The cybersecurity landscape for MSMEs in India has fundamentally changed. With CERT-In's mandatory annual cybersecurity audit requirements now in effect, compliance is no longer optional—it's a business imperative.
Understanding India's cybersecurity authority and its implications for your business
CERT-In (Indian Computer Emergency Response Team), established in 2004, operates under the Ministry of Electronics and Information Technology, Government of India.
Its primary mandate is to improve the country's cybersecurity by issuing advisories, guidelines, and best practices. It coordinates responses to cybersecurity incidents, ensuring a robust national defense against cyber threats.
CERT-In plays a pivotal role in enhancing the security posture of organizations across India by establishing cybersecurity frameworks specifically designed for MSMEs.
As a CERT-In empanelled auditor, we ensure that your IT infrastructure complies with the highest security standards mandated by CERT-In.
Mandatory Framework Effective September 2025
The framework centers around 15 Elemental Cyber Defense Controls specifically designed for smaller businesses:
Establish and maintain an efficient asset management framework.
Safeguard networks and email systems against unauthorized access.
Safeguard end-user devices with security policies.
Implement secure configuration of hardware and software.
Reduce security vulnerabilities through systematic patching.
Ensure timely detection, reporting, and response to incidents.
Ensure only authorized users can access systems and data.
Implement encryption, backups, and secure storage practices.
Protect applications through secure coding and testing.
Ensure cloud environments follow strict security measures.
Maintain regular backups and test recovery processes.
Educate employees about threats and safe practices.
Regularly scan and remediate vulnerabilities.
Assess and secure third-party/vendor relationships.
Continuously monitor systems to detect anomalies.
Our comprehensive approach to ensuring your business meets all requirements
As a CERT-In empanelled auditor, we provide comprehensive security audits that adhere to the stringent guidelines set by CERT-In.
We help you navigate complex Indian regulations including PDPA, RBI, IT Act 2000, and PCI-DSS, safeguarding your data, infrastructure, and payments.
Our team provides continuous support to ensure your organization remains compliant and secure against evolving cyber threats.
Don't wait until it's too late. Our team of CERT-In empanelled experts is ready to guide you through the entire compliance process.
Fill out the form below and our CERT-In experts will contact you within 24 hours.
Everything you need to know about CERT-In MSME compliance
From September 2025, all MSMEs in India must undergo a mandatory annual cybersecurity audit by a CERT-In empanelled auditor. The audit evaluates organizations against 15 Elemental Cyber Defense Controls including asset management, patching, access control, incident response, and log retention.
All Micro, Small, and Medium Enterprises (MSMEs) that use IT infrastructure, store or process customer data, or operate digitally are required to comply, as per the MSME Ministry classification and IT Act Section 70B.
Non-compliance carries strict penalties:
– Financial fines up to ₹1 crore
– Criminal liability: up to 1 year
imprisonment
– Business risks: debarment from government
contracts
– Reputational damage and customer trust
loss
Organizations must report any cybersecurity incident — including data breaches, ransomware, unauthorized access, or major attacks — to CERT-In within 6 hours of detection. This is a legal requirement under Section 70B of the IT Act.
CERT-In mandates that MSMEs undergo a cybersecurity audit every year. The audit report must be submitted to CERT-In within 5 days of completion and renewed annually.
The complete compliance cycle usually takes
16–20 weeks, covering:
1. Gap assessment
2. Control implementation
3. Employee training & process integration
4. Final certification audit by a CERT-In empanelled auditor
As a VAPT provider, we assist MSMEs by:
– Conducting pre-audit readiness checks
– Performing
Vulnerability Assessments & Penetration Testing
– Helping implement the
15 mandated CERT-In controls
– Coordinating with CERT-In empanelled auditors
– Providing continuous compliance support
Beyond avoiding penalties, compliance offers:
– Customer trust & stronger reputation
– Competitive edge in security-conscious
markets
–
Eligibility for government & enterprise contracts
– Reduced cyber insurance premiums
– Business continuity through stronger
cyber resilience
Copyright 2025 Cyethack Solutions.