
Let's clear up the most common misconception first: CERT-In does not issue a universal cybersecurity certification to ordinary companies. There is no "CERT-In certificate" that any business can simply apply for and frame on the wall.
What actually exists is a set of obligations and audit mechanisms. Depending on your industry, contracts, and customers, your business may need to:
This CERT-In compliance checklist walks through all three — what is legally mandatory, what is sectoral, and what is simply good practice — so founders, compliance officers, CISOs, and IT managers know exactly what to prepare.
The Indian Computer Emergency Response Team (CERT-In) is India's national agency for responding to cybersecurity incidents, operating under the Ministry of Electronics and Information Technology (MeitY) and designated under Section 70B of the Information Technology Act, 2000. It has been operational since 2004 (cert-in.org.in).
Three instruments matter most to businesses:
Non-compliance is not theoretical: under Section 70B(7) of the IT Act, failing to furnish information or comply with CERT-In directions is punishable with imprisonment of up to one year, a fine of up to ₹1 lakh, or both.
When a tender, customer, or investor asks for "CERT-In certification," they almost always mean one of these:
If someone offers to get your company "CERT-In certified" directly by CERT-In, that is a red flag — the correct path is an audit by an empanelled firm against a defined scope.
How to read the tables: Mandatory = required by the CERT-In Directions (28 April 2022) or the IT Act for entities in scope. Sectoral = mandatory if a regulator (SEBI/RBI/IRDAI), tender, or contract covers you — otherwise strongly recommended. Recommended = good practice that CERT-In-empanelled auditors will test and record observations against.
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Identify applicable CERT-In directions and sectoral regulations | Mandatory | Legal / Compliance | Applicability assessment, regulatory register | Nobody has written down what applies | Annual applicability review, plus on every new contract |
| Appoint and register a CERT-In point of contact | Mandatory | CISO / IT Head | PoC designation letter, submission to CERT-In | PoC left the company; details stale | Use a role-based mailbox; update on every change |
| Information-security policies and governance | Sectoral | CISO | Board-approved policies, review minutes | Template policies never operationalised | Approve, assign owners, review annually |
| Risk assessment and risk-treatment plan | Sectoral | CISO / Risk | Risk register, treatment plan, sign-off | One-time assessment, now stale | Re-run yearly and after major changes |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Asset, application, cloud, API and data inventories | Sectoral | IT / Engineering | Asset register, cloud account list, API catalogue, data-flow maps | Shadow SaaS and undocumented APIs | Automated discovery; quarterly reconciliation |
| Network and cloud-security review | Recommended | Infra / DevOps | Network diagrams, firewall and security-group reviews | Outdated diagrams; flat networks | Refresh before audit; segment critical systems |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Vulnerability assessment and penetration testing (VAPT) | Sectoral | Security | VAPT reports, retest certificates | Automated scans only; no retest | Manual, authenticated testing; fix and retest |
| Web, mobile, API and source-code security testing | Sectoral | Engineering | App-sec reports, SAST/DAST output | Mobile apps and APIs left out of scope | Test everything internet-facing, every release cycle |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Identity and privileged-access management | Sectoral | IT / Security | Access-control matrix, privileged-account records, recertification reports | Shared admin credentials; no access reviews | Central IAM/PAM; quarterly access reviews |
| Multi-factor authentication (MFA) | Sectoral | IT | MFA policy and enforcement configuration | MFA on email but not servers, VPN or cloud consoles | Enforce MFA for all admin, remote and cloud access |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Patch and vulnerability-management process | Recommended | IT Ops | Patch policy, SLA reports, exception log | No SLAs; end-of-life systems in production | Risk-based patching SLAs; documented exceptions |
| Secure configurations and hardening | Recommended | IT Ops | Hardening baselines (e.g., CIS), configuration-audit reports | Default credentials, unnecessary open ports | Adopt baselines; scan for drift |
| Endpoint, email and malware protection | Recommended | IT | EDR/antivirus coverage report, SPF/DKIM/DMARC records | Unmanaged laptops and personal devices | Full endpoint coverage; enforce email authentication |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Enable and retain ICT system logs for 180 days, within India | Mandatory | IT / Security | Retention configuration, log-storage evidence | Logs rotated out after days | Central log store with 180-day rolling retention |
| Synchronise clocks to NIC/NPL NTP servers | Mandatory | IT Ops | NTP configuration, time-sync verification | Systems pointed at random public NTP pools | Standardise on NIC/NPL (or traceably synced) time |
| Security monitoring, detection and response capability | Recommended | SOC / Security | Incident-response plan, alerting runbooks, drill records | Plan exists but has never been exercised | Tabletop exercises at least twice a year |
| Requirement | Mandatory? | Owner | Evidence auditors ask for | Common gap | Remediation |
|---|---|---|---|---|---|
| Report covered incidents to CERT-In within 6 hours | Mandatory | CISO / PoC | Incident log, submitted reports, acknowledgements | Teams don't know the 6-hour clock exists | Pre-filled reporting template; on-call escalation path |
| Data protection, encryption, backup and recovery | Mandatory for personal data (DPDP) | IT / Data owners | Encryption standards, backup logs, restore-test results | Backups exist but restores never tested | Quarterly restore tests; encrypt at rest and in transit |
| Business-continuity and disaster-recovery testing | Sectoral | IT / Business | BCP document, DR-drill reports, RTO/RPO definitions | DR exists on paper only | Annual DR drill with a written report |
| Third-party and supply-chain risk management | Sectoral | Procurement / Security | Vendor register, contract security clauses, assessments | No security or incident-notification clauses | Add clauses; assess critical vendors annually |
| Employee awareness training and phishing simulations | Recommended | HR / Security | Training completion records, phishing-simulation metrics | One annual slideshow | Quarterly simulations; role-based training |
| Evidence collection and audit documentation | Mandatory for audits | Compliance | Indexed evidence repository, previous audit reports | Evidence scattered across inboxes | Single evidence repository mapped to controls |
| Remediation, retesting and management sign-off | Mandatory for audits | CISO / Management | Closure report, retest certificate, sign-off | Findings marked closed without retest | Fix → retest → formal management closure |
Copy this table into your project tracker and update the status column weekly.
| Checklist Item | Mandatory/Recommended | Owner | Evidence Required | Status |
|---|---|---|---|---|
| Applicability of directions and sector rules mapped | Mandatory | Compliance | Applicability memo | ☐ |
| CERT-In point of contact appointed and registered | Mandatory | CISO | PoC letter and submission | ☐ |
| Asset, app, cloud, API and data inventories | Sectoral | IT | Registers and data-flow maps | ☐ |
| Security policies approved and reviewed | Sectoral | CISO | Policy set, review minutes | ☐ |
| Risk assessment and treatment plan current | Sectoral | Risk | Risk register | ☐ |
| Network and cloud configuration reviewed | Recommended | DevOps | Review reports, diagrams | ☐ |
| VAPT completed, findings fixed, retested | Sectoral | Security | VAPT and retest reports | ☐ |
| Web/mobile/API/source-code testing done | Sectoral | Engineering | App-sec reports | ☐ |
| IAM and privileged access controlled | Sectoral | IT | Access matrix, review records | ☐ |
| MFA enforced on admin, remote and cloud access | Sectoral | IT | Enforcement configuration | ☐ |
| Patch management with SLAs operating | Recommended | IT Ops | Patch reports | ☐ |
| Hardening baselines applied | Recommended | IT Ops | Configuration audits | ☐ |
| Endpoint, email and malware protection deployed | Recommended | IT | Coverage reports | ☐ |
| Logs retained 180 days in India | Mandatory | Security | Retention configuration | ☐ |
| Clocks synced to NIC/NPL NTP | Mandatory | IT Ops | NTP configuration | ☐ |
| Detection and response plan tested | Recommended | SOC | Drill records | ☐ |
| 6-hour CERT-In reporting procedure ready | Mandatory | CISO / PoC | Template, escalation path | ☐ |
| Encryption, backup and restore tests | Mandatory (DPDP) | IT | Restore-test results | ☐ |
| BCP/DR documented and drilled | Sectoral | IT / Business | Drill reports | ☐ |
| Vendor and supply-chain risk managed | Sectoral | Procurement | Vendor assessments | ☐ |
| Awareness training and phishing simulations | Recommended | HR / Security | Training metrics | ☐ |
| Evidence repository complete and indexed | Mandatory for audit | Compliance | Evidence index | ☐ |
| Remediation, retest and sign-off closed | Mandatory for audit | Management | Closure report | ☐ |
Auditors working under the July 2025 audit policy guidelines are evidence-driven. Have these ready before fieldwork starts:
If you are starting from zero, sequence the work this way: first the mandatory core (point of contact, 6-hour reporting readiness, 180-day logging, NTP sync), then access control (MFA, least privilege, no shared credentials), then testing and hardening (VAPT, patching, baselines), and finally resilience (backups, DR, vendor risk). The checklist tables above give the control-by-control detail — resist the temptation to buy tools before the inventories and policies exist, because auditors test whether controls operate, not whether licences were purchased.
These are the obligations most Indian businesses miss, and they are mandatory under the 28 April 2022 directions for service providers, intermediaries, data centres, body corporates, and government organisations:
CERT-In's FAQ document (May 2022) clarifies scope questions — including that the 6-hour clock starts when you notice the incident, and that logs must be produced on demand.
Timelines vary with scope, but as broad market practice: readiness preparation commonly takes 4–12 weeks for a small or mid-sized organisation, audit fieldwork 2–6 weeks, and remediation plus retest another 2–8 weeks. Costs are quote-based and driven by: the number of applications, APIs, and IP addresses in scope; cloud complexity and number of accounts; whether source-code review is included; the number of retest rounds; and the auditor's tier and sector specialisation. CERT-In does not publish fixed audit prices — treat any "flat-rate certification" offer with suspicion.
Treat the draft report as a project plan: assign every finding an owner and a deadline, fix high-severity items first, and collect closure evidence (configuration screenshots, retest scans, updated policies) as you go. The auditor then retests and issues the final report or certificate. Two habits keep the next cycle cheap: file all evidence in one indexed repository, and have management formally accept any residual risks in writing. Audit reports and certificates have a validity period — most organisations re-audit annually or after major infrastructure changes.
Most major observations in a CERT-In-empanelled audit trace back to the same root causes: nobody can say who accessed a database or server, credentials are shared, MFA stops at email, and logs can't reconstruct a session. Adaptive closes these at a single access layer — an agentless, container-based gateway in front of your databases, servers, clusters, and cloud infrastructure — so the controls exist everywhere at once instead of being retrofitted resource by resource.
| Checklist item | How Adaptive helps |
|---|---|
| MFA on admin, remote and cloud access (item 10) | Enforces SSO and MFA on every database, server, and Kubernetes access — including tools that don't support it natively |
| Identity and privileged-access management (item 9) | Replaces shared credentials with identity-based, just-in-time access; approvals and auto-expiry built in |
| 180-day log retention and evidence (items 14, 22) | Session-level audit trails — every query and command attributable to a person, exportable as auditor evidence |
| 6-hour incident reporting (item 17) | Attributable session logs let you establish who did what, where fast enough to meet the reporting clock |
| Data protection (item 18) | Data masking keeps sensitive fields hidden from users and tools that don't need them |
| Third-party and vendor access (item 20) | Time-bound, recorded vendor access without VPNs or standing accounts |
Because the gateway deploys agentlessly in your own environment, it narrows the audit scope rather than expanding it — and typically stands up in days, not months.
Q: Does CERT-In certify companies directly? No. CERT-In empanels audit firms. Your company engages an empanelled firm and receives that firm's audit report or certificate — there is no universal "CERT-In certification" for businesses.
Q: Do the CERT-In directions apply to my small business? The 28 April 2022 directions apply to service providers, intermediaries, data centres, body corporates, and government organisations — which covers virtually every company operating IT systems in India. MSMEs were given time until 25 September 2022 to comply; the obligations are in force for everyone now.
Q: Which incidents must be reported within 6 hours? The 20 categories in Annexure I of the directions — including data breaches, data leaks, unauthorised access, website defacement, ransomware, denial-of-service attacks, and incidents affecting payment systems, cloud, IoT, or AI systems.
Q: How long must we keep logs, and where? ICT system logs must be enabled and retained for a rolling 180 days within India, and produced when CERT-In directs.
Q: How do we choose a CERT-In-empanelled auditor? Start from the official list on cert-in.org.in, then shortlist by sector experience, testing depth (manual vs. purely automated), retest terms, and references — the list is updated periodically, so verify the firm's current empanelment status.
CERT-In compliance is not a certificate you buy — it is a small set of mandatory duties (6-hour incident reporting, 180-day logging, NTP sync, a registered point of contact) plus an audit discipline that regulators, tenders, and enterprise customers increasingly demand. Companies that treat the checklist as infrastructure — not paperwork — walk into a CERT-In-empanelled audit with evidence already in hand.
Preparing for a CERT-In-empanelled audit? Contact info@adaptive.live or book a demo to close the access, authentication, and audit-trail items on this checklist before the auditor arrives.
This article is for general informational purposes and does not constitute legal, regulatory or cybersecurity advice. Requirements may vary according to the organisation's industry, systems, data, contracts and regulatory status. Organisations should verify current requirements through official CERT-In publications and qualified legal and cybersecurity advisers.

