We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · Insurance

IRDAI cybersecurity audit

IRDAI replaced its 2023 Information and Cyber Security Guidelines in April 2026 with Version 2.0, and regulated entities are expected to comply from the current financial year. It reaches further than insurers alone — foreign reinsurance branches, brokers, corporate agents, web aggregators, TPAs and insurance repositories are all in scope. CyberSigma is a CERT-In empanelled auditor: we assess your governance, controls, VAPT posture, third-party and cloud risk and incident readiness against the current guidelines, and deliver a board-ready report and remediation plan you can file and defend.

Get a free IRDAI readiness snapshot →Book a 20-minute call
What changed

The 2023 guidelines have been superseded

IRDAI issued Version 2.0 of its Information and Cyber Security Guidelines in April 2026, replacing the guidelines dated 24 April 2023. Regulated entities are expected to comply from the current financial year, so an audit programme still scoped against the 2023 text is evidencing the wrong baseline.

If your last assessment was mapped to the 2023 guidelines, the practical questions are which control expectations have moved, what your board needs to see this year, and whether entities you previously treated as out of scope — intermediaries, TPAs, repositories — are now in it. We will confirm the applicable version and reference against IRDAI’s published document before any scoping is fixed.

Who needs it

Who this applies to

The guidelines apply to all Insurers including Foreign Re-Insurance Branches (FRBs) and to Insurance Intermediaries regulated by IRDAI, covering all data created, received or maintained in any form. Insurance Agents, Micro-Insurance Agents, Point of Sale Persons and Individual Surveyors are expressly outside their purview — though Insurers remain responsible for ensuring those entities follow a minimum security framework under the Insurer’s Board-approved policy.

Who may audit you

Not every firm is permitted to perform this audit

Annexure IV of the guidelines sets two alternative routes. One is a Chartered Accountant firm registered with ICAI holding at least five years of continuous practice and four partners, including a CISA/DISA holder, an ICAI Fellow, a partner with three years of cyber or information security audit experience in insurance, banking or mutual funds, and a partner experienced in IT-environment and remote audits.

The other route, in the guidelines’ own words, is a “Cert-In empanelled external systems Auditor holding CISA / DISA certifications”. CyberSigma qualifies under that route — we are listed at Sl. No. 57 of the CERT-In empanelled organisations list, which you can verify independently at cert-in.org.in rather than taking our word for it.

The guidelines also state that certification may not rest on management representation or on reliance upon another auditor’s work: the auditor must perform interviews, document verification, compliance checks and adequate testing of controls. A questionnaire-led engagement does not meet the requirement.

Scope

What the audit covers

Governance & policy
Board oversight, CISO function, policies and risk management.
Controls & VAPT
Access control, network security, logging, and application/infrastructure VAPT.
Third-party & resilience
Vendor/cloud risk, business continuity, incident response and reporting.
Timeline & cost

Timeline and cost factors

Timeline
Typically 3–6 weeks depending on entity size, systems and whether VAPT is bundled.
Cost factors
Entity size, number of applications and third parties, and remediation support scope.
Deliverables

What you receive

IRDAI-mapped audit report
Findings mapped to the applicable IRDAI guidelines, board-ready.
VAPT + closure
Application and infrastructure testing with retest evidence.
Common failures

Common findings

  • Weak third-party and cloud governance
  • Incomplete logging/monitoring and untested incident response
  • VAPT findings without documented closure
  • Board-reporting and governance gaps
Proof

See how we’ve done it before

Relevant case study
How an insurer evidenced IRDAI cyber-audit and VAPT closure to its board. Read case studies →
Redacted sample deliverable
Inspect a redacted report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • ISNP audit duty

    Insurance Self-Network Platforms operate under IRDAI permission per the Guidelines on Insurance e-commerce (circular IRDA/INT/GDL/ECM/055/03/2017, 9 March 2017). The controls, systems, procedures and safeguards of the platform must be reviewed at least once a year, at the applicant's own cost, by an external Certified Information Systems Auditor (CISA), a Chartered Accountant holding DISA (ICAI), or a CERT-In empanelled expert, and the resulting report placed before the Board or its sub-committee.

    The governing instrument is the Guidelines on Insurance e-commerce, IRDA/INT/GDL/ECM/055/03/2017 of 9 March 2017. That guidelines PDF is not retrievable in text form from the IRDAI portal, so the citation points to IRDAI's own follow-on circular, which states the reference number and date verbatim. The audit-clause wording is corroborated across multiple independent summaries; verify against the guidelines PDF before quoting it in a deliverable.

  • Who may perform the audit (Annexure IV)Effective April 2026

    Annexure IV sets two alternative routes. Either a Chartered Accountant firm registered with ICAI (partnership or LLP) with at least five years of continuous practice and four partners, including one CISA/DISA holder, one ICAI Fellow, one with three years of cyber or information security audit experience in insurance companies, banks or mutual funds, and one with IT-environment and remote-audit experience — OR, in the guidelines’ own words, a “Cert-In empanelled external systems Auditor holding CISA / DISA certifications”. The auditor must not have been debarred or declared ineligible for corrupt or fraudulent practices by the Government of India, a State Government, IRDAI, SEBI, RBI, ICAI, CERT-In or SFIO.

    Read from the guidelines document itself (VER 2.0, April 2026, 175 pages) rather than from secondary analyses. The covering circular reference number does not appear in the guidelines body and remains unconfirmed, so it is still not cited. CyberSigma qualifies under the second route as a CERT-In empanelled auditor, without needing to meet the four-partner CA-firm test.

  • Audit report submission deadlineEffective April 2026

    Insurers must submit the Audit Report (Annexure III), signed by the auditor and accompanied by the comments of the Board, to IRDAI within 90 days from the end of the financial year OR within 30 days of completion of the audit, whichever is earlier. Foreign Reinsurance Branches whose IT systems interface with overseas parent companies must comply and have the auditor certify per Annexure VI, submitted at the end of every financial year.

    Read from the guidelines document itself (VER 2.0, April 2026, 175 pages) rather than from secondary analyses. The covering circular reference number does not appear in the guidelines body and remains unconfirmed, so it is still not cited. The “whichever is earlier” limb is the one commonly missed: completing an audit early shortens the deadline rather than extending it.

  • Management representation is not acceptableEffective April 2026

    Certification under these guidelines may not rest on management representation or on reliance upon the work of other auditors, because the auditor is appointed by regulated entities that must protect policyholder and public data. The auditor is required to perform the work through interviews, document verification, compliance checks and adequate testing of controls.

    Read from the guidelines document itself (VER 2.0, April 2026, 175 pages) rather than from secondary analyses. The covering circular reference number does not appear in the guidelines body and remains unconfirmed, so it is still not cited.

  • Information and Cybersecurity Guidelines, 2026 (current)Effective 6 April 2026

    IRDAI issued Version 2.0 of its Information and Cyber Security Guidelines in April 2026, replacing the Information and Cyber Security Guidelines, 2023 dated 24 April 2023. They apply to all Insurers including Foreign Re-Insurance Branches (FRBs) and Insurance Intermediaries regulated by IRDAI, and to all data created, received or maintained by Regulated Entities in any form. Insurance Agents, Micro-Insurance Agents, Point of Sale Persons and Individual Surveyors are expressly outside their purview, though Insurers remain responsible for ensuring those entities follow a minimum security framework under the Insurer’s Board-approved policy.

    Read from the guidelines document itself (VER 2.0, April 2026, 175 pages) rather than from secondary analyses. The covering circular reference number does not appear in the guidelines body and remains unconfirmed, so it is still not cited. An earlier version of this entry listed brokers, corporate agents, web aggregators, TPAs, ISNPs and IIB as in-scope; that enumeration came from secondary summaries and is not how the guidelines define scope.

  • Information and Cyber Security Guidelines, 2023 (superseded)Effective 24 April 2023

    IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 (ref IRDAI/GA&HR/GDL/MISC/88/04/2023), superseding the 2017 guidelines (IRDA/IT/GDL/MISC/082/04/2017) and three subsequent circulars. These were themselves superseded on 6 April 2026 by the IRDAI Information and Cybersecurity Guidelines, 2026 (Version 2.0) - the 2023 text is retained here as the previous baseline, not as the current requirement.

IRDAI cyber audit — FAQs

Are you eligible to perform the IRDAI audit?

Yes. Annexure IV permits a CERT-In empanelled external systems auditor holding CISA/DISA certifications as an alternative to the Chartered Accountant firm route. CyberSigma is listed at Sl. No. 57 of the CERT-In empanelled organisations list, which is publicly verifiable at cert-in.org.in.

Which version of the IRDAI guidelines applies now?

Version 2.0, issued in April 2026, which replaced the Information and Cyber Security Guidelines dated 24 April 2023. Compliance is expected from the current financial year. We confirm the applicable version and its reference against IRDAI’s published document at the start of every engagement rather than assuming it.

Who must comply with IRDAI cyber-security guidelines?

IRDAI-regulated entities — insurers, intermediaries, web-aggregators and insurance-tech — on a scale-appropriate basis, with periodic audits and VAPT.

Is VAPT part of the audit?

Yes. As a CERT-In empanelled auditor we combine the governance audit with application and infrastructure VAPT and document closure.

Talk to our insurance audit practice

We map your applicable IRDAI guidelines, run the audit and VAPT, and give you a board-ready report. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your IRDAI cybersecurity audit requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.