Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
Compliance

A CERT-In Security Audit Checklist for SaaS Companies

April 28, 2026·CyVigilant Security Team
ComplianceCyVigilant

SaaS companies operating in India — particularly those serving BFSI, healthcare, or government clients — increasingly face requirements to produce CERT-In aligned security audit reports. Whether driven by a specific regulatory mandate, an enterprise customer's vendor due diligence process, or a tendering requirement, passing a CERT-In security audit requires systematic preparation. This checklist covers the domains typically assessed and the evidence organisations should have ready.

1. Network and perimeter security

Auditors will assess your network architecture, firewall rules, and perimeter controls. Typical checklist items include: network segmentation between production and non-production environments, documented and reviewed firewall rule sets with no overly permissive rules, intrusion detection or prevention systems (IDS/IPS) covering inbound traffic to production systems, removal or disabling of unused services and ports on all internet-facing hosts, and documented change control for network changes. Evidence to prepare: firewall configuration exports, network topology diagrams, and IDS alert logs.

2. Application security controls

Your web and API application layer will be assessed against the OWASP Application Security Verification Standard (ASVS). Key areas include: authentication mechanisms (MFA for administrative functions, strong password policies), authorisation controls and prevention of Insecure Direct Object References (IDOR), input validation and output encoding to prevent injection attacks, secure session management and CSRF protection, error handling that does not expose stack traces or system details, and HTTPS enforcement with valid TLS configuration. For SaaS products, the OWASP Top 10 list provides a baseline — auditors will probe each of the top ten categories.

If your product includes APIs, expect specific testing against the OWASP API Security Top 10. See our detailed guide on API security testing for a thorough breakdown.

3. Access control and identity management

Access control failures are among the most frequently cited findings in CERT-In audit reports. Prepare evidence for: role-based access control (RBAC) implementation with documented roles and permissions, a documented access provisioning and deprovisioning process with timely offboarding, privileged access management controls for administrators, multi-factor authentication on all administrative, developer, and cloud console access, and quarterly or more frequent access reviews with evidence of completion.

4. Data protection and encryption

Data handling is scrutinised in detail. Checklist items include: encryption at rest for all datastores holding customer or sensitive data (AES-256 or equivalent), TLS 1.2 or higher for all data in transit with no downgrade to weaker ciphers, documented data classification policy and evidence of its application, data retention and deletion procedures, and controls around Personally Identifiable Information (PII) relevant to the DPDP Act 2023. If you process sensitive financial data, ensure your PCI-DSS alignment is documented.

5. Logging, monitoring, and incident response

A functioning security monitoring and response capability is essential. Auditors typically verify: centralised log collection from all production systems, application, and infrastructure layers; log integrity controls to prevent tampering; an active Security Information and Event Management (SIEM) or equivalent with documented alert rules; a documented incident response plan tested within the past 12 months; and alignment with CERT-In's Directions of 28 April 2022, which mandate reporting of security incidents within 6 hours of detection to CERT-In.

6. Secure software development lifecycle (SDLC)

For SaaS companies, SDLC security is a differentiating factor. Prepare evidence for: security requirements in the development process, code review practices (manual and/or SAST tooling), dependency vulnerability scanning in CI/CD, a documented vulnerability management policy with defined SLAs for patching based on severity (critical: 24–72 hours is the CERT-In Directions standard), and evidence of previous security testing with remediation status.

Preparing for the audit engagement

Beyond the technical controls, administrative preparation significantly affects audit outcomes. Designate a single point of contact who understands your architecture. Prepare an asset inventory covering all in-scope systems, services, and data flows. Have architecture diagrams, data flow diagrams, and network topology documentation ready. Ensure that the audit scope is clearly defined and agreed before testing begins — scope creep in both directions (too narrow or too broad) is a common source of friction.

A pre-audit internal assessment, sometimes called a readiness review, can identify and remediate high-severity findings before the formal audit engagement, reducing the risk of critical findings in the final report. CyVigilant's CERT-In empanelled audit service includes a readiness review as part of the engagement. Talk to an expert to plan your audit timeline.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert