CERT-In Readiness Checklist

The CERT-In Readiness Checklist

and  |  Edited : August 24, 2026

Most teams already have the security controls CERT-In expects — the real gap is proof. This six-pillar checklist helps you find out whether you have audit-ready evidence or just working controls, and shows you exactly where to focus first.

Reading Time: 3 minutes

On 10 June 2026, CERT-In released new cybersecurity guidelines for OEMs and technology providers — a category that includes SaaS, cloud, and platform companies, not just hardware manufacturers. This checklist breaks the guideline into six practical pillars so any team can self-assess where they stand, before a regulator or a customer’s security team asks first.

How to Use This Checklist

Work through each pillar and check off what your organization already has documented and ready to show. This isn’t about whether the underlying control exists — most teams already have solid security practices. It’s about whether you can prove it: dated records, consolidated evidence, and a package you could hand to an auditor or a customer’s security team without a scramble.

CERT-In Checklist

If most boxes in a pillar are checked, that pillar is likely in good shape technically — the remaining work is usually consolidation, not new controls. If a pillar has several unchecked boxes, that’s where to start.

The Six-Pillar Checklist

1. Continuous Assessment & Runtime Protection

☐  Dated penetration-test, SCA and SAST reports covering the full in-scope environment
☐  Runtime monitoring and alerting logs with investigation and closure timestamps
☐  A documented process for tracking findings from detection through to closure

2. AI Risk & Software Inventories

☐  A four-factor AI risk assessment (data sensitivity, autonomy, connectivity, blast radius) for every AI-enabled service
☐  A consolidated SBOM covering products, APIs and third-party dependencies
☐  An inventory of exposed services, endpoints and cryptography in use

SBOM 2 1
Centralized visibility into SBOMs, findings, and components

3. Vulnerability Disclosure & Patching

☐  A formal external vulnerability-disclosure procedure
☐  A zero-day / active-exploitation response playbook
☐  Patch timelines mapped explicitly to CERT-In’s indicative windows
☐  An evidence chain linking each material finding to mitigation, patch and verification

4. Secure Development & Release Validation

☐  A documented Secure Development Lifecycle (architecture review, secure coding, threat modelling)
☐  Release-level evidence: scope, test results, approvals, exceptions, deployment record
☐  A periodically signed SDL evidence package

SBOM 4 4
Comparing software inventories to track component changes

5. Identity, Credentials & Privileged Access

☐  Documented access-control policy (least privilege, role-based access)
☐  Credential rotation and privileged-session records
☐  Scheduled access reviews and credential-hygiene checks

6. Incident Response, Reporting & Assurance

☐  A formal incident-response plan covering detection through post-incident review
☐  A tested, timed six-hour reporting workflow
☐  The five Section 7 deliverables: security-posture assessment, remediation action plan, management commitment, continuous assurance report, SDL compliance evidence

SBOM datasheet download

Reading Your Results

If your results look like… Suggested next step

Mostly checked across all six pillars

You’re in strong shape. Focus on consolidating evidence into audit-ready packages.

Checked in some pillars, gaps in others

Prioritize the pillars with the most unchecked boxes — that’s usually where documentation, not new controls, is needed.

Few boxes checked overall

Start with Pillar 1 (continuous assessment) and Pillar 6 (incident response) — they underpin evidence for the other four.

Want Help Closing the Gaps?

AccuKnox works with SaaS and technology providers on exactly this: turning working security controls into audit-ready evidence for CERT-In and other regulatory frameworks. If you’d like a second set of eyes on your results, reach out.

Talk to AccuKnox: [email protected]

This checklist is an educational self-assessment tool. It does not constitute CERT-In certification, legal advice, or a guarantee of regulatory compliance.

Ready For A Personalized Security Assessment?

“Choosing AccuKnox was driven by opensource KubeArmor’s novel use of eBPF and LSM technologies, delivering runtime security”

idt

Golan Ben-Oni

Chief Information Officer

“At Prudent, we advocate for a comprehensive end-to-end methodology in application and cloud security. AccuKnox excelled in all areas in our in depth evaluation.”

prudent

Manoj Kern

CIO

“Tible is committed to delivering comprehensive security, compliance, and governance for all of its stakeholders.”

tible

Merijn Boom

Managing Director

×