EBook

CERT-In Cybersecurity
Audit Mandate,
Effective July 2025

CERT-In, the Indian Computer Emergency Response Team, is the national nodal agency for responding to computer security incidents. In July 2025, CERT-In released a new mandate requiring all public and private organizations to undergo comprehensive annual cybersecurity audits, exclusively conducted by auditors who are officially empanelled by CERT-In.

Who Must Comply?

All Organizations operating in India, regardless of sector or size.

CERT-In Audit Mandate Coverage

CERT-In Audit Mandate Coverage
Read

Auditee Responsibilities

Check

Governance & Oversight

Approve, oversee, and regularly review audit strategy and corrective actions. Annual reporting of audit program scope, frequency.

Check

Audit Scope Definition

Define comprehensive scope: all IT, OT/ICS, cloud, APIs, and data environments.

Check

Remediation & Follow-up

Implement recommended changes quickly. Patch vulnerabilities; facilitate follow-up audits as needed.

Check

Asset & Configuration Management

Maintain a full, updated inventory of hardware, software, and APIs. Enforce hardened, secure configurations (disable unused ports, secure defaults, principle of least privilege). Robust patch management.

Check

Monitoring & Secure Dev

Run ongoing internal security audits and risk reviews. Build secure coding and "secure by design" into projects from RFP stage onward. Version control and change management for audit artefacts/infrastructure.

Check

Active Audit Participation

Attend all kick off/exit meetings with auditors. Limit audit info access to essential staff; avoid "cosmetic" fixes.

Check

Risk Acceptance

Leadership must formally document and approve any risk exceptions.

Check

Data Handling

Securely store all audit artefacts (hashes, logs, evidence). Apply strict access control and data disposal per CERT-In guidelines.

Check

Continuous Improvement

Use audits to drive tangible, ongoing security enhancements. Move beyond "checkbox" compliance to true risk reduction.

CERT-In Mandated API Security for Indian Firms - Ebook Preview
Trusted by teams at:
Himalaya
Akasa
mjunction
Bandhan Bank
DRDO
GMDA
NIIC
InvoiceMart

Scan your platform for

API threats within minutes

Just add your public API or URL. No integration needed.