Adaptive Logo
Product
View Product
Use Cases
View Product
Resources
View Product
Pricing
Partners
Careers
General 18 min read

CERT-In Compliance Checklist: A Practical Guide for Indian Businesses

Debarshi BasakAug 5, 2026
CERT-In Compliance Checklist: A Practical Guide for Indian Businesses
Assets

Introduction

Let's clear up the most common misconception first: CERT-In does not issue a universal cybersecurity certification to ordinary companies. There is no "CERT-In certificate" that any business can simply apply for and frame on the wall.

What actually exists is a set of obligations and audit mechanisms. Depending on your industry, contracts, and customers, your business may need to:

  • Comply with the CERT-In directions of 28 April 2022 — mandatory incident reporting, logging, and related duties that apply to almost every organisation operating in India;
  • Undergo a cybersecurity audit by a CERT-In-empanelled auditor — an independent audit firm that CERT-In has vetted and listed; or
  • Obtain an audit or compliance report because a regulator (SEBI, RBI, IRDAI), a government tender, a customer contract, or an IPO process demands one.

This CERT-In compliance checklist walks through all three — what is legally mandatory, what is sectoral, and what is simply good practice — so founders, compliance officers, CISOs, and IT managers know exactly what to prepare.

What Is CERT-In?

The Indian Computer Emergency Response Team (CERT-In) is India's national agency for responding to cybersecurity incidents, operating under the Ministry of Electronics and Information Technology (MeitY) and designated under Section 70B of the Information Technology Act, 2000. It has been operational since 2004 (cert-in.org.in).

Three instruments matter most to businesses:

  • The IT (CERT-In and Manner of Performing Functions and Duties) Rules, 2013 (notified 16 January 2014), which made reporting of certain incident types mandatory.
  • The Cyber Security Directions of 28 April 2022 (No. 20(3)/2022-CERT-In), issued under Section 70B(6), which took effect in June 2022 — with an extended timeline to 25 September 2022 for MSMEs, per CERT-In's FAQ document published in May 2022.
  • The Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0, released 25 July 2025), which standardise how CERT-In-empanelled audits are scoped, conducted, and evidenced (cert-in.org.in).

Non-compliance is not theoretical: under Section 70B(7) of the IT Act, failing to furnish information or comply with CERT-In directions is punishable with imprisonment of up to one year, a fine of up to ₹1 lakh, or both.

What Does "CERT-In Certification" Usually Mean?

When a tender, customer, or investor asks for "CERT-In certification," they almost always mean one of these:

  • A security audit report or "safe-to-host" certificate issued by a CERT-In-empanelled auditor. CERT-In empanels private audit firms — the official empanelled list is published and periodically updated. The empanelment certifies the auditor, not your company. Your company receives the audit firm's report or certificate.
  • Evidence of compliance with the CERT-In directions — incident-reporting readiness, log retention, a registered point of contact.
  • A sectoral audit mandated by SEBI, RBI, or IRDAI that must (or in practice does) use a CERT-In-empanelled firm.

If someone offers to get your company "CERT-In certified" directly by CERT-In, that is a red flag — the correct path is an audit by an empanelled firm against a defined scope.

Who May Need a CERT-In-Empanelled Cybersecurity Audit?

  • Government departments, PSUs, and their vendors. Websites and applications hosted on government infrastructure (e.g., with NIC) require a security audit clearance from a CERT-In-empanelled auditor before go-live and after major changes, in line with the Guidelines for Indian Government Websites (GIGW 3.0, 2023). CERT-In's Guidelines on Information Security Practices for Government Entities (June 2023) set the baseline controls.
  • SEBI-regulated entities. The Cybersecurity and Cyber Resilience Framework (CSCRF), issued 20 August 2024, requires cyber audits and VAPT through CERT-In-empanelled organisations; SEBI extended compliance timelines for most regulated entities to 30 June 2025 via subsequent circulars.
  • RBI-regulated entities. The Master Direction on IT Governance, Risk, Controls and Assurance Practices (7 November 2023, effective 1 April 2024) requires information-systems audits and VAPT; banks and NBFCs commonly engage CERT-In-empanelled firms to satisfy these.
  • Insurers and intermediaries. IRDAI's Information and Cyber Security Guidelines, 2023 (24 April 2023) require periodic cybersecurity audits and VAPT; Insurance Self-Network Platform approvals additionally involve CERT-In-empanelled audits.
  • Anyone bidding on tenders or selling to enterprises where the contract demands a CERT-In-empanelled audit report.
  • Companies handling personal data. The Digital Personal Data Protection Act, 2023 (11 August 2023) and the DPDP Rules, 2025 (notified 13 November 2025) require "reasonable security safeguards" — an independent audit is a strong way to demonstrate them (meity.gov.in).

What This Looks Like in Practice

  • Startup (20 people): No regulator demands an audit yet — but the 6-hour incident-reporting and 180-day logging duties already apply. One shared Google Sheet of assets and a named point of contact is the minimum.
  • SaaS company: An enterprise customer's procurement team asks for a VAPT report "from a CERT-In-empanelled auditor" before signing. The audit scope is your production cloud, APIs, and web app.
  • E-commerce business: Payment incidents and data breaches are explicitly reportable to CERT-In within six hours; expect customer contracts to require annual application security testing.
  • Financial-services company: SEBI's CSCRF or RBI's Master Direction makes audits and VAPT a recurring regulatory obligation with board-level reporting — not a one-off.
  • IPO-bound company: Bankers and auditors increasingly expect a recent independent cybersecurity audit as part of diligence; unresolved major observations become disclosure questions.

CERT-In Compliance Checklist

How to read the tables: Mandatory = required by the CERT-In Directions (28 April 2022) or the IT Act for entities in scope. Sectoral = mandatory if a regulator (SEBI/RBI/IRDAI), tender, or contract covers you — otherwise strongly recommended. Recommended = good practice that CERT-In-empanelled auditors will test and record observations against.

1. Scope, Governance and Ownership

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Identify applicable CERT-In directions and sectoral regulationsMandatoryLegal / ComplianceApplicability assessment, regulatory registerNobody has written down what appliesAnnual applicability review, plus on every new contract
Appoint and register a CERT-In point of contactMandatoryCISO / IT HeadPoC designation letter, submission to CERT-InPoC left the company; details staleUse a role-based mailbox; update on every change
Information-security policies and governanceSectoralCISOBoard-approved policies, review minutesTemplate policies never operationalisedApprove, assign owners, review annually
Risk assessment and risk-treatment planSectoralCISO / RiskRisk register, treatment plan, sign-offOne-time assessment, now staleRe-run yearly and after major changes

2. Know What You Are Protecting

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Asset, application, cloud, API and data inventoriesSectoralIT / EngineeringAsset register, cloud account list, API catalogue, data-flow mapsShadow SaaS and undocumented APIsAutomated discovery; quarterly reconciliation
Network and cloud-security reviewRecommendedInfra / DevOpsNetwork diagrams, firewall and security-group reviewsOutdated diagrams; flat networksRefresh before audit; segment critical systems

3. Security Testing

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Vulnerability assessment and penetration testing (VAPT)SectoralSecurityVAPT reports, retest certificatesAutomated scans only; no retestManual, authenticated testing; fix and retest
Web, mobile, API and source-code security testingSectoralEngineeringApp-sec reports, SAST/DAST outputMobile apps and APIs left out of scopeTest everything internet-facing, every release cycle

4. Identity and Access

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Identity and privileged-access managementSectoralIT / SecurityAccess-control matrix, privileged-account records, recertification reportsShared admin credentials; no access reviewsCentral IAM/PAM; quarterly access reviews
Multi-factor authentication (MFA)SectoralITMFA policy and enforcement configurationMFA on email but not servers, VPN or cloud consolesEnforce MFA for all admin, remote and cloud access

5. Hardening and Operations

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Patch and vulnerability-management processRecommendedIT OpsPatch policy, SLA reports, exception logNo SLAs; end-of-life systems in productionRisk-based patching SLAs; documented exceptions
Secure configurations and hardeningRecommendedIT OpsHardening baselines (e.g., CIS), configuration-audit reportsDefault credentials, unnecessary open portsAdopt baselines; scan for drift
Endpoint, email and malware protectionRecommendedITEDR/antivirus coverage report, SPF/DKIM/DMARC recordsUnmanaged laptops and personal devicesFull endpoint coverage; enforce email authentication

6. Logging, Monitoring and Time — the Mandatory Core

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Enable and retain ICT system logs for 180 days, within IndiaMandatoryIT / SecurityRetention configuration, log-storage evidenceLogs rotated out after daysCentral log store with 180-day rolling retention
Synchronise clocks to NIC/NPL NTP serversMandatoryIT OpsNTP configuration, time-sync verificationSystems pointed at random public NTP poolsStandardise on NIC/NPL (or traceably synced) time
Security monitoring, detection and response capabilityRecommendedSOC / SecurityIncident-response plan, alerting runbooks, drill recordsPlan exists but has never been exercisedTabletop exercises at least twice a year

7. Incidents, Resilience and Third Parties

RequirementMandatory?OwnerEvidence auditors ask forCommon gapRemediation
Report covered incidents to CERT-In within 6 hoursMandatoryCISO / PoCIncident log, submitted reports, acknowledgementsTeams don't know the 6-hour clock existsPre-filled reporting template; on-call escalation path
Data protection, encryption, backup and recoveryMandatory for personal data (DPDP)IT / Data ownersEncryption standards, backup logs, restore-test resultsBackups exist but restores never testedQuarterly restore tests; encrypt at rest and in transit
Business-continuity and disaster-recovery testingSectoralIT / BusinessBCP document, DR-drill reports, RTO/RPO definitionsDR exists on paper onlyAnnual DR drill with a written report
Third-party and supply-chain risk managementSectoralProcurement / SecurityVendor register, contract security clauses, assessmentsNo security or incident-notification clausesAdd clauses; assess critical vendors annually
Employee awareness training and phishing simulationsRecommendedHR / SecurityTraining completion records, phishing-simulation metricsOne annual slideshowQuarterly simulations; role-based training
Evidence collection and audit documentationMandatory for auditsComplianceIndexed evidence repository, previous audit reportsEvidence scattered across inboxesSingle evidence repository mapped to controls
Remediation, retesting and management sign-offMandatory for auditsCISO / ManagementClosure report, retest certificate, sign-offFindings marked closed without retestFix → retest → formal management closure

Your CERT-In Audit Tracker

Copy this table into your project tracker and update the status column weekly.

Checklist ItemMandatory/RecommendedOwnerEvidence RequiredStatus
Applicability of directions and sector rules mappedMandatoryComplianceApplicability memo
CERT-In point of contact appointed and registeredMandatoryCISOPoC letter and submission
Asset, app, cloud, API and data inventoriesSectoralITRegisters and data-flow maps
Security policies approved and reviewedSectoralCISOPolicy set, review minutes
Risk assessment and treatment plan currentSectoralRiskRisk register
Network and cloud configuration reviewedRecommendedDevOpsReview reports, diagrams
VAPT completed, findings fixed, retestedSectoralSecurityVAPT and retest reports
Web/mobile/API/source-code testing doneSectoralEngineeringApp-sec reports
IAM and privileged access controlledSectoralITAccess matrix, review records
MFA enforced on admin, remote and cloud accessSectoralITEnforcement configuration
Patch management with SLAs operatingRecommendedIT OpsPatch reports
Hardening baselines appliedRecommendedIT OpsConfiguration audits
Endpoint, email and malware protection deployedRecommendedITCoverage reports
Logs retained 180 days in IndiaMandatorySecurityRetention configuration
Clocks synced to NIC/NPL NTPMandatoryIT OpsNTP configuration
Detection and response plan testedRecommendedSOCDrill records
6-hour CERT-In reporting procedure readyMandatoryCISO / PoCTemplate, escalation path
Encryption, backup and restore testsMandatory (DPDP)ITRestore-test results
BCP/DR documented and drilledSectoralIT / BusinessDrill reports
Vendor and supply-chain risk managedSectoralProcurementVendor assessments
Awareness training and phishing simulationsRecommendedHR / SecurityTraining metrics
Evidence repository complete and indexedMandatory for auditComplianceEvidence index
Remediation, retest and sign-off closedMandatory for auditManagementClosure report

Documents and Evidence Required for the Audit

Auditors working under the July 2025 audit policy guidelines are evidence-driven. Have these ready before fieldwork starts:

  • Organisation chart, audit scope statement, and network/architecture diagrams
  • Asset, application, cloud, and API inventories with owners
  • Approved security policies, risk register, and previous audit reports
  • VAPT and application-security reports with closure evidence
  • Access-control matrix, MFA configuration, and privileged-access records
  • Log-retention configuration, sample logs, and NTP settings
  • Incident-response plan, incident log, and any CERT-In submissions
  • Backup/restore test results, DR-drill reports, vendor contracts and assessments
  • Training records and management review minutes

Technical Security Controls to Implement

If you are starting from zero, sequence the work this way: first the mandatory core (point of contact, 6-hour reporting readiness, 180-day logging, NTP sync), then access control (MFA, least privilege, no shared credentials), then testing and hardening (VAPT, patching, baselines), and finally resilience (backups, DR, vendor risk). The checklist tables above give the control-by-control detail — resist the temptation to buy tools before the inventories and policies exist, because auditors test whether controls operate, not whether licences were purchased.

Incident-Reporting and Logging Requirements

These are the obligations most Indian businesses miss, and they are mandatory under the 28 April 2022 directions for service providers, intermediaries, data centres, body corporates, and government organisations:

  • Report covered cyber incidents within 6 hours of noticing or being notified — by email (incident@cert-in.org.in), phone (1800-11-4949), or the formats CERT-In publishes.
  • Annexure I lists 20 reportable incident categories, including data breaches and data leaks, unauthorised access to systems or data, website defacement or intrusion, ransomware and other malicious code, attacks on servers and network equipment, identity theft and phishing, denial-of-service attacks, incidents affecting digital payment systems, malicious or fake mobile apps, and incidents affecting cloud, IoT, or AI systems.
  • Designate a point of contact and share their details with CERT-In in the prescribed format.
  • Enable logs of all ICT systems and retain them for a rolling 180 days, within India, to be produced when CERT-In orders or directs.
  • Synchronise system clocks to the NTP servers of NIC or NPL (or NTP servers traceably synced to them).
  • VPN, cloud, and data-centre providers must keep prescribed subscriber/customer records for 5 years; virtual-asset businesses must keep KYC and transaction records for 5 years.

CERT-In's FAQ document (May 2022) clarifies scope questions — including that the 6-hour clock starts when you notice the incident, and that logs must be produced on demand.

Steps in a CERT-In-Empanelled Audit

  1. Select an auditor from the official empanelled list and check sector experience.
  2. Agree the scope — networks, applications, APIs, cloud accounts, locations — in writing.
  3. Pre-audit readiness — gather the evidence pack, close obvious gaps.
  4. Fieldwork — interviews, configuration reviews, VAPT, and evidence sampling.
  5. Draft report — findings classified by severity, with auditee comments.
  6. Remediation window — fix findings, collect closure evidence.
  7. Retest — the auditor verifies fixes.
  8. Final report / certificate — issued with a validity period and scope statement; management signs off.

Common Reasons Companies Fail or Receive Major Observations

  • Logs kept for 7–30 days instead of 180, or stored only with a foreign SaaS with no India copy
  • No named CERT-In point of contact, or a contact who left the company
  • MFA missing on VPNs, cloud consoles, and database access
  • Shared administrator credentials with no accountability trail
  • VAPT findings "closed" without retest evidence
  • Backups never restore-tested; DR plans never exercised
  • Vendor contracts with no security or incident-notification clauses
  • Evidence assembled during the audit rather than maintained continuously

Expected Audit Timeline and Factors Affecting Cost

Timelines vary with scope, but as broad market practice: readiness preparation commonly takes 4–12 weeks for a small or mid-sized organisation, audit fieldwork 2–6 weeks, and remediation plus retest another 2–8 weeks. Costs are quote-based and driven by: the number of applications, APIs, and IP addresses in scope; cloud complexity and number of accounts; whether source-code review is included; the number of retest rounds; and the auditor's tier and sector specialisation. CERT-In does not publish fixed audit prices — treat any "flat-rate certification" offer with suspicion.

How to Prepare Employees and Vendors

  • Brief every employee on what counts as a reportable incident and the internal escalation path — the 6-hour clock leaves no room for "we'll mention it Monday."
  • Run phishing simulations and short role-based training for engineering, finance, and support teams.
  • Give the audit team a single coordinator so auditor requests don't stall in inboxes.
  • For vendors: add security and incident-notification clauses to contracts, collect their audit reports or questionnaires annually, and know which vendors store your data and where.

Post-Audit Remediation and Closure Process

Treat the draft report as a project plan: assign every finding an owner and a deadline, fix high-severity items first, and collect closure evidence (configuration screenshots, retest scans, updated policies) as you go. The auditor then retests and issues the final report or certificate. Two habits keep the next cycle cheap: file all evidence in one indexed repository, and have management formally accept any residual risks in writing. Audit reports and certificates have a validity period — most organisations re-audit annually or after major infrastructure changes.

How Adaptive Helps with CERT-In Compliance

Most major observations in a CERT-In-empanelled audit trace back to the same root causes: nobody can say who accessed a database or server, credentials are shared, MFA stops at email, and logs can't reconstruct a session. Adaptive closes these at a single access layer — an agentless, container-based gateway in front of your databases, servers, clusters, and cloud infrastructure — so the controls exist everywhere at once instead of being retrofitted resource by resource.

Checklist itemHow Adaptive helps
MFA on admin, remote and cloud access (item 10)Enforces SSO and MFA on every database, server, and Kubernetes access — including tools that don't support it natively
Identity and privileged-access management (item 9)Replaces shared credentials with identity-based, just-in-time access; approvals and auto-expiry built in
180-day log retention and evidence (items 14, 22)Session-level audit trails — every query and command attributable to a person, exportable as auditor evidence
6-hour incident reporting (item 17)Attributable session logs let you establish who did what, where fast enough to meet the reporting clock
Data protection (item 18)Data masking keeps sensitive fields hidden from users and tools that don't need them
Third-party and vendor access (item 20)Time-bound, recorded vendor access without VPNs or standing accounts

Because the gateway deploys agentlessly in your own environment, it narrows the audit scope rather than expanding it — and typically stands up in days, not months.

Frequently Asked Questions

Q: Does CERT-In certify companies directly? No. CERT-In empanels audit firms. Your company engages an empanelled firm and receives that firm's audit report or certificate — there is no universal "CERT-In certification" for businesses.

Q: Do the CERT-In directions apply to my small business? The 28 April 2022 directions apply to service providers, intermediaries, data centres, body corporates, and government organisations — which covers virtually every company operating IT systems in India. MSMEs were given time until 25 September 2022 to comply; the obligations are in force for everyone now.

Q: Which incidents must be reported within 6 hours? The 20 categories in Annexure I of the directions — including data breaches, data leaks, unauthorised access, website defacement, ransomware, denial-of-service attacks, and incidents affecting payment systems, cloud, IoT, or AI systems.

Q: How long must we keep logs, and where? ICT system logs must be enabled and retained for a rolling 180 days within India, and produced when CERT-In directs.

Q: How do we choose a CERT-In-empanelled auditor? Start from the official list on cert-in.org.in, then shortlist by sector experience, testing depth (manual vs. purely automated), retest terms, and references — the list is updated periodically, so verify the firm's current empanelment status.

Conclusion and Next Step

CERT-In compliance is not a certificate you buy — it is a small set of mandatory duties (6-hour incident reporting, 180-day logging, NTP sync, a registered point of contact) plus an audit discipline that regulators, tenders, and enterprise customers increasingly demand. Companies that treat the checklist as infrastructure — not paperwork — walk into a CERT-In-empanelled audit with evidence already in hand.

Preparing for a CERT-In-empanelled audit? Contact info@adaptive.live or book a demo to close the access, authentication, and audit-trail items on this checklist before the auditor arrives.


This article is for general informational purposes and does not constitute legal, regulatory or cybersecurity advice. Requirements may vary according to the organisation's industry, systems, data, contracts and regulatory status. Organisations should verify current requirements through official CERT-In publications and qualified legal and cybersecurity advisers.

References
  1. cert-in.org.inhttps://www.cert-in.org.in
  2. Cyber Security Directions of 28 April 2022https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
  3. FAQ document published in May 2022https://www.cert-in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf
  4. official empanelled listhttps://www.cert-in.org.in/PDF/Empanel_org.pdf
  5. Guidelines for Indian Government Websites (GIGW 3.0, 2023)https://guidelines.india.gov.in
  6. Cybersecurity and Cyber Resilience Framework (CSCRF)https://www.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  7. Master Direction on IT Governance, Risk, Controls and Assurance Practiceshttps://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562
  8. Information and Cyber Security Guidelines, 2023https://irdai.gov.in/document-detail?documentId=3314780
  9. meity.gov.inhttps://www.meity.gov.in
  10. Adaptivehttps://adaptive.live
  11. audit trailshttps://adaptive.live/product/auditability
  12. vendor accesshttps://adaptive.live/usecases/reduce-insider-threat
  13. SEBI CSCRF Checklist: Complete Compliance Requirements Explainedhttps://adaptive.live/blog/sebi-cscrf-checklist-2025-complete-compliance-requirements-and-guidelines-explained
  14. RBI CSITE Audit: Complete Guide, Checklist, and Preparation Tipshttps://adaptive.live/blog/rbi-csite-audit-complete-guide-checklist-and-preparation-tips-2025
  15. Cybersecurity Process Checklist for Companies Preparing for an IPO in Indiahttps://adaptive.live/blog/cybersecurity-process-checklist-for-companies-preparing-for-an-ipo-in-india
  16. Access Security Requirements Across Major Compliance Frameworkshttps://adaptive.live/blog/access-security-requirements-across-major-compliance-frameworks
  17. KiranaPro Hack: Servers Deleted and Customer Data Compromisedhttps://adaptive.live/blog/indian-grocery-startup-kiranapro-hacked-servers-deleted-and-customer-data-compromised
Agents are the new perimeter. Contain the chaos.
No Network Changes Required
Cloud or On-Premises Deployment
Enterprise-Grade Security