Skip to main content
CERT-In Empanelled Since 2008

Compliance assessments
that regulators accept.

Audit-ready reports for every Indian and global regulatory framework. Trusted by 1,000+ organisations across BFSI, healthcare, insurance, and government.

By Regulator

Mandatory Indian regulatory frameworks

As India's longest-serving CERT-In empanelled firm, our reports satisfy statutory requirements for all Indian regulators.

CERT-In Security Audit

Empanelled security auditor since 2008 — mandatory for critical infrastructure, government, and regulated entities under CERT-In directives.

MandatoryGovernmentCritical Infrastructure

RBI Cybersecurity Framework

Six-monthly VA and annual PT, IS audit and cybersecurity compliance for banks, NBFCs and co-operative banks under the RBI Directions, 2026 — which repealed the 2016 framework on 31 July and took effect on issuance, with no transition period.

BanksNBFCsCooperative Banks

RBI Directions, 2026 — all six instruments

RBI issued six entity-specific cybersecurity Directions on 31 July 2026, all in force on issuance. Compared side by side with paragraph numbers — VA/PT cadence, red teaming, incident reporting, and the NBFC layer and UCB Level scoping that decides which chapters bind you.

BanksSFBsNBFCsUCBsCICs

SEBI CSCRF Compliance

Cybersecurity and cyber resilience framework compliance for 22 SEBI-regulated entity categories — MIIs, Qualified REs, Mid-size, Small-size and Self-cert REs. Master circular Aug 2024 read with Apr/Aug 2025 amendments and the May 2026 AI advisory.

MIIsQualified REsAMCsBrokersAIFsCustodians

SEBI AI Vulnerability Detection Advisory

May 2026 advisory (HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026) on AI tools like Claude Mythos. Mandates AI-based VA, M-SOC onboarding, ZTNA, SBOM, and a long-term agentic-defence plan across 19 categories of regulated entities.

AdvisoryAI SecurityMay 2026

CERT-In Audit Policy Guidelines

CISG-2025-02 (July 2025) sets how cyber security audits in India must be scoped, conducted, evidenced and reported. Expects comprehensive ICT audit coverage at least once a year, names 26 engagement types, and defines how auditees must select an auditor.

CISG-2025-02Audit PolicyJul 2025

NIST Cybersecurity Framework (CSF 2.0)

Current and Target Profiles, implementation Tiers and a prioritised gap analysis across all six CSF 2.0 functions. Asked for by global parents, enterprise vendor questionnaires and cyber insurers — and most SEBI CSCRF evidence already maps onto it.

CSF 2.0ProfilesTiers

IRDAI Cybersecurity

Cybersecurity compliance for insurers and ISNPs under IRDAI guidelines — vulnerability assessment, IS audit, and incident response readiness.

InsurersISNPReinsurers

Specialised Audits

Distinct-scope audits across the payments + identity ecosystem

Dedicated engagements for SAR, payment aggregators, UIDAI, NPCI, SBI VSCC, ATM/POS, and vendor risk — each with its own deliverable format and procurement intent.

SAR · System Audit Report (Data Localization)

RBI-mandated annual system audit for PA-PG, PPI, BBPOU, UPI TPAPs, and CDSL depository participants. Distinct deliverable per regulator format.

RBIPA-PGUPICDSL

RBI Payment Aggregator (PA-PG) Audit

Annual system audit + cybersecurity audit by CERT-In empanelled auditors per RBI 2025 PA Master Direction. Merchant onboarding to escrow to settlement.

RBICERT-InAnnual

UIDAI AUA-KUA Audit

Aadhaar ecosystem security and compliance audit for AUAs, KUAs, Sub-AUAs, and Sub-KUAs. UIDAI checklist + management comments + closure validation.

UIDAIAadhaareKYC

NPCI / UPI Audit

Payment ecosystem audit for PSPs, TPAPs, sponsor banks, BBPS/BBPOU, and RuPay. Role-specific scope plus UPI 2.0, AutoPay, Credit-on-UPI add-ons.

NPCIUPITPAPBBPS

SBI VSCC Audit

Vendor Site Compliance Certificate for SBI ePay / SBI payment gateway merchant onboarding. Issued by CERT-In empanelled auditor with VSCC Form C.

SBIVSCCMerchant Onboarding

ATM & POS Security Audit

Payment-channel security audit covering ATMs, POS, CDMs, kiosks, microATMs, NFC tap-to-pay, payment middleware, and switch integration.

ATMPOSEMVPCI DSS

Vendor Risk Assessment (VRA)

Compliance-focused vendor / third-party risk audit for RBI, SEBI, DPDP, NPCI, M&A, and customer-questionnaire mandates. Bridges to ShadowMap VRM + TPRM.

TPRMVendor RiskShadowMap

NSE Trading Member VAPT

NSE-mandated VAPT submission for stock brokers and trading members under SEBI CSCRF. Covers the Sep 2025 inspection circular timelines, reporting formats, and CERT-In auditor norms.

NSETrading MembersFY 2026-27
6,700+

Security assessments delivered

1,000+

Organisations served

Since 2008

CERT-In empanelment

22

Framework pages · 17+ mandates

Not sure which compliance framework applies?

Run the self-service wizard for your regulator and get back tier classification, obligations, and prioritised gaps in 8–10 questions. Or talk to a compliance specialist directly.