IRDAI Cyber Security Audit
IRDAI Information & Cyber Security Guidelines 2026 - Independent Audit for Insurers & Intermediaries
Praxis-Q conducts independent cyber security audits against the IRDAI Information and Cyber Security Guidelines 2026 (issued 6 April 2026) for insurance companies, intermediaries, TPAs, brokers and web aggregators regulated by the Insurance Regulatory and Development Authority of India. The audit covers governance, IT infrastructure, data protection, VAPT and incident response, producing the report required for submission to IRDAI.
At a Glance
IRDAI Audit
IRDAI Cyber Security Audit
IRDAI Information & Cyber Security Guidelines 2026 - Independent Audit for Insurers & Intermediaries
The Problem
IRDAI's revised guidelines of 6 April 2026 moved VAPT to every six months, grey/white box, by a CERT-In empanelled auditor, and gave the Board twelve months to close every identified gap. Annual black-box testing built for the 2023 framework no longer satisfies the mandate.
What We Do
- Scope & Planning
- Control Assessment
- Technical VAPT
- Gap Remediation Plan
- Audit Report Delivery
What You Get
- Independent audit against IRDAI Information & Cyber Security Guidelines 2026
- Covers insurers, brokers, TPAs, web aggregators and corporate agents
- CISO independence and Board 12-month gap-closure accountability
- Data protection and policyholder data security controls assessment
- Half-yearly grey/white box VAPT by a CERT-In empanelled auditor
- Supply-chain controls: sub-outsourcing approval, MeitY/STQC cloud
- Incident response and breach-notification readiness
- Audit report formatted for IRDAI regulatory submission
Who the 2026 Guidelines Apply To
Scope is deliberately wide and extends well past insurance companies. Insurers and Foreign Reinsurance Branches are covered, and so are brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers and the Insurance Information Bureau. If you are an intermediary who assumed the guidelines were an insurer problem, they are not. Praxis-Q begins by fixing entity type and applicable control set, because a TPA and an ISNP operator carry materially different obligations.
What Changed From the 2023 Framework
Four shifts matter operationally. CISO independence is now structural - no reporting line into IT, no business targets - which removes the pressure that historically got findings deprioritised. Board accountability is now time-bound, with a twelve-month ceiling on gap closure that turns the risk register into a tracked commitment. ISRMC cadence doubles to quarterly, so reporting must run on current exposure data rather than an annual audit snapshot. And testing intensifies from annual black-box to half-yearly grey or white box. Programmes designed for the 2023 guidelines will not clear the 2026 bar without rework.
The Half-Yearly VAPT Mandate and CERT-In Empanelment
The revised guidelines require vulnerability assessment and penetration testing every six months, as grey or white box engagements, performed by a CERT-In empanelled auditor. Grey and white box testing needs something black-box did not: a complete and current asset inventory, credentials, and access to application logic. The payoff is that business-logic flaws which automated scanners never reach are actually found. Praxis-Q delivers CERT-In-aligned VAPT to OWASP and PTES with CVSS-scored findings and re-testing after remediation, and works alongside empanelled signatories where the mandate requires an empanelled auditor's report.
Supply Chain, Cloud and Cryptography Controls
The 2026 revision formalises vendor oversight that was previously left to interpretation. Sub-outsourcing now needs written approval rather than silent delegation. Cloud service providers must be MeitY-empanelled with valid STQC status, which rules out a number of arrangements insurers currently run. Contracts need complete data-elimination clauses and NDAs covering both security and business continuity. Separately, the cryptography control requires maintaining an up-to-date inventory of cryptographic assets - the groundwork for post-quantum migration, and something almost no insurance-sector organisation has today.
Where IRDAI Sits Alongside RBI SAR, CERT-In and ISO 27001
Insurance groups rarely carry only one mandate. A CERT-In-aligned audit produces evidence usable for IRDAI, for RBI System Audit Reports where a regulated payment entity sits inside the group, and for ISO 27001 certification. The DPDP Act adds its own security-safeguard obligations over the same estate. Praxis-Q scopes these together so one testing cycle and one evidence set serve several regulators, rather than running parallel audits that examine the same systems three times a year.
Related Services
Frequently Asked Questions
Who needs an IRDAI Cyber Security Audit?
What are the IRDAI Information & Cyber Security Guidelines?
How often is the audit required?
Is a standard VAPT report enough for IRDAI?
Do outsourced partners of insurers need this too?
Are the IRDAI 2023 cyber security guidelines still in force?
How often must insurers conduct VAPT under the 2026 guidelines?
Do the guidelines apply to intermediaries and TPAs, or only to insurers?
What changed about the CISO role?
How long do we have to close identified gaps?
Can one audit cover IRDAI and our other obligations?
Ready to Get Started?
Free gap analysis · Proposal in 24hrs · Delivery in weeks