CERT-In Compliance & Audit
CERT-In (the Indian Computer Emergency Response Team) sets security audit and incident-reporting expectations referenced by RBI, SEBI and ministries - including the requirement to report listed incidents within six hours and retain logs in India. We deliver CERT-In-style audits and reporting support.
Overview
CERT-In (the Indian Computer Emergency Response Team) sets security audit and incident-reporting expectations referenced by RBI, SEBI and ministries - including the requirement to report listed incidents within six hours and retain logs in India. We deliver CERT-In-style audits and reporting support.
Who Needs to Comply?
Service providers, intermediaries, data centres, banks and govt-facing entities in India.
Key Requirements
Audit in expected format
VAPT, configuration and compliance audit structured for CERT-In acceptance.
6-hour incident reporting
Process and support for CERT-In's mandatory reporting timeline.
Log retention
Guidance on the 180-day in-India log-retention requirement.
How we help you comply
Cyber Governance & Audit
CERT-In Empanelled Audit (via Partner)
VAPT, configuration and compliance audit aligned to CERT-In expectations, with closure support.
Offensive Security & VAPT
VAPT - Web & Network
Deep manual VAPT for web apps and networks, mapped to OWASP, with proof-of-concept exploits.
Defensive & Managed SOC
Incident Response & Retainer
Emergency incident response and retainers: contain, eradicate, recover and report (CERT-In aligned).
Need help with CERT-In?
Prove both before launch.
Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.

