CERT-In audit cost and timeline
A CERT-In audit (empanelled-auditor VAPT plus, where required, a safe-to-host confirmation) is priced by the number of applications, APIs and network hosts in scope, the testing depth, and the number of retest cycles — not a flat rate. Timeline is typically 2–4 days scoping, 1–3 weeks testing, and a few days for the report and free retest. CyberSigma is a CERT-In empanelled auditor: we scope in a short call, return a fixed quote and start date, and sequence testing to meet tender or go-live deadlines.
What drives CERT-In audit cost
- Number of applications, APIs, mobile apps and network hosts in scope
- Grey-box vs black-box, and whether source-code review is included
- Whether a safe-to-host confirmation is required for go-live
- Number of retest cycles and reporting depth for regulators/tenders
Typical timeline
When a CERT-In audit is required
For RBI/SEBI/IRDAI obligations, government and PSU tenders that mandate an empanelled auditor, NIC/department hosting go-live, and enterprise customer security reviews.
What you receive
See how we’ve done it before
Is your application one bug away from a breach?
Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.
CERT-In audit cost & timeline — FAQs
How much does a CERT-In audit cost?
It depends on the number of applications, APIs and hosts, testing depth, and whether a safe-to-host confirmation and retests are included. We provide a fixed quote after a short scoping call.
How quickly can it be done?
Scoping 2–4 days, testing 1–3 weeks by scope, then report and free retest in a few days. Tender deadlines can be prioritised.
Get a fixed CERT-In audit quote
A short scoping call and we return a fixed price, start date and timeline that meets your deadline. Reply within four business hours.
Book a 20-minute call →Ready to discuss your CERT-In audit requirement?
CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.
