Compliance · Indian Regulatory
CERT-In audit evidence, from an empanelled team.
SecurityBoat is CERT-In empanelled. TriNetra is the platform our auditors and yours work from — every finding validated, every retest recorded, every report generated from live engagement data.
SQL injection in legacy reporting export
payments-service · reported by PTaaS engagement PT-2026-182
Retest queued the moment the fix landed — the loop that proves the fix held.Retest SLA · 3d
The regulation
What CERT-In expects of you.
The Indian Computer Emergency Response Team's April 2022 Directions are the umbrella every sectoral regulator on this site builds on: 6-hour incident reporting for specified categories of cyber incidents — data breaches, unauthorized access, DDoS, ransomware, and more — measured from detection, not confirmation; 180-day log retention for ICT systems, stored within Indian jurisdiction; synchronized time sources tied to Indian time references (NIC/NPL) rather than arbitrary NTP servers; and CERT-In empanelment as a hard gate for any firm conducting a "CERT-In audit" — a report from a non-empanelled firm doesn't satisfy the requirement, regardless of quality. That's a genuine scarcity constraint: only a small fraction of India's security vendors hold current empanelment, and between audit cycles attack surfaces don't stand still — subdomains get spun up, credentials leak onto paste sites, a vendor gets breached and inherits access to your environment.
How TriNetra maps to it
One platform. The whole audit trail.
| TriNetra module | Evidence produced |
|---|---|
| PTaaS | CERT-In-scoped engagements delivered by an empanelled team — the Coverage tab tracks methodology directly against CERT-In's baseline control categories (Cyber Security Management, Protection, Detection, Response, Recovery, Improvement), the same mechanism used for OWASP WSTG coverage on other engagements. |
| PTaaS | Proof that findings were fixed, not just found — the enforced remediation-retest loop: you mark a fix ready, the tester confirms or sends it back, all on an append-only history a reviewer can walk end to end. |
| Attack Surface Management | Continuous surveillance between audits — monitored targets, discovered subdomains, and exposed assets tracked on a recurring schedule rather than a point-in-time scan, closing exactly the drift gap a once-a-year audit leaves open. |
| Continuous Controls Validation | Control test history logged against CERT-In's 180-day retention windows, with a single passing control mapped simultaneously across CERT-In's baseline and whichever sectoral framework — RBI, SEBI, IRDAI — also applies. Findings, severity breakdown, and a methodology checklist auto-aggregate into a CERT-In-aligned report through the same pipeline used for RBI, ISO 27001, and SOC 2. |
| Trust Center | Sharing audit artifacts with stakeholders — reports filed under Pentest Reports in a governed document library; access granted through an approval workflow, every view logged. |
Keep evidence current between audits with Continuous Controls Validation.
On the platform
Scoped audits, moving on visible rails.
Every CERT-In-scoped engagement runs as a live object — state, assigned team, and findings count visible — not a PDF that arrives six weeks later.
Pentest Engagements
Total 20Active 14Completed 6Why SecurityBoat
The empanelment is ours. The evidence is yours.
CERT-In empanelment means our audit work meets the bar India's national CERT sets for its own ecosystem. Add CREST membership, ISO 27001, ISO 9001, and SOC 2 Type 2, and you get an audit partner whose own house passes the checks it runs on yours — delivering through a platform instead of an inbox full of PDFs.
Ready when you are
Book your CERT-In audit on a platform.
Scope it once, watch findings land in real time, retest to closure, submit an approved report. That's the whole engagement.
