Qualysec
Blog

ABDM Security Audit: Cost, Timeline & NHA Compliance Guide

Get your ABDM Safe to Host certificate without launch delays. See real VAPT costs, testing timelines, and NHA compliance steps for HealthTech teams.

Published on September 2, 2026
Read Time: 9 min
CONNECT WITH US

The National Health Authority (NHA) runs the Ayushman Bharat Digital Mission (ABDM) to help India’s healthcare providers share patient records securely with patient consent.

If your software works as a Health Information Provider (HIP), Health Information User (HIU), Health Locker, or Consent Manager, you cannot get live production keys without proving your system is secure.

The NHA holds back live production keys until your software passes a full Vulnerability Assessment and Penetration Testing (VAPT) audit.

This guide breaks down everything required to get your Safe to Host certificate without pushing back your launch date: testing requirements for each ABDM milestone, real costs, expected timelines, and practical tips to avoid delays.

Why Do You Need an ABDM Security Audit?

The ABDM network works by sharing patient data across different systems, connecting hospitals, labs, health lockers, and patients. Because your software links directly to the central ABDM gateway, any security weakness in your code can leave sensitive medical records open to a data breach.

To keep patient data safe, the NHA requires every connected application to meet strict Indian cybersecurity standards—including the Digital Personal Data Protection (DPDP) Act 2023, the IT Act 2000, and CERT-In security rules.

Passing this audit proves three key things:

  • Your APIs are secure: Hackers cannot exploit your gateway connections to harvest patient records.
  • Your data transfer is protected: Medical files stay encrypted and tamper-proof whether they are moving across the network or stored in your database.
  • You are cleared to go live: You receive an official Safe to Host certificate (aligned with CERT-In rules), which is the final requirement to unlock your live production keys from the NHA.

ABDM Audit Objectives

ABDM Security Requirements Across the 3 Milestones

The NHA breaks ABDM integration into three core technical phases. What gets tested during your audit depends entirely on which milestones your software actually uses:

  • Milestone 1 (M1) – ABHA Creation & Verification: This covers digital identity. Testers check how your app handles logins, OTPs, API tokens, and user lookups to ensure nobody can create fake ABHA accounts, bypass authentication, or harvest identity details.
  • Milestone 2 (M2) – Health Information Provider (HIP): This lets your software link and send medical records—like lab reports or prescriptions—into the ABDM network. Testing makes sure your FHIR R4 data formatting is spot on, your encryption handshakes are secure, and patient files stay protected on your servers.
  • Milestone 3 (M3) – Health Information User (HIU): This allows your platform to request and view medical records from other providers. Testers focus heavily on your Consent Manager APIs to verify that your system strictly honors patient permissions and can’t pull records a user hasn’t approved.

Timelines: How Long Does an ABDM VAPT Audit Take?

A proper VAPT audit is not something you can rush through with a one-click scanner. It takes real hands-on testing by security engineers to evaluate your actual business logic. For a standard web-based HMIS, telemedicine portal, or PHR app, the full cycle typically takes 10 to 18 business days.

Stage 1: Scope & Staging Setup (1–2 Days)

We work directly with your tech team to map out your setup. We identify every API endpoint connected to the ABDM gateway, review user roles, and ensure we have solid access to your staging environment.

Stage 2: Active Penetration Testing (4–5 Days)

Our security team performs hands-on manual testing alongside automated checks. Beyond basic web bugs, we probe your core business logic—attempting to break ABHA authentication flows, tamper with API calls, and inspect FHIR data handling.

Stage 3: Fixing Flaws (3–5 Days)

We share a detailed VAPT report listing every security bug we found, starting with the most serious risks. It includes direct guidance so your developers know exactly how to fix each problem on your staging server.

Stage 4: Re-Testing & Final Clearance (2–3 Days)

After your team pushes the updates, we go back and re-test every weak spot. Once we confirm all the bugs are patched, we issue your official, NHA-compliant Safe to Host certificate.

Pass Your ABDM Audit on the First Try and Secure Your Healthcare Platform.

CREST-accredited manual penetration testing with zero false positives and free patch retesting.

Book Your ABDM Audit

Pass Your ABDM Security Audit on the First Attempt

ABDM Security Audit Costs in India

Audit pricing mostly depends on how much code we need to test. Automated scanners can’t test complex application logic on their own, so the price comes down to the actual engineering time spent testing your app by hand.

Audit Scope Who It’s For Average Cost (INR)
Tier 1: Core API Only Startups using external frontends with custom backend code for ABDM ₹45,000 – ₹75,000
Tier 2: Web App + APIs Full Telemedicine platforms, cloud hospital management systems, or lab software ₹80,000 – ₹1,50,000
Tier 3: Full Platform Larger hospital systems running web portals, Android/iOS apps, and local servers ₹1,80,000+

What Moves the Price?

  1. Number of Milestones: Testing M1, M2, and M3 together takes more work than testing just M1, and it affects the cost of the ABDM security audit.
  2. App Count: Web, Android, and iOS apps use different code, so we have to test each app separately. 
  3. System Design: Microservices and spread-out databases take longer to test than a single unified web app.

What We Check During Your ABDM Security Audit

We test your entire setup to make sure there are no hidden security holes. Here is what we look at:

  • ABDM Gateway APIs: We check your API connections to make sure nobody can bypass login checks, reuse old tokens, or pull patient data they shouldn’t see.
  • Web & Mobile Apps: We test your admin portals, doctor dashboards, and patient apps for everyday security bugs like broken logins, unsafe data inputs, and unauthorized access.
  • Cloud & Database Setup: We check how your app handles sensitive medical records to make sure patient data stays encrypted when stored in your database and sent across the network.

ABDM Security Audit Challenges Qualysec Help Mitigate

Qualysec’s 6-Step Audit Methodology

Our Audit Process:

  1. Mapping Your Setup: We start by listing all your API endpoints, system connections, and the specific ABDM milestones your app uses.
  2. Automated Scans: We run quick scans first to catch simple setup mistakes and missing security settings.
  3. Manual Testing: We manually check your app for ways someone could bypass logins, alter API calls, or break your system logic.
  4. Detailed Reports: You get a straightforward report listing every bug by risk level, with direct steps on how to fix each one.
  5. Remediation / Developer Support: We walk your dev team through the findings so they can patch every bug quickly. 
  6. Re-Testing & Clearance: Once your updates are live on staging, we re-test everything to make sure it’s secure and issue your official Safe to Host certificate.

3 Ways HealthTech Founders Can Cut Audit Costs and Delays

  • Lock Your Code: Don’t add new features or change how your app works while we test. Adding new stuff mid-audit means we have to test things twice, which delays the project and adds cost.
  • Fix Simple Bugs First: Have your team run a free scanner on your staging site before sending it to us. Cleaning up basic mistakes early saves time and keeps the audit moving fast.
  • Pick an Auditor Who Helps You Patch: Work with a team that shows your developers exactly how to fix each bug, instead of just sending a heavy report with no clear guidance.

Why HealthTech Leaders Work With Qualysec for ABDM Audits

We help your team pass compliance quickly without skipping real security checks:

  • Real Testers, Not Just Scanners: We use automated tools for speed, but our team tests your app manually to catch hidden logic bugs scanners miss.
  • Deep ABDM & Healthcare Experience: We know NHA gateway rules and FHIR data standards inside out, so you don’t have to explain them to us.
  • Clear, Upfront Pricing: You get a flat rate that covers your first test, calls with your developers, and final re-testing—no hidden costs along the way.

Conclusion

Getting your ABDM Safe to Host certificate doesn’t have to hold up your launch or create constant back-and-forth for your developers. Once you prepare your staging server, fix simple bugs early, and work with people who actually know healthcare security, you can get through compliance quickly and pick up your live NHA keys with zero headache.

Whether you’re just starting with an M1 setup or pushing out full M1, M2, and M3 features on web and mobile, getting your security audit wrapped up is the final green light to launch with confidence.

Frequently Asked Questions:-

Q: What is an ABDM Security Audit?

Ans: It is a required security check (VAPT) that tests your healthcare app, APIs, and data safety before the NHA grants you access to live production systems.

Q: How long is a “Safe to Host” certificate valid?

Ans: It lasts for one year, provided you don’t rebuild core parts of your app or make major changes to how your system works.

Q: Who needs to get an ABDM Security Audit?

Ans: Any company connecting to ABDM—like healthtech startups, hospitals, labs, and SaaS tools using M1, M2, or M3 milestones—must get audited.

Q: What security standards does the audit cover?

Ans: We check your application against government guidelines from CERT-In, common web and API security risks under the OWASP Top 10, and data privacy requirements listed in the DPDP Act.

Q: Can we get production keys without doing a manual VAPT?

Ans: No. The NHA will not move your app from the sandbox to live production without a verified VAPT report and a valid “Safe to Host” certificate.

Clear Your Compliance Hurdle with Qualysec!

Ready to take your app from the ABDM sandbox into production? Reach out to our team today and get your testing schedule locked in.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.