Skip to main content
CERT-In Empanelled Since 2008 — One of the earliest empanelled auditors in India, mandatory for IRDAI audits

IRDAI Cybersecurity Compliance: Insurance Companies, ISNP Audit & Broker/TPA Assessments

End-to-end IRDAI compliance for life, general, health insurers, ISNP platforms, insurance brokers, and TPAs. CERT-In empanelled auditor delivering regulator-ready reports, gap assessments, and remediation support across every IRDAI cyber mandate.

107+
Insurance Clients
IRDAI-Aligned
Methodology
ISNP-Ready
Audit Coverage
Since 2008
CERT-In Empanelled

The Insurance Regulatory and Development Authority of India (IRDAI) mandates cybersecurity controls across the entire insurance value chain. Whether you operate as an insurance company, run an Insurance Self-Network Platform (ISNP), or function as an insurance broker or Third-Party Administrator, IRDAI expects documented evidence of cybersecurity governance, technical controls, incident response readiness, and periodic audits by CERT-In empanelled auditors. Security Brigade has delivered IRDAI cybersecurity audits for insurers, ISNP platforms, and intermediaries, helping regulated entities achieve and maintain compliance without disrupting business operations.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Scope

Most of the entities named in this circular are not insurers

Applicability is the part of this instrument people get wrong, and it is set out in the covering circular itself, reference IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026.

Most of the entities named in this circular are not insurers
StateWhat it meansWhat follows
Insurers, including FRBs Life, general, health and reinsurance, and foreign reinsurance branches operating in India. The population everyone expects to be in scope.
Brokers and corporate agents Named in the circular in their own right, not by virtue of who they place business with. Frequently assume the insurer’s compliance covers them. It does not.
Web aggregators and IMFs Insurance web aggregators and Insurance Marketing Firms. Digital-first businesses, often small, holding quote and proposal data at volume.
TPAs Third Party Administrators handling health claims. Hold the most sensitive data in the chain (diagnosis, treatment, claim history) and sit outside the insurer’s own estate.
ISNP operators Insurance Self Network Platforms: the e-commerce channel for insurance. A named category with its own architecture, and the reason this page carries an ISNP audit scope at all.
Insurance repositories The entities holding electronic insurance accounts. Custodians of policy records across insurers.
Corporate surveyors and MISPs Corporate surveyors and loss assessors, and Motor Insurance Service Providers. MISPs are automobile dealers selling motor cover. A dealership is now inside an insurance cyber security instrument, which is the single most surprising line in the circular.
CSCs and the IIB Common Service Centres, and the Insurance Information Bureau of India. Distribution reach and the industry data bureau, both named.
Key
  • Most often surprised to be in scope
  • Named in its own right
  • Expected

The instrument

If your register cites a 2017 or 2020 circular, it is two revisions behind

Four superseded instruments sit behind the current one, and compliance registers tend to carry whichever was current when they were written.

The current instrument is the IRDAI Information and Cyber Security Guidelines, 2026, issued under covering circular IRDAI/GA&HR/CIR/MISC/51/4/2026 on 6 April 2026 and signed by the Executive Director (GA&HR). It revises the 2023 Guidelines, which were issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 on 24 April 2023, and those in turn expressly superseded four earlier circulars: IRDAI/IT/GDL/MISC/082/04/2017 of 7 April 2017, IRDA/IT/CIR/MISC/301/12/2020 of 29 December 2020, IRDA/GA&HR/GLD/MISC/184/09/2022 of 2 September 2022 and IRDAI/GA&HR/GDL/MISC/211/10/2022 of 11 October 2022. Six instruments in nine years, each one replacing the reference the last one taught people to cite. The practical consequence sits in your own documentation, not in the regulation: a policy, a board paper or a vendor questionnaire citing the 2017 or 2020 circular is citing an instrument that has been replaced twice over, and that is the kind of thing a supervisory inspection notices before it notices anything technical. On timing, the 2026 circular is direct: regulated entities shall strictly adhere to the guidelines and ensure compliance from the current financial year. The 2023 revision had carried a concession for entities that had already completed a security audit for FY 2022-23, who were given until the following financial year. The current circular carries no equivalent.

Three positions

The same instrument, read from three sides of the chain

An insurer, an intermediary and an ISNP operator are all named by the same circular and arrive at an assessment with different problems.

01 Largest estate

The insurer

What is in front of them
Core policy administration, claims, actuarial, a broker and agent portal estate, a customer app, and a long tail of integrations with TPAs, repositories and aggregators that were built at different times by different people.
Where the difficulty is
Scoping. The estate is large enough that an assessment either samples it or takes a quarter, and the boundary with the intermediaries is where ownership is least clear.
What we do
Application, API and infrastructure testing across the customer-facing and partner-facing estate, with the integration boundaries scoped explicitly instead of assumed to belong to the counterparty.
02 Named in its own right

The intermediary

What is in front of them
A broking or aggregator platform, quote and proposal data, and frequently a single engineering team or an outsourced build.
Where the difficulty is
The assumption that the insurer’s compliance reaches them. The circular names brokers, corporate agents, web aggregators and IMFs separately, which is what makes that assumption expensive.
What we do
A proportionate assessment sized to a single platform, which is the difference between an engagement that happens and one that gets deferred another year.
03 Its own category

The ISNP operator

What is in front of them
An Insurance Self Network Platform, the e-commerce channel, with payment flows, policy issuance and customer identity in one system.
Where the difficulty is
ISNP is named as its own category, so the audit has to address the platform as a platform, not as one more application inside somebody else’s estate.
What we do
An ISNP-scoped audit covering the transaction path end to end: issuance, payment, identity and the integrations either side of them.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade follows a structured audit methodology designed for IRDAI-regulated entities. Each engagement is scoped to the entity type, whether insurance company, ISNP platform, insurance broker, or TPA, and mapped to the specific IRDAI guidelines and controls applicable to that entity. The methodology ensures that the audit is comprehensive, evidence-backed, and produces a report that meets IRDAI submission expectations while also being actionable for your technology and security teams.

Discovery
01

Scoping and Regulatory Mapping

Identify entity type, applicable IRDAI guidelines, audit scope, systems in scope, third-party integrations, and regulatory submission timeline. For ISNP audits, scope includes the complete platform architecture and pre-launch requirements.

02

Document and Policy Review

Review information security policies, cybersecurity governance documentation, BCP/DR plans, incident response procedures, vendor agreements, and prior audit reports against IRDAI requirements.

Testing
03

Technical Assessment

Vulnerability assessment and penetration testing of in-scope applications, networks, infrastructure, and cloud environments. Application security testing for core insurance platforms, ISNP portals, claims systems, and broker management tools.

04

Controls Validation and Evidence Collection

Validate implementation of access controls, encryption, logging, monitoring, patch management, change management, backup and recovery, and incident response. Collect evidence through system demonstrations, configuration review, and interviews.

Delivery
05

Gap Analysis and Remediation Support

Document gaps with risk ratings, provide prioritised remediation roadmap with practical implementation guidance, and support your team through closure of critical and high findings.

06

Regulator-Ready Report and Attestation

Final audit report structured for IRDAI submission including scope, methodology, control status, findings, evidence references, remediation status, and compliance attestation signed by the CERT-In empanelled auditor.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

What insurers and intermediaries ask

Answered at the level the published circular actually supports, which is a shorter list than most vendor pages offer.

Contact us
Which instrument applies to us right now?+
The IRDAI Information and Cyber Security Guidelines, 2026, issued under covering circular IRDAI/GA&HR/CIR/MISC/51/4/2026 dated 6 April 2026. It revises the 2023 Guidelines (IRDAI/GA&HR/GDL/MISC/88/04/2023). If your policy documents or vendor questionnaires still cite the 2017 or 2020 circulars, they are two revisions behind: those were expressly superseded by the 2023 instrument.
We are a broker, not an insurer. Are we in scope?+
The covering circular names brokers alongside corporate agents, web aggregators, Third Party Administrators, Insurance Marketing Firms, insurance repositories, ISNP, corporate surveyors and loss assessors, Motor Insurance Service Providers, Common Service Centres and the Insurance Information Bureau of India, as well as insurers including foreign reinsurance branches. Intermediaries are named in their own right, and not reached through the insurer they place business with.
When do we have to comply from?+
The circular states that regulated entities shall strictly adhere to the guidelines and ensure compliance from the current financial year. The 2023 revision had given entities that already completed a security audit for FY 2022-23 until the following financial year; the 2026 circular carries no equivalent concession.
Can you send us the guidelines themselves?+
IRDAI issues the guidelines as an annexure to the covering circular and publishes the circular. The annexure reaches regulated entities through IRDAI, so the authoritative copy is the one you hold. We scope against the instrument you are working to.
Do you audit ISNP platforms specifically?+
Yes. An Insurance Self Network Platform is named as its own category, and we scope it as its own system: the issuance and payment path end to end, plus the integrations either side. It is never treated as one more application inside a wider estate.
Why does CERT-In empanelment matter for an insurance audit?+
Empanelment is the auditor qualification recognised across Indian financial-sector supervision. The Indian Computer Emergency Response Team grants it to the firm; no firm can claim it for itself. Security Brigade has held it continuously since 2008. Whatever submission the report is going into, the status of the firm that produced it is a question you should expect to be asked.
Can one engagement cover our insurance arm and our bank or broking arm?+
Often, and it is worth scoping for at the start. A group with entities under more than one supervisor is working to more than one instrument with different reporting structures and different places to file, so the saving comes from testing once and reporting several ways, which is a decision made during scoping and an expensive one to retrofit afterwards.

Ready to Achieve IRDAI Cybersecurity Compliance?

Talk to our compliance team to scope your IRDAI cybersecurity audit, ISNP pre-launch certification, or broker and TPA assessment

Typically responds within 1 business day · No commitment required

Request a Scoping Call