We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

CERT-In Empanelment Explained: Why It Matters for Your Audit

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

CERT-In Empanelment Explained: Why It Matters for Your Audit

A procurement head at a mid-size NBFC once forwarded us a VAPT report and asked one question: is this valid? It was forty pages, neatly formatted, with CVSS scores and screenshots. It was also worthless for what she actually needed, because the firm that produced it was not CERT-In empanelled, and her RBI cyber-audit clause required exactly that. She had paid, she had a report, and she still had a finding waiting for her.

That is the gap almost nobody explains to buyers. Empanelment is not a quality badge you can safely ignore. In several Indian regulatory contexts it is the difference between an audit that closes a gap and an audit that becomes one.

What CERT-In empanelment actually is

CERT-In is the Indian Computer Emergency Response Team, the national nodal agency for cybersecurity incidents, operating under the Ministry of Electronics and Information Technology (MeitY). Under Section 70B of the Information Technology Act, 2000, CERT-In is empowered to issue directions and to maintain a panel of information security auditing organisations. That panel is the empanelment.

So when someone says they are CERT-In empanelled, they mean their organisation has passed CERT-In's evaluation and appears on the official list of auditors that CERT-In recognises for third-party information security audits. It is an organisational status, not an individual certification. A single auditor cannot be empanelled; the firm is.

This matters because of how the panel is used downstream. Regulators and public bodies do not each run their own auditor-vetting programme. They point at the CERT-In panel and say: use one of these. The empanelment therefore carries weight far beyond CERT-In's own incident-response remit.

What it is not

  • It is not a certification of your organisation. Empanelment certifies the auditor, not the audited. You do not get empanelled by passing an audit.
  • It is not the same as ISO 27001 certification or a PCI DSS Attestation of Compliance. Those are separate frameworks with their own accredited bodies (ISO via accredited certification bodies, PCI via the PCI SSC's QSA programme).
  • It is not permanent. Empanelment is granted for a defined term and must be renewed, and CERT-In can and does refresh the panel.
  • It is not a guarantee of competence on your specific stack. It means the firm cleared a bar; it does not mean every engineer they field knows your OT network or your UPI switch.

Why it matters for your audit and not just on paper

The honest answer is that empanelment matters because other people's rules make it matter. Let me be concrete about who those people are, because this is where buyers get burned.

The Reserve Bank of India (RBI) is the biggest driver. RBI's cybersecurity frameworks for banks, its Master Direction on Digital Payment Security Controls, and its guidelines for NBFCs and cooperative banks repeatedly require independent security audits and VAPT (Vulnerability Assessment and Penetration Testing) by empanelled auditors. When an RBI inspection team reviews your audit trail, one of the first things they check is whether the auditor was on the CERT-In panel at the time of the engagement. A report from a non-empanelled firm does not close the requirement. It reopens it.

SEBI (the Securities and Exchange Board of India) does the same through its Cyber Security and Cyber Resilience Framework for market infrastructure institutions, stock brokers, depositories and mutual funds. UIDAI, which runs Aadhaar, mandates audits by CERT-In empanelled auditors for AUAs and KUAs (authentication and KYC user agencies). NPCI attaches empanelment expectations to onboarding for UPI and other payment participants. Government departments procuring security audits under GIGW and various e-governance rules default to the panel.

So the reason your audit needs an empanelled firm is rarely CERT-In itself knocking on your door. It is your own regulator, your payment network, or your enterprise customer's vendor-risk team reading your audit report and checking the letterhead against a list.

Who requires itIn which contextWhat they check
RBIBank/NBFC/UCB cyber frameworks, Digital Payment Security Controls MDVAPT and IS audit by empanelled auditor, at engagement date
SEBICyber Security and Cyber Resilience FrameworkIndependent audit and VAPT for MIIs, brokers, DPs
UIDAIAadhaar AUA/KUA complianceAudit by CERT-In empanelled organisation
NPCIUPI and payment participant onboardingSecurity audit from panel firm as part of go-live
Enterprise buyersVendor security due diligenceEmpanelled VAPT report before contract sign-off

What actually happens in the audit room

Picture a Tuesday at a payments company preparing for RBI's off-site scrutiny. The compliance lead has a shelf of reports. We sit down and go clause by clause, and within twenty minutes three things surface that no glossy report had flagged.

First, the previous year's VAPT was scoped to the corporate website and a couple of internal apps. The actual payment switch, the piece RBI cares most about, was never in scope. The report was clean because the risky thing was never tested. Second, the retest was missing. The framework expects that identified vulnerabilities are fixed and then verified by retest; there were closure emails but no evidence of the retest itself. Third, the report was signed by a firm that had been empanelled the previous cycle but had lapsed and not renewed before this engagement. All three are findings. None of them are exotic. They are the ordinary ways audits fail.

This is the part practitioners understand and buyers do not: the value of the audit is in the scope, the evidence chain, and the auditor's standing, not in the page count. A thin, correctly scoped report from a currently empanelled firm with a clean retest trail beats a thick one every time.

What a real auditor will ask you

  • Show me your asset inventory and network diagram, and tell me which of these are in scope and why the rest are out.
  • Where is the payment application, the database, and the crypto/key management, and are they in this year's VAPT scope?
  • For last year's high and critical findings, show me the fix and the retest evidence, not the closure email.
  • Who has privileged access to production, and where is the review log for that access?
  • When was your last incident, and can you show the CERT-In reporting record within the mandated timeline?

The 2022 Directions everyone forgets to mention

Empanelment is often discussed as an audit-procurement issue. But CERT-In's own directions of 28 April 2022 (issued under Section 70B(6)) put obligations directly on you, the audited entity, regardless of who your auditor is. If you operate in India and you skip these, an empanelled audit will still write you up.

  • Report specified cyber incidents to CERT-In within six hours of noticing them. Not six days. Six hours. This single clause catches more organisations off guard than any technical control.
  • Maintain ICT system logs for a rolling period of 180 days, within Indian jurisdiction, and produce them when directed.
  • Synchronise all system clocks to NIC or NPL time servers, so that log timelines are consistent and defensible.
  • Data centres, VPS providers, cloud providers and VPN providers must maintain specified subscriber and KYC records for five years.
  • Virtual asset and exchange providers have their own KYC and record obligations under the same directions.

The six-hour reporting window is the one to internalise. Build the runbook now, with the contact path and the template, because you cannot draft it calmly during a live incident. A good empanelled auditor will test whether that runbook exists and whether anyone has ever rehearsed it.

How to verify a firm is genuinely empanelled

Do not take the logo on the proposal at face value. Empanelment status changes between cycles, and some firms keep old badges up. Verify it the way an examiner would.

  • Check the current empanelled-auditor list published on the CERT-In website (certin.org.in) and confirm the firm's exact legal name appears on it.
  • Confirm the empanelment is valid for the dates of your engagement, not just at some point in the past. Ask for the empanelment letter with its validity period.
  • Ask which category or scope of audit they are empanelled for, and match it to what you actually need (application, network, cloud, source code review).
  • Ask who will actually execute the work and what their credentials are (OSCP, CREST, CEH, ISO 27001 Lead Auditor, PCI QSA where relevant). Empanelment is organisational; competence is per-person.
  • Get the scope, methodology and retest terms in writing before you sign, so the deliverable maps to your regulator's clause.
SignalGreen flagRed flag
Panel listingExact legal name on current CERT-In listOnly a logo, name not found on list
ValidityEmpanelment covers engagement datesLapsed or renewal pending
Scope clarityWritten scope tied to your regulator's clauseGeneric VAPT with no crown-jewel systems named
RetestRetest included and evidencedClosure by email only, no verification
PeopleNamed, certified testersAnonymous team, no credentials shared

What it costs and how long it takes

Buyers ask for a number and get frustrated when the honest answer is that it depends on scope. It genuinely does, but you can plan around realistic ranges. These are indicative Indian market figures for a currently empanelled firm; complex payment, cloud-native or OT environments sit at the upper end or beyond.

Engagement typeTypical INR rangeTypical duration
Web/mobile application VAPT (single app)1,00,000 to 3,50,0001 to 3 weeks
Network VAPT (external + internal, mid-size)1,50,000 to 5,00,0002 to 4 weeks
Full RBI-aligned IS audit + VAPT (NBFC)5,00,000 to 15,00,0004 to 8 weeks
Cloud configuration and architecture review2,00,000 to 6,00,0002 to 4 weeks
Retest of remediated findings20 to 35 percent of original3 to 7 days

Two cost lessons practitioners learn the hard way. First, the cheapest quote is usually the most expensive one, because a thin scope means a reopened finding and a second audit under regulatory pressure. Second, budget for the retest up front. Every serious framework expects verified closure of high and critical findings, and if you have not planned for the retest you will scramble for it at quarter-end.

Your fix-it checklist before you engage an auditor

  • Confirm the firm's exact legal name on the current CERT-In empanelled list and get the empanelment letter with valid dates.
  • Write the scope yourself first: list your crown-jewel systems (payment switch, core database, key management, admin panels) and insist they are in scope.
  • Map each regulator clause you must satisfy (RBI, SEBI, UIDAI, NPCI) to a line item in the audit scope.
  • Get retest terms and timelines in the contract, not as an afterthought.
  • Ask for the named testers and their certifications, and reject anonymous teams.
  • Stand up your CERT-In six-hour incident-reporting runbook and 180-day log retention before the audit, because they will be tested.
  • Fix your clock synchronisation to NIC or NPL sources so your logs are defensible.
  • Keep the previous audit's findings, fixes and retest evidence in one place, so year-on-year closure is provable.

The point most reports miss

That NBFC procurement head did not have a bad report. She had a report that did not do the one job it needed to do, because empanelment was treated as a footnote instead of a requirement. The lesson is not that empanelment is magic. It is that the audit only counts if the right firm, currently on the panel, tests the right systems and proves the fixes. Everything else is paper.

At CyberSigma we sit on the CERT-In panel and do this work hands-on, scoping to the crown jewels and carrying findings through to verified retest. If you want a second set of senior eyes on a scope or a report before you commit, that conversation is one we are happy to have.

FAQs

Does my company become CERT-In empanelled after passing an audit?

No. Empanelment is a status held by the auditing firm, not the audited organisation. You cannot become empanelled by passing an audit. What you get is a valid audit report from an empanelled auditor, which is what your regulator or customer asks for.

Is a CERT-In empanelled VAPT the same as ISO 27001 or PCI DSS?

No. They are separate frameworks. ISO 27001 is an information security management system certification issued by accredited certification bodies. PCI DSS applies to cardholder data and is assessed by QSAs under the PCI SSC. CERT-In empanelment is about the auditor's recognition for Indian third-party security audits. You may need more than one depending on your regulators and your business.

How do I check if an auditor is really empanelled?

Look up the firm's exact legal name on the current empanelled-auditor list on the CERT-In website, confirm the empanelment is valid for your engagement dates, and ask for the empanelment letter. Do not rely on a logo on a proposal, because panels are refreshed and some firms display lapsed status.

What is the CERT-In six-hour incident reporting rule?

Under CERT-In's April 2022 directions, organisations in India must report specified cyber incidents to CERT-In within six hours of noticing them. You should have a runbook, contact path and template ready in advance, because six hours is not enough time to design a reporting process during a live incident.

How much does a CERT-In empanelled audit cost in India?

It depends on scope. A single application VAPT typically runs from around 1,00,000 to 3,50,000 INR, while a full RBI-aligned IS audit and VAPT for an NBFC can run from 5,00,000 to 15,00,000 INR or more. Budget separately for the retest, usually 20 to 35 percent of the original fee.

Why does RBI care whether my auditor is empanelled?

RBI's cybersecurity and digital payment frameworks require independent audits and VAPT by empanelled auditors. During inspection, RBI checks that your auditor was on the CERT-In panel at the time of the engagement. A report from a non-empanelled firm does not satisfy the clause and becomes a finding you have to remediate.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity firm helping Indian businesses with VAPT, ISO 27001, PCI DSS, SOC 2 and DPDP compliance — delivered by senior auditors, not juniors.

Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →