CERT-In Empanelment

CERT-In empanelment and the audit chain explained

CERT-In empanelment is the approval that lets an auditing organisation perform the security audits Indian regulators and government departments accept.

  • Glossary
  • India

The short answer

CERT-In empanelment is a status granted to information security auditing organisations by the Indian Computer Emergency Response Team. Empanelled auditors appear on a published panel and are the only ones whose reports satisfy audit requirements set by regulators such as RBI and SEBI, and by government departments procuring software. Empanelment applies to the auditor, not to the organisation being audited. There is no such thing as a CERT-In empanelled product or a CERT-In certified company.

That last point is where most confusion sits. If a customer asks whether you are CERT-In empanelled, they almost always mean something else: whether you have been audited by an empanelled auditor.

What empanelment actually is

CERT-In The national agency under MeitY empanels Empanelled auditor An approved auditing organisation on the panel audits Your organisation Receives an audit report the regulator will accept Empanelment attaches to the auditor. You are never empanelled yourself.
Swipe to see the full diagram. The status flows one way. Being audited by an empanelled firm does not make you empanelled.

CERT-In operates under the Ministry of Electronics and Information Technology and is India’s national nodal agency for cyber security incidents. Alongside incident response, it maintains a panel of auditing organisations that have passed its technical evaluation.

Who needs an empanelled auditor

Empanelment is not a general legal requirement. It becomes mandatory where a specific regulator or buyer says so, and that list has grown.

ContextWhy an empanelled auditor is asked for
Government web applications and portalsA safe-to-host clearance from an empanelled auditor is typically required before go-live
Public sector tenders and PSU procurementThe tender specifies an audit report from a listed auditor as an eligibility condition
Banks, NBFCs and regulated financial entitiesRBI cyber security frameworks direct regulated entities toward CERT-In empanelled auditors for certain assessments
Stock brokers, depository participants and market intermediariesSEBI cyber security circulars reference audits by empanelled organisations
SaaS vendors selling into any of the aboveThe requirement is passed down through procurement and vendor security review

The vendor-side version of the problem

Most software companies never deal with CERT-In directly. They meet it inside a customer’s procurement checklist, usually late, usually as a blocker on a deal that was otherwise agreed. The fix is having the assessment done before the question arrives, not after.

How the panel works

Application and evaluation

Auditing organisations apply and are assessed on methodology, tooling, team qualifications and past work.

A published list

Successful organisations appear on the panel CERT-In publishes, which buyers check directly.

Fixed validity

Empanelment runs for a defined term and must be renewed. Panels are refreshed periodically.

Panels change between cycles, so confirm an auditor’s status against the current published list rather than a claim in a proposal.

Empanelment is not the CERT-In Directions

Two separate things share the same name and get conflated constantly.

EmpanelmentThe 2022 Directions
Applies toAuditing organisationsService providers, intermediaries, data centres, body corporates
NatureAn approval statusBinding obligations
Core contentEligibility to perform accepted auditsIncident reporting within six hours, log retention, clock synchronisation, KYC record keeping
Who it burdensOnly the auditorAlmost every technology company operating in India

If someone tells you CERT-In compliance is mandatory for your company, they are describing the Directions, not empanelment. The two require completely different work.

Preparing for the audit

An empanelled audit is, in practice, a structured vulnerability assessment and penetration test with a report and a remediation cycle. Findings must be fixed and re-verified before clearance is issued.

What auditors consistently findFix before they arrive
OWASP Top 10 issues in the web applicationRun DAST and manual testing on your own schedule first
Undocumented or unauthenticated API endpointsDiscover and inventory every endpoint, then enforce API authentication
Misconfigured cloud storage and over-broad IAMCloud posture management with continuous checks
Missing or unreviewed logsCentralised logging with retention that meets the Directions
Weak authentication on admin interfacesMFA everywhere, and ZTNA in front of internal tools

How Osto gets you audit-ready

Osto prepares your environment and your evidence so the empanelled audit confirms rather than discovers. Expert-led VAPT plus an AI scanner finds what an auditor would find, cloud posture, code security and API discovery close the common findings, and logging and monitoring covers the retention side of the Directions. The gap analysis approach is the same one that works for SOC 2 and ISO 27001, so one control set serves all three.

The audit itself is performed by an empanelled auditing organisation. Osto’s role is everything before and after: finding the issues first, fixing them, and holding the evidence.

Free security assessment

Walk into the audit with nothing left to find

Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. Expert-led VAPT, cloud posture, code security and logging in one platform.

Get a free security assessment Book a platform walkthrough

Audit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything

Frequently asked questions

What is CERT-In empanelment?

A status granted by the Indian Computer Emergency Response Team to information security auditing organisations that pass its technical evaluation. Empanelled auditors appear on a published panel, and their reports are accepted where regulators or government buyers require one.

Can a company be CERT-In empanelled?

Only if it is an auditing organisation applying to join the panel. A product company or SaaS vendor cannot be empanelled. What it can have is an audit report from an empanelled auditor, which is usually what a customer is actually asking for.

Is a CERT-In audit mandatory?

Not universally. It becomes mandatory where a sectoral regulator or a government tender specifies it, which commonly covers government web applications, public sector procurement, and entities regulated by RBI or SEBI.

What is the difference between CERT-In empanelment and the CERT-In Directions?

Empanelment is an approval status for auditors. The 2022 Directions are binding obligations on service providers and body corporates covering six-hour incident reporting, log retention, clock synchronisation and KYC records. They are unrelated requirements that share a name.

Does an empanelled audit replace SOC 2 or ISO 27001?

No. It answers an India-specific regulatory or procurement requirement. SOC 2 and ISO 27001 answer different questions for different buyers. The underlying controls overlap heavily, so one security programme can support all three.