CERT-In Compliance: VAPT, SCA & SAST Reports
Indian regulated entities — fintech, banks, exchanges, payment aggregators, data processors — must meet CERT-In's 2022 Directions, 6-hour incident reporting, and annual VAPT requirements. TigerGate generates CERT-In-aligned VAPT, SCA, and SAST reports continuously, so your empanelled auditor review becomes a formality.
Who Needs CERT-In Compliance?
The CERT-In 2022 Directions (effective 28 June 2022) and related MeitY guidelines apply to:
- Service providers, intermediaries, data centers, and body corporates operating in India or serving Indian users.
- Banks and NBFCs under RBI's cybersecurity framework (Master Direction on Cyber Resilience).
- Securities market intermediaries under SEBI's Cybersecurity & Cyber Resilience Framework (CSCRF).
- Payment aggregators and payment gateways under RBI PA/PG framework.
- Crypto exchanges and VDA service providers explicitly named by the 2022 Directions.
- Any entity processing significant personal data under the Digital Personal Data Protection Act 2023 (DPDP Act).
CERT-In VAPT Reports
CERT-In empanelled auditors require Vulnerability Assessment and Penetration Testing (VAPT) reports in a specific format aligned to CERT-In's guidance for information security auditors. Required coverage:
- Network VAPT — external and internal network, firewall rules, segmentation.
- Application VAPT — web app and API testing against OWASP Top 10.
- Cloud infrastructure VAPT — AWS/Azure/GCP posture, IAM, data stores.
- Mobile VAPT — if the service exposes mobile apps.
- Thick-client / API VAPT — for backend integrations.
TigerGate automates the continuous portion of VAPT:
Continuous VAPT scanning
Network and application scanning runs continuously, with findings mapped to CERT-In severity classes and OWASP references.
CERT-In report format
Export VAPT reports in the exact format CERT-In empanelled auditors expect — executive summary, methodology, findings with CVSS v3.1 scores, remediation guidance, and retest status.
Retest & closure evidence
Automated retest after remediation. Closure evidence attached to each finding for auditor sign-off.
6-hour reporting support
For incident-grade findings (critical, exploitable), alerts route to your IR team in time to meet the 6-hour CERT-In reporting window.
Pair TigerGate's continuous VAPT with your CERT-In empanelled auditor's annual penetration test — automation handles the quarterly reassessments and continuous monitoring; humans do the deep business-logic testing. See automated API security testing.
CERT-In SCA & SAST Reports
CERT-In's secure application development guidelines (and RBI/SEBI equivalents) require Static Application Security Testing (SAST) and Software Composition Analysis (SCA) evidence per release. TigerGate generates both:
CERT-In SAST Report
Per-release static analysis report with:
- OWASP Top 10 and SANS CWE Top 25 mapping
- CVSS v3.1 severity scoring
- Repository, branch, commit, and PR traceability
- Remediation guidance per finding
- Auditor-ready PDF export
CERT-In SCA Report
Per-release dependency scan report with:
- Full dependency inventory (direct + transitive)
- CVE and GHSA mapping with CVSS v3.1
- License compliance findings
- SBOM in CycloneDX and SPDX format
- Reachability analysis to downgrade non-reachable CVEs
- Auditor-ready PDF export
Both reports export directly from TigerGate with your organization's branding and are accepted by CERT-In empanelled auditors across the major audit firms in India. See code security, SCA / SBOM, and the best SCA tools guide.
CERT-In 2022 Directions: Technical Coverage
Beyond VAPT and SCA/SAST, the 2022 Directions require specific technical capabilities. TigerGate maps to each:
- ICT system log retention (180 days) — eBPF runtime + cloud log validation ensures logs are complete and tamper-evident.
- Time synchronization to NIC NTP / NPL — automated check across all monitored systems.
- Incident reporting within 6 hours — critical findings routed to IR with pre-filled CERT-In incident template fields.
- Virtual asset / crypto-specific controls — hot wallet exposure, key-rotation evidence, and transaction monitoring hooks for crypto exchanges and VDA service providers.
RBI, SEBI, and MeitY Alignment
CERT-In doesn't operate alone — regulated entities also face sector-specific frameworks:
- RBI Master Direction on Cyber Resilience and Digital Payment Security Controls — banks, NBFCs, payment aggregators.
- SEBI CSCRF (Cybersecurity & Cyber Resilience Framework) — exchanges, brokers, mutual funds.
- IRDAI Information and Cybersecurity Guidelines — insurers.
- MeitY SIEM / SOC guidelines — government-adjacent cloud deployments.
TigerGate's compliance mappings include all four frameworks alongside CERT-In — one scan, multiple framework reports.
DPDP Act 2023 Readiness
The Digital Personal Data Protection Act 2023 brings GDPR-style data protection to India. TigerGate's DSPM (Data Security Posture Management) identifies personal data stores across your cloud estate, flags unencrypted or publicly accessible resources, and generates data processing evidence for DPDP compliance. See DSPM.
CERT-In FAQ
Automate CERT-In VAPT, SCA & SAST
Free tier. India-region hosting available. First CERT-In-aligned VAPT, SCA, and SAST reports inside the trial.