CERT-In Empanelment Explained: What to Actually Check Before You Hire a VAPT Vendor
If you've spent any time evaluating penetration testing vendors in India, you've seen the phrase "CERT-In empanelled" on nearly every homepage. It's become shorthand for "trustworthy," which is exactly why it's worth understanding precisely what it means — and what it doesn't — before it decides who you hire.
What CERT-In empanelment actually is
CERT-In (the Indian Computer Emergency Response Team, under the Ministry of Electronics and IT) maintains an official empanelment of security auditing organisations authorised to conduct information security audits, including VAPT, for government bodies and regulated entities. Getting empanelled means a firm has been evaluated on technical capability, methodology, and how it actually runs engagements — not just paperwork.
It matters for a specific, practical reason: government tenders, several RBI and SEBI regulatory requirements, and some sector-specific mandates require the auditor to be CERT-In empanelled, not just "good at pentesting." If your compliance obligation specifically names CERT-In empanelment, a vendor without it — however skilled — can't fulfil that requirement on paper, regardless of report quality.
Empanelment isn't one blanket credential — it's categories
This is the detail most pitches skip. CERT-In empanelment is split into categories covering different types of work — web/application testing, network infrastructure, mobile applications, industrial/OT environments, and compliance-focused audits, among others. A firm empanelled for one category isn't automatically qualified or authorised for another. A vendor with only a compliance-audit category empanelment, for instance, isn't the same as one empanelled for the technical VAPT categories your engagement actually needs.
When a vendor says "we're CERT-In empanelled," the useful follow-up question is: for which categories, and does that match what you're hiring them to do?
How to verify a claim in under five minutes
Empanelment status, categories, and validity periods are published by CERT-In and checkable directly — don't take a claim on a sales page at face value for a regulatory-driving decision. Ask for the vendor's empanelment number and cross-check it against CERT-In's own auditor list before signing anything where the empanelment is doing real compliance work.
Where "CERT-In aligned" fits
You'll also see vendors describe their methodology as "CERT-In aligned" rather than claiming empanelment outright — that's a meaningfully different claim, and an honest one when stated clearly. It means the testing approach, reporting structure, and severity classification follow CERT-In's published guidelines and are built to produce evidence a CERT-In-recognised audit would accept, without the firm itself holding the empanelment. For engagements where the regulatory requirement is "professional VAPT following recognised standards" rather than "must be conducted by an empanelled firm specifically," that distinction is often exactly what you need — and it's worth a vendor being upfront about which one they're offering.
Not sure whether your specific compliance obligation requires empanelment or just a rigorous, standards-aligned methodology? We'll help you figure out which one you actually need before you scope an engagement.
Talk to our team →