← Government bodies
CERT-In Audit for Government Departments and PSUs
Government departments and PSUs cannot host public-facing applications without a security audit by a CERT-In empanelled organisation, and tenders name the empanelment explicitly. The audit is a gate on go-live, which makes timing as important as findings.
What CERT-In requires of government bodies
- Audit by an organisation on the current CERT-In empanelled list — verified against the published list, not a logo.
- Safe-to-host certification for public-facing applications before deployment.
- Alignment with GIGW where the application is citizen-facing, including accessibility obligations.
- Incident reporting within six hours of detection, and log retention for 180 days in Indian jurisdiction.
- Retest and closure evidence — a safe-to-host certificate follows remediation, not the first report.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Audit report from the empanelled organisation, with the empanelment reference
- Safe-to-host certificate covering the deployed version
- Retest evidence closing every high and critical finding
- Log retention configuration meeting the 180-day requirement
- GIGW/accessibility conformance where citizen-facing
Where government bodies usually come unstuck
- Auditing a build that then changes before go-live, invalidating the certificate.
- Accepting an empanelment claim without checking the current published list.
- Log retention configured outside Indian jurisdiction.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
