CERT-In empanelment is not a certification you study for and collect. It is a competitive annual selection run by a government agency, with one three-month application window a year, two practical hacking exams that both demand a 90% score, a face-to-face technical interrogation, and a background check by a government agency that can still reject you after you have passed everything else. This is what the process actually looks like from the inside.
Most articles about CERT-In empanelment are written for buyers — what an empanelled audit is, who needs one, what the report looks like. If that is what you came for, read our CERT-In empanelled audit guide instead. This piece answers the other question: how does an organisation get empanelled in the first place, and what does that bar tell you about the firm you are about to hire?
What CERT-In empanelment is
CERT-In — the Indian Computer Emergency Response Team, operating under the Ministry of Electronics and Information Technology (MeitY) — maintains a panel of information security auditing organisations approved to audit computer systems, networks and applications for government bodies and other sectors of the Indian economy. As of August 2026 the published list carries 237 organisations.
Two things about the panel are widely misunderstood. First, CERT-In does not hand out work: it explicitly states that it will not award any audit assignment to any auditor, and that the auditee organisation is free to choose any firm on the panel, with CERT-In having no role in that choice. Empanelment is a licence to be considered, not a pipeline. Second, empanelment is not permanent — it runs for three years from the year of empanelment, and CERT-In can suspend it in between.
The cycle: one window a year, and it is closing
Since July 2020, CERT-In has opened empanelment exactly once a year on a published calendar. Applications are invited for a three-month period from 1 July to 30 September. Everything after that — clarifications, the two practical skill tests, the interview, background verification — runs on fixed dates through to the following July.
The consequence people underestimate is the length of the cycle. Apply in September 2026 and, if you clear every stage at the first attempt, you are empanelled on 1 July 2027 — roughly ten months later. Miss a 90% threshold once and you use your second attempt; miss it twice and you are out of the cycle entirely.
| Window | Stage | What has to happen |
|---|---|---|
| 1 Jul – 30 Sep | Applications | Application form plus all annexures, submitted by email. No late submissions. |
| 1 Oct – 31 Oct | Clarifications | CERT-In raises queries; you have 15 days to answer or the application is dropped. Offline test setups are issued in this window only, and only to organisations that cleared the documentation round. |
| 1 Nov – 31 Dec | Step 2 — Offline PST | Submit the offline practical skill test report within 15 days of receiving the setup. 90% or above to progress. |
| 10–12 Jan | Step 3 — Online VA/PT PST | First attempt. Runs three days on a 24x7 basis; report due within 7 working days. |
| 20–22 Feb | Step 3 — second attempt | Only for organisations that missed 90% in January. Same format, same report deadline. |
| 2nd–3rd week Mar | Step 4 — Personal Interaction | Face-to-face session with the Technical Evaluation Committee in Delhi and Bangalore. |
| Mar – 30 Jun | Background verification | Details forwarded to a government agency for verification and clearance. |
| 1 Jul | Empanelment effective | Valid for three years from the year of empanelment. |
The annual empanelment calendar, as published by CERT-In
Who is eligible to apply
CERT-In's published guidelines set a minimum bar that is more about demonstrated audit history than company size. An applicant may be any organisation, company or firm providing IT security auditing services, and must meet the following:
- A minimum of five technical staff able to perform security testing — specifically vulnerability assessment and penetration testing — and to analyse and evaluate the results.
- Personnel holding information-security qualifications such as CISSP, CISM or CISA (ISACA), DISA / ISA (ICAI), DISSA (ICMAI), or another formal IT security qualification.
- Preferably three years of experience in IT security auditing work.
- At least five IT security audits already carried out, preferably two of them within the last 12 months.
- Adequate knowledge of trusted computer information systems, telecommunications and networking environments.
Note the shape of that list: you cannot apply as a newly formed firm with strong CVs. CERT-In wants completed audits on the record — and Annexure A requires detailed information on the last five audits carried out over the past three years, plus full copies of any two of those audit reports. The panel is designed to admit organisations that already audit, not organisations that intend to.
The four steps
Step 1 — Documentation review
Scanned copies of the application form and annexures, signed and stamped by an authorised person, go to CERT-In's empanelment address by email. CERT-In is explicit that hard-copy applications will not be entertained under any circumstances. Four annexures accompany the form: a background verification certificate from the organisation (I), a consent form (II), an undertaking on code of conduct (III), and the audit history described above (A).
A duly constituted Technical Evaluation Committee (TEC) evaluates applicants against the essential criteria at this stage, and may call an applicant in to present. Only organisations declared successful at Step 1 go forward.
Step 2 — Offline Practical Skill Test (OFFPST)
Successful applicants are issued two or more virtual machine images on DVD, carrying applications and services with known vulnerabilities and built-in penetration paths. You test them at your own premises and submit a VA/PT report. Guidelines for setting up the testbed and a mandatory report template ship with the DVD, and reports can only be submitted in that template.
The threshold is 90% of the known vulnerabilities and successful penetrations. Two attempts are allowed. Fail both and the organisation may only reapply as a fresh applicant after a one-year cooling period from the date of the last test.
Step 3 — VA/PT Practical Skill Test
This is the live round. CERT-In hosts different setups with different vulnerability sets on its own testbed, and participating organisations have to find the vulnerabilities and complete the challenges in their assigned environment. Challenges are declared in real time over an IRC channel. A Rules of Engagement document and a post-exercise report template are emailed in advance.
The first attempt runs 10–12 January on a 24x7 basis, with the report due within seven working days. Organisations that miss 90% get a second attempt on 20–22 February. As with the offline test, two failures mean a one-year cooling period and a fresh application. CERT-In notes that it reserves the right to require testbed access from a static public IP at your premises, or from a location of its choosing such as CERT-In or IISc, under direct supervision.
Step 4 — Personal Interaction Session
The TEC meets in Delhi and in Bangalore to interview organisations that cleared Step 3. The session involves a face-to-face meeting with an auditor team, which must include the technical personnel actually named in the application form — not a sales team. Candidates are asked to interpret vulnerabilities and explain means of exploitation, and technical competence may be verified at CERT-In or at IISc Bangalore on a testbed similar to the one used in Step 3.
The Personal Interaction Session committee and the TEC then make the final recommendation on which organisations are forwarded for background verification.
The step after you pass: background verification
What it costs
The direct cost is trivial and the indirect cost is not. CERT-In charges a non-refundable application processing fee of Rs. 5,000, which covers the practical skill tests, paid by demand draft in favour of PAO, MeitY, New Delhi. That is the entire published fee.
The real expense is everything the fee does not cover: maintaining at least five certified testers on payroll through a ten-month cycle, the senior time consumed by two full VA/PT exercises against unfamiliar environments under a hard reporting deadline, travel to Delhi or Bangalore for the interaction session, and the opportunity cost of a one-year lockout if the tests go badly twice.
Staying on the panel
Empanelment carries continuing obligations, and CERT-In is explicit that continued status depends on the quality of auditing service rendered and on the satisfaction of auditee organisations as reflected in feedback to CERT-In. Empanelled organisations must send a bi-monthly report listing audit work in hand and completed, with durations.
- CERT-In may carry out sample analysis of an empanelled organisation's audit work.
- It may depute its own expert representatives to witness an audit while it is underway at the auditee's site.
- It may seek the opinion of the auditee organisations directly, and publishes a customer feedback form for exactly that purpose.
- Where a complaint or adverse feedback casts doubt on technical competence, a Special Round of practical skill testing can be imposed on an already-empanelled auditor.
- Depending on the outcome, CERT-In may either allow corrective action with evidence, or temporarily withdraw or put the empanelment status on hold.
What the process tells you if you are hiring an auditor
Read the steps again from a buyer's seat and the panel starts to mean something specific. An empanelled firm has demonstrated, on CERT-In's own testbed and against CERT-In's own master list, that it can find 90% of the vulnerabilities in an environment it had never seen — twice, once offline and once live under time pressure. It has put its named technical staff in front of a government technical committee to explain how they exploit what they find. Its organisation and its people have passed a government background check.
That is a materially different assurance from a marketing claim about experience, and it is why regulators lean on the panel. What it does not tell you is anything about the specific team CERT-In will not be sending — because CERT-In awards no work and plays no part in your selection. Empanelment is the floor, not the differentiator. The questions that separate two empanelled firms are about scope, methodology, who is actually assigned to your engagement, and whether the retest is included.
For a fuller buyer-side walkthrough — what the audit itself covers, the CERT-In report format, the 2022 Directions and the six-hour incident reporting clock — see our CERT-In empanelled audit guide, and our note on how to choose a cybersecurity company in India.
Macksofy Technologies is a CERT-In empanelled information security auditing organisation, delivering audits in the CERT-In report format for BFSI, fintech, SaaS and government auditees across India.
