We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled auditor

CERT-In empanelled VAPT company

CyberSigma is a CERT-In empanelled information-security auditor. We perform vulnerability assessment and penetration testing (VAPT) across web applications, mobile apps, APIs, cloud and network infrastructure, and issue CERT-In-aligned reports and safe-to-host confirmations that regulators, acquiring banks and government tenders accept. If you need CERT-In empanelled VAPT for an RBI, SEBI or IRDAI obligation, a government RFP, or a customer security review, we scope the engagement, test to the CERT-In methodology, and give you a prioritised, retest-backed closure report.

Get a free VAPT scope & quote →Book a 20-minute call
Who needs it

Who needs CERT-In empanelled VAPT

Regulated entities
Banks, NBFCs, payment firms, brokers and insurers where RBI/SEBI/IRDAI require empanelled-auditor testing.
Government tenders
RFPs that mandate a CERT-In empanelled auditor and a safe-to-host confirmation before go-live.
SaaS & product teams
Vendors who must evidence independent application and infrastructure testing for enterprise buyers.
Scope

What we test

Web application, mobile application (Android/iOS) and API penetration testing; external and internal network VAPT; cloud configuration review (AWS/Azure/GCP); and, where required, thick-client and secure code review.

  • Grey-box and black-box testing to the CERT-In methodology and OWASP standards
  • Business-logic and authentication/authorisation testing, not just automated scanning
  • Expert-verified findings with proof-of-concept and remediation guidance
  • Free retest to confirm closure and issue the final report
Regulation

Applicable regulation

CERT-In empanelment underpins RBI cyber-security and IT-audit expectations, SEBI CSCRF, IRDAI guidelines, and most government and PSU security requirements. Empanelled testing plus a safe-to-host confirmation is frequently the gate for public-facing go-live.

Timeline

How long it takes

Scoping — 2–4 days
Asset inventory, test windows, rules of engagement and a fixed quote.
Testing — 1–3 weeks
Depends on the number of applications, APIs and hosts in scope.
Report & retest — 3–5 days
Prioritised report, then a free retest once fixes are in.
Cost factors

What drives VAPT cost

  • Number of applications, APIs, mobile apps and network hosts in scope
  • Grey-box vs black-box, and whether source-code review is included
  • Retest and re-issue cycles, and reporting depth for regulators/tenders
Deliverables

What you receive

Executive report
Risk-rated summary for management and auditors.
Technical report
Every finding with evidence, CVSS rating and step-by-step remediation.
Safe-to-host confirmation
Issued on a clean retest where required for go-live.
Closure evidence
Retest results your regulator or customer can rely on.
Common failures

What we most often find

  • Broken access control and insecure direct object references (IDOR)
  • Authentication and session-management weaknesses
  • Cloud misconfiguration — public storage, over-permissive IAM roles
  • Injection, SSRF and outdated components with known CVEs
Proof

See how we’ve done it before

Relevant case study
How independent VAPT closed critical exposures before a regulated go-live. Read case studies →
Redacted sample deliverable
Inspect the quality of our reporting first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Issue and commencementEffective 28 June 2022

    Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Incident reporting windowEffective 28 June 2022

    Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Log retentionEffective 28 June 2022

    ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Time synchronisationEffective 28 June 2022

    System clocks must be synchronised to NIC or NPL time sources.

    CERT-In Directions (official PDF) · verified 31 July 2026
  • Provider record-keepingEffective 28 June 2022

    Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.

    CERT-In Directions (official PDF) · verified 31 July 2026
Related in this cluster

CERT-In VAPT — FAQs

Is CyberSigma CERT-In empanelled?

Yes. CyberSigma Consulting Services LLP is empanelled by CERT-In for information-security auditing services, and issues CERT-In-aligned VAPT reports and safe-to-host confirmations.

Do you provide a safe-to-host certificate?

Yes. On a clean retest we issue a safe-to-host confirmation where your go-live, tender or regulator requires it. It is a CyberSigma-issued attestation of the testing performed, not a third-party certificate.

How much does a web-app VAPT cost?

Cost scales with the number of applications, APIs and hosts, and whether testing is grey-box or includes source-code review. We give a fixed quote after a short scoping call.

How quickly can you start?

Scoping typically takes 2–4 days; testing then runs 1–3 weeks depending on scope. Urgent tender deadlines can be prioritised.

Talk to a CERT-In empanelled tester

Get a fixed VAPT scope and quote this week, with senior testers — not a sales rep. We reply within four business hours.

Book a 20-minute VAPT call →

Ready to discuss your CERT-In VAPT requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.