Fast-Track · Weeks, Not Months

CERT-In Empanelled Audit

CERT-In Empanelled VAPT & Security Audit

CERT-In empanelment is the prerequisite for RBI System Audit Reports (SAR), MeitY compliance, SEBI cyber-security audits, and government tenders. Praxis-Q delivers CERT-In-aligned VAPT and security audits with regulator-ready reports and support for the 6-hour incident-reporting directive under the CERT-In Directions 2022.

CERT-In empanelment is the credential that makes a security audit acceptable to India's regulators. RBI requires that System Audit Reports (SAR) for payment aggregators, payment gateways, banks and NBFCs be signed by a CERT-In empanelled auditor; MeitY, SEBI, and most government tenders require the same. Praxis-Q delivers CERT-In-aligned VAPT and security audits with regulator-ready reporting, covering web applications, networks, cloud, and APIs to OWASP/PTES standards with CVSS-scored findings. We also advise on the CERT-In Directions 2022, including the six-hour incident-reporting obligation. Because a CERT-In-aligned audit produces evidence usable across RBI SAR, DPDP security safeguards, and ISO 27001, one engagement can satisfy multiple mandates — reducing duplicate testing and accelerating your compliance timeline.

At a Glance

Prereq forRBI SAR
Also coversMeitY/SEBI
StandardsOWASP/PTES
ReportRegulator-ready

CERT-In Audit

CERT-In Empanelled Audit

CERT-In Empanelled VAPT & Security Audit

The Problem

RBI SAR, MeitY, SEBI and most government tenders require an audit signed by a CERT-In empanelled auditor. Use a non-empanelled vendor and the report is not accepted — you fail the mandate.

What We Do

  • Scoping
  • Assessment
  • Penetration Testing
  • Reporting
  • Re-test & Sign-off

What You Get

  • Required credential for RBI SAR & data-localization audits
  • Accepted for MeitY, SEBI, and government tenders
  • CERT-In Directions 2022 (6-hour breach reporting) advisory
  • VAPT aligned to OWASP / PTES with CVSS scoring
  • Regulator-ready audit report format
  • Re-testing after remediation included
  • Covers web, network, cloud, and API assessments
  • Supports DPDP and ISO 27001 evidence simultaneously

CERT-In Empanelment: The Prerequisite for RBI SAR

RBI mandates that the System Audit Report for payment aggregators, payment gateways, banks and NBFCs be conducted by a CERT-In empanelled auditor, with the report submitted to RBI (generally by 31 May after financial-year end). A report from a non-empanelled vendor is not accepted. Praxis-Q's CERT-In-aligned audits are structured specifically for RBI SAR submission, including data-localization verification where applicable.

Scope: VAPT Across Web, Network, Cloud & API

Our assessments combine automated scanning with expert manual penetration testing across web applications, internal and external networks, cloud environments, and APIs, aligned to OWASP and PTES. Findings are CVSS-scored and prioritised, with clear remediation guidance and re-testing after fixes.

MeitY, SEBI & Government Tenders

Beyond RBI, CERT-In-aligned audits are required for MeitY compliance, SEBI's cyber-security and cyber-resilience framework for regulated entities, and a wide range of government tenders. Praxis-Q tailors scope and reporting to the specific mandate so your submission is accepted the first time.

CERT-In Directions 2022 & 6-Hour Incident Reporting

The CERT-In Directions 2022 impose strict obligations, including reporting specified cyber incidents within six hours. We advise on incident-classification, log-retention, and reporting workflows so your organisation can meet the directive and evidence it during audit.

One Audit, Multiple Mandates

A CERT-In-aligned audit produces evidence usable across RBI SAR, DPDP Act security-safeguard obligations, and ISO 27001. Praxis-Q designs engagements to satisfy several regulatory requirements at once, cutting duplicate assessments and compliance cost.

Frequently Asked Questions

Why does CERT-In empanelment matter?
RBI mandates that System Audit Reports (SAR) for payment aggregators, payment gateways, banks and NBFCs be conducted by a CERT-In empanelled auditor. MeitY, SEBI, and most government tenders require the same. A report from a non-empanelled vendor is not accepted.
What does a CERT-In audit cover?
Vulnerability assessment and penetration testing across web applications, networks, cloud, and APIs, aligned to OWASP/PTES, with CVSS-scored findings and a regulator-ready report. Advisory on the CERT-In Directions 2022 6-hour incident-reporting requirement is included.
Is this the same as VAPT?
It is VAPT delivered to CERT-In standards with regulator-acceptable reporting. The distinction that matters for RBI SAR, MeitY and SEBI is that the audit is CERT-In-aligned and the report is accepted by the regulator.
Can one audit satisfy RBI SAR and DPDP/ISO 27001?
Yes. A CERT-In-aligned audit provides evidence usable across RBI SAR, DPDP security-safeguard obligations, and ISO 27001, reducing duplicate assessments.
What is a CERT-In empanelled auditor and why is it required?
CERT-In (Indian Computer Emergency Response Team) empanels auditors approved to conduct security audits for regulated entities. RBI requires SAR audits to be performed by a CERT-In empanelled auditor; MeitY, SEBI and government tenders require the same. Without it, the audit report is not accepted.
Does a CERT-In audit satisfy RBI SAR for payment aggregators?
Yes. Praxis-Q's CERT-In-aligned audit is structured for RBI System Audit Report submission for payment aggregators, payment gateways, banks and NBFCs, including data-localization checks where required, with reports formatted for RBI submission.
What standards and scope does the audit cover?
VAPT across web, network, cloud and API surfaces aligned to OWASP and PTES, with CVSS-scored findings, remediation guidance, and post-fix re-testing, delivered in a regulator-ready report.
What are the CERT-In Directions 2022 6-hour rules?
The CERT-In Directions 2022 require organisations to report specified cyber incidents to CERT-In within six hours of detection, alongside log-retention and other obligations. Praxis-Q advises on incident classification and reporting workflows to meet the directive.
Can one CERT-In audit cover RBI, DPDP and ISO 27001?
Largely, yes. A CERT-In-aligned audit produces evidence usable across RBI SAR, DPDP security safeguards, and ISO 27001, so a single engagement can support multiple mandates and reduce duplicate testing.

Ready to Get Started?

Free gap analysis · Proposal in 24hrs · Delivery in weeks