What CERT-In is, when a CERT-In empanelled auditor is required, what the April 2022 directions changed, and how to prepare for a CERT-In VAPT audit.
What CERT-In is
The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cyber security incident response, operating under the Ministry of Electronics and Information Technology. Among its roles, CERT-In maintains a panel of information security auditing organisations that meet its technical and organisational requirements.
When a regulator, department or customer asks for a 'CERT-In audit', they usually mean a security audit, often VAPT, carried out by an organisation on that panel.
Who needs a CERT-In empanelled auditor
Government ministries, departments and PSUs commonly require empanelled auditors for their applications and infrastructure. Critical sector organisations and many regulated entities follow the same practice. Private companies bidding for government tenders often need a VAPT report from an empanelled auditor. Increasingly, large enterprises in India also specify empanelled auditors in vendor security requirements.
Always check the exact wording of your regulator, tender or contract, because requirements differ.
The April 2022 CERT-In directions
In April 2022 CERT-In issued directions under section 70B of the IT Act. Key points include reporting specified cyber incidents to CERT-In within six hours of noticing them, maintaining logs of ICT systems for a rolling 180 days within Indian jurisdiction, and synchronising clocks with specified NTP sources. These directions are not VAPT requirements in themselves, but a good audit should check that your logging and incident response are ready to meet them. Refer to the official CERT-In website for the current text.
How to prepare for a CERT-In VAPT audit
List every in-scope asset: URLs, apps, APIs, IPs and cloud accounts. Prepare a staging environment and test accounts. Confirm the deadline and reporting format your regulator or customer expects. Plan time to fix findings and complete a retest before the deadline, since most stakeholders want to see a clean or accepted-risk final report.
Scantra Security is CERT-In empanelled and delivers CERT-In VAPT audits with a free retest and a final audit certificate.
