
This is a buyer’s guide, not legal advice. It sets out what changed in 2026, what each document actually says, which parts bind whom, and how to turn all of it into a VAPT scope and statement of work that produces usable evidence. We link to the primary sources throughout. Where a date is our own calculation rather than an official statement, we say so.
1. What changed, and what did not
Nothing in 2026 created a new, general legal duty for every Indian company to commission a penetration test. What changed is the expected pace and shape of testing, and the evidence you will want once the DPDP safeguards apply.
| Date | Document | Why a VAPT buyer should care |
|---|---|---|
| 28 April 2022 | CERT-In Directions No. 20(3)/2022 under section 70B(6) of the IT Act | Report specified cyber incidents to CERT-In within 6 hours; keep ICT logs for a rolling 180 days within India; synchronise clocks to NIC/NPL-traceable NTP |
| 25 July 2025 | Comprehensive Cyber Security Audit Policy Guidelines (CISG-2025-02) | Defines scope, methodology, severity scoring, follow-up audits and reporting for audits by CERT-In empanelled organisations |
| 13 November 2025 | DPDP Rules, 2025 (G.S.R. 846(E)) and the Act’s commencement notification (G.S.R. 843(E)) | Rule 6 sets minimum “reasonable security safeguards”; Rule 7 sets breach intimation, including a 72-hour report to the Data Protection Board |
| 26 April 2026 | CERT-In advisory CIAD-2026-0020, “Defending Against Frontier AI Driven Cyber Risks” (severity: High) | Asks organisations to reduce internet-exposed attack surface and watch for unusually fast, automated activity |
| 25 May 2026 | Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation (CISG-2026-02) | Indicative remediation timelines; continuous validation, VAPT, red teaming and AI system testing |
| 10 June 2026 | Guidelines for OEMs and Technology Providers (CISG-2026-03) | Vendors supplying Indian organisations are advised to run continuous VAPT and keep assessment reports current; customers may request evidence and verify independently |
| 13 November 2026* | DPDP Rules: Rule 4 (Consent Managers) commences | Not a security-testing duty, but the first DPDP compliance milestone |
| 13 May 2027* | DPDP Rules: Rules 3, 5 to 16, 22 and 23 commence | Rule 6 safeguards, Rule 7 breach intimation and Rule 13 Significant Data Fiduciary duties apply |
* Our plain count of “one year” and “eighteen months” after publication in the Gazette on 13 November 2025. The Rules state periods, not calendar dates. A Lok Sabha answer dated 12 August 2026 restated the same phased timeline, and as at 5 October 2026 we have not found a notification changing it.
2. Who these documents actually bind
Buyers often hear all of this flattened into “CERT-In says you must”. The documents are more careful than that, and your scope should be too.
- The audit guidelines state that they are binding on CERT-In empanelled auditing organisations and on auditee entities covered under the relevant provisions. If your regulator, contract or tender requires an empanelled auditor, these rules apply to your engagement. If not, they are still the most detailed public yardstick in India for what a credible VAPT should include. Our guide Do you need CERT-In empanelled VAPT? covers how to tell which case you are in. PoCForge (Cyber Security) does not claim CERT-In empanelment.
- The AI blueprint encourages organisations to implement its recommendations “in a risk-informed manner” based on criticality and threat conditions. Its remediation timelines are labelled indicative.
- The OEM and technology provider guidelines are addressed to global and domestic OEMs and technology providers, a wide group that includes software vendors, cloud and managed service providers, system integrators and digital service providers supplying Indian organisations. They state that Indian organisations, including CERT-In, may run independent assessments of supplied products and services.
- The 2022 Directions apply to service providers, intermediaries, data centres, body corporate and government organisations. The 6-hour reporting and 180-day log requirements have applied since 2022.
- The DPDP Rules apply to Data Fiduciaries. The DPDP Act and Rules do not name penetration testing. Rule 6 names outcomes, and testing is one practical way to show those outcomes hold.
3. The new pace: remediation measured in hours and days
The blueprint’s most practical section for buyers is its table of indicative remediation timelines. It is worth reading next to whatever retest window your current VAPT contract gives you.
| Finding type (CERT-In blueprint, section 9) | Indicative remediation expectation |
|---|---|
| Known exploited vulnerability on internet-facing and crown-jewel systems | Immediate containment; patch, mitigate or remove exposure within 12 hours where feasible |
| Critical externally exposed vulnerability | Patch, mitigate or remove exposure within 1 day |
| Known exploited vulnerability on internal systems | Patch or mitigate within 1 day unless compensating controls are implemented and documented |
| Critical internal vulnerability on high-value systems | Patch or mitigate within 3 days |
| High-severity vulnerability | Patch or mitigate within 5 days based on risk prioritisation |
| No patch available | Temporary mitigation (isolation, access restriction, WAF/API protection, enhanced monitoring or feature disablement) until a fix exists |
Two consequences for how you buy testing follow from this:
- A report that arrives three weeks after the testing window is too late for the findings that matter most. The audit guidelines already require empanelled auditors to notify critical and high findings to the auditee as they are found, not only in the final report. Ask for the same thing in any VAPT contract.
- Severity alone is not enough to prioritise. The blueprint prioritises by known exploitation (KEV) and exploit likelihood (EPSS) as well as business criticality. The audit guidelines require reports to rate findings by CVSS, supplement them with EPSS, and map every observation to CWE and CVE identifiers. A report that only says “High” gives your engineers nothing to sort by.
4. Ten scoping clauses worth adding to your next VAPT RFQ
Our VAPT RFQ guide covers the basics: assets, roles, environments and rules of engagement. The clauses below are the additions that the 2025 audit guidelines and the 2026 CERT-In documents make worth writing down. Each maps to a specific provision in the sources listed at the end.
- Derive the scope from the asset inventory, not from memory. The audit guidelines say scope must come from the consolidated, updated asset inventory and should cover testing/UAT, development and production environments. If you only test staging, the guidelines require the final report to say explicitly that production was not audited.
- Name the test types. The guidelines list scope types to be stated up front: VAPT, external attack penetration testing, device-level audit, configuration audit, process audit, mobile, web application and API security audits, compliance audits and so on. “VAPT for our app” is not a scope.
- Require manual testing against a comprehensive standard. Solely tool-based testing is discouraged, and limited lists such as the OWASP Top 10 or SANS Top 25 “should not be considered as standards or references for audits”. Name a fuller reference: the OWASP Web Security Testing Guide, ASVS, the Mobile Security Testing Guide, OSSTMM, CSA CCM for cloud.
- Specify the scoring. CVSS for severity, EPSS for exploit likelihood, and CWE/CVE mapping for every finding.
- Get critical and high findings as they are found. Agree the channel and the contact before testing starts.
- Put the follow-up audit in the original scope. The guidelines say follow-up audits should be within the scope or RFP and conducted after closure, and that the final report should be issued after closure and follow-up on production.
- Include third parties. Third-party, vendor and supply-chain risk assessment should be part of scope under the guidelines. The OEM guidelines now give you a hook: ask key suppliers for their current security posture and continuous assessment reports, and reserve the right to verify independently.
- Keep the fee independent of the outcome. The guidelines say payment should not depend on whether results are favourable or on closure reports, and recommend fees based on predefined scope, deliverables and timelines.
- Agree data handling and retention. How the tester stores, retains and destroys your data is a scope item under the guidelines, alongside report format, standards, timeline and, for empanelled audits, the requirement to share audit metadata and reports with CERT-In within five days of completion.
- Test the 2022 Directions controls. Empanelled audits must verify compliance with the 28 April 2022 Directions in every assignment. Even outside that regime, NTP synchronisation, 180-day log retention within India and a working 6-hour reporting path are cheap to check during an infrastructure test.
Before you send the RFQ
0 checked
Ticks stay in this browser. They are not saved anywhere.
5. Mapping DPDP Rule 6 to test objectives
Rule 6(1) lists seven minimum safeguards. None of them says “commission a penetration test”, but most of them describe things a well-scoped test can confirm or refute. This is how we would translate them into objectives a tester can work against.
| Rule 6(1) | What the Rule requires (summarised) | Test objective you can scope |
|---|---|---|
| (a) | Data security measures such as encryption, obfuscation, masking or virtual tokens | Can an attacker read personal data in clear text through APIs, exports, logs, backups, storage buckets or error messages? |
| (b) | Measures to control access to computer resources, including a Data Processor’s | Authorisation testing: object-level access (BOLA/IDOR), role and tenant isolation, privilege escalation, cloud IAM paths, admin interfaces |
| (c) | Visibility of access through logs, monitoring and review, to detect, investigate and remediate unauthorised access | Detection validation: did the test activity appear in your logs and alerts, and could your team reconstruct it afterwards? |
| (d) | Reasonable measures for continued processing, such as backups | Usually outside a classic VAPT. Pair with a restore test or a tabletop, and check whether backups are reachable from a compromised account |
| (e) | Retain logs and personal data for one year for detection, investigation and remediation, unless another law requires otherwise | Configuration review of log retention and integrity. Note the separate 180-day, in-India requirement in the 2022 CERT-In Directions |
| (f) | Contract provisions requiring Data Processors to take reasonable safeguards | Include processor-hosted components and integrations in scope, or obtain the processor’s own assessment evidence |
| (g) | Technical and organisational measures to ensure the safeguards are effectively observed | A repeatable cycle of testing, fixing and retesting, with dated evidence that findings were closed |
Two further points matter for buyers. First, once in force, Rule 7 requires a detailed report to the Data Protection Board within 72 hours of becoming aware of a personal data breach, including the circumstances and the measures taken to prevent recurrence. A recent test that already mapped your attack paths and logging gaps makes that report faster and more credible. Second, the government’s published penalty schedule puts the highest penalty, up to ₹250 crore, on a Data Fiduciary’s failure to maintain reasonable security safeguards. For organisations notified as Significant Data Fiduciaries, Rule 13 adds a Data Protection Impact Assessment and an audit once in every twelve months.
6. A practical plan for the 220 days to 13 May 2027
The blueprint itself sets out a phased roadmap: immediate risk reduction in 0 to 7 days (identify internet-facing systems, run vulnerability assessments, patch known exploited flaws), operational strengthening in 8 to 30 days (cloud and API security assessments, tabletop exercises, backup restoration testing), and advanced validation in 31 to 60 days (red team exercises and adversarial simulations). That is aggressive for most teams. A realistic version for a mid-sized Indian SaaS or fintech, working back from May 2027, might look like this. The sequence is our suggestion, not a regulatory timetable.
- October to November 2026: inventory and scope. Rebuild the asset inventory, decide whether any contract or regulator requires an empanelled auditor, and write the RFQ with the clauses above.
- November 2026 to January 2027: test what is exposed first. External infrastructure, customer-facing web applications and APIs, and cloud identity. These are the surfaces the April advisory and the blueprint single out for AI-accelerated reconnaissance.
- February to March 2027: fix, retest and validate detection. Close findings against the indicative timelines, run the follow-up audit, and check whether your logging would have caught the testing.
- April 2027: internal and adversarial testing where warranted. Active Directory, internal segmentation, an assumed-breach exercise, and AI features that can touch personal data or tools.
- Early May 2027: assemble the evidence pack. Scope, reports, retest results, closure dates and accepted risks signed off at the right level. The audit guidelines say risk acceptance and exceptions must be authorised by the head of the auditee organisation.
7. What this costs
None of this needs an exotic engagement. It needs the right surfaces in scope and a retest in the price. As a planning reference, our penetration testing cost guide for India publishes indicative ranges, all excluding GST: web and API from ₹55,000 to ₹1,10,000; external network and infrastructure from ₹25,000 to ₹65,000; cloud security review from ₹35,000 to ₹90,000; internal and Active Directory from ₹55,000 to ₹1,35,000; and AI/LLM security testing from ₹45,000 to ₹1,10,000. These are planning bands, not fixed packages. PoCForge engagements include a remediation retest for in-scope fixed findings within the window agreed in the statement of work.
8. Where PoCForge fits
PoCForge (Cyber Security) is an offensive-security firm based in Delhi NCR. We deliver VAPT remotely across India and work on-site when an engagement needs it. We test web applications, APIs, external infrastructure, internal networks and Active Directory, cloud environments and AI/LLM features, and run red team exercises. We do not claim CERT-In empanelment. If your contract requires an empanelled auditor, verify the official list first. If it does not, we are happy to scope against the clauses in this guide. Start from the VAPT services in India page or send us your draft scope.
Sources
- Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure, CERT-In, CISG-2026-02, version 1.0, 25 May 2026
- Guidelines regarding AI-Accelerated Vulnerability Protection and Response Requirements for OEMs and Technology Providers, CERT-In, CISG-2026-03, version 1.0, 10 June 2026
- CERT-In Advisory CIAD-2026-0020: Defending Against Frontier AI Driven Cyber Risks, 26 April 2026
- Comprehensive Cyber Security Audit Policy Guidelines, CERT-In, CISG-2025-02, version 1.0, 25 July 2025
- CERT-In Security Guidelines index, listing CISG-2026-01 to CISG-2026-03 with issue dates
- CERT-In Directions No. 20(3)/2022 under section 70B(6) of the IT Act, 28 April 2022
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Gazette of India, 13 November 2025
- DPDP Act commencement notification, G.S.R. 843(E), Gazette of India, 13 November 2025
- Government notifies DPDP Rules to empower citizens and protect privacy, PIB, 14 November 2025
- DPDP Rules, 2025 Notified, PIB backgrounder, 17 November 2025 (penalty schedule)
- Lok Sabha Unstarred Question No. 3943: Implementation of Rules under DPDP Act, 2023, answered 12 August 2026
Frequently asked questions
Does the DPDP Act require a penetration test?
No. Neither the Act nor the Rules name penetration testing. Rule 6 requires reasonable security safeguards, including encryption or masking, access control, logging and monitoring, backups, one-year log retention, processor contracts and measures to make sure the safeguards are actually observed. A scoped test is one practical way to produce evidence for several of those.
When do the DPDP security safeguards apply?
Rule 6 is among the rules that come into force eighteen months after the Rules were published in the Gazette on 13 November 2025. On a plain count that is 13 May 2027. The Rules state the period, not the calendar date.
Are CERT-In’s 2026 remediation timelines mandatory?
The blueprint labels them indicative and encourages a risk-informed approach. They are still the clearest public statement of what CERT-In considers a reasonable pace, and a useful benchmark for your patch process and retest windows.
Do the CERT-In audit guidelines apply if my tester is not empanelled?
The guidelines state that they bind CERT-In empanelled auditing organisations and covered auditee entities. If your engagement does not require empanelment, they are not binding on it, but they remain a detailed reference for scope, scoring and follow-up. See our guide Do you need CERT-In empanelled VAPT?
How often should we test?
The audit guidelines treat at least once a year as the minimum for a comprehensive audit and note that sectoral regulators may require more. The 2026 blueprint goes further, saying organisations can no longer rely solely on periodic assessments and should validate controls continuously. In practice that means an annual comprehensive test plus targeted tests after significant changes.
PoCForge (Cyber Security) publishes research and buyer guides to help organisations scope and buy security testing well. This article summarises public regulatory documents as at 5 October 2026. It is not legal advice, and it does not describe a named client engagement.
