
The CERT-In Readiness Checklist
Most teams already have the security controls CERT-In expects — the real gap is proof. This six-pillar checklist helps you find out whether you have audit-ready evidence or just working controls, and shows you exactly where to focus first.
Reading Time: 3 minutes
On 10 June 2026, CERT-In released new cybersecurity guidelines for OEMs and technology providers — a category that includes SaaS, cloud, and platform companies, not just hardware manufacturers. This checklist breaks the guideline into six practical pillars so any team can self-assess where they stand, before a regulator or a customer’s security team asks first.
How to Use This Checklist
Work through each pillar and check off what your organization already has documented and ready to show. This isn’t about whether the underlying control exists — most teams already have solid security practices. It’s about whether you can prove it: dated records, consolidated evidence, and a package you could hand to an auditor or a customer’s security team without a scramble.

If most boxes in a pillar are checked, that pillar is likely in good shape technically — the remaining work is usually consolidation, not new controls. If a pillar has several unchecked boxes, that’s where to start.
The Six-Pillar Checklist
1. Continuous Assessment & Runtime Protection
☐ Dated penetration-test, SCA and SAST reports covering the full in-scope environment
☐ Runtime monitoring and alerting logs with investigation and closure timestamps
☐ A documented process for tracking findings from detection through to closure
2. AI Risk & Software Inventories
☐ A four-factor AI risk assessment (data sensitivity, autonomy, connectivity, blast radius) for every AI-enabled service
☐ A consolidated SBOM covering products, APIs and third-party dependencies
☐ An inventory of exposed services, endpoints and cryptography in use

3. Vulnerability Disclosure & Patching
☐ A formal external vulnerability-disclosure procedure
☐ A zero-day / active-exploitation response playbook
☐ Patch timelines mapped explicitly to CERT-In’s indicative windows
☐ An evidence chain linking each material finding to mitigation, patch and verification
4. Secure Development & Release Validation
☐ A documented Secure Development Lifecycle (architecture review, secure coding, threat modelling)
☐ Release-level evidence: scope, test results, approvals, exceptions, deployment record
☐ A periodically signed SDL evidence package

5. Identity, Credentials & Privileged Access
☐ Documented access-control policy (least privilege, role-based access)
☐ Credential rotation and privileged-session records
☐ Scheduled access reviews and credential-hygiene checks
6. Incident Response, Reporting & Assurance
☐ A formal incident-response plan covering detection through post-incident review
☐ A tested, timed six-hour reporting workflow
☐ The five Section 7 deliverables: security-posture assessment, remediation action plan, management commitment, continuous assurance report, SDL compliance evidence

Reading Your Results
| If your results look like… | Suggested next step |
|---|---|
Mostly checked across all six pillars | You’re in strong shape. Focus on consolidating evidence into audit-ready packages. |
Checked in some pillars, gaps in others | Prioritize the pillars with the most unchecked boxes — that’s usually where documentation, not new controls, is needed. |
Few boxes checked overall | Start with Pillar 1 (continuous assessment) and Pillar 6 (incident response) — they underpin evidence for the other four. |
Want Help Closing the Gaps?
AccuKnox works with SaaS and technology providers on exactly this: turning working security controls into audit-ready evidence for CERT-In and other regulatory frameworks. If you’d like a second set of eyes on your results, reach out.
This checklist is an educational self-assessment tool. It does not constitute CERT-In certification, legal advice, or a guarantee of regulatory compliance.
Get a LIVE Tour
Ready For A Personalized Security Assessment?
“Choosing AccuKnox was driven by opensource KubeArmor’s novel use of eBPF and LSM technologies, delivering runtime security”

Golan Ben-Oni
Chief Information Officer
“At Prudent, we advocate for a comprehensive end-to-end methodology in application and cloud security. AccuKnox excelled in all areas in our in depth evaluation.”

Manoj Kern
CIO
“Tible is committed to delivering comprehensive security, compliance, and governance for all of its stakeholders.”

Merijn Boom
Managing Director




