A clear, no-jargon breakdown of what CERT-In empanelled audits actually cost in India — by audit type, sector, and organisation size — plus the exact steps to reach Safe-to-Host status.
India's threat landscape has shifted fast. Ransomware, credential-stuffing and supply-chain attacks now target mid-sized businesses as often as large enterprises, and regulators have responded by tightening the rules around who must prove their systems are secure.
CERT-In the Indian Computer Emergency Response Team, operating under the Ministry of Electronics and Information Technology (MeitY) is the national authority on this. It doesn't run a helpdesk you call for a badge; it sets the rules, empanels the auditors, and receives the incident reports.
The question most founders and CISOs actually ask us isn't "what is CERT-In" it's "what will this cost, and how long will it take." This page answers both, using real pricing bands from audits we run across banking, insurance, healthcare and general IT.
Get a scoping call and a written quote within 24 hours no obligation, no generic PDF brochure.
Request PricingThe single biggest misconception we correct on every first call: CERT-In does not issue a certificate directly to your business. It governs three distinct actions instead.
CERT-In vets and licenses private cybersecurity firms as "empanelled auditors" — the only entities authorised to test systems on its behalf.
You hire one of these empanelled firms to test your infrastructure. Once you pass, they issue a report commonly known as a Safe-to-Host certificate.
Under the 2022 directions, specified categories of incidents must be reported to CERT-In within 6 hours of detection — regardless of severity.
A handful of sectors carry a hard regulatory mandate. Everyone else usually needs it because a partner, investor or enterprise customer asks for proof.
RBI-regulated entities must run periodic VAPT and IS audits as a licensing condition.
Apps and hospitals on the ABDM network need ABDM-specific VAPT before go-live.
IRDAI mandates security assessments for insurers, brokers and policy-servicing portals.
Any platform storing customer or government data typically needs a Safe-to-Host report to close enterprise deals.
Every audit we run does double duty: it satisfies the regulator on file, and it closes the actual gaps that lead to breaches. Clients who stay current on audits report far fewer repeat findings year over year.
There is no fixed government fee. What you pay depends on the regulator, your data sensitivity, and the size of the environment being tested. These are our current bands, all-inclusive.
Standard vulnerability assessment & penetration test for web, mobile or network assets.
Assessment aligned to Ayushman Bharat Digital Mission requirements for health-tech platforms.
Security testing scoped to IRDAI's information and cyber security guidelines for insurers.
Penetration testing scoped to RBI cyber security framework requirements for banks and NBFCs.
Full IS audit covering policy, access controls, infrastructure and application-layer review.
IT General Controls review for change management, access provisioning and backup governance.
Environments holding PII, card data or health records require deeper testing than a marketing site, which raises effort and cost.
A single application audit is cheaper than a full network, Active Directory and cloud-configuration review across every asset.
Clean documentation and consistent configurations pass faster. Ad-hoc environments need extra remediation cycles, which adds cost.
They solve different problems and most regulated businesses in India eventually need both.
| Metric | CERT-In Compliance | ISO 27001 |
|---|---|---|
| Primary focus | Government oversight & incident response inside India | Global information security management framework |
| Mandate status | Mandatory for banks, insurers, health-tech & critical infra | Voluntary, but often required by enterprise buyers |
| Governing body | Ministry of Electronics & IT (MeitY) | International Organization for Standardization |
| Output | Safe-to-Host report / audit certificate | ISO 27001 certification (3-year cycle) |
| Renewal cycle | Typically annual, or after major changes | Annual surveillance, full recertification every 3 years |
Five stages, run in order — each one has to close before the next starts.
We map every domain, server, API and data store in play, and agree the boundary of what's being tested with you in writing.
Your engagement is matched to the right specialist — banking, healthcare, insurance or general IT — from our CERT-In empanelled bench.
Vulnerability scanning, manual penetration testing and configuration review, executed against the agreed scope.
Your team fixes flagged issues with our guidance; we prioritise by exploitability so the critical items get closed first.
We re-test the fixed items and issue your Safe-to-Host report once every finding is verifiably closed.
Real testing against real attack paths, not a checkbox review.
Closing findings early prevents the costlier fallout of an actual attack.
Stay current with MeitY, RBI, IRDAI and ABDM expectations at once.
A Safe-to-Host report is often the difference in enterprise procurement.
Every report ranks findings so your team knows exactly what to fix first.
We track your audit cycle so nothing lapses silently.
No. CERT-In itself doesn't charge a certification fee — the cost you pay is to the empanelled auditing firm that performs the assessment and issues your Safe-to-Host report.
Most regulated entities re-audit annually, or immediately after a significant change to infrastructure, application architecture, or a security incident.
CERT-In is India-specific and mandatory for certain sectors; ISO 27001 is a voluntary, internationally recognised management-system certification. Many businesses hold both.
It confirms the tested systems were free of the vulnerabilities identified during the assessment at the time of the re-audit, scoped to whatever assets were included in the engagement.
Yes — our smallest engagements start around ₹25,000 for a focused VAPT on a single web or mobile application.
A focused VAPT typically takes 1–2 weeks. Full IS or ITGC audits across larger environments can take 3–6 weeks depending on scope and how quickly findings are remediated.
One team across every audit you'll ever need, so you're not juggling separate vendors for VAPT, IS and ITGC.
CERT-In compliance in India isn't a single fixed-price product — it's a range that depends on your sector, the sensitivity of your data, and how much of your environment is in scope. Focused audits start around ₹25,000; full-scale IS or ITGC engagements across larger enterprises can run into several lakhs.
Treat it as an investment rather than an expense: the cost of a breach, and the enterprise deals lost without a Safe-to-Host report, are usually far higher than the audit itself.
Speak With Our Audit Experts →Fill out the form below and our team will contact you shortly.
No spam, no auto-dialler. A real auditor reviews your scope before we ever call you.