We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled auditor

Safe-to-host certificate — process and requirements

A “safe-to-host” confirmation is an attestation from a CERT-In empanelled auditor that an application and its hosting environment have been security-tested and found fit to go live — frequently required by government departments, PSUs and hosting/NIC arrangements before a public-facing launch. CyberSigma performs the VAPT, verifies remediation on a retest, and issues the safe-to-host confirmation. It attests to the testing we performed; it is a CyberSigma-issued attestation, not a third-party certificate.

Get a free safe-to-host scope →Book a 20-minute call
Who needs it

Who needs safe-to-host

Government departments, PSUs, and vendors deploying public-facing applications where a CERT-In empanelled auditor’s confirmation is a go-live gate — often tied to NIC or department hosting policies and tender conditions.

Process

The process, step by step

1. Scoping
Application, APIs and hosting environment defined; rules of engagement agreed.
2. VAPT
Application and infrastructure penetration testing to CERT-In methodology and OWASP.
3. Remediation & retest
You fix findings; we retest to confirm closure.
4. Confirmation issued
On a clean retest we issue the safe-to-host confirmation for go-live.
Requirements

What a clean confirmation requires

  • No open high/critical findings at retest
  • Secure hosting configuration and TLS
  • Patched components with no known-exploitable CVEs
  • Evidence of remediation for medium findings or a risk-accepted plan
Timeline & cost

Timeline and cost

Timeline
Scoping 2–4 days; testing 1–2 weeks; retest and issuance a few days after fixes.
Cost factors
Application count, API surface, and number of retest cycles.
Common failures

Why first attempts fail

  • Open high/critical findings at retest
  • Exposed admin panels and default credentials
  • Outdated components and missing security headers
  • Hosting misconfiguration outside the app itself
Proof

See how we’ve done it before

Relevant case study
How an application passed safe-to-host on retest and launched on schedule. Read case studies →
Redacted sample deliverable
Inspect a redacted VAPT report first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Safe-to-host — FAQs

Is a safe-to-host certificate an official certificate?

It is an attestation from a CERT-In empanelled auditor confirming the testing performed and that the application is fit to host. CyberSigma issues it as the auditor; it is not a third-party certification.

How long does it take?

Typically 2–3 weeks end to end: scoping, testing, your remediation, then a retest and issuance on a clean result.

What if findings remain?

High/critical findings must be closed before issuance. We retest after your fixes; medium findings may be risk-accepted with a documented plan where the owner permits.

Get your safe-to-host confirmation

We scope, test and retest fast so your go-live is not held up. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your Safe-to-host confirmation requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.