Cybersecurity Audit · India
Cybersecurity Audit in India
Independent cybersecurity audits mapped to the CERT-In Directions, RBI's IT and cyber directions, SEBI's CSCRF and IRDAI's guidelines — alongside ISO 27001 — for organisations in Bengaluru, Mumbai, Delhi NCR, Hyderabad, Chennai and Pune.
Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm
A cybersecurity audit in India is an independent review of your security controls against the framework your sector actually answers to — the CERT-In Directions issued under Section 70B(6) of the IT Act 2000, the RBI's IT governance and cyber-security directions for regulated entities, SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for market participants, and IRDAI's guidelines for insurers — usually alongside ISO 27001. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA); we scope the framework your regulator genuinely checks, test the controls against evidence, and hand you a prioritised, regulator-ready report.
Which Indian regulations actually require a cybersecurity audit?
There is no single 'Indian cybersecurity law'. What applies depends on your sector and your regulator, and an audit is only useful if it is scoped to the framework that will actually be checked. These are the ones we most often map to:
- CERT-In Directions (28 April 2022, in force from 28 June 2022) — issued under Section 70B(6) of the Information Technology Act, 2000. They apply broadly to service providers, intermediaries, data centres, body corporates and government organisations, and carry concrete obligations: report specified cyber incidents within six hours of noticing them, retain ICT logs for 180 days within Indian jurisdiction, and synchronise system clocks to NIC or NPL time servers.
- RBI — the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, together with the cyber security framework for banks and the directions on outsourcing of IT services. These apply to banks, NBFCs, payment system operators and other regulated entities, and expect periodic independent assurance rather than self-attestation.
- SEBI CSCRF — the Cybersecurity and Cyber Resilience Framework consolidating SEBI's earlier cyber circulars for regulated entities across market infrastructure institutions, intermediaries and asset managers.
- IRDAI — information and cyber security guidelines for insurers, brokers and intermediaries, including periodic audit and board-level reporting expectations.
- DPDP Act 2023 — a Significant Data Fiduciary must appoint a Data Protection Officer, run data protection impact assessments and commission an independent data audit. That is a statutory audit obligation rather than a best practice, and it is being phased in alongside the DPDP Rules, 2025 (notified 13 November 2025), with the substantive duties commencing in May 2027.
- ISO/IEC 27001:2022 — the international baseline most Indian enterprises certify against for customers and tenders, and which underpins much of the sectoral guidance above.
What a CERT-In empanelled audit actually covers
We run the audit as an evidence-based gap assessment, not a documentation walk-through. Across a typical engagement we:
- Confirm scope and the applicable framework(s) for your sector and regulator, so you are not assessed against controls that do not apply to you.
- Review governance, policy, risk management and board reporting against the standard's management controls.
- Technically validate the controls that matter — identity and access, network segmentation, logging and monitoring, backup and recovery, and cloud configuration — rather than taking documents at face value.
- Check the CERT-In obligations specifically: whether your incident-response process can actually meet the six-hour reporting window, whether logs are retained for 180 days inside India, and whether time synchronisation is configured as directed.
- Test the process and people layers: third-party and vendor risk, incident-response readiness, and staff security awareness.
- Deliver a findings report mapped clause-by-clause to your regulator's controls, with a remediation plan ordered by risk.
- Re-test after remediation, so you can evidence closed findings — not just identified ones.
Representative engagement: an NBFC preparing for an RBI inspection
A useful way to picture the work: an NBFC expecting an RBI inspection needed assurance against the RBI's IT governance direction while also holding ISO 27001 for its enterprise customers. We scoped a single combined assessment, so they ran one evidence-gathering exercise rather than two, mapped each finding to both frameworks, and produced one remediation backlog ordered by risk. The outcome that mattered to their board was that they could answer the inspector's questions with dated evidence rather than intentions. This example is representative of how we structure Indian audits; named client references are available under NDA on request.
How long does an Indian cybersecurity audit take, and what does it cost?
Most audits run a few weeks end to end, depending on the number of in-scope systems, locations and frameworks. Cost follows that scope rather than a fixed list price, so we run a short, free discovery call, agree the scope in writing, and give you a fixed quote before any work starts — no open-ended day rates. If you are working to a regulator or customer deadline, tell us the date and we will tell you honestly whether it is achievable.
Why CyberSigma for an Indian audit
We are CERT-In empanelled — which matters directly when a government department, PSU or regulated entity requires an empanelled auditor's report — and PCI QSA authorised across CEMEA, Asia Pacific and the USA. We audit against India's own frameworks rather than a generic global template, so you get an assessor who knows which controls your regulator actually enforces, a report written for that regulator, and a remediation partner who will re-test the fixes.
Related services
Data privacy audit
DPDP Act readiness, consent, rights and breach response.
VAPT & penetration testing
Web, mobile, API, network and cloud penetration testing.
National cyber compliance
CERT-In Directions readiness and sectoral cyber mandates.
AI security
Security and governance for AI and LLM systems.
Frequently asked questions
Is a cybersecurity audit mandatory in India?
It depends on your sector. Banks, NBFCs and payment system operators answer to the RBI; market intermediaries to SEBI's CSCRF; insurers to IRDAI — all of which expect periodic independent assurance. Under the DPDP Act 2023, an entity notified as a Significant Data Fiduciary must commission an independent data audit. Separately, the CERT-In Directions apply broadly regardless of sector. Even where an audit is not strictly mandatory, government tenders and enterprise customers increasingly require ISO 27001 or a CERT-In empanelled auditor's report.
What does CERT-In empanelment mean, and why does it matter?
CERT-In maintains a list of information security auditing organisations it has empanelled to audit government and critical-sector systems. Many government, PSU and regulated-sector tenders require the audit to be performed by an empanelled organisation, and will not accept a report from one that is not. CyberSigma is empanelled, so our report is accepted where empanelment is a condition.
What are the CERT-In Directions and the six-hour reporting rule?
The Directions issued on 28 April 2022 under Section 70B(6) of the IT Act took effect on 28 June 2022. They require specified cyber incidents to be reported to CERT-In within six hours of being noticed, ICT logs to be maintained for a rolling 180 days within Indian jurisdiction, and system clocks to be synchronised to NIC or NPL time servers. Service providers, data centres, VPS, cloud and VPN providers also have customer record-keeping obligations. Most organisations discover in an audit that the six-hour window is a process problem, not a technology one.
Does the DPDP Act require an audit?
For Significant Data Fiduciaries, yes — the Act requires them to appoint a Data Protection Officer based in India, carry out data protection impact assessments, and have an independent data audit conducted. Those duties are being phased in with the DPDP Rules, 2025 (notified 13 November 2025), the substantive obligations commencing in May 2027. Other data fiduciaries still carry duties around notice, consent, security safeguards, breach reporting and data principal rights, which an audit is the practical way to evidence. We cover this in detail on our data privacy audit page.
How often should we run a cybersecurity audit?
At least annually, and again after any material change — a new core system, a cloud migration, a merger, or a serious incident. Several Indian frameworks expect a regular assessment cycle, and customers in regulated supply chains routinely ask for evidence dated within the last 12 months.
Can one audit cover RBI, SEBI and ISO 27001 together?
Usually yes, and it costs less than running them separately. Because the underlying controls overlap heavily, we gather evidence once and map it to each applicable framework, then give you a single risk-ordered remediation plan instead of three competing ones.
Sources & references
- Digital Personal Data Protection Act, 2023 — official Gazette text — Act No. 22 of 2023, as published in the Gazette of India
- Digital Personal Data Protection Rules, 2025 — MeitY — notified 13 November 2025 (G.S.R. 843(E)); commences in phases
- CERT-In (Indian Computer Emergency Response Team) — the national nodal agency under Section 70B of the IT Act 2000
- CERT-In Directions under Section 70B(6), 28 April 2022 — the binding directions text — incident reporting, log retention and NTP synchronisation
- Reserve Bank of India — IT governance, cyber security and outsourcing directions for regulated entities
- Securities and Exchange Board of India — the Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities
- Insurance Regulatory and Development Authority of India — information and cyber security guidelines for insurers and intermediaries
- ISO/IEC 27001 — information security management — the international baseline most Indian enterprises certify against

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
