Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
August 3, 2025
No Result
View All Result
Concur News

Home » How CERT-In’s Updated Cybersecurity Guidelines Affect Compliance Standards

How CERT-In’s Updated Cybersecurity Guidelines Affect Compliance Standards

August 2, 2025
in India, News
Reading Time: 5 mins read
How CERT-In’s Updated Cybersecurity Guidelines Affect Compliance Standards
Share on LinkedinShare on Whatsapp

The Indian government has introduced official rules for conducting cybersecurity audits. CERT-In’s (Indian Computer Emergency Response Team) has published the Comprehensive Cyber Security Audit Policy Guidelines under the IT Act, 2000. The guidelines aim to make the audit process consistent across various types of organisations.

Although the rules explain the process clearly, some parts are still vague. These unclear rules leave companies confused, especially when they also have to follow other laws like the DPDP Act, 2023.

What Do the Guidelines Include?

1. Who Must Follow Them?

CERT-In’s rules apply to two groups:

Consent Foundation
  • Auditors officially approved (empanelled) by CERT-In.
  • Any organisation can check its cybersecurity—either because it must or because it chooses to.

This includes government bodies, telecom operators, banks, hospitals, and any business that handles sensitive or regulated data.

2. What Should the Audit Cover?

Audits must:

  • Check if an organisation is following cybersecurity rules.
  • Find security gaps or weak points.
  • Review areas like cloud systems, IoT (Internet of Things), apps, supply chains, and even physical security measures.

The guidelines recommend that organisations perform audits at least once a year or after major IT changes. However, they don’t explain what qualifies as a “major” change, leaving it open to interpretation.

3. Which Standards Must Be Followed?

Auditors need to follow global security standards such as:

  • ISO/IEC standards
  • OWASP (for application security)
  • OSSTMM
  • CSA’s Cloud Controls Matrix

They must also:

  • Use CERT-In’s advisories.
  • Apply risk scoring methods like CVSS and EPSS.
  • Keep the audit findings confidential.

4. What Happens After the Audit?

Companies must:

  • Fix any problems found in the audit.
  • Do follow-up reviews to confirm issues are resolved.

If an audit is poorly done or a company doesn’t take action, CERT-In may:

  • Take legal steps.
  • Remove the auditor from their approved list.

The Confusion Around Compliance

Although CERT-In names specific sectors, the rules are written in broad terms. This means any company dealing with user data or serving regulated industries could fall under these rules—even if not directly mentioned.

Also, there are no exemptions for small businesses. A small startup may be expected to meet the same standards as a national telecom provider. This creates a potential problem for businesses with limited resources or legal knowledge.

How the DPDP Act Adds Complexity

The DPDP Act, 2023 already requires businesses that handle personal data to take reasonable steps to prevent data leaks. One of its key points says:

“The Data Fiduciary shall protect personal data… by taking reasonable security safeguards to prevent personal data breach.”

This applies to all businesses, no matter their size.

For larger businesses classified as Significant Data Fiduciaries (SDFs), the law adds more duties:

  • Appoint an independent data auditor.
  • Conduct Data Protection Impact Assessments (DPIAs).
  • Carry out regular data audits.

CERT-In’s new guidelines also demand audits—but under a separate system. There’s no clarity on:

  • Whether a CERT-In audit will meet the DPDP Act’s audit requirements.
  • If breach reports filed with CERT-In count for DPDP compliance.
  • How to avoid doing the same audit twice under two laws.

Why These Questions Matter

The new CERT-In guidelines are important. They set a clear format for how companies should do cybersecurity audits. But they also create confusion if there’s no alignment with other laws.

For example:

  • How often should audits be done if no time frame is given?
  • What counts as a “major” change requiring a new audit?
  • Will businesses have to report the same cyber incident to multiple regulators?
  • Can CERT-In and DPDP audits be combined, or must they be separate?

Until regulators explain how these systems work together, companies may face double work, higher costs, and greater legal risks. These rules aim to strengthen India’s cybersecurity, but without better coordination between laws, they might create more problems for businesses.



Also read: State Cyber Unit Breach Raises Alarm Over Possible Inside Sabotage

Tags: Cyber securityData privacyData Protection

Related Posts

Nvidia Must Submit Security Evidence, Says Chinese Media
China

Nvidia Must Submit Security Evidence, Says Chinese Media

August 2, 2025
State Cyber Unit Breach Raises Alarm Over Possible Inside Sabotage
India

State Cyber Unit Breach Raises Alarm Over Possible Inside Sabotage

August 2, 2025
Digital Arrest Scam in Gujarat: Woman Doctor Cheated of ₹19.24 Crore
Africa

Digital Arrest Scam in Gujarat: Woman Doctor Cheated of ₹19.24 Crore

August 1, 2025
Hacker Breaches Customer Data at Max Financial’s Insurance Arm in India
India

Hacker Breaches Customer Data at Max Financial’s Insurance Arm in India

August 1, 2025

RECOMMENDED NEWS

Japan’s New AID Bill Sparks Controversy Over Privacy

AID Bill of Japan Sparks Controversy Over Privacy

4 months ago
Insider Threats: The Growing Cybersecurity Challenge for Corporate India

Insider Threats: The Growing Cybersecurity Challenge for Corporate India

3 weeks ago
Sentra Raises $50 Million to Enhance Data Security and AI Integration

Sentra Raises $50 Million to Enhance Data Security and AI Integration

3 months ago
Nigeria

Nigeria fines Meta $220 million for Facebook and WhatsApp data misuse

3 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent Cross-Border Cyber Breach Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital Digital India DPDP DPDPA DPDP Act Fines GDPR Hack Hacked Industry Interview Investigation Law Meity online services penalty Personal data Press Release Privacy RBI RTI Act Startek Tech giants Technology Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager