Report an IncidentTalk to Sales

CERT-In VAPT Guidelines: Full Scope, Methodology & Deliverables

Author: Jay Thakker
Reviewed By: Nilesh Yadav
Updated on: July 20, 2026
Reading Time: 14 Min
Published: 
July 17, 2026

CERT-In's 2025 Comprehensive Cyber Security Audit Policy Guidelines have introduced a more structured approach to Vulnerability Assessment and Penetration Testing (VAPT), expanding expectations around audit scope, methodology, reporting, and governance. This article explains the latest CERT-In VAPT requirements, audit processes, compliance obligations, deliverables, and auditor selection considerations that organisations should understand. 

Key Takeaway

  • CERT-In VAPT is a structured cybersecurity audit activity: The framework combines vulnerability assessment, penetration testing, risk validation, remediation verification, and formal reporting to provide a comprehensive view of an organisation's security posture.
  • The 2025 Audit Policy Guidelines significantly expanded assessment requirements: Modern audits can cover cloud vulnnerability environments, APIs, operational technology, software supply chains, AI systems, blockchain platforms, and other emerging technologies depending on organisational risk and scope.
  • Manual validation remains a core requirement of the assessment methodology: CERT-In empanelled auditors are expected to validate findings through manual testing, controlled exploitation, security control reviews, and independent quality assurance rather than relying solely on automated tools.
  • A successful engagement extends beyond identifying vulnerabilities: Scope definition, testing approvals, remediation activities, re-testing, evidence collection, and final reporting are all essential components of the audit lifecycle.
  • Audit outputs are designed to support both security improvement and compliance objectives: Findings are risk-rated, mapped to recognised standards such as CVSS, CWE, and CVE where applicable, and documented through formal reports that support remediation and governance activities.

What Are CERT-In VAPT Guidelines and Who Must Comply?

CERT-In VAPT guidelines define how vulnerability assessments and penetration tests should be planned, executed, documented, and validated during cybersecurity audits. They apply to CERT-In-aligned assessments conducted for government, critical infrastructure, and regulated organisations. 

VAPT Under the CERT-In Framework Explained

Under the CERT-In framework, VAPT serves as a technical assessment mechanism for evaluating the security of digital assets.

It combines two activities:

  • Vulnerability Assessment (VA): Identifies known security weaknesses.
  • Penetration Testing (PT): Validates whether those weaknesses can be exploited.

Together, they help organisations understand real-world exposure across applications, networks, cloud environments, APIs, and supporting infrastructure.

The Security Audit Baseline Requirements (SABR)

The Security Audit Baseline Requirements establish the minimum expectations for cybersecurity audits conducted by CERT-In-empanelled auditors.

SABR guides on:

  • Audit scope
  • Testing coverage
  • Evidence collection
  • Risk classification
  • Reporting requirements
  • Remediation validation

The objective is to promote consistency and audit quality across assessments.

How the July 2025 Comprehensive Audit Policy Guidelines Changed VAPT

The July 2025 Comprehensive Cyber Security Audit Policy Guidelines expanded VAPT from a standalone testing activity into a broader audit and assurance process.

Key changes include:

  • Greater emphasis on risk-based assessments
  • Formal documentation requirements
  • Evidence preservation and traceability
  • Remediation verification
  • Follow-up assessments
  • Coverage of cloud, APIs, third-party services, and operational technology environments

Also read

Who Must Comply?

The guidelines are primarily intended for CERT-In empanelled auditors and organisations undergoing CERT-In-aligned cyber security audits.

They are particularly relevant for:

  • Government departments and agencies
  • Critical Information Infrastructure (CII) operators
  • Public-sector organisations
  • Organisations subject to cyber security requirements issued by regulators such as RBI, IRDAI, and SEBI
  • Digital service providers supporting government or critical systems

Also Read: CERT-In 6-Hour Incident Reporting: Complete Process, Timeline, Reporting Format & Checklist 2026

What Is the Full Scope of a CERT-In VAPT Audit?

A CERT-In VAPT audit can cover applications, infrastructure, cloud services, operational technology, source code, and emerging technologies, depending on the organisation's risk profile and audit objectives.

Assets in Scope: Web Apps, APIs, Networks, Cloud & OT/ICS

The audit scope typically includes internet-facing web applications, APIs, internal and external networks, cloud workloads, databases, identity systems, and supporting infrastructure. For organisations operating industrial environments, Operational Technology (OT) and Industrial Control Systems (ICS) may also be assessed to identify weaknesses that could affect operational continuity, safety, or security.

Recognised Audit Types: Compliance, VA, PT, Red Team & Source Code Review

CERT-In recognises multiple assessment approaches based on audit objectives. These include compliance audits for regulatory validation, Vulnerability Assessments to identify weaknesses, Penetration Testing to validate exploitability, Red Team exercises to simulate real-world attacks, and Source Code Reviews to identify security flaws within application code before deployment.

New 2025 Scope: AI Systems, Blockchain, IoT, Quantum & SBOM/AIBOM

The 2025 Comprehensive Cyber Security Audit Policy Guidelines expanded audit coverage to address emerging technologies and software supply chain risks. The updated scope includes artificial intelligence systems, blockchain platforms, Internet of Things (IoT) environments, quantum-resistant security considerations, Software Bills of Materials (SBOMs), and AI Bills of Materials (AIBOMs) used to improve visibility into software and AI component dependencies.

Production vs. Staging and Defining Scope in the Engagement Agreement

The audit environment and testing boundaries must be documented before assessment activities begin. Organisations and auditors should clearly define whether testing will occur in production, staging, or both, identify in-scope assets, establish permitted testing methods, and document exclusions within the engagement agreement to minimise operational disruption and ensure audit objectives are clearly understood.

What Methodology Do CERT-In Empanelled Auditors Follow?

CERT-In empanelled auditors follow a risk-based methodology that combines manual testing, security control validation, controlled exploitation, compliance assessment, and remediation verification to evaluate an organisation's security posture.

Manual Security Testing and Vulnerability Validation

The methodology begins with vulnerability discovery using both automated and manual techniques. Auditors validate identified findings, confirm exploitability, eliminate false positives, and assess potential business impact. Manual testing is particularly important for identifying authentication flaws, access control weaknesses, insecure workflows, privilege escalation paths, and other vulnerabilities that automated tools may not accurately detect.

Security Control Assessment Across Five Control Domains

Auditors evaluate the effectiveness of security controls across five domains: management, protective, detection, response, and recovery. This assessment examines whether governance processes, preventive safeguards, monitoring capabilities, incident response procedures, and recovery mechanisms are implemented correctly and operating as intended within the organisation's environment.

Exploitation, Configuration Review, and Remediation Verification

Once vulnerabilities are identified, auditors perform controlled exploitation to determine whether weaknesses can be used in real-world attack scenarios. The assessment may also include configuration reviews, log analysis, IDS/IPS validation, and incident response readiness checks. After remediation activities are completed, re-testing is conducted to verify that corrective actions have effectively resolved the identified findings.

Quality Assurance and Compliance Verification

Before the audit is finalised, findings undergo an independent maker-checker review to validate evidence, risk ratings, and recommendations. Auditors also assess whether applicable security controls, processes, and operational practices align with relevant CERT-In requirements and directions, ensuring that both technical and compliance objectives have been addressed during the assessment.

Preparing for a CERT-In-aligned VAPT assessment requires more than running automated scans. Eventus Security Vulnerability Assessment and Penetration Testing services support the assessment of web applications, APIs, cloud environments, mobile applications, and enterprise infrastructure through a combination of automated testing and manual validation. This helps organisations identify security weaknesses and prioritise remediation efforts.  

How Does the CERT-In VAPT Process Work Step by Step?

A CERT-In-aligned VAPT engagement typically follows four stages: auditor selection, audit planning and scope definition, technical assessment and remediation, followed by validation and final reporting.

Step 1: Select a CERT-In Empanelled Auditor

The process begins by appointing a CERT-In empanelled auditor authorised to perform cybersecurity audits and assessments. Organisations should select an auditor whose empanelment category, technical capabilities, and sector experience align with the systems, applications, and infrastructure included in the assessment scope.

Step 2: Define Scope, Rules of Engagement, and Testing Approvals

Before testing begins, the auditor and organisation formally define the audit scope, target assets, assessment methodology, timelines, communication procedures, and testing boundaries. Any high-risk activities that could affect service availability, data integrity, or production operations must be explicitly approved and documented within the engagement agreement.

Step 3: Perform VAPT and Address Identified Findings

The auditor conducts vulnerability assessment and penetration testing activities against the approved scope. Identified findings are validated, risk-rated, and documented with supporting evidence. The organisation then implements remediation measures to address confirmed vulnerabilities, misconfigurations, and control weaknesses identified during the assessment.

Step 4: Validate Remediation and Issue the Final Audit Report

Once remediation is completed, the auditor performs re-testing to verify that corrective actions have been implemented effectively. The engagement concludes with a final report that documents the assessment scope, methodology, findings, remediation status, residual risks, and audit conclusions. Where specifically required by the engagement, regulatory framework, or contracting authority, additional attestations or certification-related documents may also be issued following successful remediation validation.

What Are the Deliverables of a CERT-In VAPT Engagement?

A CERT-In VAPT engagement typically produces a formal audit report containing validated findings, risk ratings, remediation guidance, supporting evidence, and the final assessment outcome.

The exact deliverables may vary depending on the audit scope and engagement requirements, but most CERT-In-aligned assessments include the following:

  • Executive Summary: A high-level overview of the assessment, including audit objectives, key observations, overall security posture, and major risks identified during the engagement.
  • Scope and Methodology Documentation: Details of the assets assessed, testing boundaries, assessment approach, tools used, manual validation activities, assumptions, limitations, and rules of engagement.
  • Detailed Technical Findings: A comprehensive record of identified vulnerabilities, affected assets, proof-of-concept evidence, attack paths, business impact, and recommended remediation actions.
  • CVSS, EPSS, CWE, and CVE Mapping: Vulnerabilities are commonly mapped to Common Vulnerability Scoring System (CVSS) scores, Exploit Prediction Scoring System (EPSS) ratings, Common Weakness Enumeration (CWE) categories, and Common Vulnerabilities and Exposures (CVE) references where applicable.
  • Severity Classification and Risk Prioritisation: Findings are categorised according to severity levels such as Critical, High, Medium, Low, or Informational to help organisations prioritise remediation efforts based on risk.
  • Critical Vulnerability Notifications: Vulnerabilities that present an immediate and significant security risk may be reported to the organisation as soon as they are discovered rather than waiting for the final report, enabling faster remediation and risk reduction.
  • Remediation Validation and Re-Test Results: Where re-testing is performed, the report documents whether identified findings have been successfully remediated, partially resolved, or remain open after corrective actions.
  • Final Audit Sign-Off and Authorisation: The completed report is reviewed, approved, and formally issued by the auditing organisation in accordance with its quality assurance and reporting procedures.
  • Safe to Host Certificate (Where Applicable): Certain engagements may include a Safe to Host certificate or similar attestation after successful remediation and validation. The issuance, format, and acceptance of such certificates depend on the assessment scope, customer requirements, and applicable regulatory or contractual obligations.

What Are the Data Handling, Confidentiality & Non-Compliance Rules?

The CERT-In audit framework establishes requirements for audit data storage, confidentiality, information access, contractual safeguards, and enforcement actions for non-compliance.

Data Localisation: Storage Only on Systems in India

The 2025 Comprehensive Cyber Security Audit Policy Guidelines require audit data, working papers, evidence, reports, logs, screenshots, and related artefacts to be stored on systems located within India. This requirement is intended to maintain control over sensitive audit information and reduce risks associated with cross-border data exposure.

Access Controls, Retention, Secure Destruction & the Ban on Foreign Sharing

Access to audit information must be restricted to authorised personnel directly involved in the engagement. Audit records should be retained for the prescribed period, protected against unauthorised disclosure, and securely destroyed once retention obligations are fulfilled. The guidelines also place restrictions on sharing audit artefacts, findings, and supporting evidence with foreign entities or unauthorised third parties without appropriate approval.

NDA and Engagement-Letter Requirements

Before audit activities begin, the auditor and auditee are expected to execute formal engagement documentation that defines scope, responsibilities, confidentiality obligations, ownership of audit artefacts, reporting procedures, and data-handling requirements. Non-disclosure agreements (NDAs) form an important part of protecting sensitive technical and business information exchanged during the assessment.

The "Deter & Punish" Enforcement Model: Watch-List, Suspension, De-Empanelment & Legal Action

The framework adopts a deterrence-based enforcement approach for auditor misconduct and serious violations of audit requirements. Depending on the severity of the breach, actions may include placement on a watch-list, suspension of audit activities, de-empanelment from the CERT-In programme, financial consequences, or legal action where contractual, regulatory, or statutory obligations have been violated.

How Do You Choose the Right Auditor and What Does It Cost?

Organisations should evaluate auditor qualifications, technical expertise, sector experience, engagement scope, and assessment complexity when selecting a CERT-In empanelled auditor and estimating project costs.

Credentials to Verify: CISSP, CISA & CISM

A qualified auditor should possess recognised cyber security and audit certifications that demonstrate technical competence and professional expertise.

Common certifications include:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Offensive Security certifications
  • Cloud security and application security certifications

These qualifications help validate an auditor's ability to assess complex technology environments and conduct security assessments using recognised industry practices.

Mapping Auditor Competencies & Multi-Year Contracts for Critical Apps

Auditor selection should align with the technologies, business functions, and regulatory obligations associated with the systems being assessed.

Organisations should evaluate:

  • Experience with cloud environments
  • API security expertise
  • Application security testing capabilities
  • OT/ICS assessment experience
  • Sector-specific knowledge
  • Regulatory assessment experience

For highly critical applications and long-term security programmes, organisations may choose to engage the same auditor across multiple assessment cycles to maintain consistency in testing, reporting, and remediation tracking.

Cost Drivers, Typical Timeline & Re-Audit Frequency

The cost and duration of a VAPT engagement depend largely on assessment scope and technical complexity.

Common cost drivers include:

  • Number of applications and assets
  • API coverage requirements
  • Network size
  • Cloud infrastructure complexity
  • Source code review requirements
  • Re-testing activities
  • OT/ICS environments
  • Third-party integrations

Assessment timelines can range from a few days for limited-scope engagements to several weeks for large enterprise environments. Re-audit frequency is generally determined by regulatory obligations, risk exposure, major infrastructure changes, and system criticality.

How CERT-In VAPT Compares to ISO 27001, SOC 2 & PCI DSS

CERT-In VAPT focuses on identifying and validating technical security weaknesses through assessment and testing activities as part of an organisation's broader cybersecurity strategy.

For organisations pursuing multiple compliance initiatives, CERT-In VAPT is often implemented alongside frameworks such as SOC 2, ISO 27001, and PCI DSS to strengthen security governance and meet industry or customer requirements. To better understand how CERT-In compliance aligns with SOC audits, read our guide on CERT-In Compliance & SOC Audit Guidelines.

The primary differences include:

  • CERT-In VAPT: Technical security assessment and vulnerability validation.
  • ISO 27001:  Evaluation of an Information Security Management System (ISMS).
  • SOC 2: Assessment of security and operational controls against trust service criteria.
  • PCI DSS: Security requirements for organisations that process, store, or transmit payment card data.

These frameworks serve different objectives and are often implemented together as part of a broader security and compliance programme to improve overall cyber risk management and organisational resilience.

Strengthen Your VAPT Programme with Eventus Security

Effective VAPT requires more than identifying vulnerabilities. Organisations also need validated findings, clear remediation guidance, and visibility into security risks across applications, infrastructure, APIs, and cloud environments. Eventus Security provides VAPT services designed to help organisations assess security weaknesses and support remediation efforts across modern technology environments.

How Eventus Security Supports VAPT Engagements:

  • Comprehensive Security Assessments: VAPT services cover web applications, mobile applications, APIs, networks, cloud environments, wireless infrastructure, IoT ecosystems, and thick-client applications.
  • Manual Validation of Findings: Automated assessment results are validated through manual testing to confirm findings, reduce false positives, and provide additional insight into identified security weaknesses.
  • Risk-Based Reporting and Remediation Guidance: Assessment reports prioritise vulnerabilities based on risk and include recommendations to support remediation planning and risk reduction efforts.
  • Re-Testing Support: After remediation activities are completed, re-testing can be performed to verify whether identified findings have been addressed.
  • Coverage for Modern Technology Environments: Assessments can be tailored for traditional enterprise infrastructure, cloud-native applications, APIs, and DevSecOps environments.

Speak with the Eventus Security team to learn how its VAPT services can help your organisation identify security weaknesses, support remediation efforts, and strengthen overall cyber resilience.

FAQs

1. Can internal security teams perform a CERT-In VAPT audit?

No. If an organisation requires a CERT-In-aligned audit under a regulatory, contractual, or government mandate, the assessment typically needs to be conducted by a CERT-In-empanelled auditor. Internal security teams may support remediation and preparedness activities but cannot replace an independent audit where empanelment is required.

2. Does passing a CERT-In VAPT audit mean an organisation is secure?

No. A VAPT audit provides a point-in-time assessment of identified vulnerabilities and security weaknesses. New threats, software updates, configuration changes, and emerging attack techniques can introduce additional risks after an assessment has been completed.

3. What happens if critical vulnerabilities are found during a CERT-In VAPT assessment?

Critical vulnerabilities are generally communicated to the organisation as soon as they are validated rather than waiting for the final report. This enables immediate remediation and reduces the risk of exploitation during or after the assessment period.

4. Is a source code review mandatory in every CERT-In VAPT engagement?

No. Source code review is one of several recognised assessment activities and is generally performed when required by the engagement scope, application risk profile, regulatory expectations, or customer requirements.

Jay Thakker
Jay is cybersecurity professional with over 10 years of experience in Application Security, specializing in the design and implementation of Breach and Attack Simulation (BAS) programs to proactively assess and strengthen organizational defenses against evolving cyber threats. Possesses strong expertise in Threat Hunting, leveraging advanced analytical techniques to identify, investigate, and neutralize emerging and stealthy adversary activity before impact.

Report an Incident

Report an Incident - Blog

free consultation

Our team of expert is available 24x7 to help any organization experiencing an active breach.

More Topics

crossmenuchevron-down
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram