vista infosec white

Audit & compliance since 2004

21 years. Seven offices. Auditors in your region.

Licensed and accredited where it matters: CERT-In empanelled in India, CSRO-licensed for penetration testing in Singapore, CREST accredited for EU threat-led testing. PCI QSA-led assessments delivered by full-time VISTA auditors in your regulatory environment, your language and your time zone.

EU · From 11 Sep 2026

Cyber Resilience Act  -vulnerability reporting obligations begin

EU · In force since 2 Aug 2026

AI Act Article 50 transparency obligations apply

Global · In force

PCI DSS v4.0 — future-dated requirements now mandatory

UK · Sep 2026

Cyber Security and Resilience Bill at Lords Committee — managed service providers newly in scope

Information Security & Compliance Audits | VISTA InfoSec
21
Years
7
Offices worldwide
500+
Clients assessed
16
Frameworks covered
PCI QSAPCI SSFACREST Accredited CERT-In EmpanelledCSRO Pen Testing Licence — SingaporeISO 27001 Certified OurselvesEU Entity — Zulon Audits OÜ
Who you work with

You will know your auditor by name

A named contact in your region, and a credentialled assessor on your engagement — not a rotating pool.

NS

Narendra Sahoo

Founder & Managing Director · Leads India & APAC · PCI QSA, PCI SSFA, CISSP, CISA, CRISC, ISO 27001 LA

Founded VISTA InfoSec in 2004. Twenty-one years leading payment security and compliance programmes across banking, telecoms and fintech. Leads engagements across India and Asia Pacific, including CERT-In empanelled work in India and CSRO-licensed penetration testing through VISTA InfoSec Pte. Ltd. in Singapore.

Mumbai · Pune · Singapore · Request an introduction
AS

Avinash Sharma

Director of Operations, Europe & UK · Based in Germany · Former PCI QSA

Leads engagements across the European Union and the United Kingdom from VISTA’s German base, working in German and English. EU work covers NIS2, DORA, TISAX, GDPR, the AI Act and the CRA, contracted through Zulon Audits OÜ in Tallinn. UK work covers UK GDPR, the NIS Regulations and FCA operational resilience, contracted through VISTA InfoSec Ltd in London.

Germany · +49 172 7223867 · UK +44 208 133 3131 · Deutsch & English
NK

Nathan Khanna

Head of Sales, North America · Based in New York · ISO 27001 Lead Auditor, MBA (IT)

Your first point of contact in the United States. Scopes SOC 2, PCI DSS, HIPAA and ISO 27001 engagements for North American clients through VISTA InfoSec LLC, and brings in the assessment team that will run your audit.

New York · +1 (646) 627-1823 · ET hours
Where we are

Seven offices, four regional entities

You contract with the entity in your region, under the law of your region.

Mumbai
VISTA InfoSec
India & APAC hub
Pune
VISTA InfoSec
New York
VISTA InfoSec LLC
North America hub
London
VISTA InfoSec Ltd
UK hub
Singapore
VISTA InfoSec Pte. Ltd. (UEN 201930384Z)
CSRO Penetration Testing Licence CS/PTS/C-2023-0460R
Dubai
VISTA InfoSec
Middle East hub
Europe
Zulon Audits OÜ (17480429) - Estonia
Europe hub
Your region
Remote delivery worldwide
VISTA InfoSec operates as a group of regional entities rather than from a single head office. European engagements are contracted and delivered through Zulon Audits OÜ, registry code 17480429, Narva mnt 5, 10117 Tallinn, Estonia, with EU-region data processing available where evidence must remain within the Union. UK engagements contract through VISTA InfoSec Ltd, Office 7318, 182–184 High Street North, East Ham, London E6 2JA. North American engagements contract through VISTA InfoSec LLC, New York. Singapore penetration testing is delivered by VISTA InfoSec Pte. Ltd. (UEN 201930384Z) under CSRO licence CS/PTS/C-2023-0460R.
How we work

Built to remove the reasons audits stall

Full-time VISTA auditors

Your audit is delivered by full-time VISTA auditors, accountable directly to you.

100% vendor neutral

We earn nothing from hardware or software sales. No conflict between our advice and our revenue.

EU

EU-region data processing

Available where your regulator or your customers require evidence to stay inside the Union.

Timelines with an SLA

Deadlines committed in writing. If we miss one, you receive 10% off the engagement fee.

§

Licensed in your jurisdiction

CERT-In empanelled in India. Penetration testing in Singapore delivered by VISTA InfoSec Pte. Ltd. under CSRO licence CS/PTS/C-2023-0460R. CREST accredited for EU threat-led testing.

Expert Auditors. Faster Certification.