Tools
Which security obligations actually apply
Four questions about your organisation, and the instruments that reach it: each one named, numbered, and dated.
Most of what a Sri Lankan company gets told about security law is sold to it. This page is the opposite exercise. It says which rules bind you, what evidence each one expects, and, where the honest answer is that nothing requires a penetration test, it says that instead.
Answer four questions
Nothing you select leaves this page. There is no backend behind it and no request is made. Your answers are written into the address bar instead, so the link you copy carries the result, and carries nothing else.
On these answers, nothing here requires you to commission an independent penetration test. That is a real answer, and we would rather give it than sell you one.
Binding / Act of Parliament No test mandated: risk-based
Personal Data Protection Act No. 9 of 2022
Sri Lanka's data protection statute, overseen by the Data Protection Authority. It reaches controllers outside Sri Lanka that offer goods or services to people in Sri Lanka.
Clause not cited Instrument cited, clause not. We have not verified section numbers against the gazetted Act, so we do not print them. The substance below we do stand behind.
- Requires
- Appropriate technical and organisational measures, proportionate to the risk, together with a data protection management programme and a route for notifying the Authority of a personal data breach. The Act does not mandate a penetration test. Anyone who tells you the PDPA requires one is selling you something.
- Evidence
- The written risk assessment showing why the measures you chose are appropriate, the management programme itself, your breach procedure, and your contracts with processors. A test is one way to evidence the word appropriate. It is not the requirement.
- Next step
- Start with the assessment and the record of it. Commission testing where that assessment says the risk warrants it, not to satisfy a clause that does not exist. How we handle data
Guidance / Not binding No test mandated: risk-based
Sri Lanka CERT|CC guidance
Sri Lanka Computer Emergency Readiness Team, Coordination Centre. Guidance and recommendation, not an instrument that binds a private company.
Clause not cited Cited as guidance, which is what it is. No clause, because nothing here is enforced against a private company.
- Requires
- Periodic security assessment, at least annually, is the recommended baseline. CERT|CC also published Web Application Security Guidelines for government organisations in 2022.
- Evidence
- Nothing is audited against this. It is a floor to argue from when no binding instrument reaches you, and a reasonable answer to a board that asks what good looks like locally.
- Next step
- Useful as a reference point in a risk paper. Do not let it be presented to you as a legal requirement, because it is not one.
What these answers do not create
- The Personal Data Protection Act No. 9 of 2022 does not require a penetration test. It requires measures appropriate to the risk, and a record of why yours are appropriate.
- No sector regulator, so no CBSL Direction reaches you. Being a technology company, or holding a lot of data, does not by itself create a testing obligation in Sri Lanka.
- No card handling, so PCI DSS 11.4 does not reach you. Check the answer before you rely on it: a page on your own domain that collects a card number before redirecting is card handling.
- No customer is asking for SOC 2 or ISO 27001, so neither reaches you. Neither is law anywhere. Both are things a customer or an auditor asks for, and both become urgent the week someone does.
- Nothing on this page obliges you to commission an independent penetration test. Whatever you do next is a risk decision, not a compliance one, and it should be argued on those terms.
This is orientation, not legal advice, and not a compliance opinion. It reads four answers and nothing else: it does not know your architecture, your contracts, or your regulator’s current supervisory position. Take it to counsel or to your supervisor before you rely on it. Nothing you selected left this browser. Talk to an engineer or email ryan@ghosts.lk.
Every instrument this tool can cite
Nine instruments, listed whether or not your answers reach them. Where a clause is printed, we hold it. Where it is not, the line says so.
Found one of these out of date? Email ryan@ghosts.lk and we will correct it. Last reviewed 2026-08-29.
- 01
Banking Act Directions No. 16 of 2021
Technology Risk Management and Resilience, Central Bank of Sri Lanka, binding on licensed banks. Clause cited: s.5.8.3, the penetration-testing provision. Verify it against the gazetted Direction before it goes into a board paper.
- 02
Finance Business Act Directions No. 01 of 2022
Technology Risk Management and Resilience, Central Bank of Sri Lanka, for licensed finance companies under the Finance Business Act No. 42 of 2011. Instrument cited, clause not: we have not verified the section numbering.
- 03
Payment and Settlement Systems Act No. 28 of 2005
The statute under which the Central Bank authorises and supervises payment systems and payment service providers. Instrument cited, clause not: which technology Direction applies depends on the category of authorisation held.
- 04
Colombo Stock Exchange Listing Rules
The corporate governance rules, binding on listed entities. Instrument cited, clause not: we have not verified the rule numbering in the current edition. It is a board oversight and disclosure duty, not a testing mandate.
- 05
Personal Data Protection Act No. 9 of 2022
Sri Lanka's data protection statute, overseen by the Data Protection Authority. Instrument cited, clause not. It requires measures appropriate to the risk and a data protection management programme. It does not mandate a penetration test.
- 06
PCI DSS requirement 11.4
PCI Security Standards Council. Contractual, reaching you through your acquirer and the card brands rather than through statute. 11.4.3 (external application-layer testing) and 11.4.4 (correct and retest) cited; internal and segmentation testing sit under the same requirement.
- 07
SOC 2 Trust Services Criteria, CC4.1
AICPA criteria, applied by your auditor. No criterion names penetration testing; CC4.1 is where auditors file the test as evidence that controls are evaluated. Cited as the mapping it is.
- 08
ISO/IEC 27001:2022, A.8.8 and A.8.29
Management of technical vulnerabilities, and security testing in development and acceptance. The 2022 numbering: a customer quoting the 2013 Annex A is quoting different control numbers.
- 09
Sri Lanka CERT|CC guidance
Recommends periodic security assessment, at least annually, and published Web Application Security Guidelines for government organisations in 2022. Guidance, not an instrument that binds a private company.
This page is orientation. The decision is not.
If a row above turned out to be yours, the next conversation is about scope: which systems are critical, what an auditor or a supervisor will accept as evidence, and what can honestly be left alone. Fifteen minutes, no obligation, and we will tell you if you do not need us.
