CERT-In Empanelled Audit
CERT-In Empanelled VAPT & Security Audit
CERT-In empanelment is the prerequisite for RBI System Audit Reports (SAR), MeitY compliance, SEBI cyber-security audits, and government tenders. Praxis-Q delivers CERT-In-aligned VAPT and security audits with regulator-ready reports and support for the 6-hour incident-reporting directive under the CERT-In Directions 2022.
At a Glance
CERT-In Audit
CERT-In Empanelled Audit
CERT-In Empanelled VAPT & Security Audit
The Problem
RBI SAR, MeitY, SEBI and most government tenders require an audit signed by a CERT-In empanelled auditor. Use a non-empanelled vendor and the report is not accepted — you fail the mandate.
What We Do
- Scoping
- Assessment
- Penetration Testing
- Reporting
- Re-test & Sign-off
What You Get
- Required credential for RBI SAR & data-localization audits
- Accepted for MeitY, SEBI, and government tenders
- CERT-In Directions 2022 (6-hour breach reporting) advisory
- VAPT aligned to OWASP / PTES with CVSS scoring
- Regulator-ready audit report format
- Re-testing after remediation included
- Covers web, network, cloud, and API assessments
- Supports DPDP and ISO 27001 evidence simultaneously
CERT-In Empanelment: The Prerequisite for RBI SAR
RBI mandates that the System Audit Report for payment aggregators, payment gateways, banks and NBFCs be conducted by a CERT-In empanelled auditor, with the report submitted to RBI (generally by 31 May after financial-year end). A report from a non-empanelled vendor is not accepted. Praxis-Q's CERT-In-aligned audits are structured specifically for RBI SAR submission, including data-localization verification where applicable.
Scope: VAPT Across Web, Network, Cloud & API
Our assessments combine automated scanning with expert manual penetration testing across web applications, internal and external networks, cloud environments, and APIs, aligned to OWASP and PTES. Findings are CVSS-scored and prioritised, with clear remediation guidance and re-testing after fixes.
MeitY, SEBI & Government Tenders
Beyond RBI, CERT-In-aligned audits are required for MeitY compliance, SEBI's cyber-security and cyber-resilience framework for regulated entities, and a wide range of government tenders. Praxis-Q tailors scope and reporting to the specific mandate so your submission is accepted the first time.
CERT-In Directions 2022 & 6-Hour Incident Reporting
The CERT-In Directions 2022 impose strict obligations, including reporting specified cyber incidents within six hours. We advise on incident-classification, log-retention, and reporting workflows so your organisation can meet the directive and evidence it during audit.
One Audit, Multiple Mandates
A CERT-In-aligned audit produces evidence usable across RBI SAR, DPDP Act security-safeguard obligations, and ISO 27001. Praxis-Q designs engagements to satisfy several regulatory requirements at once, cutting duplicate assessments and compliance cost.
Related Services
Frequently Asked Questions
Why does CERT-In empanelment matter?
What does a CERT-In audit cover?
Is this the same as VAPT?
Can one audit satisfy RBI SAR and DPDP/ISO 27001?
What is a CERT-In empanelled auditor and why is it required?
Does a CERT-In audit satisfy RBI SAR for payment aggregators?
What standards and scope does the audit cover?
What are the CERT-In Directions 2022 6-hour rules?
Can one CERT-In audit cover RBI, DPDP and ISO 27001?
Ready to Get Started?
Free gap analysis · Proposal in 24hrs · Delivery in weeks