We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled auditor

CERT-In VAPT for government tenders

Government and PSU tenders frequently require a CERT-In empanelled auditor to perform VAPT and issue a safe-to-host confirmation before a public-facing application goes live. CyberSigma is CERT-In empanelled: we provide the empanelment evidence tenders ask for, test your application and infrastructure to the CERT-In methodology, and deliver the reports and safe-to-host confirmation on a deadline — so your bid and go-live are not held up by security clearance.

Get a free tender-VAPT scope →Book a 20-minute call
Who needs it

Who this is for

Vendors bidding for or delivering government/PSU projects where the RFP mandates VAPT by a CERT-In empanelled auditor and a safe-to-host confirmation, and departments deploying public-facing applications.

What tenders require

What the tender usually asks for

  • A CERT-In empanelled auditor (with empanelment evidence)
  • Application and infrastructure VAPT to CERT-In methodology
  • A safe-to-host confirmation for public-facing go-live
  • Evidence of closure via retest
Timeline

Deadline-driven delivery

Scoping — 2–4 days
Rapid scoping to fit the tender/go-live date.
Testing — 1–2 weeks
Application and infrastructure testing.
Confirmation — a few days
Report, retest and safe-to-host issuance.
Deliverables

What you receive

Empanelment evidence
Documentation tenders require to prove the auditor is CERT-In empanelled.
Reports + safe-to-host
CERT-In-aligned reports and the safe-to-host confirmation for go-live.
Proof

See how we’ve done it before

Relevant case study
How a bidder cleared security clearance and launched a public-facing portal on time. Read case studies →
Redacted sample deliverable
Inspect a redacted report first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Issue and commencementEffective 28 June 2022

    Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Incident reporting windowEffective 28 June 2022

    Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Log retentionEffective 28 June 2022

    ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Time synchronisationEffective 28 June 2022

    System clocks must be synchronised to NIC or NPL time sources.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Provider record-keepingEffective 28 June 2022

    Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

    CERT-In Directions (official PDF) · verified 31 July 2026
Related in this cluster

CERT-In VAPT for tenders — FAQs

Is CyberSigma CERT-In empanelled for tenders?

Yes. We are CERT-In empanelled and provide the empanelment evidence government and PSU tenders require, along with CERT-In-aligned VAPT and safe-to-host confirmations.

Can you meet a tight tender deadline?

Yes. We scope in 2–4 days and prioritise testing to fit tender and go-live dates, delivering reports, retest and safe-to-host issuance on schedule.

Meet your tender security requirement

We provide empanelment evidence, test to CERT-In methodology and issue safe-to-host on your deadline. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your CERT-In VAPT for government tenders requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.