CERT-In Empanelment vs ISO 27001: What Indian RFPs Require
Quick Answer
ISO/IEC 27001 certifies your own information security management system. CERT-In empanelment is an Indian government designation held by firms approved to perform security audits. A buyer asking for a CERT-In empanelled auditor wants an audit report produced by one of those firms. Your ISO certificate does not produce that report, so the two are not interchangeable. By Mr. Sumeet Katariya, CEO, Accucia Softwares Pvt. Ltd.
A buyer asks for your ISO 27001 certificate and your CERT-In audit report.
Those are two different things. Vendors who assume the first covers the second can lose the deal at the compliance stage—sometimes before anyone has even read the technical proposal.
The Two Documents Side by Side
ISO/IEC 27001 is an international standard for information security management systems. The current edition is ISO/IEC 27001:2022. An accredited certification body assesses your organisation against the standard and, if the requirements are met, issues a certificate covering a defined scope.
CERT-In empanelment is different.
CERT-In, under the Ministry of Electronics and Information Technology, maintains a roster of organisations approved to conduct information security audits. Being empanelled does not certify the security of that firm's own software. It means the organisation is authorised to audit other organisations' systems.
So when an RFP asks for a CERT-In audit, it normally means your application needs to be audited by a CERT-In empanelled organisation. It does not mean your software company itself needs to be CERT-In empanelled.
ISO 27001
What it is: Certification of your information security management system.
Who issues it: An accredited certification body.
What it demonstrates: That documented information-security controls operate across a defined scope.
Typical buyers asking for it: Enterprise buyers, offshore clients, insurers and regulated organisations.
Timeline: Stage 1 and Stage 2 audits followed by surveillance within the three-year certification cycle.
CERT-In Empanelment / Audit
What it is: CERT-In empanelment identifies organisations approved to conduct information-security audits.
What the software vendor needs: When an RFP requires a CERT-In audit, the application is audited by an organisation on the CERT-In roster.
Who typically asks for it: Government departments and BFSI organisations requiring security assessment by an approved auditor.
Timeline: Depends heavily on audit scope, findings and remediation cycles.
Who Asks for What, and When?
The two requirements often appear at different stages of procurement.
For government projects, CERT-In audit requirements can appear during pre-qualification. Government guidance requires applicable websites, portals and mobile applications to undergo security auditing before production hosting, with CERT-In guidance also calling for audits before hosting, annually and following major changes.
That matters because pre-qualification is generally a gate: you either satisfy the requirement or you do not.
ISO 27001 can appear differently. It may be part of technical evaluation, where certification strengthens the vendor's security evidence rather than serving as the same kind of application-level audit clearance.
In securities markets, the requirement is particularly important. Under SEBI's Cybersecurity and Cyber Resilience Framework, the auditing organisation must be CERT-In empanelled.
The RBI Angle for NBFCs and Banks
For NBFC buyers, outsourcing requirements also affect software vendors.
Under the RBI's 2025 outsourcing directions, the regulated entity remains responsible for outsourced activities. The vendor therefore inherits several practical obligations through its contract.
Depending on the applicable requirements and scope, these can include Indian data-storage requirements, audit rights covering the service provider and subcontractors, subcontractor controls, regulator inspection rights and rapid cyber-incident reporting.
There is also an important provision for certifications.
Paragraph 79 allows an NBFC, depending on its risk assessment, to rely on globally recognised third-party certifications provided by the service provider instead of conducting independent audits. But the decision remains with the regulated entity, and the certification needs to cover the relevant scope.
That last word matters: scope.
An ISO certificate covering only a registered office may not satisfy a buyer whose concern is the actual development and delivery environment.
What a Mid-Size Software Vendor Should Do
The sequence matters.
1. Scope your ISMS first.
Decide which legal entity, offices, delivery environments and client systems will fall inside the certification scope. A narrow but defensible scope is better than a broad scope you cannot evidence.
2. Close obvious control gaps.
Review access controls, secrets management, logging, retention, backups, joiner/leaver processes, patching and vendor management before the external assessment begins.
3. Complete the CERT-In empanelled audit where required.
For projects where the RFP requires it, have the application and relevant infrastructure assessed by the appropriate empanelled auditor and remediate the findings.
4. Pursue ISO 27001 certification.
Once the controls and evidence are established, proceed through Stage 1, Stage 2 and the subsequent surveillance cycle.
Starting by purchasing a certificate purely to satisfy one tender can leave you with a scope that does not cover what the buyer actually needs.
What to Write in an RFP Response
If you hold some credentials but not others, precision is better than vague compliance language.
State your position clearly.
If you are not CERT-In empanelled, explain that empanelment applies to organisations conducting security audits. State who will perform the required audit and confirm that your team will remediate findings within the delivery scope.
For ISO 27001, state the exact certification status: certified, not certified, or certification in progress. If you hold certification, attach the scope statement rather than only the certificate face.
Procurement teams can verify both certification and empanelment, so ambiguity usually creates more risk than it removes.
Cost and Timeline Expectations
Neither process has one universal published price.
For a CERT-In audit, the empanelled auditor prices the engagement commercially. Cost depends on factors such as the number of applications and APIs, environments, infrastructure scope and remediation or retesting rounds.
For ISO 27001, certification bodies determine their fees based on factors including scope, audit days, headcount and number of sites.
The important budgeting lesson is simple:
Budget for remediation, not only the audit.
Unresolved findings and repeated testing can become a significant part of the actual cost.
Accucia's Position
At Accucia, where a CERT-In empanelled audit is required, the client commissions the audit and we work directly with the appointed auditor. We respond to findings and implement required remediation within the application being delivered.
We do not currently hold CERT-In empanelment, and we do not represent ourselves as doing so.
For ISO 27001, Accucia is implementing an information security management system. An auditor has been appointed, with certification targeted for Q1 2027. ISO 9001 certification is also in progress and is not currently held.
For regulated projects, we would rather state exactly which requirements we can satisfy today than discover a compliance mismatch after a contract is signed.
Frequently Asked Questions
Is ISO 27001 the same as CERT-In empanelment?
No. ISO/IEC 27001 certifies an organisation's information security management system. CERT-In empanelment identifies organisations approved to conduct security audits.
Who pays for a CERT-In empanelled audit?
CERT-In itself is not a party to the commercial contract. The customer directly contracts the auditor; in practice, the client or regulated entity commissions the audit while the software vendor works through the resulting requirements and findings.
Does ISO 27001 satisfy an RBI-regulated entity's audit requirements?
It can in some circumstances. The RBI's 2025 NBFC outsourcing directions allow reliance on globally recognised third-party certifications instead of independent audits based on the NBFC's risk assessment. The decision remains with the regulated entity.
How often does a government website need a security audit?
The source guide states that CERT-In guidance requires applications and websites to be audited before hosting, at least annually, and after major changes.
What should you write if you hold neither credential?
State the exact position. Explain your CERT-In audit arrangement, accurately describe your ISO certification status, and provide target dates only where they genuinely exist. Procurement teams verify these claims.
Make Your Next RFP Compliance-Ready.