Skip to main content

Security Consulting & Compliance

CERT-In Cyber Security Audit

CERT-In empanelled audit and certification for government and regulated entities.

CERT-In Audit as-a-Service

Every engagement includes manual validation, a two audience report and free re-testing.

Get a scoped quote+91 96682 00222

What this actually is

CERT-In sits under the Ministry of Electronics and Information Technology and is the national nodal agency for cyber security incidents. If you host with NIC, sell software or services to central or state government, or fall under RBI, SEBI, UIDAI or IRDAI mandates, you will be asked for a CERT-In audit certificate.

Threatsys conducts the audit end to end. We test, you fix, we re-test, and then the certificate is issued with the supporting documentation your customer or regulator will ask to see.

We have run these across government departments, banks, NBFCs and technology companies, including national-scale citizen platforms. We know what the reviewers look for and where applications usually fail the first pass.

What we go after

  • Web application and API security audit
  • Network and infrastructure vulnerability assessment
  • Server, database and configuration review
  • Mobile application audit where in scope
  • Source code review where required by the mandate
  • Cloud configuration assessment

How we run it

  1. 01

    Level 1 audit

    A full audit of the application, network or infrastructure in scope, delivered as a version 1 technical report.

  2. 02

    You remediate

    Your team fixes what was found. Our engineers stay available while you do, because the second pass goes far better when the first fix is right.

  3. 03

    Level 2 re-test

    Every patch verified and a version 2 technical report issued confirming closure.

  4. 04

    Certificate issued

    Draft certificate confirmed, then the final CERT-In security audit certificate with compliance documentation for your customers and partners.

What you receive

  • Version 1 technical audit report
  • Version 2 re-test and verification report
  • CERT-In security audit certificate or Safe to Host certificate
  • Supporting compliance documentation for your customer or regulator
  • Remediation guidance throughout

Who needs this

Organisations hosting at NIC, vendors selling to central or state government, and entities under the RBI cyber security framework, RBI payment aggregator and gateway guidelines, urban cooperative bank and NBFC directions, SEBI, UIDAI or IRDAI mandates.

How long it takes

Two to four weeks for the first pass, then dependent on how quickly findings are remediated before re-test.

Standards this satisfies

  • CERT-In
  • RBI
  • SEBI
  • UIDAI
  • IRDAI
  • NIC hosting

Why it matters

Almost nobody starts a certification because they want one. It starts because a customer will not sign without it, a regulator has asked, or a deal is sitting still while procurement waits for evidence. The commercial driver is real and it is worth being honest that it, rather than security, is usually what pays for the programme.

The security benefit is real too, but it comes from a specific place: the discipline of having to evidence that a control operated over a period, rather than that it was configured once. That is the part that changes behaviour, and it is also the part organisations consistently underestimate.

Choose how you want this delivered

Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.

Gap assessment, then we work alongside your team through remediation, internal audit and the certification audit itself. Your people do the work and own the outcome, which is what makes the management system survive after we leave. This is what most organisations should choose.

Choose this when

  • You have a team who can absorb the work alongside their day job
  • You want the capability to remain in-house afterwards
  • First certification where documentation is the main gap

Effort and cost

Moderate. The calendar is longer than a managed programme because the work competes with everyone's existing responsibilities.

Scope it yourself, before you call anyone

Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.

1/5

Which framework are you going for?

What we look for, and keep finding

These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.

  • Controls that exist on paper only

    The policy says quarterly access reviews. The evidence shows one, eighteen months ago, and it was not completed. This is the single most common audit finding across every framework.

  • Scope drawn too narrowly

    A certificate covering a subset of the business that customers assume covers all of it. Auditors check the boundary; buyers rarely do. Getting scope right is the most consequential early decision.

  • Evidence that cannot be reproduced

    A screenshot proves a control was configured on the day someone took it. A framework wants proof it operated throughout the period. Those are very different, and the gap only appears at the audit.

  • Exceptions with no expiry

    Risk accepted once, recorded, and never revisited. Over a few years these accumulate into an undocumented second control framework nobody is managing.

  • Third parties outside the boundary

    Processing carried out by a supplier who was assessed at onboarding and never since, while your obligation for their handling of your data continues regardless.

Who runs your engagement

A lead assessor who has sat on the other side of the table

Compliance work is led by an assessor who has taken organisations through certification, not by a consultant reading the standard for the first time with you. They know which findings a certification body will actually raise, which is a different list from what the standard technically says.

Questions we get asked

How long is the certificate valid?

Typically one year, and most mandates require an annual audit. Where your application changes significantly during the year, a fresh audit of the changed surface is usually expected.

What if we fail the first audit?

Almost everyone has findings on the first pass. That is what it is for. The certificate is issued after the re-test confirms closure, so findings early are not a problem, they are the process working.

Can you audit an application hosted outside India?

Yes. The audit is about the application and its controls. Where data residency is itself part of your obligation, we will flag that separately as a compliance finding.

Ready to scope your cert-in cyber security audit?

Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.