Short answer: yes, an insurance web aggregator needs an annual IRDAI cyber security audit, and the rules changed on 6 April 2026. IRDAI's Information and Cyber Security Guidelines, 2026 (circular IRDAI/GA&HR/CIR/MISC/51/4/2026) replaced the April 2023 guidelines. They name web aggregators in scope and apply from the current financial year, which is FY 2026-27. The audit is a yearly independent assurance audit by a CERT-In empanelled auditor. You must also run a vulnerability assessment and a grey- or white-box penetration test on every internet-facing system every six months. Report cyber incidents to CERT-In within six hours. Most important for an aggregator, the audit report goes to each insurer you work with within 30 days of the audit closing, and those insurers use it to decide whether to keep doing business with you.
This guide covers only the web-aggregator side of the 2026 guidelines: what changed, what the audit covers, who enforces it and how to prepare. For the broader intermediary picture (brokers, corporate agents, TPAs), see our IRDAI compliance guide for insurance intermediaries.
What IRDAI actually notified in 2026
On 6 April 2026 IRDAI issued version 2.0 of its Information and Cyber Security Guidelines. The circular says regulated entities "shall strictly adhere to the said guidelines and ensure compliance from the current financial year." It replaces the guidelines of 24 April 2023. The 175-page framework keeps the NIST Cybersecurity Framework structure (Identify, Protect, Detect, Respond, Recover) and tightens governance, testing, cloud, outsourcing and data-protection controls.
Section 1.4 of the guidelines applies them to all insurers, foreign reinsurance branches and insurance intermediaries regulated by IRDAI. That covers brokers, corporate agents, web aggregators, TPAs, insurance marketing firms and other licensed intermediaries. It explicitly excludes individual insurance agents, micro-insurance agents, Point of Sale Persons and individual surveyors. Their insurers still have to hold them to a minimum security baseline.
Your registration as a web aggregator still rests on the IRDAI (Insurance Web Aggregators) Regulations, 2017. The 2026 cyber guidelines add a security layer on top of it; they do not replace it.
The 2026 requirements at a glance
| Requirement | What the 2026 guidelines say |
|---|---|
| Annual audit | An independent assurance audit every year by a CERT-In empanelled auditor, or an audit firm meeting the Annexure IV criteria |
| Who gets the report | The intermediary submits the Annexure III report, its compliance response and the comments of its Board, Audit/Risk Committee or Principal Officer to its insurer(s), within 30 days of the audit closing |
| Auditor rotation | The independent assurance auditor must change every three years |
| Vulnerability assessment | All internet-facing assets, at least once every 6 months, by a CERT-In empanelled auditor |
| Penetration testing | External grey- or white-box PT of all internet-facing systems once every 6 months. Critical internal applications at least once a year |
| Change testing | Every change to an internet-facing system must be security-tested, and gaps closed before it reaches production. Applications, APIs and web services need a security audit, VAPT and secure code review before go-live |
| Incident reporting | To CERT-In within 6 hours of noticing an incident, with a copy to IRDAI |
| Log retention | ICT infrastructure logs kept for a rolling 180 days, within Indian jurisdiction |
| Gap closure | Audit gaps closed within 12 months of being reported |
| Cloud | Cloud services only from MeitY-empanelled providers whose data centres hold a valid STQC (or equivalent) audit status |
| Outsourcing | SLAs must prevent vendors from sub-outsourcing without the regulated entity's prior written permission |
| Privacy | Technical and organisational measures to comply with the DPDP Act and its rules |
Why web aggregators are the hardest case
For a broker, the internet-facing surface is often a website and a portal. For a web aggregator, the internet-facing surface is the whole business. The comparison engine, quote forms, lead capture, payment redirects, insurer APIs and the call-centre CRM that follows up on leads all process policyholder data online. Under the 2026 guidelines every one of those systems falls under the six-monthly VA and grey/white-box PT cycle.
Three features of the aggregator model make this harder than the guideline text suggests:
- Integrations with every insurer. Each insurer integration is an API or web service. The guidelines require a security audit, VAPT and secure code review before any API goes live. That applies to new insurer connections as well as updates to existing ones.
- Frequent releases. Aggregator platforms ship weekly or faster. Every change to an internet-facing system must be security-tested before production, so the security test belongs in the release pipeline, not in a once-a-year event.
- Your vendors' vendors. Lead-management SaaS, marketing pixels, telephony, analytics and cloud hosting all touch the same data. The 2026 guidelines require SLAs that block sub-outsourcing without your written permission. They also allow cloud hosting only on MeitY-empanelled providers with STQC status, and require ICT logs to stay in India for 180 days. A SaaS tool that keeps its logs outside India, or a hosting region that is not empanelled, is an audit finding.
Your insurer is the enforcer
Many aggregators miss this. The 2026 guidelines make each insurer responsible for ensuring that the intermediaries it engages comply "during the currency of their engagement", under a Board-approved policy. The audit checklist (Annexure III, Part C) carries a risk rating that the insurer uses to decide whether to enter into or continue business with the intermediary.
In practice, then, IRDAI may never read your audit report, but every insurer on your platform will. A weak rating does not arrive as a regulatory notice. It shows up when a partner insurer declines to renew your integration. Intermediaries that hold insurer data only on paper and never access insurer systems can give an annual self-certification instead. A web aggregator will almost never fit that exception.
Which controls apply to you
The guidelines do not apply every control to every intermediary equally. Annexure II classifies intermediaries by gross insurance revenue, and Annexure I maps which NIST functions and controls apply to each class. Before scoping the audit, confirm your band from the Annexure II table published with the circular, using your latest audited gross insurance revenue. Two aggregators of different sizes can face different audit scopes.
Where the DPDP Act comes in
The 2026 guidelines require compliance with the Digital Personal Data Protection Act and the rules under it. The DPDP Rules were notified on 14 November 2025 with a phased start. The core data fiduciary obligations (consent, security safeguards, breach notification and data principal rights) take effect on 14 May 2027. The rules also require personal data, traffic data and processing logs to be kept for at least one year for specified purposes.
An aggregator captures consent from people comparing quotes and passes their data to several insurers, so these two regimes overlap heavily. Build one control set that satisfies both: consent records, data flows to each insurer, log retention (180 days of ICT logs in India for IRDAI, one year of processing logs for DPDP) and a single incident runbook that meets the six-hour CERT-In deadline and DPDP breach notification. Our DPDP compliance service covers the privacy side.
A 90-day preparation plan for FY 2026-27
- Weeks 1–2: scope and classify. Confirm your Annexure II band. List every internet-facing asset: domains, sub-domains, APIs, mobile apps and admin panels. List every insurer that will receive your report.
- Weeks 2–5: gap assessment against the 2026 controls. Focus on what changed since 2023: six-monthly grey/white-box PT, change-triggered testing, sub-outsourcing clauses, MeitY/STQC cloud status, 180-day in-India log retention and DPDP measures.
- Weeks 4–8: fix the structural gaps. Add security tests to the release pipeline, move logs into India, amend vendor SLAs and write the six-hour incident runbook with named owners.
- Weeks 8–10: first VA and grey/white-box PT cycle by a CERT-In empanelled auditor, with retests before closure.
- Weeks 10–13: independent assurance audit. Your governing body reviews the findings, and the Annexure III report goes to every partner insurer within 30 days of the audit closing.
After that the cycle runs itself: VA and PT every six months, testing on every change, the audit every year and a new auditor every three years.
Common findings to fix before the auditor arrives
- A VAPT report that is black-box only. The 2026 guidelines require grey- or white-box testing for internet-facing systems.
- Insurer APIs that went live without a documented security audit and code review.
- Application or CDN logs kept for 30 days, or stored outside India.
- Vendor contracts with no clause restricting sub-outsourcing.
- Cloud workloads in a region or on a provider that is not MeitY-empanelled.
- No written procedure showing who reports to CERT-In, and how, within six hours.
- Last year's findings still open beyond the 12-month closure window.
How Praxis-Q helps web aggregators
Praxis-Q is a CERT-In empanelled audit firm. We run the annual IRDAI cyber security audit and the six-monthly grey/white-box VAPT cycle for insurance intermediaries, and we write the Annexure III report in the form your partner insurers expect. The effort depends on your Annexure II band, the number of internet-facing applications and APIs, how many insurers you integrate with, and whether DPDP work is in scope. Pricing is scoped per engagement. Request a proposal.
Frequently asked questions
Do insurance web aggregators need an IRDAI cyber security audit?
Yes. The IRDAI Information and Cyber Security Guidelines, 2026 apply to all insurance intermediaries regulated by IRDAI, including web aggregators. You need an independent assurance audit every year by a CERT-In empanelled auditor or an audit firm meeting Annexure IV.
Where does a web aggregator submit its IRDAI audit report?
To its insurers. The intermediary submits the Annexure III report, its compliance response and its governing body's comments to each insurer it works with, within 30 days of the audit closing. Insurers file their own audit reports with IRDAI.
How often must a web aggregator run VAPT under the 2026 guidelines?
Every six months for all internet-facing assets: a vulnerability assessment plus an external grey- or white-box penetration test, both by a CERT-In empanelled auditor. Any change to an internet-facing system also needs a security test before it goes to production.
Do the 2026 guidelines replace the 2023 IRDAI cyber security guidelines?
Yes. The circular dated 6 April 2026 replaces the guidelines issued on 24 April 2023, and compliance is required from the current financial year.
How fast must a cyber incident be reported?
To CERT-In within six hours of noticing the incident or being told about it, with a copy to IRDAI and any other regulator concerned.
Can the same firm audit us every year?
Not indefinitely. The guidelines require the independent assurance auditor to be rotated every three years.
Sources
- IRDAI circular IRDAI/GA&HR/CIR/MISC/51/4/2026, Information and Cyber Security Guidelines, 2026 (6 April 2026), irdai.gov.in. Sections 1.4 (applicability), the audit provisions, 3.6 (incident notification), the logging controls and the cloud security policy
- CERT-In Directions under Section 70B(6) of the IT Act (28 April 2022), cert-in.org.in
- Digital Personal Data Protection Rules, 2025 (notified 14 November 2025), PIB
- IRDAI (Insurance Web Aggregators) Regulations, 2017, Department of Financial Services
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Sahil Dubey
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
