{"id":949,"date":"2026-08-23T19:26:22","date_gmt":"2026-08-23T19:26:22","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=949"},"modified":"2026-08-23T19:26:22","modified_gmt":"2026-08-23T19:26:22","slug":"cert-in-empanelment","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/","title":{"rendered":"CERT-In Empanelment"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CERT-IN EMPANELMENT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">CERT-In empanelment is the approval that lets an auditing organisation perform the security audits Indian regulators and government departments accept.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">India<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>CERT-In empanelment is a status granted to information security auditing organisations by the Indian Computer Emergency Response Team. Empanelled auditors appear on a published panel and are the only ones whose reports satisfy audit requirements set by regulators such as RBI and SEBI, and by government departments procuring software. Empanelment applies to the auditor, not to the organisation being audited. There is no such thing as a CERT-In empanelled product or a CERT-In certified company.<\/p>\n<\/div>\n\n<p>That last point is where most confusion sits. If a customer asks whether you are CERT-In empanelled, they almost always mean something else: whether you have been audited by an empanelled auditor.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What empanelment actually is<\/a><\/li>\n    <li><a href=\"#needs\">Who needs an empanelled auditor<\/a><\/li>\n    <li><a href=\"#panel\">How the panel works<\/a><\/li>\n    <li><a href=\"#directions\">Empanelment is not the CERT-In Directions<\/a><\/li>\n    <li><a href=\"#prepare\">Preparing for the audit<\/a><\/li>\n    <li><a href=\"#osto\">How Osto gets you audit-ready<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What empanelment actually is<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 220\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"CERT-In empanels auditors; the auditor audits your organisation; the report satisfies the regulator or government buyer.\">\n  <defs><marker id=\"ceA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"48\" width=\"196\" height=\"82\" rx=\"15\" fill=\"#1c267a\"\/>\n  <text x=\"112\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">CERT-In<\/text>\n  <text x=\"112\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">The national agency<\/text>\n  <text x=\"112\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">under MeitY<\/text>\n\n  <line x1=\"216\" y1=\"89\" x2=\"256\" y2=\"89\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ceA)\"\/>\n  <text x=\"236\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#4a52a8\">empanels<\/text>\n\n  <rect x=\"262\" y=\"48\" width=\"196\" height=\"82\" rx=\"15\" fill=\"#e3f0e9\"\/>\n  <text x=\"360\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Empanelled auditor<\/text>\n  <text x=\"360\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">An approved auditing<\/text>\n  <text x=\"360\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">organisation on the panel<\/text>\n\n  <line x1=\"464\" y1=\"89\" x2=\"504\" y2=\"89\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ceA)\"\/>\n  <text x=\"484\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#4a52a8\">audits<\/text>\n\n  <rect x=\"510\" y=\"48\" width=\"236\" height=\"82\" rx=\"15\" fill=\"#e9ecfa\"\/>\n  <text x=\"628\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Your organisation<\/text>\n  <text x=\"628\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Receives an audit report<\/text>\n  <text x=\"628\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">the regulator will accept<\/text>\n\n  <rect x=\"14\" y=\"160\" width=\"732\" height=\"42\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"186\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Empanelment attaches to the auditor. You are never empanelled yourself.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The status flows one way. Being audited by an empanelled firm does not make you empanelled.<\/figcaption>\n<\/figure>\n\n<p>CERT-In operates under the Ministry of Electronics and Information Technology and is India&#8217;s national nodal agency for cyber security incidents. Alongside incident response, it maintains a panel of auditing organisations that have passed its technical evaluation.<\/p>\n\n<h2 id=\"needs\" class=\"c-sage\">Who needs an empanelled auditor<\/h2>\n\n<p>Empanelment is not a general legal requirement. It becomes mandatory where a specific regulator or buyer says so, and that list has grown.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Context<\/th><th>Why an empanelled auditor is asked for<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Government web applications and portals<\/td><td>A safe-to-host clearance from an empanelled auditor is typically required before go-live<\/td><\/tr>\n    <tr><td>Public sector tenders and PSU procurement<\/td><td>The tender specifies an audit report from a listed auditor as an eligibility condition<\/td><\/tr>\n    <tr><td>Banks, NBFCs and regulated financial entities<\/td><td>RBI cyber security frameworks direct regulated entities toward CERT-In empanelled auditors for certain assessments<\/td><\/tr>\n    <tr><td>Stock brokers, depository participants and market intermediaries<\/td><td>SEBI cyber security circulars reference audits by empanelled organisations<\/td><\/tr>\n    <tr><td>SaaS vendors selling into any of the above<\/td><td>The requirement is passed down through procurement and vendor security review<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The vendor-side version of the problem<\/p>\n  <p>Most software companies never deal with CERT-In directly. They meet it inside a customer&#8217;s procurement checklist, usually late, usually as a blocker on a deal that was otherwise agreed. The fix is having the assessment done before the question arrives, not after.<\/p>\n<\/div>\n\n<h2 id=\"panel\" class=\"c-apri\">How the panel works<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Application and evaluation<\/p>\n    <p>Auditing organisations apply and are assessed on methodology, tooling, team qualifications and past work.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">A published list<\/p>\n    <p>Successful organisations appear on the panel CERT-In publishes, which buyers check directly.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Fixed validity<\/p>\n    <p>Empanelment runs for a defined term and must be renewed. Panels are refreshed periodically.<\/p>\n  <\/div>\n<\/div>\n\n<p>Panels change between cycles, so confirm an auditor&#8217;s status against the current published list rather than a claim in a proposal.<\/p>\n\n<h2 id=\"directions\" class=\"c-plum\">Empanelment is not the CERT-In Directions<\/h2>\n\n<p>Two separate things share the same name and get conflated constantly.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th><\/th><th>Empanelment<\/th><th>The 2022 Directions<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Applies to<\/strong><\/td><td>Auditing organisations<\/td><td>Service providers, intermediaries, data centres, body corporates<\/td><\/tr>\n    <tr><td><strong>Nature<\/strong><\/td><td>An approval status<\/td><td>Binding obligations<\/td><\/tr>\n    <tr><td><strong>Core content<\/strong><\/td><td>Eligibility to perform accepted audits<\/td><td>Incident reporting within six hours, log retention, clock synchronisation, KYC record keeping<\/td><\/tr>\n    <tr><td><strong>Who it burdens<\/strong><\/td><td>Only the auditor<\/td><td>Almost every technology company operating in India<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>If someone tells you CERT-In compliance is mandatory for your company, they are describing the Directions, not empanelment. The two require completely different work.<\/p>\n\n<h2 id=\"prepare\" class=\"c-sage\">Preparing for the audit<\/h2>\n\n<p>An empanelled audit is, in practice, a structured <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">vulnerability assessment and penetration test<\/a> with a report and a remediation cycle. Findings must be fixed and re-verified before clearance is issued.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>What auditors consistently find<\/th><th>Fix before they arrive<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>OWASP Top 10 issues in the web application<\/td><td>Run <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a> and manual testing on your own schedule first<\/td><\/tr>\n    <tr><td>Undocumented or unauthenticated API endpoints<\/td><td>Discover and inventory every endpoint, then enforce <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API authentication<\/a><\/td><\/tr>\n    <tr><td>Misconfigured cloud storage and over-broad IAM<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> with continuous checks<\/td><\/tr>\n    <tr><td>Missing or unreviewed logs<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">Centralised logging<\/a> with retention that meets the Directions<\/td><\/tr>\n    <tr><td>Weak authentication on admin interfaces<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> everywhere, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> in front of internal tools<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto gets you audit-ready<\/h2>\n\n<p>Osto prepares your environment and your evidence so the empanelled audit confirms rather than discovers. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> plus an AI scanner finds what an auditor would find, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">code security<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API discovery<\/a> close the common findings, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">logging and monitoring<\/a> covers the retention side of the Directions. The <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-gap-analysis\/\" target=\"_blank\" rel=\"noopener\">gap analysis approach<\/a> is the same one that works for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, so one control set serves all three.<\/p>\n\n<p>The audit itself is performed by an empanelled auditing organisation. Osto&#8217;s role is everything before and after: finding the issues first, fixing them, and holding the evidence.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Walk into the audit with nothing left to find<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. Expert-led VAPT, cloud posture, code security and logging in one platform.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; RBI, SEBI and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is CERT-In empanelment?<\/summary>\n  <p>A status granted by the Indian Computer Emergency Response Team to information security auditing organisations that pass its technical evaluation. Empanelled auditors appear on a published panel, and their reports are accepted where regulators or government buyers require one.<\/p>\n<\/details>\n\n<details>\n  <summary>Can a company be CERT-In empanelled?<\/summary>\n  <p>Only if it is an auditing organisation applying to join the panel. A product company or SaaS vendor cannot be empanelled. What it can have is an audit report from an empanelled auditor, which is usually what a customer is actually asking for.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a CERT-In audit mandatory?<\/summary>\n  <p>Not universally. It becomes mandatory where a sectoral regulator or a government tender specifies it, which commonly covers government web applications, public sector procurement, and entities regulated by RBI or SEBI.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between CERT-In empanelment and the CERT-In Directions?<\/summary>\n  <p>Empanelment is an approval status for auditors. The 2022 Directions are binding obligations on service providers and body corporates covering six-hour incident reporting, log retention, clock synchronisation and KYC records. They are unrelated requirements that share a name.<\/p>\n<\/details>\n\n<details>\n  <summary>Does an empanelled audit replace SOC 2 or ISO 27001?<\/summary>\n  <p>No. It answers an India-specific regulatory or procurement requirement. SOC 2 and ISO 27001 answer different questions for different buyers. The underlying controls overlap heavily, so one security programme can support all three.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> VAPT &middot; Penetration Testing &middot; DPDP Act &middot; Vulnerability Assessment &middot; SOC 2 &middot; ISO 27001<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CERT-In empanelment is the approval that lets an auditing organisation perform the security audits Indian regulators and government departments accept.\u2026<\/p>\n","protected":false},"author":8,"featured_media":950,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[415,417,414,416],"class_list":["post-949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-cert-in-audit","tag-cert-in-empanelled-auditor","tag-cert-in-empanelment","tag-cert-in-empanelment-process"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=949"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/949\/revisions"}],"predecessor-version":[{"id":951,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/949\/revisions\/951"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/950"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}