We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled auditor

CERT-In audit cost and timeline

A CERT-In audit (empanelled-auditor VAPT plus, where required, a safe-to-host confirmation) is priced by the number of applications, APIs and network hosts in scope, the testing depth, and the number of retest cycles — not a flat rate. Timeline is typically 2–4 days scoping, 1–3 weeks testing, and a few days for the report and free retest. CyberSigma is a CERT-In empanelled auditor: we scope in a short call, return a fixed quote and start date, and sequence testing to meet tender or go-live deadlines.

Get a fixed CERT-In audit quote →Book a 20-minute call
Cost factors

What drives CERT-In audit cost

  • Number of applications, APIs, mobile apps and network hosts in scope
  • Grey-box vs black-box, and whether source-code review is included
  • Whether a safe-to-host confirmation is required for go-live
  • Number of retest cycles and reporting depth for regulators/tenders
Timeline

Typical timeline

Scoping — 2–4 days
Asset inventory, rules of engagement and a fixed quote.
Testing — 1–3 weeks
By the number of applications and hosts in scope.
Report & retest — 3–5 days
Prioritised report, then a free retest and (where needed) safe-to-host issuance.
When you need it

When a CERT-In audit is required

For RBI/SEBI/IRDAI obligations, government and PSU tenders that mandate an empanelled auditor, NIC/department hosting go-live, and enterprise customer security reviews.

Deliverables

What you receive

CERT-In-aligned reports
Executive and technical reports with proof-of-concept and remediation.
Safe-to-host + closure
Safe-to-host confirmation where required, and retest evidence of closure.
Proof

See how we’ve done it before

Relevant case study
How a scoped CERT-In audit met a tender deadline with evidenced closure. Read case studies →
Redacted sample deliverable
Inspect a redacted report first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Issue and commencementEffective 28 June 2022

    Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Incident reporting windowEffective 28 June 2022

    Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Log retentionEffective 28 June 2022

    ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Time synchronisationEffective 28 June 2022

    System clocks must be synchronised to NIC or NPL time sources.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Provider record-keepingEffective 28 June 2022

    Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

    CERT-In Directions (official PDF) · verified 31 July 2026
Related in this cluster

CERT-In audit cost & timeline — FAQs

How much does a CERT-In audit cost?

It depends on the number of applications, APIs and hosts, testing depth, and whether a safe-to-host confirmation and retests are included. We provide a fixed quote after a short scoping call.

How quickly can it be done?

Scoping 2–4 days, testing 1–3 weeks by scope, then report and free retest in a few days. Tender deadlines can be prioritised.

Get a fixed CERT-In audit quote

A short scoping call and we return a fixed price, start date and timeline that meets your deadline. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your CERT-In audit requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.