The CERT-In audit policy guidelines.
What they require, decoded.
In July 2025 CERT-In published the rulebook for how cyber security audits in India must be run — for the auditor and the auditee. It expects comprehensive ICT audit coverage at least once a year, names 26 engagement types, tells you exactly how to select an auditor, and sets out what happens to auditors who fall short.
What CERT-In published
A rulebook for the audit itself — not just the auditor.
Empanelment says who is allowed to audit you. CISG-2025-02 says how that audit has to be conducted: the principles it must follow, the standards it must map to, the evidence and working notes it must produce, how the opinion must be formed and reported, and what happens when any of that is not met.
It runs to 69 pages across 20 sections, and it is issued under the same statutory authority as CERT-In itself — section 70B of the Information Technology Act, 2000, and rule 9 of the CERT-In Rules, 2013.
Who it binds
Public and private sector alike.
“These guidelines are intended for organizations in both the public and private sectors that are required to or are seeking to evaluate their cyber security posture, identify vulnerabilities, assess risks, and ensure compliance with applicable regulatory standards and industry best practices.”
— CISG-2025-02, §4 Applicability
The cadence
Comprehensive. All ICT systems. At least once a year.
“Auditee organizations, which are expected to ensure a comprehensive audit covering all aspects of their Information and Communication Technology (ICT) systems at least once a year, may also opt for additional assessments and audits during the year.”
— CISG-2025-02, §6 Scope of Engagements Covered
The load-bearing words are comprehensive and all aspects. An annual web application pentest is not an annual ICT audit. Most organisations we assess against this clause find their programme covers the systems that are easy to scope and leaves out the ones that carry the actual risk — OT, cloud control planes, identity, third-party integrations, and the endpoint estate.
Scope of engagements covered
All 26 engagement types named in §6.
The guideline lists these as "including, but not limited to". Linked items are services we market individually; the rest we deliver inside a broader audit engagement.
§12 · Selection of auditor
How CERT-In says you should choose an auditor.
Six obligations the guideline places on the auditee. Several of them are routinely skipped — and each one is a fair question to put to every firm bidding for your audit, including us.
Check the CERT-In snapshot before you shortlist
"The snapshot information of skills and competence of CERT-In empaneled auditing organizations published on CERT-In’s website should be utilized by the organizations or sectoral regulators to identify and select the auditing organizations by mapping their requirements with the competence of auditing organizations."
The snapshot shows manpower and skillsets, audit experience by category, audits carried out in the last 12 months by sector, and the tools used. It is the one public, regulator-maintained record of what an auditor has actually done — as opposed to what a proposal claims.
Interview the actual people, not the firm
"The Auditee organizations should interview and select the resources aligned by auditing organizations for competency and experience with respect to the scope of Audit."
The guideline puts the obligation on you to assess the individuals who will do the work. We expect this and support it — you meet the consultants who will run your engagement before it starts, not a pre-sales team you never see again.
No freelancers, no interns, no notice-period staff
"Auditing organizations should not field freelancers, interns, freshers, moonlighters, third party consultant or employees who are serving their notice period and the auditee organizations should verify compliance."
This is the sharpest line in the guideline, and the one most likely to be quietly breached in a low-cost bid. Verifying it is explicitly your responsibility as the auditee. Our engagements are delivered by full-time employed senior consultants, and every auditor is declared to CERT-In.
Verify identity and credentials at your end
"Auditee organizations must verify the identity, official identity cards/ government issued documents and designations of the auditing team to ensure that the individuals conducting the audit are legitimate and authorized."
Credentials must line up with CERT-In’s published qualification requirements for empanelment. We provide identity and designation evidence for every named auditor as part of engagement onboarding.
Only CERT-In-declared manpower may be deployed
"Auditing Organization must only deploy manpower declared to CERT-In in Snapshot Information Form published on CERT-In’s website."
Background verification is the sole responsibility of the auditing organisation, before employment and if necessary after. Auditors moving between empanelled firms require an NOC or relieving letter from the previous organisation, and the snapshot must be updated with CERT-In.
Fees must not depend on the result
"Payments to the auditing organization should not be contingent upon the outcome of the audit—whether favorable or unfavorable—nor should they be tied to the submission or approval of any closure reports."
From §7, Independence. A commercial structure that pays on a clean report is a structure that buys a clean report. If a bid ties fees to closure sign-off, that is a guideline problem before it is a quality problem.
§19 · Consequences of non-compliance
There is an enforcement ladder, and it has four rungs.
CERT-In describes this as a framework of "enabling actions as well as deter & punish mechanism". Graded actions apply to adverse reports, guideline violations, breaches of empanelment terms, and poor audit quality.
Watch list, with warning and written commitment
Inadequate closure of non-compliances; no clear relation between noting and issues raised; inadequate sampling, coverage or improper conclusions; minor-impact breaches of CERT-In terms; a first adverse report missing up to two vulnerabilities.
Suspension
Adverse auditee feedback on technical competency; repeated failures in audit planning or coverage; issues appearing soon after an audit was signed off; major-impact breaches of CERT-In terms or multiple adverse reports of missed vulnerabilities.
Debarment under GFR and de-empanelment by CERT-In
Sustained or severe failure against the parameters above.
Penal and legal action
The guideline is issued under section 70B of the IT Act, 2000. Non-compliance with a direction issued under section 70B(6) attracts punitive action under section 70B(7).
Read the other way round, this is a quality guarantee for auditees: "issues appearing soon after conduct of audit" and "adverse feedback from auditee regarding technical competency" are named triggers for suspending an auditor. If an audit misses something that surfaces immediately afterwards, that is a reportable matter — not just a bad experience.
Common questions
CISG-2025-02, answered.
What is CISG-2025-02?
It is CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines, version 1.0, issued 25 July 2025. It is a 69-page document that sets out how cyber security audits in India should be scoped, planned, performed, evidenced and reported — covering both the auditing organisation and the organisation being audited. It is issued under section 70B of the Information Technology Act, 2000 and rule 9 of the CERT-In Rules, 2013.
Does it apply to private companies, or only government?
Both. Section 4 states the guideline applies to CERT-In empanelled auditing organisations and to auditee organisations "in both the public and private sectors that are required to or are seeking to evaluate their cyber security posture." It is not restricted to government bodies or to CII.
How often does CERT-In expect an audit?
Section 6 states that auditee organisations "are expected to ensure a comprehensive audit covering all aspects of their Information and Communication Technology (ICT) systems at least once a year," and may opt for additional assessments and audits during the year. The annual expectation is for comprehensive ICT coverage — not a single application or a single network range.
Is this the same thing as CERT-In empanelment?
No, and the distinction matters. Empanelment is the status that authorises an organisation to conduct these audits. CISG-2025-02 governs how the audit itself must be run once an empanelled auditor is appointed — planning, evidence, working notes, reporting, independence — and what happens when those standards are not met. An auditor can be empanelled and still be in breach of the guideline.
What happens to an auditor that does not follow the guideline?
Section 19 sets out a graded enforcement ladder: move to a watch list with warning and written commitment; suspension; debarment under GFR and de-empanelment by CERT-In; and penal and legal action. Triggers include missed vulnerabilities, inadequate sampling or coverage, weak closure of non-compliances, and adverse auditee feedback on technical competency.
Can we pay our auditor on successful closure of findings?
No. Section 7 is explicit that payments "should not be contingent upon the outcome of the audit — whether favorable or unfavorable — nor should they be tied to the submission or approval of any closure reports," because linking payment to outcome compromises independence. This is worth checking in any competitive bid, because outcome-linked commercials are not unusual and are a direct breach of the guideline.
Which types of assessment fall under the guideline?
Section 6 names 26 engagement types, explicitly "including, but not limited to". They range from vulnerability assessment, penetration testing and source code review through to red team assessment, cloud security testing, ICS/OT and IoT testing, AI system audits, vendor risk management audits, blockchain security audits, and SBOM/QBOM/AIBOM auditing. Most organisations discover their annual programme is narrower than the guideline contemplates.
How does this interact with SEBI CSCRF or RBI requirements?
It sits underneath them. Sectoral regulators mandate that regulated entities be audited; CISG-2025-02 governs the conduct and quality of the audit that satisfies those mandates, and CERT-In empanelment is generally the qualification the sectoral regulator relies on. In practice a SEBI or RBI submission is only as defensible as the audit behind it, and the guideline is the standard that audit is measured against.
Does your audit programme meet the guideline?
We map your current programme against §6 coverage, §12 selection obligations and §7 independence requirements, and tell you where the gaps are — including the ones that are our problem to fix rather than yours.