Insights/Regulatory Newsroom
CERT-In Empanelment: A Step-by-Step Guide for Cybersecurity Firms
Published
Reading time2 minutes
FromTriad ICS Research

Empanelment as an information security auditing organisation opens doors to regulated and government work. What the process involves.
CERT-In maintains a panel of information security auditing organisations. Government departments, public sector undertakings and many regulated entities are required or encouraged to use empanelled auditors for their security audits. For a cybersecurity firm in India, empanelment is therefore both a mark of capability and a practical requirement for a significant part of the market.
This guide describes the process in general terms. The eligibility criteria and procedure are set by CERT-In and revised from time to time, so always work from the current guidelines published on cert-in.org.in.
Step 1: Check eligibility
CERT-In’s guidelines set out who can apply. Typically they cover:
- Being an organisation registered and operating in India
- A minimum number of full-time technical staff with recognised security qualifications
- Demonstrable experience of carrying out security audits
- Appropriate internal policies, including for handling client data and confidentiality
Step 2: Build your evidence
Before applying, assemble documents that show capability rather than claim it: staff qualifications and employment records, audit methodologies, sample (anonymised) reports, tools used, and your own information security policies. Firms with their own well-run ISMS find this step much easier.
Step 3: Apply when applications open
CERT-In invites applications through published notices. Submit the application with the required documents and fees within the stated window.
Step 4: Technical evaluation
Shortlisted applicants go through a technical evaluation designed to test practical auditing skills. Expect to demonstrate capability, not just describe it. Prepare your team with realistic practice across web applications, networks and infrastructure.
Step 5: Empanelment and ongoing obligations
Empanelled organisations are listed on CERT-In’s website for a defined period. Empanelment comes with continuing obligations: following CERT-In’s audit guidelines, maintaining staff and quality standards, reporting as required, and being subject to review. Empanelment can be withdrawn if standards slip.
Preparing well
- Invest in people first; qualifications and hands-on skill carry the process.
- Standardise your methodology around recognised references such as the OWASP guides, the CIS benchmarks and ISO 27001.
- Keep audit quality consistent: peer review of reports, evidence for every finding, and clear remediation guidance.
- Treat your own security as seriously as your clients’, since you will hold some of their most sensitive information.
Empanelment is demanding by design. The discipline it requires is the same discipline that makes an audit useful to the organisation being audited.
This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.