Cybersecurity Requirements for Insurance Web Aggregators

Cybersecurity requirements for insurance web aggregators guide
Cybersecurity for Web Aggregators: 6 Complete Rules | Osto

Cybersecurity requirements for insurance web aggregators are among the strictest for any IRDAI intermediary, because your platform sells insurance and holds policyholder data. Here is exactly what the guidelines demand, and how a lean team meets it.

Osto Security Team10 min readIRDAI Compliance

The short answer

Cybersecurity requirements for insurance web aggregators come from the IRDAI Information and Cyber Security Guidelines. Because an aggregator runs an Insurance Self-Network Platform, it must pass an annual ISNP security audit covering its web app, mobile app, APIs, and infrastructure, appoint an independent CISO, run VAPT at least twice a year with critical findings closed in 30 days, report critical incidents to CERT-In within six hours, and manage third-party risk. Under the 2026 tier classification, aggregators sit at a higher control tier regardless of revenue.

Why the cybersecurity requirements for insurance web aggregators are strict

A web aggregator is a customer-facing platform that compares and sells insurance online, which means it sits directly on the flow of policyholder data. The Insurance Regulatory and Development Authority of India names web aggregators explicitly as an intermediary bound by its Information and Cyber Security Guidelines, so these requirements apply to aggregators in full. Unlike an agent, an aggregator operates its own digital platform, so it carries the heavier, platform-level obligations rather than a minimum baseline.

The ISNP platform audit

The requirement that most defines these obligations is the Insurance Self-Network Platform audit. An ISNP is the website or app an aggregator runs with IRDAI permission to transact insurance online, and it must be security-reviewed at least once a year, and often before go-live.

The platform
What an ISNP audit actually examines
Web aggregators run an Insurance Self-Network Platform, so the requirements centre on that platform. The audit reaches four connected surfaces, not just the website.
What the ISNP security audit coversWeb applicationThe public aggregatorsite and portalMobile appThe customer-facingapp and journeysAPIsData pipelines toinsurers and partnersInfrastructureServers, cloud, andaccess controls

The ISNP audit is not a website scan. It covers the web application, the mobile app and its customer journeys, the APIs that pipe data between the aggregator, insurers, and partners, and the underlying infrastructure and access controls. API security matters especially here, because an aggregator’s whole model is moving data between parties. A grounding in the types of VAPT helps scope this correctly across all four surfaces.

The platform is the product, and the audit knows it
For an aggregator, the ISNP is the business. An audit that only checks the marketing site and skips the APIs and mobile app gives false comfort, and will not satisfy an IRDAI review of your platform.

Your tier and the web-aggregator special rule

The cybersecurity requirements for insurance web aggregators also scale with size. The 2026 version of the guidelines added a formal three-tier classification of intermediaries by gross insurance revenue, and your tier sets how intense your controls must be.

Where you sit
Your tier sets the intensity
The 2026 guidelines classify intermediaries into three tiers by gross insurance revenue, and the tier decides how heavy your controls are. There is one exception aggregators need to know.
Intermediaries are tiered by revenue Category 1 Largest by grossinsurance revenue Heaviest controls Category 2 Mid-tier byrevenue Core controls Category 3 Smallest in scope Baseline controls Special rule: web aggregators and ISNP operators sit at a higher control tier, whatever their revenue

Larger intermediaries by revenue fall into the higher categories with the heaviest controls, and smaller ones into lighter tiers. But there is a special rule that matters directly to aggregators: because aggregators and ISNP operators run a public transaction platform, they are placed at a higher control tier regardless of their revenue. In short, you do not get the light-tier treatment just because you are small, running the platform is what sets your obligations.

The core cybersecurity requirements for insurance web aggregators

Alongside the platform audit, a common set of controls completes the picture. These formalise strong practice into mandatory, evidenced duties.

The obligations
What you have to run and evidence
Beyond the platform audit, a recognisable core of controls makes up the cybersecurity requirements for insurance web aggregators. These are the duties an inspection checks first.
The core obligations for web aggregatorsIndependent CISONot reporting to the head of ITVAPT twice a yearWeb, mobile, and API testingSix-hour reportingCritical incidents to CERT-InAnnual auditCERT-In empanelled, ISNP reviewVendor riskAssess every data partnerData protectionEncryption and access control

In practice that means an independent Chief Information Security Officer who does not report to the head of IT and carries no business targets, a vulnerability assessment and penetration testing programme run at least twice a year across web, mobile, and API surfaces, cyber incident reporting to CERT-In within six hours, an annual audit by a CERT-In empanelled auditor, third-party risk management for every data partner, and data protection with encryption and access control. Together these are the operating core of the obligations.

CISO independence is now structural
The guidelines are explicit that the CISO must not sit under the head of IT or carry business targets, and must brief the board and risk committee regularly. For an aggregator, that separation is one of the first things an inspection verifies.

Testing cadence and incident reporting

Two timelines sit at the heart of day-to-day compliance. VAPT must run at least twice a year, and any critical or high-severity finding has to be remediated within thirty days. An internet-facing platform carrying an open high finding past that window is a common failure.

On incidents, critical events such as a breach or ransomware must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and other incidents within twenty-four hours. Because the clock starts at detection, meeting it is really a demand for monitoring good enough to catch and confirm an incident fast. An automated scan alone will not satisfy the testing requirement, our guide on VAPT versus vulnerability scanning explains why skilled, human-led testing is what an ISNP audit expects.

How Osto helps aggregators comply

Meeting all of this, an ISNP-grade platform audit, a twice-yearly VAPT cadence across web, mobile, and API, six-hour-ready incident detection, vendor risk, and an audit-ready file, is a heavy lift for a lean aggregator without a dedicated security team. Piecing it together from separate tools and consultants is slow and hard to keep current, which is the gap Osto is built to close.

Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. For a web aggregator, it runs VAPT across your web application, mobile app, and APIs, correlates security events so incidents surface fast enough to report on time, supports encryption, data-handling, and third-party risk controls, and keeps organised, audit-ready evidence mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets your platform audit-ready and keeps it there, so the ISNP audit becomes a verification rather than a scramble.

Get your ISNP audit-ready without a big team.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Test your web, mobile, and API surfaces, stand up monitoring for fast incident reporting, manage vendor risk, and keep audit-ready evidence, on one platform. No security team required.

Book a Demo →

Frequently asked questions

Do IRDAI cybersecurity rules apply to web aggregators?

Yes. Web aggregators are named explicitly as an insurance intermediary bound by the IRDAI Information and Cyber Security Guidelines. Because they run a public platform, they carry heavier, platform-level obligations than agents.

What is an ISNP security audit?

An Insurance Self-Network Platform audit is a security review of the platform an aggregator runs with IRDAI permission to sell insurance online. It covers the web application, mobile app, APIs, and infrastructure, and is required at least annually, often before go-live.

How often must a web aggregator run VAPT?

At least twice a year, across web, mobile, and API surfaces, with critical and high-severity findings remediated within thirty days. Evidence of remediation is checked at the annual audit.

Does the tier classification affect web aggregators?

Yes, but with a special rule. Intermediaries are tiered by gross insurance revenue, yet web aggregators and ISNP operators are placed at a higher control tier regardless of revenue, because they run a public transaction platform.

What is the incident reporting timeline for aggregators?

Critical incidents must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. The clock runs from detection.

Who conducts the audit, and can Osto do it?

The annual audit is conducted by a CERT-In empanelled auditor. Osto gets your platform audit-ready, running VAPT, monitoring, and evidence, but it does not act as the empanelled auditor or as an insurer.