We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · Insurance

IRDAI cybersecurity audit

IRDAI’s Information and Cyber Security Guidelines require insurers, intermediaries and insurance-tech entities to run periodic information-security audits, VAPT and board-level cyber governance. CyberSigma is a CERT-In empanelled auditor: we assess your security controls, VAPT posture, third-party/cloud risk and incident readiness against the applicable IRDAI guidelines, and deliver a board-ready audit report and remediation plan you can file and defend.

Get a free IRDAI readiness snapshot →Book a 20-minute call
Who needs it

Who this applies to

Insurers (life, general, health), corporate agents, brokers, web-aggregators and insurance-tech entities regulated by IRDAI, on a scale-appropriate basis.

Scope

What the audit covers

Governance & policy
Board oversight, CISO function, policies and risk management.
Controls & VAPT
Access control, network security, logging, and application/infrastructure VAPT.
Third-party & resilience
Vendor/cloud risk, business continuity, incident response and reporting.
Timeline & cost

Timeline and cost factors

Timeline
Typically 3–6 weeks depending on entity size, systems and whether VAPT is bundled.
Cost factors
Entity size, number of applications and third parties, and remediation support scope.
Deliverables

What you receive

IRDAI-mapped audit report
Findings mapped to the applicable IRDAI guidelines, board-ready.
VAPT + closure
Application and infrastructure testing with retest evidence.
Common failures

Common findings

  • Weak third-party and cloud governance
  • Incomplete logging/monitoring and untested incident response
  • VAPT findings without documented closure
  • Board-reporting and governance gaps
Proof

See how we’ve done it before

Relevant case study
How an insurer evidenced IRDAI cyber-audit and VAPT closure to its board. Read case studies →
Redacted sample deliverable
Inspect a redacted report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

IRDAI cyber audit — FAQs

Who must comply with IRDAI cyber-security guidelines?

IRDAI-regulated entities — insurers, intermediaries, web-aggregators and insurance-tech — on a scale-appropriate basis, with periodic audits and VAPT.

Is VAPT part of the audit?

Yes. As a CERT-In empanelled auditor we combine the governance audit with application and infrastructure VAPT and document closure.

Talk to our insurance audit practice

We map your applicable IRDAI guidelines, run the audit and VAPT, and give you a board-ready report. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your IRDAI cybersecurity audit requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.