Skip to main content
CERT-In Empanelled Since 2008

Security services
that find what scanners miss.

Every engagement powered by B-52 — our AI-powered pentesting and red-teaming platform — backed by three-layer expert review.

Testing and response services

Web Application Penetration Testing

Deep manual testing of business logic, auth, API, and OWASP ASVS L2/L3 with AI-validated coverage.

Vulnerability Assessment & Penetration Testing

Comprehensive security testing to identify and exploit vulnerabilities

Mobile Application Security Testing

MASVS-aligned iOS and Android binary analysis, reverse engineering, and mobile-specific vulnerability testing.

Network Penetration Testing

Internal and external network assessments with infrastructure hardening guidance, incl. Active Directory + assumed-breach.

API Security Testing

REST, GraphQL, gRPC, WebSocket - OWASP API Top 10 (2023) with deep business logic analysis.

Cloud Security Assessment

AWS, Azure, GCP security assessments with CIS benchmarks + IAM graph analysis and compliance mapping.

Secure Code Review

Manual and AI-assisted source code analysis with technology-specific remediation guidance. SAST + SCA included.

Red Team Assessment

Full adversary simulation - OSINT, social engineering, exploitation, lateral movement. MITRE ATT&CK aligned.

AI-Resilient VAPT

B-52 powered VAPT positioned against the SEBI AI advisory. AI-augmented attacker + AI-system-defender tracks.

OT/SCADA Security

Expert OT penetration testing & industrial security assessments for critical infrastructure.

Ransomware Response

Ransomware attack?

Breach and Attack Simulation

Validate your security controls with human-led breach and attack simulation.

AI Security Testing

AI security testing for LLMs, agentic pipelines and RAG systems.

Incident Response

24/7 cyber incident response and digital forensics by CERT-In empanelled experts.

Configuration and Hardening Review

Server hardening, firewall rule base, network architecture and access control, reviewed against CERT-In benchmarks and CIS baselines by an empanelled auditor.

DevSecOps and CI/CD Security

Security testing triggered from your pipeline, and review of the pipeline itself: IaC, runners, secrets, image signing. Findings arrive as issues, not a PDF.

Microsoft 365 Red Team & Identity Attack-Path Assessment

Adversary simulation against your Microsoft 365 tenant: device-code phishing, OAuth token theft, rogue device registration, Graph-based exfiltration.

RASP Security Assessment

Independent assessment of mobile application protections: RASP, obfuscation, anti-tamper, root and jailbreak detection, tested on the APK and IPA you publish. CERT-In empanelled since 2008.

Where we write about this in more depth

VAPT India — a library on how penetration tests are scoped and priced, what a report should contain, and which Indian regulators require testing. Red Team India — on adversary simulation — how engagements are scoped, what the report says about your detection, and where Indian regulators ask for it. Security Certification India — on who actually issues an ISO 27001 certificate, why the firm that prepares you cannot be the firm that certifies you, and what "SOC 2 certified" means when no such certificate exists. PCI DSS India — on who produces which artefact in a PCI DSS engagement, what Requirement 11 asks of testing, and where the Indian regulators sit alongside the standard.

Compliance

Audit-ready reporting for every framework

As a CERT-In empanelled firm since 2008, our reports are written for the submission they are going into.

MAS TRM Compliance — Technology Risk Management Audit

MAS Technology Risk Management compliance and audit services. Meet Singapore TRM guidelines with CERT-In empanelled assessments and gap analysis.

NPCI Compliance — UPI, BBPS, RuPay Audit Services

NPCI compliance audit for payment ecosystem participants. PSP, TPAP and BBPS security assessments by CERT-In empanelled auditors.

SOC 2 Compliance

Get SOC 2 Type 2 attestation with automated compliance platform. Gap analysis, continuous monitoring & audit support for Indian SaaS companies.

NSE Trading Member VAPT

NSE VAPT submission for trading members under SEBI CSCRF. CERT-In empanelled auditor since 2008.

HIPAA Compliance

Expert HIPAA compliance services for Privacy Rule, Security Rule & Business Associates. Get comprehensive risk assessment & technical safeguards audit today.

PCI DSS Compliance

0 compliance with CERT-In empanelled, QSA-ready assessments. End-to-end payment flow testing and gap analysis.

SEBI CSCRF Compliance

SEBI CSCRF compliance services for stock brokers, AMCs, mutual funds, and MIIs. CERT-In empanelled auditor.

Compliance-Focused Vendor Risk Assessment

Expert vendor risk assessment & TPRM audit for RBI, SEBI, NPCI compliance. Platform + service + hybrid options.

UIDAI AUA-KUA Audit (Aadhaar Compliance)

CERT-In empanelled UIDAI AUA/KUA audit for Aadhaar compliance. eKYC, Sub-AUA, Sub-KUA audits with full checklist validation.

System Audit Report (SAR) for Data Localization

Expert SAR audit for RBI data localisation compliance. PA-PG, PPI, BBPOU, UPI TPAP & CDSL system audits by CERT-In empanelled auditors.

ISO 27001 Consulting

ISMS implementation, gap assessment & audit support. CERT-In empanelled.

IRDAI Cybersecurity Compliance

IRDAI Information and Cyber Security Guidelines, 2026 compliance for insurers, brokers and TPAs. CERT-In empanelled ISNP and IS audits, scoped to your entity.

GDPR and DPDP Act Compliance

GDPR and DPDP Act 2023 compliance: technical assessments, data flow mapping and dual compliance for India-EU data transfers.

GDPR Compliance for Indian Businesses

GDPR compliance services for Indian businesses serving EU customers. Gap analysis, DPIA, DPO advisory, and audit-ready evidence.

DPDP Act Compliance for Indian Enterprises

DPDP Act 2023 compliance, gap analysis & audit readiness for Indian enterprises. DPDP Rules 2025 are live.

CERT-In Compliance

Empanelled by CERT-In since 2008. What empanelment means, which audits require it, how the process works, and how to verify an auditor's current status.

ATM and POS Security Audit

ATM security audit & POS security audit services. EMV, NFC, microATM & payment terminal testing.

NPCI / UPI Security and Compliance Audit

NPCI & UPI security audit for PSPs, TPAPs, sponsor banks, BBPS & RuPay. CERT-In empanelled.

SBI VSCC (Vendor Site Compliance Certificate) Audit

Get your SBI Vendor Site Compliance Certificate (VSCC) from a CERT-In empanelled auditor. Fast certification for SBI ePay and payment gateway merchant

RBI Payment Aggregator and Payment Gateway (PA-PG) Audit

RBI Payment Aggregator & Payment Gateway audit by CERT-In empanelled auditors. Annual system audit per 2025 PA Master Direction.

RBI Cybersecurity Framework Compliance

RBI cybersecurity compliance for banks, NBFCs, and cooperative banks. CERT-In empanelled auditor since 2008.

IEC 62443 Compliance

IEC 62443 compliance for industrial control systems: OT security assessments, gap analysis and certification preparation.

Not sure where to start?

Our security architects will assess your risk profile and recommend the right combination of services.

Talk to an Expert

Working out what to ask for? The types of security audit — what each one examines, and what the RBI Directions specify by clause.