AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Government cybersecurity · India

Audited before hosting. Secure after it?

Every government website and application in India has to be security-audited before it goes live, and audited again after. That rule is sound. The problem is what happens between audits: a certificate describes one version of one application on one day, and citizen portals keep changing. This page is about what the rules actually require, where portals really fail, and what to write into the tender so the next audit is not the first time anyone looks.

Reviewed 24 September 2026 · 14 sources cited

The short answer

Government cybersecurity in India runs on CERT-In’s rules. Every government website and application must be audited before hosting — the clearance comes from NIC, STQC or a CERT-In- or STQC-empanelled lab — and again at least annually and after every major change, with internal audits every six months. Incidents go to CERT-In within six hours. Write security into the tender, test between audits, and verify fixes before the empanelled auditor’s retest.

Why government

The rules are strict. The gaps are between the audits.

India’s rule for government technology is clear. The Minister of State for Electronics and IT told the Lok Sabha in August 2026 that all government websites and applications must be audited for cyber security before hosting and undergo regular audits thereafter, and that CERT-In had empanelled 237 auditing organisations to do it. CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines of July 2025 set the rhythm: a comprehensive audit at least once a year, and another after every major change.

The threat has grown faster than the audit calendar. CERT-In handled 29.44 lakh incidents in 2025, up from 15.92 lakh in 2023 — an 85% rise in two years. And the government incidents that became public were not exotic. In September 2025 a researcher found that changing one identifier in a request to the Income Tax e-filing portal, a service with more than 135 million registered users, exposed other taxpayers’ names, addresses, bank details and Aadhaar numbers. In January 2025 more than 90 gov.in links were found redirecting visitors to betting and investment scams. In June 2026 researchers reported more than 100 government and public-sector sites hijacked for gambling spam — invisible to the administrators, who were shown a normal page.

Each of those passed an audit at some point. None was caught by one, because each appeared between audits: a feature added, a component left unpatched, an account taken over. The certificate described the version that was audited; the attacker found the version that was live.

None of this argues against the audit regime. It argues for treating the empanelled audit as the checkpoint it is — and for testing, fixing and verifying continuously in between, so the checkpoint finds little.

What gets assumed

Six beliefs about government audits that the rules do not support.

Each is common in departments and among vendors. Each is contradicted by CERT-In’s or MeitY’s own documents.

What people assume“The audit certificate means the site is secure.”

What is actually trueIt means one version of the application passed an audit on the dates shown. CERT-In’s 2025 guidelines have the auditor record the application’s hash values and version numbers for exactly this reason: change the code and the certificate no longer describes what is live. That is why the same guidelines require another audit after every major change.

What people assume“Any security company can clear a site for hosting.”

What is actually trueGIGW 3.0 requires the application to be security-audited and an audit clearance certificate issued by NIC, STQC, an STQC-empanelled laboratory or a CERT-In-empanelled laboratory before it is hosted in production. A report from anyone else — including us — is useful preparation, but it is not the clearance.

What people assume“The empanelled firm can subcontract the actual testing.”

What is actually trueCERT-In’s guidelines say empanelled organisations should not engage in sub-letting or outsourcing of an audit assignment, and that the audit process must not be delegated. Ask the auditor who will do the work, and put the answer in the contract.

What people assume“Once the site is hosted, we are done until next year.”

What is actually trueCERT-In’s guidelines for government entities ask for an internal audit at least once every six months as well as a third-party audit at least once a year — plus a re-audit after every major change. The sites hijacked for gambling spam in 2026 showed their administrators a normal page; only an outside view would have noticed.

What people assume“The DPDP Act does not apply to government.”

What is actually trueOnly instrumentalities the Central Government notifies under section 17(2)(a) are exempt, and only for processing in the interests the section lists. Other departments, PSUs and municipal bodies are Data Fiduciaries. Section 7(b) lets them process personal data for subsidies, benefits and services without consent — but not without security safeguards or breach notice.

What people assume“The vendor who built it is responsible for its security.”

What is actually trueCERT-In’s guidelines for government entities put it on the department: contracts must carry a right to audit and incident-reporting terms, and the department should obtain the vendor’s audit report and a software bill of materials. The risk stays with the office that owns the service.

Evidence

The numbers behind the audit regime

Indian figures from CERT-In and MeitY, global public-sector patterns from Verizon. Each figure is linked in the sources.

29.44 lakh Cyber incidents handled by CERT-In in 2025 [5]
+85% Rise in incidents handled from 2023 (15.92 lakh) to 2025, as MeitY told the Lok Sabha [4]
237 CERT-In-empanelled auditing organisations, as of August 2026 [4]
40% Of public-sector breaches with a known way in began with an exploited vulnerability, in Verizon’s 2026 data [13]
44% Of public-administration breaches involved internal actors — errors and misuse as well as malice [13]
35% Of public-administration breaches were attributed to state-affiliated actors [13]

Verizon’s figures describe public-administration breaches in its global dataset, not Indian ones; the pattern — exploited vulnerabilities and insiders ahead of anything exotic — matches the Indian cases on this page.

Real patterns

Four ways citizen services have actually failed

Each from a reported Indian case in 2025–26. None required anything more than an ordinary flaw left in place.

01

One changed number, another citizen’s record

  1. Way inA logged-in request to the Income Tax e-filing portal that trusted the PAN supplied in it.
  2. ThenSwapping the PAN returned another taxpayer’s name, address, bank details and Aadhaar number.
  3. CostA service used by more than 135 million people exposed to anyone with an account, until a researcher reported it and it was fixed.

What we test: Authorisation on every request, not only at login — logged in as two citizens, trying each other’s identifiers. See web application testing.

02

The site that sends visitors to a casino

  1. Way inAn unpatched component or a stolen administrator login on a departmental site.
  2. ThenPages rewritten or redirected to betting and investment scams, with cloaking that shows administrators the normal site.
  3. CostCitizens defrauded under a government domain, and a search ranking poisoned for months. More than 100 government and public-sector sites were reported hijacked this way in 2026.

What we test: The site as a visitor and a search engine see it, not as the administrator does — plus the CMS, its plugins and admin access.

03

Aadhaar in plain text, one service removed

  1. Way inA citizen app that brokers many departments’ services, each with its own back end.
  2. ThenLinked services stored sensitive identifiers — Aadhaar, EPFO account numbers — without protection.
  3. CostThe central app is only as strong as the weakest service it connects. MeitY acknowledged the UMANG findings in July 2026 and said fixes were under way.

What we test: The APIs between the citizen app and each department’s service, and how each stores what it receives. See API security testing.

04

The forgotten microsite

  1. Way inA campaign or event site hosted years ago on an old platform and never decommissioned.
  2. ThenIt still resolves under gov.in, still runs the old software, and nobody owns it.
  3. CostA trusted government domain available for phishing, defacement or scam redirects — with nobody watching it.

What we test: Discovery of everything that resolves under your domains, including what nobody remembers hosting.

The cycle, done properly

Audit before hosting — and everything around it

Built from CERT-In’s 2025 audit guidelines and its guidelines for government entities. The empanelled audit is one step; the others decide whether it finds anything.

  1. Before the tender

    Write security in

    • Secure-by-design requirements stated in the RFP, as the 2025 guidelines expect
    • Static code analysis by the developer or system integrator, stated as a deliverable
    • A software bill of materials delivered with the application
    • Audit scope that covers development, UAT and production, and third-party components
  2. Before the audit

    Leave nothing to find

    • An independent test of the staging build that will be audited
    • Fixes made and verified before the empanelled auditor arrives
    • A staging environment that matches production, since that is where the audit runs
    • Logging switched on and retained for 180 days in India
  3. The mandatory audit

    Clearance, recorded properly

    • Carried out by the empanelled auditor you appoint — who may not sub-let it
    • Hash values and version numbers of the audited build recorded in the certificate
    • Audit metadata filed with CERT-In by the auditor within five days
    • Findings closed, re-audited and confirmed in a closure report before hosting
  4. After hosting

    Keep it true

    • An internal audit at least every six months; a third-party audit at least yearly
    • A fresh audit after every major change, not only on the anniversary
    • Watching the live site from outside for redirects, defacement and new exposure
    • A six-hour CERT-In reporting drill, with the point of contact named

Next step

Make the empanelled audit a formality.

A 30-minute call with a practitioner who knows the CERT-In guidelines. No charge, and no obligation.

  • A pre-audit test of the staging build, so the mandatory audit finds little
  • Fix verification before your empanelled auditor retests
  • Testing between audits — after each major change, not only once a year
  • A plain statement, before any work starts, of what we cannot do: issue the clearance
Book the call We reply within 24 business hours.

For the RFP

Eight things to write into a tender for a government application

Each comes from CERT-In’s 2025 audit guidelines or its guidelines for government entities. Written in at the start, they cost little; bolted on after award, they are change requests.

  1. Secure-by-design requirements, stated up front

    CERT-In’s 2025 guidelines make them mandatory in RFPs and tenders. Name the standard the application is built against, and make it acceptance criteria rather than an aspiration.

  2. Static code analysis by the developer

    Require the system integrator to run and fix static analysis before handing over, and to share the results. The empanelled audit should not be the first time the code is examined.

  3. A software bill of materials with every release

    The government-entity guidelines ask departments to obtain one. Without it, nobody can say whether the next published vulnerability affects your portal.

  4. A right to audit, and incident-reporting terms

    The vendor must tell the department quickly enough for the department to meet its own six-hour CERT-In deadline. Write the vendor’s notice period in hours, not “promptly”.

  5. An audit scope that covers every environment

    Development, UAT and production, plus third-party components and integrations — as the 2025 guidelines require — so nothing ships from an environment nobody tested.

  6. Follow-up audits inside the original scope

    Budget the re-audit after fixes, and the audits after major changes, in the original contract. A closure report should be a deliverable, not an optional extra.

  7. Logs kept for 180 days, in India

    The CERT-In Directions require it of government organisations. Specify which logs, where they live and who can retrieve them during an incident.

  8. The named auditor does the work

    Empanelled auditors may not sub-let or outsource an audit. Ask for the team in the proposal and hold the contract to it.

Where SemperWise fits

Around the mandatory audit, not instead of it

Services are people doing the work; SemperWise One is the platform that keeps the evidence current between audits. Each row says which — and none of them is an audit clearance.

“The empanelled audit is in six weeks.”

Service

A pre-audit test of the staging build, fixes prioritised for your developer, and verification that they hold before the empanelled auditor arrives.

Web application testing

“The portal is mostly APIs and a mobile app.”

Service

Object-level authorisation and data exposure tested endpoint by endpoint — the flaw class behind the tax-portal exposure.

API security testing

“We change the site every month.”

Service

Testing after each major change, on a subscription, so the audit after a major change is not the first look.

Continuous testing

“We do not know every site under our domain.”

SemperWise One™

Continuous discovery of what resolves under your domains — forgotten microsites, exposed admin panels, new services — with an alert when something appears.

Attack surface management

“Our department has no CISO yet.”

Service

A named senior practitioner a few days a month: policy, the six-monthly internal audit, vendor contracts and the incident plan.

Virtual CISO

“CERT-In’s duties, in one place.”

Service

Six-hour reporting, 180-day logs and the point of contact, tracked as controls with owners and evidence — alongside GIGW and DPDP.

CERT-In compliance

“DPDP duties from May 2027.”

Service

Role determination, notices, rights handling and a breach playbook for a department processing citizens’ personal data.

DPDP compliance

“Staff keep clicking.”

Service

Awareness sessions built around the phishing and impersonation attempts government staff actually receive.

Security training

Terms

Government security terms, defined

GIGW 3.0
The Guidelines for Indian Government Websites and Apps, which include the requirement for a security audit clearance before hosting.
Audit clearance certificate
The certificate issued after a security audit that allows an application to be hosted in production — from NIC, STQC, or an STQC- or CERT-In-empanelled lab.
CERT-In-empanelled auditor
An auditing organisation on CERT-In’s approved list. It may not sub-let or outsource an audit.
STQC
Standardisation Testing and Quality Certification, the MeitY directorate that tests and certifies, and empanels laboratories.
Closure report
The report at the end of an audit confirming that the findings were remediated or closed.
Hash value
A fingerprint of the exact build that was audited, recorded so anyone can tell whether the live application is the one that was cleared.
SBOM
A software bill of materials: the list of components and versions inside an application, needed to know what a new vulnerability affects.
IDOR
Insecure direct object reference — an application trusting an identifier in a request instead of checking the user may see that record.
Cloaking
Showing search engines and visitors different content from what the site’s administrators see, used to hide hijacked pages.
CCMP
Cyber Crisis Management Plan — the documented response every State and department is expected to have, deployed and tested.
State CISO
The chief information security officer each State or UT is expected to empower, one of MeitY’s four foundational requirements.
GeM
The Government e-Marketplace, through which ministries and departments procure goods and services under Rule 149 of the General Financial Rules.

Questions

Government security — answered.

What buyers in this sector ask us before they commit to anything.

Is a CERT-In-empanelled auditor mandatory for government websites?

For the audit that clears an application for hosting, the auditor has to be one of the bodies the rules name. GIGW 3.0 requires a security audit and an audit clearance certificate from NIC, STQC, an STQC-empanelled laboratory or a CERT-In-empanelled laboratory before hosting in production, and CERT-In’s 2025 guidelines tell the website’s content owner to ensure the audit is done by a CERT-In-empanelled organisation. Internal audits and testing between audits need not be done by an empanelled firm. SemperWise is not empanelled; we prepare you for the mandatory audit and you appoint the auditor directly.

What does “audit before hosting” actually require?

An independent security audit of the application, usually on a staging environment that mirrors production, before it goes live. The auditor records the hash values and version numbers of the audited build in the certificate, files audit metadata with CERT-In within five days, and the findings are closed and confirmed before the clearance is relied on. The detail is in CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines of July 2025. The certificate covers that build only; the next major change needs a fresh audit.

How often must a government website or application be audited?

At least once a year and after every major change, under CERT-In’s 2025 audit guidelines — and CERT-In’s guidelines for government entities add an internal audit at least once every six months. In practice a busy portal changes more often than annually, so the “major change” trigger is the one that matters most. Testing between audits, after each significant release, keeps the formal audit from being the first time a change is examined — see continuous penetration testing.

Can SemperWise audit our government website?

Not for the purposes of the audit clearance. We are not CERT-In empanelled and not an STQC or NIC lab, so we cannot issue it, and CERT-In’s guidelines forbid empanelled auditors from sub-letting an audit, so we cannot do it under another firm’s name either. What we can do is everything around it: a pre-audit test of the staging build, fixing priorities for your developer, verification that fixes hold before the empanelled auditor retests, testing between audits, and keeping your evidence in order. We say this before any work begins.

Does the DPDP Act apply to government departments?

Yes, unless a department is an instrumentality the Central Government has notified under section 17(2)(a), and then only for processing in the interests that section lists. Other departments, PSUs and municipal bodies are Data Fiduciaries. Section 7(b) lets the State process personal data for subsidies, benefits, services, certificates and licences without consent, but the duties to keep reasonable security safeguards and to report a breach still apply from about 13 May 2027. See DPDP Act compliance.

What must a government department report to CERT-In, and how fast?

The April 2022 CERT-In Directions apply expressly to government organisations: listed incidents — including website defacement, intrusion, data breaches and leaks, and attacks on applications such as e-governance services — must be reported within six hours of noticing them. Departments must also keep logs of their ICT systems for 180 days within India and name a point of contact for CERT-In. Contracts should require vendors to notify the department fast enough for it to meet that six-hour deadline.

What should we write into an RFP for a secure government application?

At minimum: secure-by-design requirements, static code analysis by the developer, a software bill of materials with each release, a right to audit and incident-reporting terms with a notice period in hours, an audit scope that covers development, UAT and production plus third-party components, follow-up audits inside the original scope, 180-day log retention in India, and a requirement that the named empanelled auditor does the work itself. The section on tender clauses above explains each, with its source in CERT-In’s guidelines.

How would we know if our site had been hijacked for gambling spam?

Often you would not, from the inside — the 2026 campaigns used cloaking so administrators saw a normal page while search engines and visitors saw spam or redirects. Check what search engines have indexed under your domain, look for unfamiliar site-verification entries in your search-console accounts, review the web server’s files and redirect rules rather than the CMS view, and monitor the site from outside. Continuous external discovery of what resolves under your domains catches forgotten microsites before they are used.

Sources

Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. Comprehensive Cyber Security Audit Policy Guidelines, v1.0 — CERT-In, 25 July 2025
  2. Guidelines for Indian Government Websites and Apps (GIGW 3.0) — security guidelines — Government of India
  3. Guidelines on Information Security Practices for Government Entities — CERT-In
  4. India recorded 29 lakh cyber security incidents in 2025 (reporting a reply in the Lok Sabha) — TechObserver, 15 August 2026
  5. CERT-In backgrounder: incidents handled in 2025 — Press Information Bureau, January 2026
  6. Workshop on State cyber security: four foundational requirements — Press Information Bureau, 11 May 2026
  7. Security bug in India’s income tax portal exposed taxpayers’ sensitive data — TechCrunch, 7 October 2025
  8. Indian government websites are still redirecting users to scam sites — TechCrunch, 7 January 2025
  9. Over 100 Indian government websites hacked to push gambling — MediaNama, June 2026
  10. Researchers find security flaws in UMANG that exposed user data across government services — MediaNama, July 2026
  11. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  12. Digital Personal Data Protection Act, 2023 (sections 7 and 17) — MeitY
  13. 2026 Data Breach Investigations Report (public administration) — Verizon, 2026
  14. General Financial Rules 2017, Rule 149 — procurement through GeM — Department of Expenditure, 24 August 2020

All 17 industries we serve

Next step

Go into the empanelled audit with nothing left to find.

A 30-minute call, no charge. We agree what we test before your auditor does, how fixes are verified, and what evidence your department keeps — then send a written scope and a fixed price, with a retest included.