Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
Compliance

What CERT-In Empanelment Means for Your Security Audit

May 12, 2026·CyVigilant Security Team
ComplianceCyVigilant

India's cyber security regulatory landscape has matured significantly over the past five years. At the centre of that landscape sits the Indian Computer Emergency Response Team — CERT-In — the national nodal agency established under Section 70B of the Information Technology Act, 2000. When a security auditing firm is listed on the CERT-In empanelled panel, it signals far more than a name on a government registry. It is a formal recognition that the firm meets the technical, organisational, and methodological standards required to conduct audits that satisfy India's highest regulatory threshold.

What is CERT-In and why does its empanelment matter?

CERT-In operates under the Ministry of Electronics and Information Technology (MeitY) and is responsible for India's cyber security incident response, threat analysis, and security auditing ecosystem. CERT-In maintains a publicly available panel of empanelled Information Security Auditing Organisations (ISAOs) — firms that have been vetted for auditor qualifications, methodology rigour, tool proficiency, and process maturity.

For regulated entities, engaging an empanelled auditor is not a matter of preference. The Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), Insurance Regulatory and Development Authority of India (IRDAI), and several government and PSU mandates explicitly require that security audits be conducted by CERT-In empanelled firms. Audits by non-empanelled vendors, however technically competent, may not satisfy regulatory compliance requirements.

What the empanelment process evaluates

Obtaining and retaining CERT-In empanelment requires meeting rigorous criteria. Auditor certifications — the team must hold recognised offensive-security and audit qualifications such as OSCP, OSWE, CEH, CISSP, and CISA. Tool competency — the firm must demonstrate proficiency with both manual testing methodologies and industry-standard tooling. Methodology documentation — the firm must have a formally documented audit methodology aligned with international standards including ISO 27001, OWASP ASVS, and CERT-In's own prescribed guidelines. Infrastructure security — the firm's own systems, report handling, and evidence storage must meet defined security standards.

Empanelment is not a one-time award; firms are periodically reviewed and must continuously meet the standards. This ongoing accountability is precisely why regulators require it.

The Safe-to-Host certificate and when it is required

A Safe-to-Host certificate is a formal declaration issued by a CERT-In empanelled auditor following a security audit, confirming that a system, application, or infrastructure has been assessed and found to meet a defined security baseline. It is most commonly associated with government and PSU website hosting requirements, where the National Informatics Centre (NIC) and various state IT departments mandate a Safe-to-Host clearance before a new or significantly updated website or application goes live.

Outside the government context, Safe-to-Host certificates and equivalent CERT-In compliant audit reports are increasingly cited in BFSI tenders and enterprise procurement requirements. A BFSI vendor handling customer financial data may be required to present a current CERT-In empanelled audit report as part of vendor due diligence — making empanelled status a commercial differentiator as much as a regulatory obligation.

RBI, SEBI, and IRDAI: when CERT-In audits are mandatory

The RBI's Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023) requires regulated entities to conduct comprehensive IS audits and VAPT by qualified, experienced auditors. While the directive does not always name CERT-In empanelment explicitly, the practical interpretation across RBI-regulated banks and NBFCs is that empanelled auditors are the expected standard. SEBI's Cyber Security and Cyber Resilience Framework (CSCRF, 2023 revision) similarly mandates periodic VAPT and application security assessments for Market Infrastructure Institutions and qualified stock brokers, with empanelled firms being the preferred or required auditors in most contexts.

IRDAI's cyber security guidelines for insurance companies and intermediaries require annual information security audits. For entities in the government and PSU sector, CERT-In empanelment is typically non-negotiable for infrastructure and website audits, security audits of critical information infrastructure, and IS audits of systems handling national security or citizen data.

What to expect from a CERT-In empanelled audit engagement

A CERT-In empanelled audit is not a faster version of a vulnerability scan. It is a structured assessment that typically follows four phases: scoping and information gathering, active testing (network, application, API, and configuration assessment), findings analysis and risk classification, and report generation. The final report includes an executive summary, a technical findings register with CVSS scores and CWE references, evidence of exploitation (where applicable), and a remediation roadmap.

Critically, the report format and content must meet CERT-In's prescribed standards to be accepted by regulators. A technically accurate report in a non-standard format may still be rejected during regulatory review. This is why working with an empanelled firm matters even for organisations that have strong in-house security teams.

CyVigilant gets you CERT-In audit-ready and delivers audits through its CERT-In empanelled partners. To discuss how a CERT-In security audit can satisfy your regulatory obligations, talk to an expert today.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert