CERT-In Empanelment vs ISO 27001: What Indian RFPs Require

Founder and CEO, Accucia Softwares Pvt. Ltd.

Quick Answer

ISO/IEC 27001 certifies your own information security management system. CERT-In empanelment is an Indian government designation held by firms approved to perform security audits. A buyer asking for a CERT-In empanelled auditor wants an audit report produced by one of those firms. Your ISO certificate does not produce that report, so the two are not interchangeable. By Mr. Sumeet Katariya, CEO, Accucia Softwares Pvt. Ltd.

A buyer asks for your ISO 27001 certificate and your CERT-In audit report.

Those are two different things. Vendors who assume the first covers the second can lose the deal at the compliance stage—sometimes before anyone has even read the technical proposal.

The Two Documents Side by Side

ISO 27001 vs CERT-In audit comparison for Indian RFP compliance.
Understanding the difference between ISO 27001 certification and CERT-In audits for Indian RFPs.

ISO/IEC 27001 is an international standard for information security management systems. The current edition is ISO/IEC 27001:2022. An accredited certification body assesses your organisation against the standard and, if the requirements are met, issues a certificate covering a defined scope.

CERT-In empanelment is different.

CERT-In, under the Ministry of Electronics and Information Technology, maintains a roster of organisations approved to conduct information security audits. Being empanelled does not certify the security of that firm's own software. It means the organisation is authorised to audit other organisations' systems.

So when an RFP asks for a CERT-In audit, it normally means your application needs to be audited by a CERT-In empanelled organisation. It does not mean your software company itself needs to be CERT-In empanelled.

ISO 27001

What it is: Certification of your information security management system.

Who issues it: An accredited certification body.

What it demonstrates: That documented information-security controls operate across a defined scope.

Typical buyers asking for it: Enterprise buyers, offshore clients, insurers and regulated organisations.

Timeline: Stage 1 and Stage 2 audits followed by surveillance within the three-year certification cycle.

CERT-In Empanelment / Audit

What it is: CERT-In empanelment identifies organisations approved to conduct information-security audits.

What the software vendor needs: When an RFP requires a CERT-In audit, the application is audited by an organisation on the CERT-In roster.

Who typically asks for it: Government departments and BFSI organisations requiring security assessment by an approved auditor.

Timeline: Depends heavily on audit scope, findings and remediation cycles.

Who Asks for What, and When?

The two requirements often appear at different stages of procurement.

For government projects, CERT-In audit requirements can appear during pre-qualification. Government guidance requires applicable websites, portals and mobile applications to undergo security auditing before production hosting, with CERT-In guidance also calling for audits before hosting, annually and following major changes.

That matters because pre-qualification is generally a gate: you either satisfy the requirement or you do not.

ISO 27001 can appear differently. It may be part of technical evaluation, where certification strengthens the vendor's security evidence rather than serving as the same kind of application-level audit clearance.

In securities markets, the requirement is particularly important. Under SEBI's Cybersecurity and Cyber Resilience Framework, the auditing organisation must be CERT-In empanelled.

The RBI Angle for NBFCs and Banks

For NBFC buyers, outsourcing requirements also affect software vendors.

Under the RBI's 2025 outsourcing directions, the regulated entity remains responsible for outsourced activities. The vendor therefore inherits several practical obligations through its contract.

Depending on the applicable requirements and scope, these can include Indian data-storage requirements, audit rights covering the service provider and subcontractors, subcontractor controls, regulator inspection rights and rapid cyber-incident reporting.

There is also an important provision for certifications.

Paragraph 79 allows an NBFC, depending on its risk assessment, to rely on globally recognised third-party certifications provided by the service provider instead of conducting independent audits. But the decision remains with the regulated entity, and the certification needs to cover the relevant scope.

That last word matters: scope.

An ISO certificate covering only a registered office may not satisfy a buyer whose concern is the actual development and delivery environment.

What a Mid-Size Software Vendor Should Do

Four-step security compliance roadmap for mid-size software vendors.
A practical four-step compliance roadmap for software vendors preparing for CERT-In audits and ISO 27001 certification.

The sequence matters.

1. Scope your ISMS first.
Decide which legal entity, offices, delivery environments and client systems will fall inside the certification scope. A narrow but defensible scope is better than a broad scope you cannot evidence.

2. Close obvious control gaps.
Review access controls, secrets management, logging, retention, backups, joiner/leaver processes, patching and vendor management before the external assessment begins.

3. Complete the CERT-In empanelled audit where required.
For projects where the RFP requires it, have the application and relevant infrastructure assessed by the appropriate empanelled auditor and remediate the findings.

4. Pursue ISO 27001 certification.
Once the controls and evidence are established, proceed through Stage 1, Stage 2 and the subsequent surveillance cycle.

Starting by purchasing a certificate purely to satisfy one tender can leave you with a scope that does not cover what the buyer actually needs.

What to Write in an RFP Response

RFP response guidelines for clear CERT-In and ISO 27001 compliance disclosure.
Clear, accurate compliance language makes RFP responses stronger and easier to verify.

If you hold some credentials but not others, precision is better than vague compliance language.

State your position clearly.

If you are not CERT-In empanelled, explain that empanelment applies to organisations conducting security audits. State who will perform the required audit and confirm that your team will remediate findings within the delivery scope.

For ISO 27001, state the exact certification status: certified, not certified, or certification in progress. If you hold certification, attach the scope statement rather than only the certificate face.

Procurement teams can verify both certification and empanelment, so ambiguity usually creates more risk than it removes.

Cost and Timeline Expectations

Neither process has one universal published price.

For a CERT-In audit, the empanelled auditor prices the engagement commercially. Cost depends on factors such as the number of applications and APIs, environments, infrastructure scope and remediation or retesting rounds.

For ISO 27001, certification bodies determine their fees based on factors including scope, audit days, headcount and number of sites.

The important budgeting lesson is simple:

Budget for remediation, not only the audit.

Unresolved findings and repeated testing can become a significant part of the actual cost.

Accucia's Position

At Accucia, where a CERT-In empanelled audit is required, the client commissions the audit and we work directly with the appointed auditor. We respond to findings and implement required remediation within the application being delivered.

We do not currently hold CERT-In empanelment, and we do not represent ourselves as doing so.

For ISO 27001, Accucia is implementing an information security management system. An auditor has been appointed, with certification targeted for Q1 2027. ISO 9001 certification is also in progress and is not currently held.

For regulated projects, we would rather state exactly which requirements we can satisfy today than discover a compliance mismatch after a contract is signed.

Frequently Asked Questions

Is ISO 27001 the same as CERT-In empanelment?

No. ISO/IEC 27001 certifies an organisation's information security management system. CERT-In empanelment identifies organisations approved to conduct security audits.

Who pays for a CERT-In empanelled audit?

CERT-In itself is not a party to the commercial contract. The customer directly contracts the auditor; in practice, the client or regulated entity commissions the audit while the software vendor works through the resulting requirements and findings.

Does ISO 27001 satisfy an RBI-regulated entity's audit requirements?

It can in some circumstances. The RBI's 2025 NBFC outsourcing directions allow reliance on globally recognised third-party certifications instead of independent audits based on the NBFC's risk assessment. The decision remains with the regulated entity.

How often does a government website need a security audit?

The source guide states that CERT-In guidance requires applications and websites to be audited before hosting, at least annually, and after major changes.

What should you write if you hold neither credential?

State the exact position. Explain your CERT-In audit arrangement, accurately describe your ISO certification status, and provide target dates only where they genuinely exist. Procurement teams verify these claims.

Make Your Next RFP Compliance-Ready.

Reviewed & Approved by

Mr. Sumeet Katariya

Founder & CEO, Accucia Softwares Pvt. Ltd.

15+ Years IT & Automation Experience | Founder of ElevatorPlus & AdBanao

Chat With Us