CERT-In Cyber Security Audit Policy Guidelines, 2025

CERT-In All Guideline Active 25 Jul 2025

Applies to: CERT-In empanelled auditing organisations and all auditee organisations (public and private) that undergo cyber security audits — including RBI/SEBI/IRDAI-regulated entities and voluntary auditees

Issued by CERT-In on 25 July 2025 under Section 70B of the IT Act, the Comprehensive Cyber Security Audit Policy Guidelines (Version 1.0) standardise how cyber security audits are conducted across India — moving from ad hoc, tool-driven checks to a structured, enforceable audit lifecycle. They bind two groups: CERT-In empanelled auditing organisations, and any auditee (public or private) undergoing an audit, including entities already mandated to audit under RBI, SEBI and IRDAI frameworks. Auditees are expected to undertake at least one comprehensive ICT audit annually or after significant infrastructure change, spanning applications, cloud, OT/ICS, IoT, supply chain and physical security. Auditors must move beyond limited checklists — OWASP Top 10 and SANS Top 25 are explicitly deemed insufficient as standalone references — and apply multi-layered frameworks (ISO/IEC, CSA Cloud Controls Matrix, OSSTMM3, OWASP ASVS, CERT-In's Audit Baseline Requirements). Every vulnerability must be scored on both CVSS (severity) and EPSS (exploit likelihood) and mapped to CWE/CVE identifiers. Auditor independence is mandatory — payment cannot be contingent on audit outcome, and auditee pressure must be escalated to CERT-In. Auditee top management (CXO/CISO/board) must approve audit scope, frequency and remediation, document risk-acceptance decisions with written executive sign-off, and disclose high-level audit outcomes in annual reports. A graded "deter and punish" enforcement mechanism (watch-list, suspension, withdrawal of empanelment, legal action) applies to auditors for substandard work.
Why it matters
This is the connective tissue under every sectoral audit obligation you already track — RBI, SEBI, IRDAI and CSCRF all require CERT-In empanelled auditors, and this is the rulebook those audits must now follow. The forward signal for a CII CISO is the shift from "did you get audited" to "was the audit good enough": CERT-In can now suspend or delist an auditor for missing vulnerabilities, so a clean certificate from a weak auditor is no longer cover — supervisory scrutiny moves onto audit quality itself. Two practical consequences. First, the explicit rejection of OWASP Top 10 / SANS Top 25 as standalone references means a scan-and-certify vendor is now non-compliant; if your auditor's methodology doesn't cite ISO/CSA CCM/OSSTMM3-class frameworks, that is a gap. Second — and this is the unresolved one to watch — the guidelines create a CERT-In audit regime that runs parallel to DPDP's SDF independent-audit duty, with no official bridge between them: it is not yet clarified whether a CERT-In-empanelled audit satisfies the DPDP SDF audit, so entities heading toward SDF status should assume two audit tracks until MeitY and CERT-In align them.