Introduction
In today's digital-first world, cybersecurity isn't optional—it's essential. If your organization operates in India, there's a good chance you've heard about CERT-In compliance. But what exactly does it mean, and why should you care? Let's break it down in plain terms.

What is CERT-In?
CERT-In is India's computer security team. It works under the Ministry of Electronics and Information Technology. CERT-In watches for cyber threats, warns the public about emerging attacks, and coordinates responses to incident reports. It also oversees security checks for government departments and critical infrastructure including banking, telecom, IT services, and energy companies.
What CERT-In Actually Does:
Incident Coordination
Leading response strategies and mitigating exposures in the event of national or corporate cyberattacks.
Security Advisories & Auditor Empanelment
Issuing guidance mandates and managing a vetted index of approved cybersecurity auditors.
CERT-In shapes how organizations in India approach security. When the agency releases new directives—such as the major Comprehensive Cyber Security Audit Policy Guidelines in July 2025—it updates security requirements across all regulated business sectors.
CERT-In Empanelled Organizations
To maintain high evaluation standards, CERT-In publishes a vetted registry of empanelled information security auditing organizations. These firms demonstrate deep technical skill, adherence to MeitY guidelines, and strict confidentiality controls.
Empanelment Requirements
| Requirement | What's Expected |
|---|---|
| Experience | Proven track record running audits across diverse technical environments. |
| Methodologies | Ability to audit using ISO/IEC, NIST, OWASP, and MeitY frameworks. |
| Team Qualifications | A minimum of 5 full-time personnel, with at least 2 holding certified Lead Assessor roles. |
| Practical Skill Tests | Scoring 90% or higher in CERT-In's comprehensive offline and online VAPT practical evaluations. |
| Background Checks | Thorough verification for the organization and all participating assessors. |
Important Compliance Rule: Auditors cannot appoint interns, freelancers, moonlighters, or external consultants to perform security checks. Assessments must be executed solely by the empanelled firm's full-time staff.
Who Requires Empanelled Auditing Services?
Many organizations operating in or doing business with India are required to utilize CERT-In empanelled auditors:
- Banks, payment gateways, NBFCs, and platforms under RBI directives.
- Stock exchanges, trading firms, and brokers regulated by SEBI.
- Insurance companies and corporate agents under IRDAI mandates.
- UIDAI partners handling Aadhaar storage or API authentication.
- Critical national infrastructure segments (health, transport, defence, telecommunications, energy).
- Government agencies, departments, and vendors supplying public sectors.
CERT-In Security Audit Requirements
The 2025 Comprehensive Cyber Security Audit Guidelines brought major modifications to how security audits must be planned, rated, and verified:
Mandatory Annual Frequency
Audits must be performed at least once a year. Major alterations to critical hardware or application paths trigger fresh assessments.
Data Residency
All auditee logs, data mappings, and testing results must reside only on servers located in India. Offshoring is prohibited unless authorized.
Core Principles of Auditing
- Risk-Based Focus: Customizing the audit scope to reflect the organization's specific threat landscape rather than using a generic compliance checklist.
- Vulnerability Classification: Categorizing weaknesses using CVSS for severity and EPSS (Exploit Prediction Scoring System) for exploit probability.
- Independence: Auditor fees cannot be linked to the outcome of the evaluation. Maker-checker reviews ensure reports are validated objectively.
- Executive Engagement: Entry and exit audit briefings must involve the board or executive management to establish corporate responsibility.
Types of Certificates Issued
| Certificate | Purpose |
|---|---|
| CERT-In VAPT Certificate | Confirms that vulnerability assessment and penetration testing have been conducted by an empanelled auditor. |
| Safe to Host Certificate | Validates that public web/mobile applications contain no critical open vulnerabilities and are secure to host. |
| Compliance Audit Certificate | Confirms system alignment with regulatory frameworks like RBI IS Guidelines or SEBI CSCRF. |
The CERT-In Certification Process
CERT-In does not issue certificates directly to organizations. Instead, compliance validation is confirmed via security audit reports and certificates issued by MeitY-listed empanelled auditors.
Step-by-Step Methodology
Step 1: Scoping
Define the boundaries of the audit, specifying target web applications, APIs, network scopes, and databases.
Step 2: Auditor Engagement
Select a MeitY-listed auditor. Verify their active status on MeitY's official registry page.
Step 3: Security Assessment
The auditor performs vulnerability assessment (VA) and manual penetration testing (PT) to identify system flaws.
Step 4: Remediation Plan
Auditors issue a draft report detailing findings. Your engineering and IT groups patch the reported vulnerabilities.
Step 5: Validation Retesting
The auditor executes validation re-scans to verify that all flagged flaws have been resolved.
Step 6: Certification
The empanelled auditor issues the Safe to Host or VAPT certificate. The final report is uploaded to MeitY's portal within 5 days.
Benefits of CERT-In Compliance
Adhering to MeitY audit requirements helps organizations establish their security posture and capture key operational benefits:
Avoid Fines
Protect against penalties (up to ₹1 crore) under the IT Act for delays in incident reporting or log retention.
Regulatory Authorization
Verify credentials required to secure tenders, partner with banks, or interface with MeitY agencies.
Real Risk Mitigation
Identify security flaws, optimize access parameters, and prepare controls to detect compromises early.
