INDIA COMPLIANCE / BUYER GUIDE

Do you need CERT-In empanelled VAPT?

When RBI, SEBI, IRDAI or government work requires CERT-In empanelment — and when a rigorous manual pentest is enough for SaaS and SOC 2-style evidence. How to verify the official list. No false empanelment claims.

Short answer

Sometimes yes, often no. CERT-In empanelment is a procurement and regulatory construct for specific Indian contexts. It is not a universal requirement for every company that wants a penetration test, and it is not by itself a guarantee of testing depth. If your contract, regulator circular, or government tender explicitly requires an empanelled information security auditing organisation, you must use a firm that appears on the current official list under the correct legal entity name. If you are a SaaS or product company seeking high-quality offensive testing for customers, investors or ISO/SOC evidence, a capable specialist who is not empanelled may still be the right technical choice — provided your stakeholders do not mandate empanelment.

What CERT-In empanelment is

The Indian Computer Emergency Response Team (CERT-In) publishes a list of empanelled information security auditing organisations. The authoritative document is the official PDF hosted on CERT-In’s website: Empanel_org.pdf (always download the current file; lists change). Empanelment indicates that an organisation has been accepted onto that programme under CERT-In’s criteria at the time of listing — it does not automatically mean every marketing claim you see in search ads is accurate. Verify the PDF yourself and match the contracting legal name.

When buyers typically require it

  • Certain government and public-sector tenders that cite CERT-In empanelled auditors
  • Some regulated financial-sector assurance programmes where policy or customer contracts point to empanelled organisations (commonly discussed alongside RBI / SEBI / IRDAI expectations — always read the controlling circular or contract, not a vendor blog)
  • Enterprise questionnaires that explicitly ask “Is the testing firm CERT-In empanelled?” as a yes/no gate

PocForge does not claim CERT-In empanelment on this page. If you need that checkbox, use the official PDF to shortlist vendors who appear on it.

When rigorous non-empanelled testing is usually enough

  • Product security for SaaS/startups preparing customer security reviews
  • Engineering-led risk reduction before major releases
  • Evidence of penetration testing for many SOC 2 / ISO 27001 control narratives (confirm with your auditor — auditors care about scope, competence and report quality)
  • International buyers who never ask about CERT-In

In these cases, evaluate methodology, sample report quality, retest policy and people — not only badge lists. See VAPT services India and penetration testing company India.

RBI, SEBI, IRDAI, DPDP — keep the layers straight

These are distinct regimes. A penetration test report is one evidence artefact among many. Data protection obligations under India’s DPDP framework, sectoral IT/security circulars, and CERT-In directions (including incident reporting obligations for certain entities) are separate topics. Do not assume that “we did VAPT” equals “we are compliant” with any named regulator. Use counsel and your compliance team for legal interpretation; use offensive testing to reduce technical risk and produce clear findings.

Decision checklist

  1. Does a written contract, tender or regulator instruction explicitly require a CERT-In empanelled organisation?
  2. If yes — open the current official PDF, find the vendor’s legal name, and proceed only with listed entities.
  3. If no — shortlist based on scope fit, manual testing depth, reporting and price transparency (our 2026 cost guide).
  4. Either way — demand a statement of work that names assets, environments, roles and retest terms.

How PocForge positions itself

We compete as a transparent, human-led boutique for modern product teams. We will not invent empanelment status to win search clicks. If you discover you need an empanelled firm, we would rather tell you early than waste your procurement cycle. If you need serious web/API/cloud/external testing with published INR ranges and a remediation retest, contact us.

Frequently asked questions

Is PocForge CERT-In empanelled?

Do not treat this website as an empanelment certificate. Check the current official CERT-In Empanel_org.pdf and match legal entity names. We avoid false claims.

Can SOC 2 accept a non-empanelled pentest?

Many auditors accept penetration tests from competent independent providers when scope and report quality are adequate. Confirm with your auditor; requirements vary.

Where is the official list?

CERT-In hosts the empanelled organisations PDF at cert-in.org.in — direct file: https://www.cert-in.org.in/PDF/Empanel_org.pdf

What if my customer insists on CERT-In but my risk is mostly SaaS app logic?

You may need an empanelled firm for the contractual checkbox, or a split approach. We can help you articulate scope either way — without misrepresenting status.

Related PocForge guides

Unsure which path you are on?

Send the clause or questionnaire wording — we will give a straight answer.

Request a Quote →