Why CERT-In Empanelment Matters When Choosing a VAPT Partner
A CISO forwarded me a VAPT report last year with a note that read: our regulator rejected this. VAPT here means Vulnerability Assessment and Penetration Testing. The report itself was competent enough. The scanner findings were mapped, the screenshots were there, the CVSS scores were computed. The problem was the letterhead. The firm that signed it was not CERT-In empanelled, and the RBI examiner would not accept a network security audit from a non-empanelled auditor. Six weeks of work, a decent chunk of budget, and it could not be filed.
That is the quiet trap most teams walk into. You choose a VAPT partner on price, or on a slick deck, or because someone knew someone. Then at the moment it matters most, when the report has to survive a regulatory examination, it turns out the badge on the cover page was the thing that actually mattered. This piece is about that badge, what it really means, why more regulators and enterprises now insist on it, and how you verify it in about four minutes so you never get that note.
What CERT-In empanelment actually is (and what it is not)
CERT-In is the Indian Computer Emergency Response Team, the national nodal agency for cybersecurity under the Ministry of Electronics and Information Technology (MeitY), operating under Section 70B of the Information Technology Act, 2000. It maintains a published list of information security auditing organisations that it has assessed and formally empanelled to conduct security audits, including VAPT, for government bodies and, increasingly, for the regulated private sector.
Empanelment is a capability certification of the organisation, awarded through a structured evaluation. It is not a per-report stamp, it is not the same as ISO 27001 certification, and it is not a licence to do anything and everything. Here is the distinction that trips people up: an empanelled firm still has to do good work on your engagement. The badge tells a regulator the firm met a national bar for people, process and methodology. It does not guarantee your specific report is any good. Both things have to be true at once.
| What people assume empanelment means | What it actually means |
|---|---|
| A government licence to hack anything | A capability assessment of the auditing organisation by CERT-In |
| Same as ISO 27001 or SOC 2 | A separate MeitY-linked scheme specific to security auditing in India |
| Every consultant on staff is vetted | The organisation, its methodology and named auditors were assessed; team competence still varies |
| A permanent, one-time badge | A time-bound status that must be renewed, with defined validity cycles |
| Any report they sign is automatically compliant | The report still has to meet scope, depth and evidence standards on its own merits |
Why the badge went from nice-to-have to non-negotiable
For years empanelment was a government-tender concern. If you sold to a PSU or a ministry, you needed an empanelled auditor. The private sector treated it as optional. That has changed, and it changed because the regulators changed.
The turning point for most enterprises was the CERT-In Directions of 28 April 2022, issued under Section 70B(6). Those directions imposed a six-hour incident reporting window for a defined list of cyber incidents, mandatory 180-day log retention within India, and clock synchronisation to NPL or NIC time sources. Suddenly every board wanted to know whether their controls would actually hold up, and the natural way to demonstrate that was an audit signed by the same authority setting the rules. Empanelment became the shorthand for defensible.
Then the sector regulators layered on top. Where a CERT-In empanelled auditor is expected or required in practice:
- RBI: the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (effective 1 April 2024) requires periodic VAPT for banks and NBFCs, and examiners routinely expect the audit to be performed by a CERT-In empanelled organisation.
- SEBI: the Cyber Security and Cyber Resilience Framework (CSCRF), consolidated in 2024, mandates VAPT for regulated entities such as stock brokers, depositories and AMCs, and points to CERT-In empanelled auditors for the assessment.
- IRDAI: the Information and Cyber Security Guidelines require regular VAPT and independent assurance for insurers and intermediaries, with empanelled auditors as the accepted route.
- NPCI and UPI ecosystem participants: security audits by CERT-In empanelled auditors are a standing expectation for onboarding and continued participation.
- Government, PSU and CERT-In safe-to-host assessments for websites and applications going live on NIC or state infrastructure.
The pattern is consistent. When money, personal data, or public infrastructure is on the line, the Indian regulator wants the audit signed by a firm the national CERT has already vetted. Non-empanelled reports are increasingly filed and then rejected.
How a firm actually gets empanelled
Understanding the process tells you why the badge carries weight, and it tells you what questions to ask. CERT-In runs an application and evaluation cycle. In broad strokes a firm has to demonstrate the following before it makes the list:
- A minimum bench of qualified, full-time security auditors, evidenced by named individuals and recognised certifications (typically OSCP, CEH, CISSP, CISA and similar), not a hollow subcontractor model.
- A documented, repeatable audit methodology aligned to recognised standards such as OWASP for applications and OSSTMM or PTES-style methods for network testing.
- A technical evaluation of the firm's capability, including a practical assessment of how it actually conducts testing rather than a paperwork exercise.
- Legal, financial and infrastructural standing, plus signed non-disclosure and data-handling undertakings appropriate for auditing sensitive systems.
- A commitment to CERT-In's terms, including reporting obligations and adherence to the published audit scope for empanelled work.
The status is time-bound, not perpetual. Firms have to renew, and the list is periodically refreshed. That matters to you because a firm empanelled in 2021 may have lapsed by the time you sign the contract. The badge is only useful if it is current on the day your report is dated.
What actually happens in the audit room
Let me make this concrete, because empanelment is not an abstraction, it shows up as the difference between a smooth examination and a bad afternoon. Picture a mid-size NBFC, first RBI IT examination after the 2024 Master Direction took effect. The examiner sits down and works through a predictable sequence. The questions are not about your firewall brand. They are about provenance and rigour.
What the examiner asks, roughly in this order:
- Who performed your last VAPT, and are they CERT-In empanelled? Show me the current empanelment listing.
- What was the scope? Was it the whole external perimeter and the internet-facing applications, or a convenient subset?
- Was this a genuine penetration test with manual exploitation, or an automated scan relabelled as a pen test?
- Show me the critical and high findings, the remediation dates, and the retest evidence that closed them.
- When was the report dated, and does it fall within your required audit frequency?
On the good afternoon, the auditor's empanelment is current, the scope covers the actual attack surface, and there is a signed retest closing the high-severity items. The examiner moves on. On the bad afternoon, the firm is not on the list, and now the finding is not a technical gap, it is a governance gap: the entity did not obtain independent assurance from a recognised auditor. That reads far worse in an examination report, and it is the sort of observation that follows you into the next cycle.
Empanelled is necessary, not sufficient: how firms game it
Here is where I have to be blunt, because this is the part vendors will not tell you. The badge is being misused, and a careful buyer catches it. Watch for these moves:
| The move | What it looks like | How to catch it |
|---|---|---|
| Borrowed badge | A reseller or systems integrator claims empanelment that actually belongs to a partner firm doing the work | Ask which legal entity is empanelled and which entity signs the report; they must match |
| Lapsed status | The firm was empanelled two cycles ago and still uses the logo | Check the current CERT-In list on the day of contracting, not an old certificate PDF |
| Scanner-as-pentest | An automated Nessus or Burp scan exported and rebranded as manual VAPT | Ask for evidence of manual exploitation, chained findings and business-logic testing |
| Scope shrinkage | Empanelled firm, but scope quietly narrowed to a handful of low-risk assets | Insist on a scope document that maps to your real internet-facing inventory |
| Empanelled entity, junior team | Senior name on the SOW, freshers on the keyboard | Name the actual testers in the contract and ask for their certifications |
None of this means empanelment is theatre. It means empanelment is the entry ticket, and you still have to inspect the seat you were sold. Treat the badge as a filter that removes the clearly unqualified, then judge the firm on scope, method and people the way you would judge any serious partner.
How to verify empanelment in four minutes
Do not take a logo on a PDF as proof. The verification is fast and it is on you to do it before you sign, not after the regulator asks.
- Go to the official CERT-In website (cert-in.org.in) and open the current list of empanelled information security auditing organisations. This is the single source of truth.
- Match the exact legal entity name. Group and subsidiary names differ; the empanelled name must be the one that will sign your report and appear on the invoice.
- Confirm the listing is current, not a screenshot of an older cycle. Empanelment is time-bound and periodically refreshed.
- Cross-check the named auditors. Ask the firm to name, in the statement of work, the individuals who will test and their certifications, then confirm they are employees, not sourced hands.
- Ask for a redacted sample report from a comparable engagement so you can see whether their VAPT is genuinely manual and evidence-rich or a dressed-up scan.
Reading empanelment against the standard you actually have to meet
Empanelment is one requirement in a stack. Do not let it crowd out the others. Map your obligations so you know what the audit has to deliver beyond the badge.
| Your obligation | Regulator | Where CERT-In empanelment fits |
|---|---|---|
| Periodic VAPT of applications and network | RBI IT Master Direction 2024 | Auditor expected to be CERT-In empanelled; scope and retest evidence also assessed |
| VAPT under cyber resilience framework | SEBI CSCRF | CERT-In empanelled auditor is the accepted route for the mandated assessment |
| Regular VAPT and independent assurance | IRDAI Cyber Security Guidelines | Empanelled auditor accepted; frequency and remediation tracking still required |
| Six-hour incident reporting, 180-day India log retention | CERT-In Directions, 28 April 2022 | Applies regardless of auditor; empanelled auditors help design and validate compliance |
| Safe-to-host clearance for government hosting | CERT-In / NIC | Empanelled auditor sign-off is mandatory for go-live |
What a real VAPT engagement costs and how long it takes
Budget and calendar are where good intentions collide with reality. The badge does not change the physics of the work; a proper penetration test takes time and skilled people. Indicative ranges for the Indian market, empanelled firms, per assessment cycle:
| Engagement type | Typical INR range | Typical duration |
|---|---|---|
| Web or mobile application VAPT (per app) | INR 60,000 to 2,50,000 | 1 to 3 weeks |
| External network VAPT (per /24 or defined range) | INR 80,000 to 3,00,000 | 1 to 2 weeks |
| Internal network and Active Directory VAPT | INR 1,50,000 to 6,00,000 | 2 to 4 weeks |
| API security assessment | INR 75,000 to 2,50,000 | 1 to 2 weeks |
| Full regulatory VAPT programme (banking or fintech, multi-asset, with retest) | INR 6,00,000 to 25,00,000+ | 4 to 10 weeks |
Two cost lessons from the audit room. First, the cheapest quote is almost always a scan, and a scan will not survive an RBI or SEBI examination as a penetration test. Second, budget for the retest. Findings you never close are findings the examiner will hold against you, so the engagement is not done when the report lands, it is done when the highs and criticals are retested and signed off. Firms that price the retest as an afterthought are telling you how they think about closure.
The buyer's checklist before you sign
Print this, or paste it into your vendor evaluation. If a prospective partner cannot clear it, keep looking.
- Verified the exact signing entity against the current CERT-In empanelled list, today, not from a certificate PDF.
- Confirmed the empanellment is current for the cycle in which your report will be dated.
- Named testers and their certifications written into the statement of work, confirmed as full-time employees.
- Scope document that maps to your real internet-facing and internal inventory, not a convenient subset.
- Methodology stated explicitly (OWASP for apps, OSSTMM or PTES-style for network) with evidence of manual exploitation.
- Retest included in scope and price, with a defined SLA for closing critical and high findings.
- Sample redacted report reviewed for depth, chained findings and business-logic testing.
- Data-handling, NDA and log-retention terms consistent with the CERT-In 2022 Directions.
- Clear mapping of the report to your specific regulator's clause so filing is straightforward.
Back to that rejected report
The CISO who got the note re-ran the whole assessment with an empanelled auditor and filed it clean the second time. The technical findings were largely the same. The difference was that this time the report could do its job, which is to stand up under examination. That is the entire point of the badge. It is not a marketing flourish. It is the thing that decides whether your six weeks of work counts.
So verify before you sign, insist on real manual testing behind the badge, and treat the retest as part of the deliverable, not a favour. If you want a second pair of senior eyes on a vendor's empanelment claim, or a VAPT run by auditors who actually sit in the examination room with you, that is the work we do at CyberSigma, hands-on, as a CERT-In empanelled team.
FAQs
Is CERT-In empanelment legally mandatory for private companies?
Not universally by a single blanket law, but in practice it is required wherever your sector regulator expects independent VAPT assurance. RBI, SEBI and IRDAI frameworks, NPCI onboarding and government safe-to-host clearances all treat CERT-In empanelled auditors as the accepted or required route. If you are regulated, assume you need it.
How do I verify a firm is genuinely empanelled?
Go to the official CERT-In website and open the current list of empanelled information security auditing organisations. Match the exact legal entity that will sign your report and confirm the listing is current for this cycle. Do not rely on a logo or an old certificate PDF.
Does empanelment mean every consultant on the team is vetted?
No. Empanelment assesses the organisation, its methodology and its named auditors. Team quality on your specific engagement still varies, so name the actual testers and their certifications in the statement of work and confirm they are full-time employees.
Can a non-empanelled firm do good VAPT?
Technically yes, some skilled boutiques are excellent. But their report may be rejected by your regulator regardless of quality, because the examiner requires independent assurance from a recognised auditor. If your work has to survive a regulatory filing, the badge is not optional.
How often do I need to run VAPT?
It depends on your regulator, but annual VAPT is a common floor, with additional testing after significant changes to internet-facing systems. RBI, SEBI and IRDAI frameworks each specify periodic testing, and examiners check that your last report falls within the required window.
Is a vulnerability scan the same as a penetration test?
No, and conflating them is a frequent audit failure. A scan is automated and finds known issues. A penetration test adds manual exploitation, chained attacks and business-logic testing by a human. Regulators expect genuine VAPT, so ask for evidence of manual work, not just scanner output.
Liked the post? Share on:




Leave A Comment