CERT-In VAPT

CERT-In VAPT Audit by an Empanelled Auditor

A CERT-In VAPT audit is a vulnerability assessment and penetration test carried out by an organisation on CERT-In's list of empanelled information security auditors. Scantra Security is CERT-In empanelled, so we can deliver audits and reports that satisfy regulators, government tenders and enterprise customers who require an empanelled auditor.

Last reviewed 2026-09-28 by the Scantra Security testing team

What CERT-In is

The Indian Computer Emergency Response Team (CERT-In) is the national agency for cyber security incident response under the Ministry of Electronics and Information Technology. Among other duties, it maintains a panel of auditors who meet its technical and organisational standards for security auditing.

Who needs a CERT-In empanelled audit

  • Central and state government departments and PSUs
  • Critical information infrastructure and essential services
  • Banks, NBFCs and payment entities whose regulators refer to empanelled auditors
  • Vendors bidding for government or PSU tenders
  • Companies whose enterprise customers specify a CERT-In empanelled auditor

What a CERT-In VAPT audit covers

Scope depends on your systems and regulator, but usually includes web applications, mobile apps, APIs, network infrastructure and cloud configuration. Testing follows recognised methodologies such as OWASP and NIST and results are reported with CVSS severity ratings. We also review related controls, such as log retention and incident reporting readiness under the CERT-In directions of April 2022.

Our audit process

  1. 1. Scoping

    We confirm assets, regulatory drivers and deadlines, and agree a written scope.

  2. 2. Assessment and testing

    Vulnerability assessment followed by manual penetration testing of every in-scope asset.

  3. 3. Draft report

    Findings with CVSS ratings, evidence and remediation steps, reviewed with your team.

  4. 4. Remediation and free retest

    We verify fixes at no extra cost.

  5. 5. Final report and certificate

    A final audit report and certificate on Scantra letterhead referencing our empanelment.

Our empanelment

Scantra Security is a CERT-In empanelled organisation. [CONFIRM: empanelment reference, date and link to the CERT-In list to display here]

Frequently asked questions

Is a CERT-In audit mandatory for every company?

No. It is mandatory for specific entities and tenders, and requested by many enterprise customers. We can help you confirm whether it applies to you.

How long is a CERT-In VAPT report valid?

Validity is set by your regulator or customer, most commonly one year or until a major change.

Can you help with the CERT-In 6-hour incident reporting rule?

We review your logging and incident response readiness as part of the audit and flag gaps.

Do you issue a certificate?

Yes, after the retest we issue a final audit report and certificate.

Related services

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.