why it matters

PAN

Incorporation

Tax identity for banking, invoicing and filings

TAN / TDS

First salary or vendor payment

Deduct, deposit and report tax at source

GST

₹20 lakh service turnover

Compliant invoicing and input tax credit

ROC filings

Every financial year

Keeps the company in good legal standing

Professional Tax

First salaried employee (state-based)

Employer payroll compliance

EPF

20 employees

Employee retirement fund contributions

ESI

10 employees (wages up to ₹21,000)

Employee medical insurance cover

PoSH

10 employees

Workplace harassment prevention committee

DPDP Act

You process personal data

Lawful, secure handling of user data

PAN and TAN: your company’s tax identity

A PAN (Permanent Account Number) is one of the first essentials. It links the company to its tax profile and runs through banking, vendor onboarding and every filing you make.

A TAN (Tax Deduction Account Number) becomes relevant the moment you must deduct tax at source — usually your first payroll run. Both are foundational, so get them in place before you start billing or paying anyone. You can apply and verify these through the Income Tax Department portal.

TDS: the monthly discipline that trips founders

TDS is not a one-off entry. It is a monthly rhythm: deduct, deposit, file and reconcile. For IT companies it starts with salaries and quickly extends to contractor fees, consultant payments and certain vendor payouts.

Step

What the company does

1

Deduct tax where applicable on salary or vendor payments

2

Deposit the tax by the 7th of the following month

3

File quarterly TDS statements (Form 24Q / 26Q)

4

Issue TDS certificates and reconcile in Form 26AS

5

Correct mismatches quickly before they become notices

Where IT companies slip: paying consultants without checking TDS applicability, missing deductions on founder remuneration, weak vendor PAN capture, and late deposits after deduction. These small gaps are exactly what a clean payroll management process is built to prevent.

warning emoji Watch out: Deducting TDS but depositing it late attracts 1.5% interest per month, and the expense can be disallowed. Return mismatches are the most common reason IT companies receive tax notices — reconcile every quarter, not once a year.

GST for IT and SaaS companies

GST is one of the most operationally important compliances for an IT business because it touches billing, contracts, cash flow and customer experience. For service companies, registration commonly becomes relevant once you cross ₹20 lakh aggregate turnover, though special situations and inter-state rules can change that.

Why it matters more than founders expect: B2B buyers expect compliant GST invoices, broken invoicing hurts once client volume grows, and SaaS, support, implementation and subscription models each raise transaction-specific tax questions.

:info: Export of services: Software exports can qualify as zero-rated supplies under GST, letting you claim refunds or supply under a LUT without charging tax. The conditions are strict — confirm your invoicing meets them on the official GST portal.

ROC annual filings and board governance

Every company registered under the Companies Act, 2013 must file annually with the Registrar of Companies — even in a year with zero revenue. These are the filings you cannot skip.

Filing

What it is

Typical due date (FY 2025-26)

AOC-4

Financial statements

Within 30 days of AGM (by 30 Oct 2026)

MGT-7

Annual return

Within 60 days of AGM (by 29 Nov 2026)

DIR-3 KYC

Director KYC

By 30 September 2026

AGM

Annual General Meeting

By 30 September 2026

Beyond filings, keep your board meetings minuted and statutory registers current — this is the paperwork investors and auditors ask for first. The forms and due dates live on the Ministry of Corporate Affairs portal. Late filing costs ₹100 per day, per form, with no upper limit.

Payroll-linked compliance: EPF, ESI and PT

As you hire, a set of payroll-linked registrations switch on automatically. Miss the trigger and you inherit back-dated dues plus interest.

Payroll compliance triggers for IT companies: professional tax from the first employee, ESI and PoSH at ten employees, EPF at twenty employees
  • Professional Tax (PT): a state levy with no headcount floor — it usually applies from your first salaried employee, and rules vary by state.

  • ESI: mandatory once you reach 10 employees, covering staff who earn up to ₹21,000 a month in gross wages.

  • EPF: mandatory at 20 employees; smaller teams can opt in voluntarily. Deposits are due by the 15th of the following month.

  • PoSH: at 10 employees you must form an Internal Committee under the PoSH Act and file an annual report.

You can register and manage provident-fund contributions on the EPFO employer portal. Getting these thresholds right is core to clean payroll management.

bulb emoji Founder tip: Map every threshold to a headcount trigger in your HR system now. The day you make your 10th and 20th hire should auto-flag ESI, PoSH and EPF — not surprise you six months later during an audit.

Shops and Establishments and state registrations

Most states require an office-based business to register under the local Shops and Establishments Act soon after setup. It governs working hours, leave and basic employment conditions, and it is state-specific — a Bengaluru office and a Pune office follow different state rules.

If you operate across multiple states, each location can carry its own PT, Shops and Establishments, and labour registrations. Multi-state growth is where compliance complexity quietly multiplies, so plan registrations ahead of each new office.

The DPDP Act: data-privacy compliance for IT

For IT companies, data protection is now a statutory duty. The Digital Personal Data Protection (DPDP) Act, 2023, with its final Rules notified in 2025, treats your company as a Data Fiduciary — legally accountable for how you collect, store and process personal data, even when a vendor does the processing.

Three obligations matter most for a growing IT firm:

  1. Itemised consent — blanket consent forms are out. Ask separately for each use of data, so a user can say yes to one and no to another.

  2. 72-hour breach reporting — if you lose user data, notify the Data Protection Board and affected users without delay, with a detailed report inside 72 hours.

  3. Data-principal rights — users can access, correct, nominate and request deletion of their data, usually within about 30 days.

The stakes are real: a security failure that leads to a personal-data breach can attract a penalty of up to ₹250 crore, and failing to report a breach up to ₹200 crore. You can read the Act and rules on the MeitY DPDP page.

warning emoji Watch out: DPDP liability follows you to your vendors. If your cloud host or analytics tool leaks data, you are still the accountable Data Fiduciary. Update processor contracts with security and breach-reporting clauses before mid-2027.

Cybersecurity frameworks: ISO 27001 vs NIST

Laws like the DPDP Act say you must be "secure" but do not name the tools. Frameworks fill that gap — they give you a documented, auditable way to prove security. The two you will hear about most are ISO 27001 and the NIST Cybersecurity Framework.

Comparison of ISO 27001 and the NIST Cybersecurity Framework for IT companies choosing a security standard

Feature

ISO 27001

NIST CSF 2.0

Primary focus

Process-driven — how you manage security via policies

Outcome-driven — achieving specific security results

Best for

Global firms needing a certification for B2B sales

US-facing or government-linked firms (free to use)

Core structure

Clauses 4-10 plus Annex A controls

Six functions: Govern, Identify, Protect, Detect, Respond, Recover

On top of a framework, regulators increasingly expect a Zero Trust posture — never trust, always verify, with least-privilege access. It limits the damage if a password is stolen and demonstrates you did more than build a weak perimeter.

How compliance grows with your company

Compliance load scales with headcount, turnover and geography. Knowing what comes next helps you staff and budget for it.

Stage

Main compliance priority

0-5 employees

Incorporation, PAN, TAN, GST applicability, basic governance

5-20 employees

Payroll controls, PT and Shops registrations, recurring filings

20+ employees

EPF, PoSH committee, tighter payroll, audit readiness

Multi-state / export

State PT variations, cross-border GST, DPDP maturity

Common compliance mistakes IT companies make

  • Reacting to notices instead of running a calendar — the deadline always wins.

  • Ignoring payroll triggers and inheriting back-dated EPF or ESI dues with interest.

  • Treating TDS casually, then facing return mismatches and disallowed expenses.

  • Skipping ROC filings in a dormant or pre-revenue year — the ₹100/day fee still runs.

  • Postponing DPDP work until an investor or enterprise client demands it.

An annual financial audit is a good moment to catch these gaps before they surface in someone else’s data room.

Building a compliance calendar (and when to get help)

The fix for most of the above is unglamorous: a shared compliance calendar with owners, due dates and reminders for every filing — monthly TDS and GST, quarterly returns, and annual ROC and DIR-3 KYC. Assign each item to a person, not a vague "finance team".

As your headcount, turnover and data footprint grow, the load crosses tax, law, HR and security at once. That is the point to bring in expert help so nothing slips through the cracks.

Get a Free Compliance Health Check

Frequently asked questions

What statutory compliances does an IT company in India need?

An Indian IT company typically manages four layers: company law (ROC filings such as AOC-4, MGT-7 and DIR-3 KYC), tax (PAN, TAN, TDS and GST), payroll-linked compliance (EPF, ESI, professional tax and PoSH) and data protection under the DPDP Act. Which items apply depends on your headcount, turnover and state of operation.

At what employee count do EPF, ESI and PoSH apply?

ESI applies once you reach 10 employees, covering staff earning up to Rs 21,000 a month. The PoSH Act requires an Internal Committee at 10 employees. EPF becomes mandatory at 20 employees, though smaller teams can enrol voluntarily. Professional tax has no headcount floor and usually applies from your first salaried employee, depending on the state.

When are ROC annual filings due for an IT company?

For FY 2025-26, the AGM must be held by 30 September 2026. AOC-4 (financial statements) is due within 30 days of the AGM and MGT-7 (annual return) within 60 days. DIR-3 KYC for directors is due by 30 September 2026. Late filing costs Rs 100 per day, per form, with no maximum limit — even for a dormant company.

Does the DPDP Act apply to my IT company?

Yes, if you process the personal data of individuals in India, you are a Data Fiduciary under the DPDP Act, 2023. You must obtain itemised consent, report data breaches to the Data Protection Board within 72 hours, and honour data-principal rights. Penalties reach up to Rs 250 crore for a security lapse that causes a breach, with full compliance expected by mid-2027.

When is GST registration mandatory for an IT or SaaS company?

For service businesses, GST registration is generally required once aggregate turnover crosses Rs 20 lakh. Inter-state supply, certain notified categories and specific business models can make registration necessary earlier. Software exports can qualify as zero-rated supplies, allowing you to supply under a LUT or claim refunds if invoicing conditions are met.


This guide is for general information only and does not constitute tax, legal or financial advice. Statutory thresholds, forms and deadlines change — confirm the current position with a qualified professional before you act.

Talk to an EaseUp Compliance Expert

Profile photo of Aditya Chokhra

Aditya Chokhra

@adityachokhra
Aditya Chokhra is a Chartered Accountant and Registered Valuer with 15+ years of experience in valuation and deal advisory. He empowers startups and SMEs with data-backed financial…
Curated by the Editorial Team
footer-logo

Your trusted partner for all your Financial needs.

iconiconiconiconicon

Finance Management

GST Filling

Bookkeeping

Accounting and Compliances

Virtual CFO

MIS Management

Vendor Management

Monthly Accounting

Payroll Management

Financial Audits

Due Diligence

Business Valuation

Strategic Services

Mergers and Acquisition

Fundraise Preparation

Prepare for Business Loan

Expansion Planning

Personal Finance Management

Wealth Management

International Trade

GST Notice Support

Income Tax Notice Support

TDS Notice Support

Contact Us

+91-9826266300

contact@easeupnow.com

Book a Free 30-Min Consultation

Indore

Mumbai

Ahmedabad

Pune

Gurgaon

Bhilwara

Surat

Copyright © 2026

Privacy Policy

Finance Consulting Website by The Internet Folks