We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Government bodies

CERT-In Audit for Government Departments and PSUs

Government departments and PSUs cannot host public-facing applications without a security audit by a CERT-In empanelled organisation, and tenders name the empanelment explicitly. The audit is a gate on go-live, which makes timing as important as findings.

What CERT-In requires of government bodies

  • Audit by an organisation on the current CERT-In empanelled list — verified against the published list, not a logo.
  • Safe-to-host certification for public-facing applications before deployment.
  • Alignment with GIGW where the application is citizen-facing, including accessibility obligations.
  • Incident reporting within six hours of detection, and log retention for 180 days in Indian jurisdiction.
  • Retest and closure evidence — a safe-to-host certificate follows remediation, not the first report.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Audit report from the empanelled organisation, with the empanelment reference
  • Safe-to-host certificate covering the deployed version
  • Retest evidence closing every high and critical finding
  • Log retention configuration meeting the 180-day requirement
  • GIGW/accessibility conformance where citizen-facing

Where government bodies usually come unstuck

  • Auditing a build that then changes before go-live, invalidating the certificate.
  • Accepting an empanelment claim without checking the current published list.
  • Log retention configured outside Indian jurisdiction.

Related

CERT-In empanelled VAPTGovernment sectorCERT-In for tendersCERT-In cost & timeline
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your CERT-In requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →