Fast-Track · Weeks, Not Months

IRDAI Cyber Security Audit

IRDAI Information & Cyber Security Guidelines 2026 - Independent Audit for Insurers & Intermediaries

Praxis-Q conducts independent cyber security audits against the IRDAI Information and Cyber Security Guidelines 2026 (issued 6 April 2026) for insurance companies, intermediaries, TPAs, brokers and web aggregators regulated by the Insurance Regulatory and Development Authority of India. The audit covers governance, IT infrastructure, data protection, VAPT and incident response, producing the report required for submission to IRDAI.

IRDAI issued revised Information and Cyber Security Guidelines on 6 April 2026, superseding the 2023 framework that most insurance-sector security programmes were still built around. The revision is not cosmetic. The CISO may no longer report to the Head of IT and may not carry business targets. The Information Security Risk Management Committee now meets quarterly rather than twice yearly. The Board must approve gap-closure timelines and ensure every identified gap is closed within twelve months. Most consequentially for testing programmes, mandatory VAPT moves from black-box to grey or white box, conducted by a CERT-In empanelled auditor, every six months. New supply-chain controls require written approval for sub-outsourcing, MeitY-empanelled cloud providers holding valid STQC status, data-elimination clauses and security NDAs, and a new cryptography control requires an up-to-date inventory of cryptographic assets as post-quantum preparedness. Praxis-Q delivers applicability scoping, gap assessment against the 2026 control set, the half-yearly VAPT cycle, and the Board and ISRMC reporting pack that makes closure defensible.

At a Glance

RegulatorIRDAI
GuidelineICSG 2026
VAPTHalf-yearly
EntitiesInsurers/Intermediaries

IRDAI Audit

IRDAI Cyber Security Audit

IRDAI Information & Cyber Security Guidelines 2026 - Independent Audit for Insurers & Intermediaries

The Problem

IRDAI's revised guidelines of 6 April 2026 moved VAPT to every six months, grey/white box, by a CERT-In empanelled auditor, and gave the Board twelve months to close every identified gap. Annual black-box testing built for the 2023 framework no longer satisfies the mandate.

What We Do

  • Scope & Planning
  • Control Assessment
  • Technical VAPT
  • Gap Remediation Plan
  • Audit Report Delivery

What You Get

  • Independent audit against IRDAI Information & Cyber Security Guidelines 2026
  • Covers insurers, brokers, TPAs, web aggregators and corporate agents
  • CISO independence and Board 12-month gap-closure accountability
  • Data protection and policyholder data security controls assessment
  • Half-yearly grey/white box VAPT by a CERT-In empanelled auditor
  • Supply-chain controls: sub-outsourcing approval, MeitY/STQC cloud
  • Incident response and breach-notification readiness
  • Audit report formatted for IRDAI regulatory submission

Who the 2026 Guidelines Apply To

Scope is deliberately wide and extends well past insurance companies. Insurers and Foreign Reinsurance Branches are covered, and so are brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers and the Insurance Information Bureau. If you are an intermediary who assumed the guidelines were an insurer problem, they are not. Praxis-Q begins by fixing entity type and applicable control set, because a TPA and an ISNP operator carry materially different obligations.

What Changed From the 2023 Framework

Four shifts matter operationally. CISO independence is now structural - no reporting line into IT, no business targets - which removes the pressure that historically got findings deprioritised. Board accountability is now time-bound, with a twelve-month ceiling on gap closure that turns the risk register into a tracked commitment. ISRMC cadence doubles to quarterly, so reporting must run on current exposure data rather than an annual audit snapshot. And testing intensifies from annual black-box to half-yearly grey or white box. Programmes designed for the 2023 guidelines will not clear the 2026 bar without rework.

The Half-Yearly VAPT Mandate and CERT-In Empanelment

The revised guidelines require vulnerability assessment and penetration testing every six months, as grey or white box engagements, performed by a CERT-In empanelled auditor. Grey and white box testing needs something black-box did not: a complete and current asset inventory, credentials, and access to application logic. The payoff is that business-logic flaws which automated scanners never reach are actually found. Praxis-Q delivers CERT-In-aligned VAPT to OWASP and PTES with CVSS-scored findings and re-testing after remediation, and works alongside empanelled signatories where the mandate requires an empanelled auditor's report.

Supply Chain, Cloud and Cryptography Controls

The 2026 revision formalises vendor oversight that was previously left to interpretation. Sub-outsourcing now needs written approval rather than silent delegation. Cloud service providers must be MeitY-empanelled with valid STQC status, which rules out a number of arrangements insurers currently run. Contracts need complete data-elimination clauses and NDAs covering both security and business continuity. Separately, the cryptography control requires maintaining an up-to-date inventory of cryptographic assets - the groundwork for post-quantum migration, and something almost no insurance-sector organisation has today.

Where IRDAI Sits Alongside RBI SAR, CERT-In and ISO 27001

Insurance groups rarely carry only one mandate. A CERT-In-aligned audit produces evidence usable for IRDAI, for RBI System Audit Reports where a regulated payment entity sits inside the group, and for ISO 27001 certification. The DPDP Act adds its own security-safeguard obligations over the same estate. Praxis-Q scopes these together so one testing cycle and one evidence set serve several regulators, rather than running parallel audits that examine the same systems three times a year.

Frequently Asked Questions

Who needs an IRDAI Cyber Security Audit?
All insurers, reinsurers, insurance intermediaries, brokers, third-party administrators (TPAs), web aggregators and corporate agents regulated by the Insurance Regulatory and Development Authority of India.
What are the IRDAI Information & Cyber Security Guidelines?
Issued in 2023, they mandate governance, IT infrastructure security, data protection and periodic independent audit requirements for every entity IRDAI regulates.
How often is the audit required?
IRDAI requires an independent cyber security audit on an annual basis, with findings reported to the Board and submitted to the regulator as required.
Is a standard VAPT report enough for IRDAI?
No. IRDAI expects a comprehensive audit covering governance, data protection and outsourcing risk in addition to technical VAPT - a narrow VAPT-only report does not meet the guideline scope.
Do outsourced partners of insurers need this too?
Yes. The guidelines extend to outsourced service providers handling policyholder data or critical insurance systems, so vendor and TPA coverage is part of the audit scope.
Are the IRDAI 2023 cyber security guidelines still in force?
No. IRDAI issued revised Information and Cyber Security Guidelines on 6 April 2026, superseding the 2023 framework. Programmes still designed around the 2023 requirements will not meet the current CISO independence, ISRMC cadence, VAPT frequency or supply-chain obligations.
How often must insurers conduct VAPT under the 2026 guidelines?
Every six months. The testing must be grey or white box rather than black-box, and must be conducted by a CERT-In empanelled auditor. This is a significant step up from the annual black-box testing many insurers previously relied on.
Do the guidelines apply to intermediaries and TPAs, or only to insurers?
They apply far beyond insurers. Brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, ISNP operators, corporate surveyors and motor insurance service providers are all in scope, alongside insurers and Foreign Reinsurance Branches.
What changed about the CISO role?
The CISO may no longer report to the Head of IT and may not carry business targets. The intent is structural independence, so security findings are not deprioritised or exception-approved for commercial convenience. Organisations with the CISO sitting inside IT will need to change reporting lines.
How long do we have to close identified gaps?
The Board must approve gap-closure timelines and ensure all identified gaps are closed within twelve months. That converts the risk register from a narrative document into a tracked, time-bound commitment with Board-level accountability.
Can one audit cover IRDAI and our other obligations?
Largely, yes. A CERT-In-aligned audit produces evidence that also supports RBI SAR where applicable, ISO 27001 certification, and DPDP Act security safeguards. Scoping them together avoids testing the same systems repeatedly for different regulators.

Ready to Get Started?

Free gap analysis · Proposal in 24hrs · Delivery in weeks