We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

Why CERT-In Empanelment Matters When Choosing a VAPT Partner

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Why CERT-In Empanelment Matters When Choosing a VAPT Partner

A CISO forwarded me a VAPT report last year with a note that read: our regulator rejected this. VAPT here means Vulnerability Assessment and Penetration Testing. The report itself was competent enough. The scanner findings were mapped, the screenshots were there, the CVSS scores were computed. The problem was the letterhead. The firm that signed it was not CERT-In empanelled, and the RBI examiner would not accept a network security audit from a non-empanelled auditor. Six weeks of work, a decent chunk of budget, and it could not be filed.

That is the quiet trap most teams walk into. You choose a VAPT partner on price, or on a slick deck, or because someone knew someone. Then at the moment it matters most, when the report has to survive a regulatory examination, it turns out the badge on the cover page was the thing that actually mattered. This piece is about that badge, what it really means, why more regulators and enterprises now insist on it, and how you verify it in about four minutes so you never get that note.

What CERT-In empanelment actually is (and what it is not)

CERT-In is the Indian Computer Emergency Response Team, the national nodal agency for cybersecurity under the Ministry of Electronics and Information Technology (MeitY), operating under Section 70B of the Information Technology Act, 2000. It maintains a published list of information security auditing organisations that it has assessed and formally empanelled to conduct security audits, including VAPT, for government bodies and, increasingly, for the regulated private sector.

Empanelment is a capability certification of the organisation, awarded through a structured evaluation. It is not a per-report stamp, it is not the same as ISO 27001 certification, and it is not a licence to do anything and everything. Here is the distinction that trips people up: an empanelled firm still has to do good work on your engagement. The badge tells a regulator the firm met a national bar for people, process and methodology. It does not guarantee your specific report is any good. Both things have to be true at once.

What people assume empanelment meansWhat it actually means
A government licence to hack anythingA capability assessment of the auditing organisation by CERT-In
Same as ISO 27001 or SOC 2A separate MeitY-linked scheme specific to security auditing in India
Every consultant on staff is vettedThe organisation, its methodology and named auditors were assessed; team competence still varies
A permanent, one-time badgeA time-bound status that must be renewed, with defined validity cycles
Any report they sign is automatically compliantThe report still has to meet scope, depth and evidence standards on its own merits

Why the badge went from nice-to-have to non-negotiable

For years empanelment was a government-tender concern. If you sold to a PSU or a ministry, you needed an empanelled auditor. The private sector treated it as optional. That has changed, and it changed because the regulators changed.

The turning point for most enterprises was the CERT-In Directions of 28 April 2022, issued under Section 70B(6). Those directions imposed a six-hour incident reporting window for a defined list of cyber incidents, mandatory 180-day log retention within India, and clock synchronisation to NPL or NIC time sources. Suddenly every board wanted to know whether their controls would actually hold up, and the natural way to demonstrate that was an audit signed by the same authority setting the rules. Empanelment became the shorthand for defensible.

Then the sector regulators layered on top. Where a CERT-In empanelled auditor is expected or required in practice:

  • RBI: the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (effective 1 April 2024) requires periodic VAPT for banks and NBFCs, and examiners routinely expect the audit to be performed by a CERT-In empanelled organisation.
  • SEBI: the Cyber Security and Cyber Resilience Framework (CSCRF), consolidated in 2024, mandates VAPT for regulated entities such as stock brokers, depositories and AMCs, and points to CERT-In empanelled auditors for the assessment.
  • IRDAI: the Information and Cyber Security Guidelines require regular VAPT and independent assurance for insurers and intermediaries, with empanelled auditors as the accepted route.
  • NPCI and UPI ecosystem participants: security audits by CERT-In empanelled auditors are a standing expectation for onboarding and continued participation.
  • Government, PSU and CERT-In safe-to-host assessments for websites and applications going live on NIC or state infrastructure.

The pattern is consistent. When money, personal data, or public infrastructure is on the line, the Indian regulator wants the audit signed by a firm the national CERT has already vetted. Non-empanelled reports are increasingly filed and then rejected.

How a firm actually gets empanelled

Understanding the process tells you why the badge carries weight, and it tells you what questions to ask. CERT-In runs an application and evaluation cycle. In broad strokes a firm has to demonstrate the following before it makes the list:

  • A minimum bench of qualified, full-time security auditors, evidenced by named individuals and recognised certifications (typically OSCP, CEH, CISSP, CISA and similar), not a hollow subcontractor model.
  • A documented, repeatable audit methodology aligned to recognised standards such as OWASP for applications and OSSTMM or PTES-style methods for network testing.
  • A technical evaluation of the firm's capability, including a practical assessment of how it actually conducts testing rather than a paperwork exercise.
  • Legal, financial and infrastructural standing, plus signed non-disclosure and data-handling undertakings appropriate for auditing sensitive systems.
  • A commitment to CERT-In's terms, including reporting obligations and adherence to the published audit scope for empanelled work.

The status is time-bound, not perpetual. Firms have to renew, and the list is periodically refreshed. That matters to you because a firm empanelled in 2021 may have lapsed by the time you sign the contract. The badge is only useful if it is current on the day your report is dated.

What actually happens in the audit room

Let me make this concrete, because empanelment is not an abstraction, it shows up as the difference between a smooth examination and a bad afternoon. Picture a mid-size NBFC, first RBI IT examination after the 2024 Master Direction took effect. The examiner sits down and works through a predictable sequence. The questions are not about your firewall brand. They are about provenance and rigour.

What the examiner asks, roughly in this order:

  • Who performed your last VAPT, and are they CERT-In empanelled? Show me the current empanelment listing.
  • What was the scope? Was it the whole external perimeter and the internet-facing applications, or a convenient subset?
  • Was this a genuine penetration test with manual exploitation, or an automated scan relabelled as a pen test?
  • Show me the critical and high findings, the remediation dates, and the retest evidence that closed them.
  • When was the report dated, and does it fall within your required audit frequency?

On the good afternoon, the auditor's empanelment is current, the scope covers the actual attack surface, and there is a signed retest closing the high-severity items. The examiner moves on. On the bad afternoon, the firm is not on the list, and now the finding is not a technical gap, it is a governance gap: the entity did not obtain independent assurance from a recognised auditor. That reads far worse in an examination report, and it is the sort of observation that follows you into the next cycle.

Empanelled is necessary, not sufficient: how firms game it

Here is where I have to be blunt, because this is the part vendors will not tell you. The badge is being misused, and a careful buyer catches it. Watch for these moves:

The moveWhat it looks likeHow to catch it
Borrowed badgeA reseller or systems integrator claims empanelment that actually belongs to a partner firm doing the workAsk which legal entity is empanelled and which entity signs the report; they must match
Lapsed statusThe firm was empanelled two cycles ago and still uses the logoCheck the current CERT-In list on the day of contracting, not an old certificate PDF
Scanner-as-pentestAn automated Nessus or Burp scan exported and rebranded as manual VAPTAsk for evidence of manual exploitation, chained findings and business-logic testing
Scope shrinkageEmpanelled firm, but scope quietly narrowed to a handful of low-risk assetsInsist on a scope document that maps to your real internet-facing inventory
Empanelled entity, junior teamSenior name on the SOW, freshers on the keyboardName the actual testers in the contract and ask for their certifications

None of this means empanelment is theatre. It means empanelment is the entry ticket, and you still have to inspect the seat you were sold. Treat the badge as a filter that removes the clearly unqualified, then judge the firm on scope, method and people the way you would judge any serious partner.

How to verify empanelment in four minutes

Do not take a logo on a PDF as proof. The verification is fast and it is on you to do it before you sign, not after the regulator asks.

  • Go to the official CERT-In website (cert-in.org.in) and open the current list of empanelled information security auditing organisations. This is the single source of truth.
  • Match the exact legal entity name. Group and subsidiary names differ; the empanelled name must be the one that will sign your report and appear on the invoice.
  • Confirm the listing is current, not a screenshot of an older cycle. Empanelment is time-bound and periodically refreshed.
  • Cross-check the named auditors. Ask the firm to name, in the statement of work, the individuals who will test and their certifications, then confirm they are employees, not sourced hands.
  • Ask for a redacted sample report from a comparable engagement so you can see whether their VAPT is genuinely manual and evidence-rich or a dressed-up scan.

Reading empanelment against the standard you actually have to meet

Empanelment is one requirement in a stack. Do not let it crowd out the others. Map your obligations so you know what the audit has to deliver beyond the badge.

Your obligationRegulatorWhere CERT-In empanelment fits
Periodic VAPT of applications and networkRBI IT Master Direction 2024Auditor expected to be CERT-In empanelled; scope and retest evidence also assessed
VAPT under cyber resilience frameworkSEBI CSCRFCERT-In empanelled auditor is the accepted route for the mandated assessment
Regular VAPT and independent assuranceIRDAI Cyber Security GuidelinesEmpanelled auditor accepted; frequency and remediation tracking still required
Six-hour incident reporting, 180-day India log retentionCERT-In Directions, 28 April 2022Applies regardless of auditor; empanelled auditors help design and validate compliance
Safe-to-host clearance for government hostingCERT-In / NICEmpanelled auditor sign-off is mandatory for go-live

What a real VAPT engagement costs and how long it takes

Budget and calendar are where good intentions collide with reality. The badge does not change the physics of the work; a proper penetration test takes time and skilled people. Indicative ranges for the Indian market, empanelled firms, per assessment cycle:

Engagement typeTypical INR rangeTypical duration
Web or mobile application VAPT (per app)INR 60,000 to 2,50,0001 to 3 weeks
External network VAPT (per /24 or defined range)INR 80,000 to 3,00,0001 to 2 weeks
Internal network and Active Directory VAPTINR 1,50,000 to 6,00,0002 to 4 weeks
API security assessmentINR 75,000 to 2,50,0001 to 2 weeks
Full regulatory VAPT programme (banking or fintech, multi-asset, with retest)INR 6,00,000 to 25,00,000+4 to 10 weeks

Two cost lessons from the audit room. First, the cheapest quote is almost always a scan, and a scan will not survive an RBI or SEBI examination as a penetration test. Second, budget for the retest. Findings you never close are findings the examiner will hold against you, so the engagement is not done when the report lands, it is done when the highs and criticals are retested and signed off. Firms that price the retest as an afterthought are telling you how they think about closure.

The buyer's checklist before you sign

Print this, or paste it into your vendor evaluation. If a prospective partner cannot clear it, keep looking.

  • Verified the exact signing entity against the current CERT-In empanelled list, today, not from a certificate PDF.
  • Confirmed the empanellment is current for the cycle in which your report will be dated.
  • Named testers and their certifications written into the statement of work, confirmed as full-time employees.
  • Scope document that maps to your real internet-facing and internal inventory, not a convenient subset.
  • Methodology stated explicitly (OWASP for apps, OSSTMM or PTES-style for network) with evidence of manual exploitation.
  • Retest included in scope and price, with a defined SLA for closing critical and high findings.
  • Sample redacted report reviewed for depth, chained findings and business-logic testing.
  • Data-handling, NDA and log-retention terms consistent with the CERT-In 2022 Directions.
  • Clear mapping of the report to your specific regulator's clause so filing is straightforward.

Back to that rejected report

The CISO who got the note re-ran the whole assessment with an empanelled auditor and filed it clean the second time. The technical findings were largely the same. The difference was that this time the report could do its job, which is to stand up under examination. That is the entire point of the badge. It is not a marketing flourish. It is the thing that decides whether your six weeks of work counts.

So verify before you sign, insist on real manual testing behind the badge, and treat the retest as part of the deliverable, not a favour. If you want a second pair of senior eyes on a vendor's empanelment claim, or a VAPT run by auditors who actually sit in the examination room with you, that is the work we do at CyberSigma, hands-on, as a CERT-In empanelled team.

FAQs

Is CERT-In empanelment legally mandatory for private companies?

Not universally by a single blanket law, but in practice it is required wherever your sector regulator expects independent VAPT assurance. RBI, SEBI and IRDAI frameworks, NPCI onboarding and government safe-to-host clearances all treat CERT-In empanelled auditors as the accepted or required route. If you are regulated, assume you need it.

How do I verify a firm is genuinely empanelled?

Go to the official CERT-In website and open the current list of empanelled information security auditing organisations. Match the exact legal entity that will sign your report and confirm the listing is current for this cycle. Do not rely on a logo or an old certificate PDF.

Does empanelment mean every consultant on the team is vetted?

No. Empanelment assesses the organisation, its methodology and its named auditors. Team quality on your specific engagement still varies, so name the actual testers and their certifications in the statement of work and confirm they are full-time employees.

Can a non-empanelled firm do good VAPT?

Technically yes, some skilled boutiques are excellent. But their report may be rejected by your regulator regardless of quality, because the examiner requires independent assurance from a recognised auditor. If your work has to survive a regulatory filing, the badge is not optional.

How often do I need to run VAPT?

It depends on your regulator, but annual VAPT is a common floor, with additional testing after significant changes to internet-facing systems. RBI, SEBI and IRDAI frameworks each specify periodic testing, and examiners check that your last report falls within the required window.

Is a vulnerability scan the same as a penetration test?

No, and conflating them is a frequent audit failure. A scan is automated and finds known issues. A penetration test adds manual exploitation, chained attacks and business-logic testing by a human. Regulators expect genuine VAPT, so ask for evidence of manual work, not just scanner output.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity firm helping Indian businesses with VAPT, ISO 27001, PCI DSS, SOC 2 and DPDP compliance — delivered by senior auditors, not juniors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →