Empanelment & Routes
Building a Compliance Calendar for Gov Vendors
· 10 minute read
Most vendor incidents are missed dates. Put every paper that can lapse on one calendar with an owner and a 30-day alarm. This is the template.
In a 14-person firm in Ahmedabad the DSC token lived in a drawer, the ISO surveillance was in a consultant's inbox, the NICSI-adjacent letter ended on a Saturday, and GST had a notice nobody had opened. They discovered all four in the same week they tried to bid a PSU panel. They missed it. The product was fine. The calendar did not exist.
A compliance calendar is not a legal opinion. It is a list of dates that can stop you bidding or stop you delivering, each with an owner and a lead time. Government work multiplies those dates: identity papers, tax, labour, security certificates, portal tokens, panel letters, and the statutory clocks that sit on anyone who holds ICT logs or personal data.
This template is sized for a vendor who sells on-prem agents to Indian institutions. Steal it. Put it in a shared sheet, not in a founder's head. Review it on the first working Monday of each month. That meeting should last twenty minutes and feel boring. Boring is the design goal.
Not legal, tax or secretarial advice. Your CA, CS and counsel add rows. We refuse to freeze every statutory due date as if they never move. Confirm live due dates each year.
The rows that belong on the first sheet
Identity and portals: DSC / e-token expiry, portal logins (GeM, CPPP, state e-procurement), authorised-signatory list versus MCA, board resolutions that name a living person, Udyam review, DPIIT recognition review, GeM seller profile match.
Tax and corporate: GST returns and notices, TDS, ITR, company annual filings, registered-office proof, any state professional-tax or shops-and-establishment the delivery states care about. Your CA owns the statutory dates. The calendar only ensures they are visible to the bid lead.
Security and quality: ISO 27001 certificate end and surveillance, any CMMI, any STQC/GIGW obligation you took in a SOW, internal ISMS review, penetration-test date if a buyer demanded a cycle.
Empanelment and contracts: every panel letter end date, renewal window, PBG end date, insurance, work-order end, SLA review, subcontract approval renewals.
Operations that are really compliance: CERT-In log retention (rolling 180 days is the well-known direction — confirm the live PDF), incident-contact tree, isolation-drill date for each air-gapped site, deletion drills for pilot data, DPDP milestone watch as commencement phases arrive.
| Item | Typical rhythm | Lead time to start work | Owner | What fails if missed |
|---|---|---|---|---|
| DSC / token | 1–2 years | 45 days | Authorised signatory + deputy | Cannot bid or cannot sign a renewal |
| Udyam hygiene login | Before each material bid + quarterly | 7 days | COO | MSE preference claim dies |
| DPIIT text vs website | On product change + annual | 14 days | Founder | Tender contradiction |
| ISO surveillance / recert | Annual / 3-year cycle | 90 days | ISMS owner | PQ fail; mid-term delist |
| Panel letter | As the RFE said (often 1–3 years) | 90 days | Bid lead | Silent drop from the list |
| PBG / insurance | As the work order said | 30 days | Finance | Invoice hold; default |
| CERT-In log proof drill | Quarterly | 7 days | Security lead | You discover on incident day that logs rotated away |
| Isolation drill (air-gap sites) | Semi-annual | 21 days | On-prem lead | The claim is now folklore |
| Pilot-data deletion audit | 30 days after each pilot + annual | 14 days | DPO-like owner | An eval tenant full of names |
| GST / ITR (confirm live dates) | Statutory | Per CA | CA + finance | Notices; bid affidavits go false |
How to run it so it survives leave
One sheet, two people who can edit, a monthly 20-minute stand-up, and a rule that a row without an owner is a founder-owned row. Tools do not matter. A dated Google Sheet beats a beautiful GRC platform nobody opens.
Every row has: item, instrument number, start, end, lead time, next action date (end minus lead time), owner, deputy, link to the folder, status (green / amber / red), last evidence date.
Amber means the next action date has arrived. Red means the end date is inside 14 days or already missed. Red items open the Monday meeting. No status stories about culture.
When someone leaves, the Monday meeting reassigns their rows before you revoke their email. The opposite order is how DSC tokens die in drawers.
- Create the sheet from the table above.
- Import every live panel letter and certificate this week. No 'we will add later'.
- Name deputies. If you cannot name a deputy for DSC, you are one scooter accident away from a missed bid.
- Put next-action dates in a shared calendar with the owner tagged.
- Hold Monday standup. Close reds. Screenshot the sheet into the board pack quarterly.
Statutory rows you must not freeze wrongly
DPDP and the 2025 Rules have a phased commencement story. Put a row called 'DPDP watch' that forces a counsel or DPO-like read each quarter against MeitY and the Act, not a one-time blog date in your head. When a phase that affects your processor contracts arrives, that quarter's work is updating every government SOW, not updating the sheet colour.
CERT-In's 28 April 2022 directions are still the logging and incident vocabulary most files use. Confirm the live PDF and FAQs. Your row is not 'we are compliant'. Your row is 'we proved this quarter that 180-day logs still exist and the incident tree still rings a human'.
Labour, POSH, and state shops acts are not in this AI article. They still belong on the same sheet if you have employees in that state. Ask your CS. A government buyer who asks for a labour affidavit will not wait while you discover the law.
What not to put on this sheet
Do not put sales hunches. This is not a CRM. A 'likely RFE in Odisha' is a pipeline object.
Do not put every employee's passport expiry unless they travel for site visits. If they do, then yes, put it. Site visits fail on expired ID.
Do not put legal theories. Put instruments. 'We should think about DPDP' is a meeting. 'Processor addendum version 3 sent to all live SOWs' is a row.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
We are twelve people; this is enterprise theatre.
Twelve people miss more dates, not fewer, because one person holds five tokens. The sheet is how you stay small without being fragile.
Our CA already has a calendar.
Good. Import their dates. They will not track your NICSI letter or your pcap drill. This sheet is the union.
A GRC tool will solve it.
Buy a tool after the Monday meeting exists. Tools without the meeting become another expired login.
Some dates are confidential.
Then restrict the sheet. Do not remove the dates. A secret expiry is still an expiry.
Build the sheet this week
If you do nothing else from this article, do the import.
- Monday: create the sheet. Columns as above.
- Tuesday: import identity, tax (with CA), and security certificates.
- Wednesday: import every panel, PBG, insurance, and work order.
- Thursday: add CERT-In, isolation, deletion, DPDP-watch rows.
- Friday: name deputies. Put next-action dates in the shared calendar. Hold the first 20-minute standup next Monday.
How this shows up in the file
Policy sentence: 'No government bid is opened unless the calendar has been seen that week and no red item would make an affidavit false.' Founder signs. That one sentence prevents most heroic disasters.
Store the monthly screenshots in 00-calendar of the document folder structure. Auditors like history. So will your next bid manager.
This article is informational field guidance for Indian public institutions and their vendors, not legal, tax, procurement or engineering advice. Confirm the live circular, RFE, GCC, GeM term, state G.O. and your counsel before you file anything. Incentives, ceilings and portal screens change.
How to run the route without confusing the letterhead
“Building a Compliance Calendar for Gov Vendors” is a route problem. A P5 Startup/Vendor should know which legal person they are talking to — NIC, NICSI, a state IT corporation, iDEX, or a GeM buyer — and which paper that person can actually issue. Searching “government vendor compliance calendar” is not the same as being on a panel that can receive a work order.
Most vendor incidents are missed dates. Put every paper that can lapse on one calendar with an owner and a 30-day alarm. This is the template. Empanelment letters are not purchase orders. DPIIT recognition is not a technical score. Reserved startup seats, if a notice writes them, are local to that notice. IndiaAI compute empanelment is not NICSI application-software empanelment.
Keep a warm evidence pack: CIN, GST, DPIIT, Udyam, financials, work-completion letters, architecture one-pager, DPA draft. Renewals are lost by people who treat the panel as a trophy.
- Screenshot the live RFE paragraph you are relying on, dated.
- Match the bidding entity name across every certificate.
- Do not mix iDEX, TDF, NICSI and GeM clocks on one tracker cell.
- Record the validity end date 90 days before it dies.
Close this loop before the next CAB
Put “Building a Compliance Calendar for Gov Vendors” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P5 Startup/Vendor, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “government vendor compliance calendar” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Is this a legally mandated register?
- The sheet itself is not a statutory form. Some rows on it correspond to statutory or contractual duties. The sheet is how you remember them. Counsel may add true statutory registers separately.
- Who should own the calendar in a startup?
- A COO-like person or the bid lead, with the founder present monthly. Security rows need a security deputy. Tax rows need the CA. Do not make the only ML engineer the owner.
- How far ahead should we look?
- Eighteen months is enough to see ISO and panel ends. Statutory tax dates are an annual reload with your CA.
- Do we put employee background-check renewals here?
- If a buyer SOW requires a cycle, yes. Otherwise keep them in HR. Link out.
- What if a date is wrong?
- The Monday meeting exists to catch that. A wrong date that is visible is still better than a right date in a drawer.