Cybersecurity requirements for insurance web aggregators are among the strictest for any IRDAI intermediary, because your platform sells insurance and holds policyholder data. Here is exactly what the guidelines demand, and how a lean team meets it.
The short answer
Cybersecurity requirements for insurance web aggregators come from the IRDAI Information and Cyber Security Guidelines. Because an aggregator runs an Insurance Self-Network Platform, it must pass an annual ISNP security audit covering its web app, mobile app, APIs, and infrastructure, appoint an independent CISO, run VAPT at least twice a year with critical findings closed in 30 days, report critical incidents to CERT-In within six hours, and manage third-party risk. Under the 2026 tier classification, aggregators sit at a higher control tier regardless of revenue.
On this page
Why the cybersecurity requirements for insurance web aggregators are strict
A web aggregator is a customer-facing platform that compares and sells insurance online, which means it sits directly on the flow of policyholder data. The Insurance Regulatory and Development Authority of India names web aggregators explicitly as an intermediary bound by its Information and Cyber Security Guidelines, so these requirements apply to aggregators in full. Unlike an agent, an aggregator operates its own digital platform, so it carries the heavier, platform-level obligations rather than a minimum baseline.
The ISNP platform audit
The requirement that most defines these obligations is the Insurance Self-Network Platform audit. An ISNP is the website or app an aggregator runs with IRDAI permission to transact insurance online, and it must be security-reviewed at least once a year, and often before go-live.
The ISNP audit is not a website scan. It covers the web application, the mobile app and its customer journeys, the APIs that pipe data between the aggregator, insurers, and partners, and the underlying infrastructure and access controls. API security matters especially here, because an aggregator’s whole model is moving data between parties. A grounding in the types of VAPT helps scope this correctly across all four surfaces.
Your tier and the web-aggregator special rule
The cybersecurity requirements for insurance web aggregators also scale with size. The 2026 version of the guidelines added a formal three-tier classification of intermediaries by gross insurance revenue, and your tier sets how intense your controls must be.
Larger intermediaries by revenue fall into the higher categories with the heaviest controls, and smaller ones into lighter tiers. But there is a special rule that matters directly to aggregators: because aggregators and ISNP operators run a public transaction platform, they are placed at a higher control tier regardless of their revenue. In short, you do not get the light-tier treatment just because you are small, running the platform is what sets your obligations.
The core cybersecurity requirements for insurance web aggregators
Alongside the platform audit, a common set of controls completes the picture. These formalise strong practice into mandatory, evidenced duties.
In practice that means an independent Chief Information Security Officer who does not report to the head of IT and carries no business targets, a vulnerability assessment and penetration testing programme run at least twice a year across web, mobile, and API surfaces, cyber incident reporting to CERT-In within six hours, an annual audit by a CERT-In empanelled auditor, third-party risk management for every data partner, and data protection with encryption and access control. Together these are the operating core of the obligations.
Testing cadence and incident reporting
Two timelines sit at the heart of day-to-day compliance. VAPT must run at least twice a year, and any critical or high-severity finding has to be remediated within thirty days. An internet-facing platform carrying an open high finding past that window is a common failure.
On incidents, critical events such as a breach or ransomware must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and other incidents within twenty-four hours. Because the clock starts at detection, meeting it is really a demand for monitoring good enough to catch and confirm an incident fast. An automated scan alone will not satisfy the testing requirement, our guide on VAPT versus vulnerability scanning explains why skilled, human-led testing is what an ISNP audit expects.
How Osto helps aggregators comply
Meeting all of this, an ISNP-grade platform audit, a twice-yearly VAPT cadence across web, mobile, and API, six-hour-ready incident detection, vendor risk, and an audit-ready file, is a heavy lift for a lean aggregator without a dedicated security team. Piecing it together from separate tools and consultants is slow and hard to keep current, which is the gap Osto is built to close.
Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. For a web aggregator, it runs VAPT across your web application, mobile app, and APIs, correlates security events so incidents surface fast enough to report on time, supports encryption, data-handling, and third-party risk controls, and keeps organised, audit-ready evidence mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets your platform audit-ready and keeps it there, so the ISNP audit becomes a verification rather than a scramble.
Get your ISNP audit-ready without a big team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Test your web, mobile, and API surfaces, stand up monitoring for fast incident reporting, manage vendor risk, and keep audit-ready evidence, on one platform. No security team required.
Book a Demo →Frequently asked questions
Do IRDAI cybersecurity rules apply to web aggregators?
Yes. Web aggregators are named explicitly as an insurance intermediary bound by the IRDAI Information and Cyber Security Guidelines. Because they run a public platform, they carry heavier, platform-level obligations than agents.
What is an ISNP security audit?
An Insurance Self-Network Platform audit is a security review of the platform an aggregator runs with IRDAI permission to sell insurance online. It covers the web application, mobile app, APIs, and infrastructure, and is required at least annually, often before go-live.
How often must a web aggregator run VAPT?
At least twice a year, across web, mobile, and API surfaces, with critical and high-severity findings remediated within thirty days. Evidence of remediation is checked at the annual audit.
Does the tier classification affect web aggregators?
Yes, but with a special rule. Intermediaries are tiered by gross insurance revenue, yet web aggregators and ISNP operators are placed at a higher control tier regardless of revenue, because they run a public transaction platform.
What is the incident reporting timeline for aggregators?
Critical incidents must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. The clock runs from detection.
Who conducts the audit, and can Osto do it?
The annual audit is conducted by a CERT-In empanelled auditor. Osto gets your platform audit-ready, running VAPT, monitoring, and evidence, but it does not act as the empanelled auditor or as an insurer.

