Skip to main content
CERT-In Empanelled Since 2008

CERT-In Compliance and Security Audit Services

Empanelled since 2008, Security Brigade delivers end-to-end CERT-In security audits, breach notification management, and continuous compliance for enterprises and regulated entities across India.

6,700+
Assessments
Since 2008
CERT-In Empanelled
1,000+
Clients
6 hr
Reporting Window

With 18 years of CERT-In empanelment and over 6,700 security assessments completed, Security Brigade is one of the most experienced CERT-In auditors in the country. Our platform-driven approach maps every audit requirement to the CSA-BR baseline markers, ensuring complete coverage, faster turnaround, and audit reports that regulators accept without pushback.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The credential

Empanelment is a status, not a certificate

It attaches to the auditing firm, it runs for a defined period, and CERT-In publishes who holds it. Nothing about it is issued per engagement.

CERT-In empanels information security auditing organisations to audit the ICT systems of government bodies, critical sectors and private companies. The status sits with the firm, not with a report, a person or a project, which changes what a regulator is actually asking when it asks whether your auditor was empanelled. It is asking about a date: was this firm on the published list on the days the work was performed. Not on the day you signed, and not on the day the report was issued. That single distinction decides most of what follows on this page, because it means the thing you have to be able to evidence is a period, not a document. Security Brigade has held CERT-In empanelment continuously since 2008, among the earliest cohorts empanelled in India, and the audit reports we issue are accepted by regulators without pushback.

Before you appoint

CERT-In publishes a checklist for choosing an auditor. Most buyers have never seen it

Section 12 of the 2025 audit policy guidelines tells auditees what to verify before an engagement starts. Each row is what it asks of you, and where the answer comes from.

What to verifyWhat the guideline asksWhere it comes from
The firm, on the published list CERT-In publishes snapshot information for every empanelled organisation: manpower and skill sets, relevant audit experience, the categories of audit it conducts, and the audits it has carried out in the last twelve months broken down by sector. The guideline expects auditees and sectoral regulators to use that snapshot to map their requirement against a firm’s actual competence and not against its marketing. CISG-2025-02 §12.1
The people, not just the firm Auditees are told to interview and select the individuals assigned to the engagement for competence against the audit scope, and to verify their technical credentials against CERT-In’s published qualification requirements. Two of section 12’s four subsections are about the individuals, not the firm, which is the opposite of how most procurement processes weight it. CISG-2025-02 §12.2(i)-(ii)
Identity and designation Auditees must verify identity, official or government-issued identity documents and designations of the audit team, to establish that the people doing the work are legitimate and authorised. The guideline then states plainly who must not be fielded: "freelancers, interns, freshers, moonlighters, third party consultant or employees who are serving their notice period", and puts the duty to verify that on the auditee. CISG-2025-02 §12.2(iii)
Every auditor Security Brigade fields on a CERT-In engagement is a background-checked full-time employee, declared to CERT-In in our snapshot information. We expect to be asked for that evidence and send it without being chased.
Declared manpower only An auditing organisation may deploy only the manpower it has declared to CERT-In in its Snapshot Information Form, and CERT-In reserves the right to verify that independently, from the auditing organisation or from the auditee. CISG-2025-02 §12.3(iii)
The contract length For applications that are critical or have high user reach, the guideline says audit contracts should be awarded for two to three years so that auditing is continuous at a defined frequency instead of being re-tendered annually into a different firm with no memory of last year’s findings. CISG-2025-02 §12.4(i)

The firm, on the published list

What the guideline asks
CERT-In publishes snapshot information for every empanelled organisation: manpower and skill sets, relevant audit experience, the categories of audit it conducts, and the audits it has carried out in the last twelve months broken down by sector. The guideline expects auditees and sectoral regulators to use that snapshot to map their requirement against a firm’s actual competence and not against its marketing.
Where it comes from
CISG-2025-02 §12.1

The people, not just the firm

What the guideline asks
Auditees are told to interview and select the individuals assigned to the engagement for competence against the audit scope, and to verify their technical credentials against CERT-In’s published qualification requirements. Two of section 12’s four subsections are about the individuals, not the firm, which is the opposite of how most procurement processes weight it.
Where it comes from
CISG-2025-02 §12.2(i)-(ii)

Identity and designation

What the guideline asks
Auditees must verify identity, official or government-issued identity documents and designations of the audit team, to establish that the people doing the work are legitimate and authorised. The guideline then states plainly who must not be fielded: "freelancers, interns, freshers, moonlighters, third party consultant or employees who are serving their notice period", and puts the duty to verify that on the auditee.
Where it comes from
CISG-2025-02 §12.2(iii)

Every auditor Security Brigade fields on a CERT-In engagement is a background-checked full-time employee, declared to CERT-In in our snapshot information. We expect to be asked for that evidence and send it without being chased.

Declared manpower only

What the guideline asks
An auditing organisation may deploy only the manpower it has declared to CERT-In in its Snapshot Information Form, and CERT-In reserves the right to verify that independently, from the auditing organisation or from the auditee.
Where it comes from
CISG-2025-02 §12.3(iii)

The contract length

What the guideline asks
For applications that are critical or have high user reach, the guideline says audit contracts should be awarded for two to three years so that auditing is continuous at a defined frequency instead of being re-tendered annually into a different firm with no memory of last year’s findings.
Where it comes from
CISG-2025-02 §12.4(i)

Outside the audit window

Three obligations that are already running

The audit is annual. These are not. Each one is won or lost before the day it is tested, which is why they belong on a page about choosing an auditor.

Three obligations that are already running
StateWhat it meansWhat follows
Six hours Cyber incidents are reportable to CERT-In within six hours of being noticed, under the Directions issued on 28 April 2022. A six-hour clock is decided before hour one. Who is authorised to declare an incident, what gets sent and who sends it either exists in writing already or the clock is lost while it is being invented.
180 days of logs ICT system logs are to be maintained on a rolling 180-day basis, and held within Indian jurisdiction. Most organisations discover this obligation is unmet during an audit, not before one, usually because retention was configured per system and never checked as a whole.
A named point of contact A designated point of contact is to be kept on record with CERT-In for all communications. Cheap to satisfy, and routinely stale. The person named has frequently left, which is only discovered at the moment it matters.
Key
  • Fails in hours
  • Fails quietly, over months

How the report is structured

Six markers, and which assessment evidences each one

A submission is graded on structure as much as on findings. The six control families come from the Cyber Security Audit Baseline Requirements (NSCS-46-16), and this is the work that produces evidence for each.

MarkerWhat it coversEvidenced by
CSM Cyber Security Management. Policy and audit process, frameworks and standards, senior-management commitment, infrastructure classification, risk assessment and treatment, continuity planning, awareness and training, data ownership and access control: nineteen controls, and the only family that is mostly documents instead of systems. Configuration and hardening review, policy and governance review
PRO Protective Controls. Physical security of critical assets, access control, remote access and teleworking, vulnerability and patch management, removable media: twenty-one controls. Web application testing, network and infrastructure testing, configuration review
DET Detection Controls. The scope, mechanism and frequency of log collection, and whether what is collected would actually surface an incident. Network and infrastructure testing, log management review
RES Response. The incident response plan and the ability to execute it, which is also where the six-hour reporting obligation is either satisfied or lost. Incident response readiness review
REC Recovery Controls. A defined and implemented recovery plan, and evidence that it has been exercised and not merely written. Incident response readiness, continuity and recovery testing
IMP Improvement. Lessons learnt from incidents and cyber exercises, incorporated back into the response plan. The one family that cannot be evidenced by a control existing, only by something having happened and the plan having changed because of it. Post-incident review, tabletop and red team exercise debriefs
Often written up as "Implementation". It is not: §7(f) of the Baseline Requirements is "Lesson Learnt & Improvements", and imp.1 is the incorporation of those lessons into the response plan.

CSM

What it covers
Cyber Security Management. Policy and audit process, frameworks and standards, senior-management commitment, infrastructure classification, risk assessment and treatment, continuity planning, awareness and training, data ownership and access control: nineteen controls, and the only family that is mostly documents instead of systems.

PRO

What it covers
Protective Controls. Physical security of critical assets, access control, remote access and teleworking, vulnerability and patch management, removable media: twenty-one controls.

DET

What it covers
Detection Controls. The scope, mechanism and frequency of log collection, and whether what is collected would actually surface an incident.

RES

What it covers
Response. The incident response plan and the ability to execute it, which is also where the six-hour reporting obligation is either satisfied or lost.

REC

What it covers
Recovery Controls. A defined and implemented recovery plan, and evidence that it has been exercised and not merely written.
Evidenced by
Incident response readiness, continuity and recovery testing

IMP

What it covers
Improvement. Lessons learnt from incidents and cyber exercises, incorporated back into the response plan. The one family that cannot be evidenced by a control existing, only by something having happened and the plan having changed because of it.

Often written up as "Implementation". It is not: §7(f) of the Baseline Requirements is "Lesson Learnt & Improvements", and imp.1 is the incorporation of those lessons into the response plan.

Choosing between us

Every firm on that list can sign the report

Empanelment is the floor, not the differentiator. If you are holding a shortlist, all of them clear it, so the question is what happens between the testing and the submission.

What separates empanelled firms is not whether they are permitted to audit you. It is whether the report goes in once. Three things decide that. Continuity, because a methodology drawn from empanelled engagements run continuously since 2008, across more than 6,700 assessments, is a different instrument from one assembled for the engagement in front of it. Review, because every finding passes L1, L2 and L3 expert review before it reaches your report, and a finding that does not survive internal challenge should never reach a regulator. And structure, because a report written for the submission it is going into does not come back with a revision cycle attached. There is also a distinction worth holding onto while you choose: empanelment governs who is permitted to audit you, while CISG-2025-02 governs how that audit must be scoped, conducted, evidenced and reported. That includes, at §19, what follows when it is not. A firm can be empanelled and still be working outside the guideline. We have written up the whole of that guideline, clause by clause, on a separate page.

The sequence

The certificate follows the fix, not the finding

The order matters more than the artefacts do, because it is the part that decides your timeline, and the part most submissions get wrong.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's CERT-In audit methodology is mapped to the six baseline markers of the Cyber Security Audit Baseline Requirements (NSCS-46-16): CSM (Cyber Security Management), PRO (Protective Controls), DET (Detection Controls), RES (Response), REC (Recovery Controls), and IMP (Improvement). Our proprietary platform Lemon orchestrates every phase, ensuring complete coverage, structured evidence collection, and audit reports that meet regulatory expectations without revision cycles.

Discovery
01

Scoping and Baseline Mapping

We identify all assets in scope including web applications, mobile applications, APIs, network infrastructure, and cloud environments. Each asset is mapped against CSA-BR baseline markers to define the audit plan. Lemon automatically assigns testing tasks and coverage requirements based on the asset profile.

02

Vulnerability Assessment and Penetration Testing

Comprehensive VAPT across all in-scope assets using our structured methodology. Web and mobile application testing follows OWASP standards. Network and infrastructure testing covers external and internal attack surfaces. AI-validated coverage ensures no endpoint or service is missed. All findings are mapped to specific CSA-BR baseline markers.

Testing
03

Configuration and Architecture Review

Server hardening review, firewall configuration audit, network architecture assessment, and access control validation. We evaluate security configurations against CERT-In benchmarks and industry best practices, identifying misconfigurations that automated tools often miss.

04

Policy and Process Assessment

Review of information security policies, incident response procedures, access management processes, change management controls, and log management practices. We evaluate organisational readiness against CERT-In Directions 2022 requirements including the six-hour breach notification process and 180-day log retention mandate.

Delivery
05

Multi-Layer Quality Review

Every finding undergoes our L1/L2/L3 review process. L1 auditors document findings with proof-of-concepts. L2 senior consultants validate methodology and coverage completeness. L3 security architects confirm impact assessments and report quality. No audit report is released without passing all three review layers.

06

Reporting, Remediation, and Certification

We deliver a comprehensive CERT-In audit report with gap analysis, prioritised remediation roadmap, and technology-specific fix guidance. Multiple rounds of retesting are included. Once critical findings are resolved, we issue the formal CERT-In security audit certificate and provide ongoing support for regulator queries.

"We have SAP, SCADA, 200+ web apps, and factories running legacy systems. Most security firms understand IT or OT — not both. Security Brigade tested our corporate network, our plant floor, our SAP interfaces, and our cloud migration path in one engagement with one methodology. The OT findings alone justified the engagement, but the real value was having everything in a single risk register."
VP Security, Manufacturing Conglomerate
Vice President — Information Security

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

Empanelment attaches to the firm and to the person who signs, not to the tooling underneath. B-52 sets out where an automated pass sits inside an empanelled engagement and what a named auditor still has to do with the result.

See the B-52 platform Built and run by Security Brigade

FAQ

Questions that come up in diligence

These are the ones procurement and compliance teams actually send us before an engagement is signed.

Contact us
Does our auditor need to be empanelled on the audit date or the report date?+
The dates the work was performed are the ones that have to be defended, so treat the audit window as the period that matters and keep evidence of the firm’s status across it. Where an engagement runs close to the end of an empanelment period, agree in writing before the work starts which dates the report will cover.
Our regulator has asked for evidence of our auditor’s empanelment. What do we send?+
Our entry on CERT-In’s published list of empanelled organisations, the period that entry covers, the categories of audit it covers, and the identity and designation evidence for the named auditors who performed the work. We provide all four as a matter of course; you should not have to ask for them.
Can one engagement satisfy CERT-In and our sectoral regulator at the same time?+
Frequently, yes, and scoping for it deliberately beats discovering it afterwards. Sectoral regulators rely on CERT-In empanelment as the auditor qualification, so a single properly scoped engagement can produce evidence for more than one submission. What differs between them is the reporting structure and where the result is filed, which is a scoping decision made at the start and an expensive one to retrofit.
Is a CERT-In audit a pass or fail examination?+
No. A CERT-In audit is not a pass/fail examination. It identifies gaps against the applicable requirements and gives you a remediation path. Our goal is to get you compliant, not just to assess you, so the certificate is issued once the fixes are validated, not once the testing is finished.
How long does the whole process take?+
The testing is the predictable part. What sets the calendar is remediation, because the certificate waits for it. Organisations that scope early, fix as findings arrive instead of in a batch at the end, and book the retest before they need it, complete in a fraction of the time of those that treat the audit report as the finish line.

Start Your CERT-In Compliance Journey Today

18 years of CERT-In empanelment. 6,700+ assessments. Platform-driven quality your regulators will trust.

Typically responds within 1 business day · No commitment required

Request a Scoping Call