CERT-In empanelled security auditors are cybersecurity firms formally authorized by the Indian Computer Emergency Response Team (CERT-In) to conduct specified information security audits. CERT-In empanelment is critical where contractual, government, or sector-specific cybersecurity requirements apply alongside obligations under India’s DPDP framework. Because regulators will only accept a VAPT report from an actively empanelled auditor, this guide serves as an action plan to validate and select the right partner.
Key Takeaways
- CERT-In empanelment is recognised for certain regulatory, government and sector-specific security assessments.
- Audits from an organisation empanelled by RBI, SEBI CSCRF, IRDAI and the ABDM are required.
- CERT-In empanelment status can change, so buyers should verify the organisation’s current status directly against the official CERT-In roster before appointing an auditor.
- Always check the valid dates and legal entity names on the official CERT-In roster.
- Manual penetration depth, not automated scanning, is the difference between a regulatory rejection and not.
Why CERT-In Vendor Selection Matters
It is a common scenario for any procurement and compliance team in India. A regulator or enterprise customer requests a VAPT report from a CERT-In empanelled cybersecurity auditor, and the quest starts. Weeks are lost by teams looking through static government PDFs and cross-checking company names. They go to vendor websites to check badges that can be months old. It’s a tedious and unreliable process, and choosing the wrong partner carries a high cost.
The stakes are high as Indian regulators are strict. The audits conducted by any organisation which is active with CERT-In are expected under RBI Master Directions, SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), IRDAI guidelines, Ayushman Bharat Digital Mission, and the DPDP regime. It is a common practice that the report of a non-empanelled firm is rejected (SEBI CSCRF). The past tense or empanelled/revoked also does not count.
This guide cuts to the chase. It demonstrates the reading of the list of certs in empanelled auditors as a regulator would do. It defines the concept of empanelment and how to check the official list of cert in empanelled auditors. Also, it delineates exactly what to seek out when choosing a partner. It includes the mandated requirements by sector, a certification process with steps, a buyer’s checklist, commonly encountered issues, pricing factors, and the complete audit process. From BFSI to healthtech, fintech to SaaS and government, it’s all about a sure-footed, defensible decision.
What Is a CERT-In Empanelled Security Auditor?
CERT-In, established by Section 70B of the Information Technology Act, 2000, under the Ministry of Electronics and Information Technology (MeitY), is the national nodal agency for cybersecurity since 2004 (CERT-In). CERT-In empanelled security auditors are information security auditing organisations that have been empanelled by the Indian Computer Emergency Response Team (CERT-In) to conduct specified information security audits.
Empanelment is a highly stringent accreditation. Firms are listed subject to re-assessment on a regular basis, and are evaluated to ensure they have the technical capability, sound audit methodology, and real-world operational competence. This is why regulators trust top CERT-In certified auditing organisations. The credential is a sign of real commitment and rigour, and not just a marketing gimmick. CERT-In empanelled security auditors form an official panel legally recognised to provide audit reports for Indian compliance programs.
Role of an Empanelled IS Auditing Organisation
The CERT-In empanelled cybersecurity auditors you engage should do more than run tools. Top empanelled auditing firms use documented methodologies that are based on risk. They plan for engagements against recognised standards. They are well reported and are acceptable to regulators. It is the duty of the Empanelled auditors to carry out a variety of evaluations. These include network audits, application security testing, cloud assessments, source-code reviews, API testing, and red-teaming. Most importantly, the compliance certificate is backed by their sign-off.
CERT-In Empanelled vs Standard VAPT Vendor

The distinction really is the difference at the moment of submission. While a regular VAPT vendor can be technically proficient, the report doesn’t have any regulatory validity. Under the RBI Cyber Security Framework and SEBI CSCRF, audits must be conducted by a CERT-In empanelled organisation. If a non-empanelled report is submitted, it just doesn’t pass. This is the only key difference between CERT-In-empanelled companies. When a regulator is observing a company, only their work counts. That is the point among all CERT-In-empanelled companies. If a firm is not on the regulator’s list, there is a double cost involved in choosing to use them for a regulated audit.
Is CERT-In Empanelment Required for Your VAPT?
Not every organisation requires an empanelled vendor, so it is best to understand what you need. The need is highest in regulated and government-facing sectors for cert in empanelled companies.
- BFSI: For periodic VAPT, empanelled auditors are required to be engaged by banks and NBFCs regulated by RBI, as well as payment operators regulated by RBI, and market intermediaries regulated by SEBI (CSCRF).
- Healthtech: For digital health products integrating with ABDM, security assessment and production-readiness requirements may apply. Organisations should verify the current NHA/ABDM onboarding and security requirements for their specific integration and environment.
- Fintech and e-commerce: The payment-handling and data-intensive platforms are subject to PCI DSS, DPDP, and contractual audit requirements, and enterprise buyers often require an empanelled report.
- Government and PSUs: Websites and applications on Government infrastructure need to be audited and given clearance by an empanelled auditor before go-live.
- SaaS: empanelment is frequently not the law, but an increasing number of procurement teams in enterprises are looking for it as a minimum level of trust before they sign.
One similar clearance is the Go-live security clearance. The rule with respect to healthtech is strict. Two things an application can’t do without to reach ABDM production. It must pass a web application security audit and receive a Safe-to-Host certificate from an empanelled auditor. Also known as a ready-to-host certificate, this clearance is legally necessary at exactly the time when a product is attempting to go to market.
When Is a CERT-In Empanelled Auditor Required?
CERT-In empanelment requirements vary by regulator, entity type, and the specific security assessment being conducted. While some regulatory frameworks explicitly require a CERT-In empanelled auditor, others recognise multiple auditor qualifications or leave the choice to the applicable entity and framework. Always verify the latest requirement with the relevant regulator before starting an assessment.
| Sector / Regulatory Area | CERT-In Auditor Requirement | Authority |
| RBI-regulated entities | Depends on the applicable RBI direction and entity category | RBI |
| SEBI-regulated entities | CERT-In empanelled auditor requirements apply in specified VAPT contexts | SEBI CSCRF |
| Insurance | Qualified external systems auditor requirements; CERT-In empanelment is one recognised route | IRDAI |
| Government / critical sectors | CERT-In empanelled auditors are relevant for specified security audits | CERT-In |
| Healthcare / ABDM | Verify current NHA/ABDM security-assessment requirements for the specific integration | NHA/ABDM |
| DPDP | Data-protection obligations do not create a blanket CERT-In auditor requirement | MeitY |
CERT-In empanelment should not be treated as a universal requirement for every organisation in India. The applicable regulator, entity category, assessment type, and current regulatory framework determine whether an empanelled auditor is required.
CERT-In Empanelled Auditors List 2026: How to Find and Verify Active Status
The first place to start looking for a partner is not a search engine; it is the official source. Correctly reading the list of cert in empanelled auditors is a real skill which will save you from expensive errors.
Navigating the Official Roster
The official list of CERT-In empanelled companies is published directly on the CERT-In portal at cert-in.org.in. This directory contains all accredited organizations along with their empanelment categories and validity periods. Because it is updated directly by the authority, this is the only list regulators consider legally valid.
The Directory Trap
This is where many buyers get tripped up. When searching for a list of empanelled companies, the first page is usually teeming with third-party listicles. Most of these were once written, never updated, and were indexed. Empanelment is not permanent. CERT-In empanelment status can change, so buyers should verify the organisation’s current status directly against the official CERT-In roster before appointing an auditor. New companies are established, some expire, and a few fewer companies are suspended. January’s listicle may be out of date by April. This is a risk of using an old badge.
Step-by-Step Verification Protocol
Before engaging a CERT-In empanelled security auditor, run this quick protocol for every vendor on your shortlist. It only takes a few minutes and creates the clear audit trail your regulator expects to see.
- Check the active source directly – Open the current empanelment list from the official CERT-In portal, not a cached PDF or from a vendor’s website.
- Confirm the exact legal entity – Empanelment is linked to the legal entity, not just the trading or brand name.
- Verify the validity dates – Make sure that the empanelment is current as of the date the final audit report will be issued, not just today.
- Retain documented proof – Keep a copy of the listing that contains dates for your regulatory audit trail; this helps to provide evidence of due diligence when it’s time to submit.
What to Look for in CERT-In Empanelled Cybersecurity Auditors
Active empanelment is the entry ticket, not the whole decision. Among the top CERT-In certified auditing organisations, quality varies significantly, so evaluate these four dimensions before you commit.
1. Active Empanelment and Dual Accreditations
Beginning with empanelment, then searching for global credentials on top. A firm that has empanelment with CERT-In and has also acquired the CREST accreditation, ISO 27001 and SOC 2 provide a benefit, especially for software exporters. One partner meets Indian regulators and eases international enterprise buyers’ minds. This combination eliminates the need for any company to carry out assurance separately for the Indian market and the global market.
2. Manual Penetration Depth vs Automated Scanning
This is the most important criterion to pass a report. Automated vulnerability scanners are quick and limited. They can overlook business-logic issues, multi-step attack sequences and authorisation mistakes- things that only a human tester would notice. There is increasing pressure on regulators for real manual exploitation, and a scanner dump is a typical no-go item with regulators. Seek out human testing, proof-of-concept validation, and realistic chained attack scenarios, rather than tool output.
3. Asset-Specific Technical Expertise
Match the depth of the auditor with your technology. The best cert in empanelled VAPT companies demonstrate real expertise across many asset types. These include web applications, mobile applications (iOS and Android), and APIs evaluated against the OWASP API Top 10. They also provide cloud security for AWS, Azure, and GCP, and more recently, IoT and AI or LLM security. The cloud or API security knowledge of a firm with a strong web testing capability might be weak. Ensure proven experience in dealing with the assets you are covering.
4. Comprehensive Reporting and Remediation Guidance
The report is the deliverable, so do not purchase if it is not the quality you seek. There are several components to a good audit report. These are an executive summary, CVSS-based risk prioritisation and detailed step-by-step proof-of-concept. It also requires remediation guidance and validation for retesting when issues are closed, which has to be geared towards developers. If the sample report is similar to when the scan was output directly by the scanner, without this, be wary. No matter how the firm is accredited, it will be of little value to your stakeholders.
How to Choose the Right CERT-In Empanelled VAPT Company: A Buyer’s Checklist
After empanelment and capability assessment, the decision is objective and structured. This is how you distinguish reliable providers from weak ones among empanelled VAPT companies. While comparing empanelled VAPT providers, follow these six steps.
- Step 1: Define testing scope. List applications, IP ranges, microservices, APIs, and cloud infrastructure in your itemisation before requesting quotes, to enable a level playing field in the process.
- Step 2: Assess testing approach. Use of automated discovery is a must, but coupled with in-depth manual penetration testing, not scanning!
- Step 3: Review a redacted sample report. Before signing, evaluate: technical depth, evidence quality, executive clarity, remediation guidance.
- Step 4: Check the regulatory track record. Match the vendor’s experience with your framework – RBI, SEBI CSCRF, ABDM and ABHA integration or PCI DSS.
- Step 5:Confirm retesting and closure terms. Check if there are hidden charges for re-scans, patch validation and a final certificate.
- Step 6: Compare scope and depth, not just price. Consider value rather than headline price, as a cheap automated-scanning quote will result in re-audit costs later.
Common Pitfalls to Avoid When Hiring CERT-In Security Auditors
Even experienced buyers fall into a few recurring traps. Being aware of them protects your budget and timeline when vetting cert in empanelled cybersecurity auditors.
- The automated-scanner trap – Relying on basic tool output disguised as a penetration test, which misses real vulnerabilities and can fail a regulatory review.
- Post-audit remediation bottlenecks – Being handed a static PDF with no direct engineering or patching guidance, leaving your developers stuck.
- Hidden re-testing fees – Unexpected charges when you ask the auditor to verify that applied patches actually closed the findings.
- Outdated or lapsed empanelment – Some cert in empanelled companies let their status lapse; failing to confirm it before the engagement means the report cannot be submitted.
Scope Breakdown: What Security Assessments Can an Empanelled Auditor Perform?
The definition of “empanelled auditors” includes a wide variety of assessments. The most prominent cert in empanelled VAPT companies have them all, which enables you to commission the suitable engagement for your environment.
Web Application VAPT
This includes the OWASP Top 10, authentication and session management, access control, and business logic errors. Most commonly required assessment and forms the basis of ABDM WASA and compliance audits.
Mobile and API Security Testing
Mobile testing involves binary analysis and runtime testing of Android and iOS devices, whereas API testing covers the OWASP API security risks. With the growing openness of businesses revealing more functionality via APIs, it’s no longer an option, but a necessity.
Cloud and Infrastructure VAPT
This compares AWS, Azure and GCP architecture to the CIS Benchmarks, analyses misconfigurations and evaluates network security. Today, almost all of the businesses in India are operating in the cloud, and secure cloud configuration is one of the common vulnerabilities that can be exploited.
AI/ML and Emerging Tech Security
Newer scopes include prompt injection and LLM security testing, model abuse, and DevSecOps pipeline security. Even the SEBI is now talking about AI-based vulnerability assessment, indicating that this field is not only catching up with the trend but has also become expected.
Understanding CERT-In VAPT Pricing in India
Price is one of the most frequently asked questions, and the truthful answer is, “it depends on scope.” Knowing the cost drivers allows you to make a fair price comparison instead of going for the cheapest.
There is no standard CERT-In VAPT price. Cost depends on the number and type of assets, application complexity, authentication roles, API coverage, infrastructure scope, manual testing effort, source-code review and reporting requirements.
| Assessment | Main cost drivers |
| Web VAPT | URLs, roles, application complexity |
| Mobile VAPT | Android/iOS apps, binaries, API scope |
| API VAPT | API count, authentication, business logic |
| Network VAPT | IP range, external/internal scope |
| Cloud security assessment | AWS/Azure/GCP resources and architecture |
| Red team | Attack paths, duration, objectives |
When evaluating quotes, view them in the same order. So scope, methodology, testing depth, deliverables and then whether there is free retesting or not. The lower headline price that is attracted due to automated scanning can go up when a regulator rejects the report and a re-audit is required. The CERT-In empanelled cybersecurity auditors worth shortlisting will price transparently against a clearly defined scope so that you can compare fairly.
The Complete CERT-In VAPT Audit Process

Knowing the average engagement helps you to plan internally and set expectations. The top CERT-In certified auditing organisations follow a similar eight-step path.
- Step 1 — Scoping and NDA. In advance of any test, agree on the assets to be tested, rules of engagement, and confidentiality.
- Step 2 — Reconnaissance and threat modelling. Draw the attack surface and determine the probable attack routes of your environment.
- Step 3 — Automatic vulnerability analysis. Use tooling to identify a wide range of potential problems in a timely fashion.
- Step 4 – Deep Manual Penetration Testing. Vulnerabilities are tested and validated by human testers, who are able to detect business-logic and chained flaws that scanners cannot.
- Step 5 — Reporting and Dashboard Delivery. Assessment results are reported and graded, typically via a vulnerability dashboard.
- Step 6 — Developer remediation support. Your engineers are then walked through the corrections of each of these findings, a correction being not simply a list of the item, but what your engineers did to fix it.
- Step 7— Retesting and patch verification. Fixed issues are retested to ensure that they are actually closed.
- Step 8 — Final audit certificate. The certificate and the regulatory deliverables that your submission needs are issued by the empanelled auditor.
Why Organisations Choose Qualysec for CERT-In VAPT
Qualysec provides VAPT and security assessment services for organisations that need structured testing, regulatory-aligned reporting, and support through remediation. For organisations evaluating a CERT-In empanelled VAPT provider, the relevant considerations include the auditor’s empanelment status, testing methodology, technical coverage, reporting process, and post-assessment support.
- CERT-In empanelment and CREST accreditation: Qualysec is CERT-In empanelled and CREST accredited, giving organisations a provider that meets relevant Indian empanelment requirements while also following an internationally recognised security testing framework.
- Manual-led security testing: Assessments combine automated discovery with manual testing to investigate vulnerabilities that may not be identified through automated scanning alone, including access-control weaknesses, business-logic issues, and attack paths involving multiple vulnerabilities.
- Coverage across modern application environments: Testing can cover web applications, APIs, mobile applications, cloud environments, networks, and other technology-specific attack surfaces, depending on the agreed scope.
- Developer-focused reporting: Findings are documented with technical evidence, risk context, and remediation guidance so security and engineering teams can understand and address identified vulnerabilities. Qualysec also supports integrations with tools such as Jira and ServiceNow for vulnerability-management workflows.
- Retesting after remediation: After vulnerabilities are addressed, identified findings can be retested to verify whether the fixes have been implemented effectively and whether previously reported issues remain exploitable.
The right provider should ultimately be evaluated against the requirements of the specific assessment rather than accreditation alone. Organisations should verify the auditor’s current CERT-In empanelment status, confirm that the proposed scope matches their environment, review the testing methodology, and understand the reporting and retesting process before engagement.
Quick Checklist: Selecting Your CERT-In Security Auditor
The following is a checklist to use as a last check before signing with any one of the cert in empanelled vendors you are considering.
- Check the official CERT-In directory for the exact name of the legal entity for active status.
- Ensure the scope includes your web, mobile, API and cloud resources.
- Ensure that manual penetration testing is possible, rather than just automated scanning.
- Ask and examine a sample VAPT report that is redacted for depth and clarity.
- Get all retesting and patch-verification terms in writing as free.
- Check experience in your specific framework, such as RBI, SEBI CSCRF, ABDM, or PCI DSS.
Conclusion: Securing Compliance with the Right Partner
Selection of CERT-In empanelled security auditors is a strategic security choice, and not merely a compliance requirement. The right partner isn’t satisfied with just handing you a certificate. It is a tool that confirms your defences against real attack techniques and provides your developers with instructions on how to fix what counts. It also generates reporting for your regulator with first-time acceptance. It’s a combination that will keep your compliance posture and product roadmap secure in the regulated environment in India.
The rules are straightforward. Check the status of empanelment (active) in the official CERT-In empanelment list and confirm the legal entity and the validity period. Call for true depth in manual testing and insist on retesting and developer-friendly reporting. Match the experience of the auditor to your framework, be it RBI, SEBI CSCRF, IRDAI or ABDM. Then, the search that traditionally took weeks is a confident, defensible option from the top CERT-In-certified auditing organisations.
Frequently Asked Questions
What is the difference between a standard VAPT vendor and a CERT-In empanelled auditor?
A regular vendor is able to test your systems, but only CERT-In empanelled security auditors can provide reports that are accepted by the Indian regulators. Audits are required as per the RBI Cyber Security Framework and SEBI CSCRF to be conducted by an empanelled organisation. A non-empanelled report is a report that has not been filed with the regulator and is therefore unlikely to be accepted for submission.
How do I verify if an auditor’s CERT-In empanelment is currently active?
Please refer to the official roster directly on cert-in.org.in. Verify the legal entity name, NOT the brand name. Then check that the empanelment is for the date when your final report will be issued. Empanelment happens in threes and is subject to change throughout the year. Make sure to read the list of certs in empanelled auditors, and not a listicle from a third party.
Why do healthtech platforms require a CERT-In audit for ABDM and ABHA integration?
Two things are required for a digital health product to go from the ABDM sandbox into production, as per the mandate of the National Health Authority. Requires a passing Web Application Security Assessment and a Safe-to-Host certificate by an empanelled auditor. NHAs don’t accept internal or non-empanelled audits, and the use of the wrong firm is a common reason why NHAs reject applications.
How often is VAPT required for RBI-regulated organisations?
The required VAPT frequency depends on the type of RBI-regulated entity, the applicable RBI directions and the systems being assessed. Some frameworks require annual assessments, while critical or internet-facing systems may be subject to more frequent testing. Organisations should verify the latest RBI requirement applicable to their entity and scope.
Can an organisation pass an official regulatory audit using only automated vulnerability scanners?
No, generally. Automated scanners are not going to find business-logic flaws, chained attacks, or authorisation mistakes and regulators continue to expect real-world manual attacks. Many times a scanner report is presented as a penetration test, and this is a reason for submission being rejected. The top CERT-In certified auditing organisations perform both automated discovery and manual testing.
What is a CERT-In Safe-to-Host certificate and who needs it?
A Safe-to-Host certificate, sometimes known as a ready-to-host clearance, is an affirmation by an empanelled auditor that a facility is safe for hosting. It verifies that there are no known vulnerabilities in an application and that it is safe to deploy. It is mandatory prior to healthtech applications entering production, and applications on government infrastructure must have clearance before go-live.
What is the average cost of a CERT-In VAPT assessment in India?
There is no fixed cost for this; its scope dictates the cost. Drivers are the number of assets, application complexity, source code review, number of APIs, number of manual testing hours and scope of compliance. The duration of a typical web application VAPT is 5-10 working days, followed by reporting and a retest. Shop around for the scope, methodology, depth, and availability of free retesting.
Why choose Qualysec for CERT-In empanelled security testing?
Qualysec is empanelled and CREST accredited by CERT-In and also accepted by the local regulatory body and trusted worldwide. It provides human-led, process-driven VAPT capabilities, real-time dashboards, JIRA integration, ServiceNow integration, and free post-remediation retesting. That translates to submission-ready reports and a smoother road from audit to launch.







