How to Check an Auditor Is Really CERT-In Empanelled
Empanelment is claimed more often than it is checked. The register is a public PDF, it takes two minutes to search, and it carries more about each firm than the claim itself, including how many audits they say they ran last year.
Many Indian security firms describe themselves as CERT-In empanelled. The claim is checkable: the Indian Computer Emergency Response Team publishes the list, and that list settles it.
Here is how to check, and what else the register tells you once you have it open.
Where the list lives
CERT-In publishes Empanelled Information Security Auditing
Organisations as a single PDF at
cert-in.org.in/PDF/Empanel_org.pdf. The document describes itself as
the "up-to-date valid list", updated "as soon as there is any change in it".
It supersedes any list a vendor, a directory or an article gives you.
The edition retrieved on 16 August 2026 runs to 995 pages and numbers 236 organisations. The "over 150 firms" figure is out of date.
Checking a specific firm, in about two minutes
- Open the PDF. At around 6 MB, it takes a moment to load.
- Search for the firm's registered legal name, not its trading name. Entries appear as "M/s <Legal Name>", so a firm you know as one word may be listed as a Private Limited or LLP.
- Check the entry carries an address, a contact person and an email. Every listing does.
If the firm is not in the current PDF, it is not currently empanelled, whatever a certificate on their website shows. Empanelment can lapse.
The part almost nobody reads
After the roster, the same document carries a section titled Snapshot of skills and competence of CERT-In empanelled organisations. Each firm completes a standard disclosure, and two of its fields are far more useful to a buyer than the empanelment itself:
- "Capability to audit, category wise": the kinds of audit the firm states it can perform.
- "Number of audits in last 12 months, category-wise": how much of each kind it says it actually did.
That second field is the closest thing to a public track record that exists in this market. If a firm lists a category and reports no audits in it over twelve months, ask why. Ask too when the numbers are concentrated in one category and you are buying a different one.
These figures are self-declared.
What empanelment does and does not settle
Empanelment is a qualifying status. Several Indian regulatory instruments name a CERT-In empanelled auditor directly, so for those engagements it is a condition of the work being accepted: an unempanelled firm's report, however good, does not discharge the obligation.
It does not tell you which of the 236 organisations should do your work. Every firm on the list clears the same bar. They differ in the questions the register cannot answer: methodology, who actually performs the testing, what the report contains, and whether retesting is included.
Three ways the claim goes wrong
- Lapsed. A firm was empanelled and is not now. The website badge outlives the status, and only the current PDF shows it.
- A different entity. A group has several registered companies and the empanelled one is not the one on your contract. Check the legal name on the engagement letter against the legal name on the list.
- A partner's empanelment. The firm is subcontracting to an empanelled organisation. That can be legitimate as long as it is stated up front. The entity signing the report is the one that has to be listed.
Check before you shortlist
Checking the register is the cheapest step in the whole procurement, and the only one you can complete without speaking to anybody. Do it before the demo, not after the contract.
Security Brigade InfoSec Pvt. Ltd. appears at entry 177 in the edition retrieved on 16 August 2026.
About the author
Abhinav A
Lead — VAPT & Security Assessments
Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR and telecom.
Continue reading
All articles →VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors, and each of them wants something slightly different.
Which Indian Regulators Require Security Testing
Which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.