Tools

Which security obligations actually apply

Four questions about your organisation, and the instruments that reach it: each one named, numbered, and dated.

Most of what a Sri Lankan company gets told about security law is sold to it. This page is the opposite exercise. It says which rules bind you, what evidence each one expects, and, where the honest answer is that nothing requires a penetration test, it says that instead.

Sri LankaRuns in your browserOrientation, not legal advice

The tool

Answer four questions

Nothing you select leaves this page. There is no backend behind it and no request is made. Your answers are written into the address bar instead, so the link you copy carries the result, and carries nothing else.

What is the organisation?

Pick the licence or listing it holds. If it holds more than one, pick the strictest.

Does it process personal data of people in Sri Lanka?

Customers, staff, or applicants. Where the company is registered does not matter here.

Does it take card payments?

Yes if cardholder data touches a system you run, including a page on your own domain that collects a card number before it redirects.

Is an enterprise customer asking for SOC 2 or ISO 27001?

The security questionnaire or the vendor review, not something you decided to pursue.

On these answers, nothing here requires you to commission an independent penetration test. That is a real answer, and we would rather give it than sell you one.

2
Instruments that reach you
0
That expect an independent test
0
Clause numbers we will cite
  1. Binding / Act of Parliament No test mandated: risk-based

    Personal Data Protection Act No. 9 of 2022

    Sri Lanka's data protection statute, overseen by the Data Protection Authority. It reaches controllers outside Sri Lanka that offer goods or services to people in Sri Lanka.

    Clause not cited Instrument cited, clause not. We have not verified section numbers against the gazetted Act, so we do not print them. The substance below we do stand behind.

    Requires
    Appropriate technical and organisational measures, proportionate to the risk, together with a data protection management programme and a route for notifying the Authority of a personal data breach. The Act does not mandate a penetration test. Anyone who tells you the PDPA requires one is selling you something.
    Evidence
    The written risk assessment showing why the measures you chose are appropriate, the management programme itself, your breach procedure, and your contracts with processors. A test is one way to evidence the word appropriate. It is not the requirement.
    Next step
    Start with the assessment and the record of it. Commission testing where that assessment says the risk warrants it, not to satisfy a clause that does not exist. How we handle data
  2. Guidance / Not binding No test mandated: risk-based

    Sri Lanka CERT|CC guidance

    Sri Lanka Computer Emergency Readiness Team, Coordination Centre. Guidance and recommendation, not an instrument that binds a private company.

    Clause not cited Cited as guidance, which is what it is. No clause, because nothing here is enforced against a private company.

    Requires
    Periodic security assessment, at least annually, is the recommended baseline. CERT|CC also published Web Application Security Guidelines for government organisations in 2022.
    Evidence
    Nothing is audited against this. It is a floor to argue from when no binding instrument reaches you, and a reasonable answer to a board that asks what good looks like locally.
    Next step
    Useful as a reference point in a risk paper. Do not let it be presented to you as a legal requirement, because it is not one.

What these answers do not create

  • The Personal Data Protection Act No. 9 of 2022 does not require a penetration test. It requires measures appropriate to the risk, and a record of why yours are appropriate.
  • No sector regulator, so no CBSL Direction reaches you. Being a technology company, or holding a lot of data, does not by itself create a testing obligation in Sri Lanka.
  • No card handling, so PCI DSS 11.4 does not reach you. Check the answer before you rely on it: a page on your own domain that collects a card number before redirecting is card handling.
  • No customer is asking for SOC 2 or ISO 27001, so neither reaches you. Neither is law anywhere. Both are things a customer or an auditor asks for, and both become urgent the week someone does.
  • Nothing on this page obliges you to commission an independent penetration test. Whatever you do next is a risk decision, not a compliance one, and it should be argued on those terms.
Permalinkhttps://ghosts.lk/tools/security-obligations?sector=other&pdpa=y&cards=n&ask=none
Sources

Every instrument this tool can cite

Nine instruments, listed whether or not your answers reach them. Where a clause is printed, we hold it. Where it is not, the line says so.

Found one of these out of date? Email ryan@ghosts.lk and we will correct it. Last reviewed 2026-08-29.

  1. 01

    Banking Act Directions No. 16 of 2021

    Technology Risk Management and Resilience, Central Bank of Sri Lanka, binding on licensed banks. Clause cited: s.5.8.3, the penetration-testing provision. Verify it against the gazetted Direction before it goes into a board paper.

  2. 02

    Finance Business Act Directions No. 01 of 2022

    Technology Risk Management and Resilience, Central Bank of Sri Lanka, for licensed finance companies under the Finance Business Act No. 42 of 2011. Instrument cited, clause not: we have not verified the section numbering.

  3. 03

    Payment and Settlement Systems Act No. 28 of 2005

    The statute under which the Central Bank authorises and supervises payment systems and payment service providers. Instrument cited, clause not: which technology Direction applies depends on the category of authorisation held.

  4. 04

    Colombo Stock Exchange Listing Rules

    The corporate governance rules, binding on listed entities. Instrument cited, clause not: we have not verified the rule numbering in the current edition. It is a board oversight and disclosure duty, not a testing mandate.

  5. 05

    Personal Data Protection Act No. 9 of 2022

    Sri Lanka's data protection statute, overseen by the Data Protection Authority. Instrument cited, clause not. It requires measures appropriate to the risk and a data protection management programme. It does not mandate a penetration test.

  1. 06

    PCI DSS requirement 11.4

    PCI Security Standards Council. Contractual, reaching you through your acquirer and the card brands rather than through statute. 11.4.3 (external application-layer testing) and 11.4.4 (correct and retest) cited; internal and segmentation testing sit under the same requirement.

  2. 07

    SOC 2 Trust Services Criteria, CC4.1

    AICPA criteria, applied by your auditor. No criterion names penetration testing; CC4.1 is where auditors file the test as evidence that controls are evaluated. Cited as the mapping it is.

  3. 08

    ISO/IEC 27001:2022, A.8.8 and A.8.29

    Management of technical vulnerabilities, and security testing in development and acceptance. The 2022 numbering: a customer quoting the 2013 Annex A is quoting different control numbers.

  4. 09

    Sri Lanka CERT|CC guidance

    Recommends periodic security assessment, at least annually, and published Web Application Security Guidelines for government organisations in 2022. Guidance, not an instrument that binds a private company.

Method and limits

·It reads four answers and nothing else. It does not know your architecture, your contracts, your data flows, or your regulator's current supervisory position.
·Where we hold a clause, the tool prints it. Where we do not, it prints the instrument and says the clause needs checking. We do not invent a section number to look precise.
·It runs entirely in your browser. There is no backend behind this page, no request is made, nothing is stored, and no account exists. Your answers travel only in your own address bar.
·It is orientation, not legal advice and not a compliance opinion. Take the result to counsel or to your supervisor before you rely on it.
·It is deliberately incomplete. Sector rules, contracts, and your own customers can all create duties this page never sees.

A tool that returns an obligation for every answer would be better marketing and worse information. This one returns nothing for the answers that deserve nothing, which is the only way the answers that do deserve something can be trusted.

This page is orientation. The decision is not.

If a row above turned out to be yours, the next conversation is about scope: which systems are critical, what an auditor or a supervisor will accept as evidence, and what can honestly be left alone. Fifteen minutes, no obligation, and we will tell you if you do not need us.

Ghost Scan: freePentest: $2,999 / LKR 600,000Regulated: quoted per scope