Skip to content
Macksofy Technologies
India · 2026 · Process Guide

The CERT-In Empanelment Process (2026): How an Auditing Organisation Actually Gets on the Panel

A step-by-step walkthrough of how CERT-In empanels information security auditing organisations in India — the single three-month application window each year, the eligibility bar, the documentation round, the offline and online practical skill tests and their 90% pass threshold, the Personal Interaction Session, government background verification, what it costs, how long the whole cycle takes, and what an organisation has to keep doing to stay on the panel.

CERT-In Empanelment Compliance Audit VAPT MeitY India
Macksofy Audit Team· Compliance & regulatory audit practice12 August 2026 13 min read
The CERT-In Empanelment Process (2026): How an Auditing Organisation Actually Gets on the Panel — Compliance · Macksofy
In short

What is the CERT-In empanelment process?

CERT-In empanelment is an annual selection run by India's national CERT under MeitY. Organisations apply between 1 July and 30 September, then clear a documentation review, an offline practical skill test, a live VA/PT test on CERT-In's own testbed — both requiring 90% — a personal interaction session, and government background verification. Empanelment then runs three years.

CERT-In empanelment is not a certification you study for and collect. It is a competitive annual selection run by a government agency, with one three-month application window a year, two practical hacking exams that both demand a 90% score, a face-to-face technical interrogation, and a background check by a government agency that can still reject you after you have passed everything else. This is what the process actually looks like from the inside.

Most articles about CERT-In empanelment are written for buyers — what an empanelled audit is, who needs one, what the report looks like. If that is what you came for, read our CERT-In empanelled audit guide instead. This piece answers the other question: how does an organisation get empanelled in the first place, and what does that bar tell you about the firm you are about to hire?

237
Empanelled organisations (Aug 2026)
1
Application window per year
90%
Pass mark on both skill tests
3 yrs
Validity once empanelled

What CERT-In empanelment is

CERT-In — the Indian Computer Emergency Response Team, operating under the Ministry of Electronics and Information Technology (MeitY) — maintains a panel of information security auditing organisations approved to audit computer systems, networks and applications for government bodies and other sectors of the Indian economy. As of August 2026 the published list carries 237 organisations.

Two things about the panel are widely misunderstood. First, CERT-In does not hand out work: it explicitly states that it will not award any audit assignment to any auditor, and that the auditee organisation is free to choose any firm on the panel, with CERT-In having no role in that choice. Empanelment is a licence to be considered, not a pipeline. Second, empanelment is not permanent — it runs for three years from the year of empanelment, and CERT-In can suspend it in between.

The cycle: one window a year, and it is closing

Since July 2020, CERT-In has opened empanelment exactly once a year on a published calendar. Applications are invited for a three-month period from 1 July to 30 September. Everything after that — clarifications, the two practical skill tests, the interview, background verification — runs on fixed dates through to the following July.

The consequence people underestimate is the length of the cycle. Apply in September 2026 and, if you clear every stage at the first attempt, you are empanelled on 1 July 2027 — roughly ten months later. Miss a 90% threshold once and you use your second attempt; miss it twice and you are out of the cycle entirely.

WindowStageWhat has to happen
1 Jul – 30 SepApplicationsApplication form plus all annexures, submitted by email. No late submissions.
1 Oct – 31 OctClarificationsCERT-In raises queries; you have 15 days to answer or the application is dropped. Offline test setups are issued in this window only, and only to organisations that cleared the documentation round.
1 Nov – 31 DecStep 2 — Offline PSTSubmit the offline practical skill test report within 15 days of receiving the setup. 90% or above to progress.
10–12 JanStep 3 — Online VA/PT PSTFirst attempt. Runs three days on a 24x7 basis; report due within 7 working days.
20–22 FebStep 3 — second attemptOnly for organisations that missed 90% in January. Same format, same report deadline.
2nd–3rd week MarStep 4 — Personal InteractionFace-to-face session with the Technical Evaluation Committee in Delhi and Bangalore.
Mar – 30 JunBackground verificationDetails forwarded to a government agency for verification and clearance.
1 JulEmpanelment effectiveValid for three years from the year of empanelment.

The annual empanelment calendar, as published by CERT-In

Who is eligible to apply

CERT-In's published guidelines set a minimum bar that is more about demonstrated audit history than company size. An applicant may be any organisation, company or firm providing IT security auditing services, and must meet the following:

  • A minimum of five technical staff able to perform security testing — specifically vulnerability assessment and penetration testing — and to analyse and evaluate the results.
  • Personnel holding information-security qualifications such as CISSP, CISM or CISA (ISACA), DISA / ISA (ICAI), DISSA (ICMAI), or another formal IT security qualification.
  • Preferably three years of experience in IT security auditing work.
  • At least five IT security audits already carried out, preferably two of them within the last 12 months.
  • Adequate knowledge of trusted computer information systems, telecommunications and networking environments.

Note the shape of that list: you cannot apply as a newly formed firm with strong CVs. CERT-In wants completed audits on the record — and Annexure A requires detailed information on the last five audits carried out over the past three years, plus full copies of any two of those audit reports. The panel is designed to admit organisations that already audit, not organisations that intend to.

The four steps

Step 1 — Documentation review

Scanned copies of the application form and annexures, signed and stamped by an authorised person, go to CERT-In's empanelment address by email. CERT-In is explicit that hard-copy applications will not be entertained under any circumstances. Four annexures accompany the form: a background verification certificate from the organisation (I), a consent form (II), an undertaking on code of conduct (III), and the audit history described above (A).

A duly constituted Technical Evaluation Committee (TEC) evaluates applicants against the essential criteria at this stage, and may call an applicant in to present. Only organisations declared successful at Step 1 go forward.

Step 2 — Offline Practical Skill Test (OFFPST)

Successful applicants are issued two or more virtual machine images on DVD, carrying applications and services with known vulnerabilities and built-in penetration paths. You test them at your own premises and submit a VA/PT report. Guidelines for setting up the testbed and a mandatory report template ship with the DVD, and reports can only be submitted in that template.

The threshold is 90% of the known vulnerabilities and successful penetrations. Two attempts are allowed. Fail both and the organisation may only reapply as a fresh applicant after a one-year cooling period from the date of the last test.

Step 3 — VA/PT Practical Skill Test

This is the live round. CERT-In hosts different setups with different vulnerability sets on its own testbed, and participating organisations have to find the vulnerabilities and complete the challenges in their assigned environment. Challenges are declared in real time over an IRC channel. A Rules of Engagement document and a post-exercise report template are emailed in advance.

The first attempt runs 10–12 January on a 24x7 basis, with the report due within seven working days. Organisations that miss 90% get a second attempt on 20–22 February. As with the offline test, two failures mean a one-year cooling period and a fresh application. CERT-In notes that it reserves the right to require testbed access from a static public IP at your premises, or from a location of its choosing such as CERT-In or IISc, under direct supervision.

Step 4 — Personal Interaction Session

The TEC meets in Delhi and in Bangalore to interview organisations that cleared Step 3. The session involves a face-to-face meeting with an auditor team, which must include the technical personnel actually named in the application form — not a sales team. Candidates are asked to interpret vulnerabilities and explain means of exploitation, and technical competence may be verified at CERT-In or at IISc Bangalore on a testbed similar to the one used in Step 3.

The Personal Interaction Session committee and the TEC then make the final recommendation on which organisations are forwarded for background verification.

The step after you pass: background verification

What it costs

The direct cost is trivial and the indirect cost is not. CERT-In charges a non-refundable application processing fee of Rs. 5,000, which covers the practical skill tests, paid by demand draft in favour of PAO, MeitY, New Delhi. That is the entire published fee.

The real expense is everything the fee does not cover: maintaining at least five certified testers on payroll through a ten-month cycle, the senior time consumed by two full VA/PT exercises against unfamiliar environments under a hard reporting deadline, travel to Delhi or Bangalore for the interaction session, and the opportunity cost of a one-year lockout if the tests go badly twice.

Staying on the panel

Empanelment carries continuing obligations, and CERT-In is explicit that continued status depends on the quality of auditing service rendered and on the satisfaction of auditee organisations as reflected in feedback to CERT-In. Empanelled organisations must send a bi-monthly report listing audit work in hand and completed, with durations.

  • CERT-In may carry out sample analysis of an empanelled organisation's audit work.
  • It may depute its own expert representatives to witness an audit while it is underway at the auditee's site.
  • It may seek the opinion of the auditee organisations directly, and publishes a customer feedback form for exactly that purpose.
  • Where a complaint or adverse feedback casts doubt on technical competence, a Special Round of practical skill testing can be imposed on an already-empanelled auditor.
  • Depending on the outcome, CERT-In may either allow corrective action with evidence, or temporarily withdraw or put the empanelment status on hold.

What the process tells you if you are hiring an auditor

Read the steps again from a buyer's seat and the panel starts to mean something specific. An empanelled firm has demonstrated, on CERT-In's own testbed and against CERT-In's own master list, that it can find 90% of the vulnerabilities in an environment it had never seen — twice, once offline and once live under time pressure. It has put its named technical staff in front of a government technical committee to explain how they exploit what they find. Its organisation and its people have passed a government background check.

That is a materially different assurance from a marketing claim about experience, and it is why regulators lean on the panel. What it does not tell you is anything about the specific team CERT-In will not be sending — because CERT-In awards no work and plays no part in your selection. Empanelment is the floor, not the differentiator. The questions that separate two empanelled firms are about scope, methodology, who is actually assigned to your engagement, and whether the retest is included.

For a fuller buyer-side walkthrough — what the audit itself covers, the CERT-In report format, the 2022 Directions and the six-hour incident reporting clock — see our CERT-In empanelled audit guide, and our note on how to choose a cybersecurity company in India.

Need a CERT-In empanelled audit?

Macksofy Technologies is a CERT-In empanelled information security auditing organisation, delivering audits in the CERT-In report format for BFSI, fintech, SaaS and government auditees across India.

See the CERT-In audit service
FAQ

Quick answers.

Applications are accepted only once a year, from 1 July to 30 September. You email scanned copies of the application form and Annexures I, II, III and A — signed and stamped by an authorised person — to CERT-In's empanelment address, and send a non-refundable demand draft of Rs. 5,000 in favour of PAO, MeitY, New Delhi. CERT-In states that hard-copy applications will not be entertained under any circumstances.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements