CERT-In empanelment is the approval that lets an auditing organisation perform the security audits Indian regulators and government departments accept.
The short answer
CERT-In empanelment is a status granted to information security auditing organisations by the Indian Computer Emergency Response Team. Empanelled auditors appear on a published panel and are the only ones whose reports satisfy audit requirements set by regulators such as RBI and SEBI, and by government departments procuring software. Empanelment applies to the auditor, not to the organisation being audited. There is no such thing as a CERT-In empanelled product or a CERT-In certified company.
That last point is where most confusion sits. If a customer asks whether you are CERT-In empanelled, they almost always mean something else: whether you have been audited by an empanelled auditor.
On this page
What empanelment actually is
CERT-In operates under the Ministry of Electronics and Information Technology and is India’s national nodal agency for cyber security incidents. Alongside incident response, it maintains a panel of auditing organisations that have passed its technical evaluation.
Who needs an empanelled auditor
Empanelment is not a general legal requirement. It becomes mandatory where a specific regulator or buyer says so, and that list has grown.
| Context | Why an empanelled auditor is asked for |
|---|---|
| Government web applications and portals | A safe-to-host clearance from an empanelled auditor is typically required before go-live |
| Public sector tenders and PSU procurement | The tender specifies an audit report from a listed auditor as an eligibility condition |
| Banks, NBFCs and regulated financial entities | RBI cyber security frameworks direct regulated entities toward CERT-In empanelled auditors for certain assessments |
| Stock brokers, depository participants and market intermediaries | SEBI cyber security circulars reference audits by empanelled organisations |
| SaaS vendors selling into any of the above | The requirement is passed down through procurement and vendor security review |
The vendor-side version of the problem
Most software companies never deal with CERT-In directly. They meet it inside a customer’s procurement checklist, usually late, usually as a blocker on a deal that was otherwise agreed. The fix is having the assessment done before the question arrives, not after.
How the panel works
Application and evaluation
Auditing organisations apply and are assessed on methodology, tooling, team qualifications and past work.
A published list
Successful organisations appear on the panel CERT-In publishes, which buyers check directly.
Fixed validity
Empanelment runs for a defined term and must be renewed. Panels are refreshed periodically.
Panels change between cycles, so confirm an auditor’s status against the current published list rather than a claim in a proposal.
Empanelment is not the CERT-In Directions
Two separate things share the same name and get conflated constantly.
| Empanelment | The 2022 Directions | |
|---|---|---|
| Applies to | Auditing organisations | Service providers, intermediaries, data centres, body corporates |
| Nature | An approval status | Binding obligations |
| Core content | Eligibility to perform accepted audits | Incident reporting within six hours, log retention, clock synchronisation, KYC record keeping |
| Who it burdens | Only the auditor | Almost every technology company operating in India |
If someone tells you CERT-In compliance is mandatory for your company, they are describing the Directions, not empanelment. The two require completely different work.
Preparing for the audit
An empanelled audit is, in practice, a structured vulnerability assessment and penetration test with a report and a remediation cycle. Findings must be fixed and re-verified before clearance is issued.
| What auditors consistently find | Fix before they arrive |
|---|---|
| OWASP Top 10 issues in the web application | Run DAST and manual testing on your own schedule first |
| Undocumented or unauthenticated API endpoints | Discover and inventory every endpoint, then enforce API authentication |
| Misconfigured cloud storage and over-broad IAM | Cloud posture management with continuous checks |
| Missing or unreviewed logs | Centralised logging with retention that meets the Directions |
| Weak authentication on admin interfaces | MFA everywhere, and ZTNA in front of internal tools |
How Osto gets you audit-ready
Osto prepares your environment and your evidence so the empanelled audit confirms rather than discovers. Expert-led VAPT plus an AI scanner finds what an auditor would find, cloud posture, code security and API discovery close the common findings, and logging and monitoring covers the retention side of the Directions. The gap analysis approach is the same one that works for SOC 2 and ISO 27001, so one control set serves all three.
The audit itself is performed by an empanelled auditing organisation. Osto’s role is everything before and after: finding the issues first, fixing them, and holding the evidence.
Free security assessment
Walk into the audit with nothing left to find
Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. Expert-led VAPT, cloud posture, code security and logging in one platform.
Get a free security assessment Book a platform walkthroughAudit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything
Frequently asked questions
What is CERT-In empanelment?
A status granted by the Indian Computer Emergency Response Team to information security auditing organisations that pass its technical evaluation. Empanelled auditors appear on a published panel, and their reports are accepted where regulators or government buyers require one.
Can a company be CERT-In empanelled?
Only if it is an auditing organisation applying to join the panel. A product company or SaaS vendor cannot be empanelled. What it can have is an audit report from an empanelled auditor, which is usually what a customer is actually asking for.
Is a CERT-In audit mandatory?
Not universally. It becomes mandatory where a sectoral regulator or a government tender specifies it, which commonly covers government web applications, public sector procurement, and entities regulated by RBI or SEBI.
What is the difference between CERT-In empanelment and the CERT-In Directions?
Empanelment is an approval status for auditors. The 2022 Directions are binding obligations on service providers and body corporates covering six-hour incident reporting, log retention, clock synchronisation and KYC records. They are unrelated requirements that share a name.
Does an empanelled audit replace SOC 2 or ISO 27001?
No. It answers an India-specific regulatory or procurement requirement. SOC 2 and ISO 27001 answer different questions for different buyers. The underlying controls overlap heavily, so one security programme can support all three.

