Structuring Accountability: CERT-In Introduces Cybersecurity Guidelines
Author: Corporate Practice Team
CERT-In issues Comprehensive Cyber Security Audit Policy Guidelines (July 25, 2025) mandating standardized annual third-party audits and extensive security testing.
The Indian Computer Emergency Response Team (“CERT-In”), on July 25, 2025, has released the Comprehensive Cyber Security Audit Policy Guidelines (“Guidelines”), introducing a standardized and mandatory audit framework aimed at strengthening cyber resilience across both public and private sector organizations. The Guidelines apply to all CERT-In empanelled auditing organizations as well as auditee entities, including government bodies, critical infrastructure providers, and businesses operating significant digital systems. The Guidelines mandate that all such entities undergo a third-party cybersecurity audit at least once annually, with provisions for additional audits in response to major system changes such as technology migration or configuration alterations. Audits must be risk-based, domain-specific, and align with the organization’s threat landscape and business context. Furthermore, organizations must conduct a comprehensive risk and vulnerability assessment, penetration testing, source code review, network and operational infrastructure audits, and cybersecurity testing for cloud and AI systems. Audit reports are required to be signed by CERT-In-approved personnel, and organizations must implement strict safeguards for data confidentiality, including encryption, access controls, and secure post-audit data disposal practices. The Guidelines also mandate the implementation of the “least privilege” principle, directing organizations to restrict employee access rights strictly to the minimum necessary for performing their duties, thereby reducing the risk of internal threats and unauthorized access. Failure to comply with the Guidelines may attract regulatory action ranging from formal warnings and suspension to de-empanelment or legal proceedings under the Information Technology Act, 2000.
Articles
Our areas of legal expertise tailored to meet diverse client needs.
EPFO introduces a simplified process for Aadhaar seeding and UAN corrections to reduce errors and ease compliance.
Read More →NDMA issues guidelines to protect gig and platform workers from extreme heat and unsafe working conditions.
Read More →Delhi allows shops and establishments (except liquor shops) to operate night shifts under strict employee welfare safeguards.
Read More →Himachal Pradesh allows women to work night shifts in factories and shops with mandatory safety measures.
Read More →Kerala proposes updates to Factories and CLRA Rules, expanding recognition, tests, and fee structures.
Read More →Maharashtra revises Child Labour Rules, minimum wages, and mandates PoSH audits at workplaces.
Read More →Recent HC rulings cover maternity leave, dowry conviction penalties, ESI coverage, gratuity, and wage recovery.
Read More →MCA replaces Form INC-22A with a web-based version (effective July 14, 2025) to streamline company verification and compliance.
Read More →SEBI releases a consultation paper proposing LODR changes to reduce burden on listed entities — includes QR/web-link reporting for debenture holders and timelines for financials.
Read More →RBI issues revised AIF investment directions (July 29, 2025), changing how evergreening is assessed and introducing new contribution/provisioning thresholds.
Read More →DCGI to push GMP compliance; revised Schedule M aligns India with global standards — large firms must comply immediately, smaller firms have extension until Dec 31, 2025.
Read More →Supreme Court reserved decision in Arun Muthuvel v. Union of India on whether pre-Act embryo-freezing cases are exempt from new age limits.
Read More →CERT-In issues Comprehensive Cyber Security Audit Policy Guidelines (July 25, 2025) mandating standardized annual third-party audits and extensive security testing.
Read More →