Top CERT-In Empanelled AI Security Firms in India (2026)
CERT-In empanelled AI security firms in India (2026) — transparent listicle with comparison table, methodology, inclusion criteria, and verification steps.
By TheZyberSecurity
TL;DR — CERT-In empanelment is the Indian government's accreditation scheme for information-security auditing firms, administered by the Indian Computer Emergency Response Team under the Ministry of Electronics and Information Technology (MeitY). Enterprise buyers in India routinely require a vendor's CERT-In empanelment status before scoping a security engagement — especially in BFSI, telecom, healthcare, and government-adjacent sectors. AI security is a newer sub-category: no separate "AI red-teaming empanelment" exists as of 2026, so firms offering LLM red-teaming, prompt-injection assessment, OWASP LLM Top 10 v2.0 alignment, MITRE ATLAS mapping, ISO/IEC 42001 readiness, and DPDP Act 2023-aligned data-processing reviews either extend their general empanelment into AI or operate outside the empanelment lane while advertising equivalent standards. This listicle ranks firms Indian buyers are actually searching for when the query is "CERT-In empanelled AI security firm" — with a transparent methodology, honest inclusion criteria, and a comparison table at the top. Verify any firm's current empanelment status at cert-in.org.in before contracting.
Why "CERT-In empanelled" is the search Indian AI buyers actually use#
Ask a security buyer at an Indian bank, a listed fintech, a telecom operator, a public-sector undertaking, or any enterprise with a compliance function what they type into Google when they need a vendor. The pattern is consistent: "CERT-In empanelled" + [service] — CERT-In empanelled VAPT, CERT-In empanelled cloud security, CERT-In empanelled pen testing. As AI-native features multiply across Indian SaaS, the same query pattern is bending toward AI: CERT-In empanelled AI security firm, CERT-In empanelled LLM security auditor, CERT-In empanelled AI red teaming India.
The reason is procedural. Many procurement checklists — especially in regulated sectors — treat CERT-In empanelment as a hard filter. A vendor without it may never reach a shortlist. And even outside sectors where it's mandatory, the empanelment is treated as a proxy for baseline rigor: a firm that has passed CERT-In's audit-firm assessment has demonstrated a documented methodology, credentialed staff, and a track record CERT-In deemed sufficient for empanelment.
The complication in 2026: AI security is a young sub-discipline. CERT-In's empanelment scheme has traditionally focused on network security, application security, source-code review, cloud security assessments, and general VAPT. There is no separately notified "AI security auditor" category. Firms offering AI red-teaming today are almost always general-purpose CERT-In auditors extending into the AI attack surface, or specialist AI-security firms operating outside the empanelment lane while advertising equivalent methodological grounding (OWASP LLM Top 10 v2.0, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001:2023).
This listicle addresses both cases honestly. We list firms that are demonstrably CERT-In empanelled and that publicly market AI-security services. We include one specialist — The Zyber Security — with a transparent note that our own empanelment application is in progress. And we tell you exactly how to verify a firm's current status yourself, because empanelment lists change and any listicle can go stale.
What CERT-In empanelment actually means#
The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cybersecurity incident response, operating under the Ministry of Electronics and Information Technology (MeitY). It was established under the Information Technology Act, 2000, and its mandate expanded significantly with the CERT-In directives of April 2022 (mandatory incident reporting within six hours) and subsequent guidance covering breach notification, log retention, and coordinated disclosure.
Alongside its incident-response role, CERT-In administers an empanelment scheme for information security auditing organizations. Firms that apply undergo an assessment covering their auditing methodology, technical capability, personnel qualifications, quality management systems, and demonstrated experience. Firms that pass are listed on the CERT-In empanelled auditors register, published at cert-in.org.in under the "Empanelled Information Security Auditing Organisations" section.
Empanelment is time-bound. It is renewed periodically, and CERT-In has both added and removed firms across cycles. A vendor's claim of "CERT-In empanelled" is only meaningful if verified against the current published list on the CERT-In portal — the version of the list on a vendor's marketing page can lag actual status.
What empanelment does not mean:
- It is not a per-service certification. A firm empanelled for information security auditing is not automatically certified for every sub-service they offer. AI security specifically is not called out as a separate empanelment category as of 2026.
- It is not a substitute for framework alignment. A CERT-In empanelled firm can still deliver an AI-security engagement that does not map to OWASP LLM Top 10 v2.0 or MITRE ATLAS. Ask for framework anchoring in the proposal.
- It is not a substitute for evidence quality. Empanelment gates methodology at the firm level. Individual engagement quality depends on the specific team assigned. Ask who will actually work on your engagement.
Treat CERT-In empanelment as a floor, not a ceiling. It filters out firms that never demonstrated baseline methodological competence. It does not distinguish among the firms that cleared the bar.
The gap between traditional empanelment scope and AI-security testing#
Understanding what a CERT-In empanelment historically covers helps calibrate what to expect when a general-empanelled firm extends into AI. The empanelment scheme was designed for a threat model centered on network intrusion, web application exploitation, source-code vulnerability review, cloud misconfiguration assessment, and incident-response readiness. The methodology anchors that mature the empanelment process were built around OWASP Top 10 (the traditional web application list, not the LLM list), OWASP ASVS, PTES, NIST SP 800-115, and CIS benchmarks.
AI security adds framework requirements those anchors do not natively cover: OWASP Top 10 for LLM Applications (v2.0, 2025), MITRE ATLAS (the ML/AI adversary matrix that parallels ATT&CK), NIST AI Risk Management Framework, and ISO/IEC 42001:2023 (AI Management System). It also adds a new attack surface — prompt template, RAG index, tool interfaces, output pipeline, agent topology — that the traditional web application methodology does not enumerate.
The practical implication for buyers: a firm's general CERT-In empanelment tells you the firm has demonstrated traditional-security methodology. It does not tell you the firm has demonstrated AI-security methodology. Those are separate competencies. A general-empanelled firm can be excellent at both, can be excellent at traditional security but weak at AI, or can market AI-security services without having built the technique depth yet. The way to distinguish is the scoping conversation — the frameworks named, the sample deliverables shown, the specific team assigned, the manual-versus-automated split, and the retest policy. Empanelment is the filter that gets a firm to your shortlist. Everything after that is your job.
Where a firm is not empanelled but positions on AI-security depth (as The Zyber Security does, transparently), the same scoping-conversation discipline applies: ask about frameworks, deliverables, team, methodology, and retest. The absence of empanelment removes one filter but does not remove the buyer's obligation to evaluate on the substance. And where empanelment is a procurement hard filter for reasons of sector regulation, the empanelled firms on this list are the ones to shortlist. Both cases are legitimate; the buyer's job is to know which case applies to their organization.
Our listing criteria — a transparent methodology#
Any listicle in this category is a form of editorial judgment. Ours uses the following criteria, applied consistently, with the reasoning stated for each firm:
- Public presence. The firm maintains a publicly accessible website with documented service offerings, a professional presentation, and traceable corporate details (registered entity, physical office, verifiable leadership).
- CERT-In empanelment (verified independently at time of writing). The firm appears on CERT-In's published empanelled auditors register, or is documented to have appeared in a recent cycle. Verification of current status is the reader's responsibility at cert-in.org.in — empanelment cycles refresh.
- AI-security service line, publicly stated. The firm's own marketing, capability decks, or service pages reference AI, LLM, generative AI, or ML security assessment as an offering — either as a standalone service or as an extension of application security.
- Framework awareness. Public materials or engagement collateral reference at least one recognized AI-security framework: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, or ISO/IEC 42001.
- India nexus. The firm operates from India, has a substantial Indian delivery presence, or serves the Indian buyer market as a primary segment.
Firms are listed in no particular ranked order — we do not run a scoring rubric that would misrepresent our knowledge as a quantitative measurement. Each entry is a factual profile based on public information. Where we are uncertain about a specific claim, we say so or omit rather than speculate.
The Zyber Security is included at the end with a transparent note about our empanelment status — application in progress, not yet listed. We think readers deserve to know when they are reading a page that mentions the publisher, and to know exactly what our current status is.
Comparison table#
| Firm | Primary location | AI-security services (as publicly stated) | Listing basis |
|---|---|---|---|
| SecureLayer7 | Pune, India | AI/ML application security, LLM security assessments | CERT-In empanelled auditor; verify at cert-in.org.in |
| iSecurion | Bangalore, India | Application and cloud security; AI security services referenced | CERT-In empanelled auditor; verify at cert-in.org.in |
| WeSecureApp | Hyderabad, India / US | Application security including LLM/AI application testing | CERT-In empanelled auditor; verify at cert-in.org.in |
| Astra Security | Bengaluru / Delhi NCR, India | Pentest platform; AI/LLM security services announced | CERT-In empanelled auditor; verify at cert-in.org.in |
| Qualysec Technologies | Bhubaneswar, India | Web, mobile, API pen testing; AI/LLM security service line | CERT-In empanelled auditor; verify at cert-in.org.in |
| SISA Information Security | Bengaluru, India | PCI QSA; AI/ML security assessment services | CERT-In empanelled auditor; verify at cert-in.org.in |
| Network Intelligence (NII) | Mumbai, India | Broad enterprise security, MSSP, cloud, AI/ML security | CERT-In empanelled auditor; verify at cert-in.org.in |
| Kratikal Tech | Noida, India | VAPT, red-teaming, AI-security research and services | CERT-In empanelled auditor; verify at cert-in.org.in |
| eSec Forte Technologies | Gurugram, India | Wide security-services portfolio; AI security offering | CERT-In empanelled auditor; verify at cert-in.org.in |
| Cyfirma | Bengaluru / Singapore | AI-powered external threat intel; AI/ML risk advisory | CERT-In empanelled; verify at cert-in.org.in |
| The Zyber Security | India | AI penetration testing, LLM red-teaming, ISO 42001 readiness, DPDP-aligned pen testing | CERT-In empanelment application in progress — not yet empanelled as of publication |
Table entries reflect publicly stated positioning as of writing. Do not treat this table as a substitute for independent due diligence. Confirm each firm's current empanelment status, its actual AI-security service depth (case studies, sample redacted reports, framework mappings), and the specific team that will run your engagement, before contracting.
The firms#
Each entry below is a factual profile based on the firm's public presence. We include location, publicly stated service categories, and the basis for inclusion on this list. Where a firm's specific AI-security service depth is not clearly documented publicly, we say so rather than invent detail — some firms' AI-security offerings are marketed at a high level with details available only during scoping conversations.
SecureLayer7#
Pune-headquartered offensive security firm operating since the mid-2010s, with delivery presence across India and international markets. SecureLayer7's public service catalogue spans web application, mobile application, API, cloud (AWS, Azure, GCP), IoT, and network penetration testing. The firm publicly references AI and LLM application security as part of its application-security service line, reflecting the industry-wide extension of AppSec practices into the LLM attack surface.
Listing basis for this article: publicly present as a CERT-In empanelled information security auditor per the firm's own website and industry directories. AI-security services are marketed publicly. Verify current empanelment status directly at cert-in.org.in. Ask specifically, during scoping, whether the AI-security engagement will map findings to OWASP LLM Top 10 v2.0 and MITRE ATLAS, and request a sample redacted AI-security report as evidence of methodology depth.
iSecurion#
Bengaluru-based information security consulting firm covering the standard enterprise cybersecurity portfolio: VAPT, cloud security assessment, ISO 27001 consulting, PCI DSS, GDPR advisory, and source-code review. iSecurion's public presence references AI security services alongside its traditional application-security work, positioning the offering as a natural extension of its application-security methodology into the AI attack surface.
Listing basis: publicly listed as a CERT-In empanelled auditor per the firm's marketing materials and third-party directories; verify current empanelment cycle status at cert-in.org.in. For AI-specific scoping, ask what percentage of a proposed engagement is manual attack-chain construction versus automated scanning — a legitimate LLM red-team is majority manual, since jailbreak reproducibility and blast-radius reasoning are not yet reliably automatable.
WeSecureApp#
Application-security firm with delivery operations in Hyderabad (India) and Dallas (US), serving both Indian and North American markets. WeSecureApp's public service catalogue centers on application security testing — web, mobile, API, cloud-native — plus threat modeling, secure code review, and DevSecOps integration. The firm's public materials reference AI and LLM application security as part of its application-security service line.
Listing basis: publicly listed as a CERT-In empanelled auditor per third-party directories and the firm's own marketing; verify current empanelment status at cert-in.org.in. For AI engagements specifically, WeSecureApp's application-security depth is a natural fit — but ask during scoping for the specific frameworks (OWASP LLM Top 10 v2.0 is the current version; anything referencing only the 2023 version is 18 months behind) and MITRE ATLAS technique tagging in the deliverable.
Astra Security#
Bengaluru/Delhi-NCR-based security firm best known for its pentesting platform combining automated vulnerability scanning with manual penetration testing. Astra publishes prolifically on offensive security topics and has extended its offering to include AI and LLM security testing. The firm's platform-driven model is oriented toward faster time-to-first-finding and continuous re-scanning — attractive to product companies iterating quickly.
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. For AI-specific engagements, the platform-plus-manual model implies part of the AI-security assessment may be automated (prompt-injection payload sweeps, tool-boundary probing); the manual layer is where attack-chain construction and blast-radius reasoning happen. Ask, during scoping, what proportion of hours in the SoW are manual versus automated, and confirm the manual hours include indirect prompt-injection testing across every ingestion channel — not only chat input.
Qualysec Technologies#
Bhubaneswar-based pen-testing firm with strong presence in the mid-market Indian buyer segment. Qualysec's public service catalogue covers web application, mobile application (iOS and Android), API, cloud, and network penetration testing, along with source code review and IoT security. The firm publicly references AI and LLM security as part of its emerging service portfolio.
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. For AI security specifically, Qualysec's core competency is application security — a strong foundation for testing LLM applications where the wrapping API surface is often as vulnerable as the AI-specific surface. Confirm during scoping that the engagement scope includes both the traditional application layer and the AI-specific surface (prompt template, RAG, tools, output pipeline).
SISA Information Security#
Bengaluru-based information security firm best known as a PCI QSA (Payment Card Industry Qualified Security Assessor), with deep BFSI-sector delivery experience. SISA's public materials describe AI/ML security assessment as a service line, and the firm has published thought leadership on AI risk in financial services contexts — a natural fit given the sector's early adoption of AI for fraud detection, credit scoring, and customer service automation.
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. SISA's BFSI depth is a strong differentiator for financial-services buyers whose AI features touch regulated data (KYC, transaction monitoring, credit decisioning). For a BFSI-focused engagement, ask specifically about the firm's approach to model-decisioning explainability testing and RBI/SEBI/IRDAI sector guidance alignment alongside standard OWASP LLM Top 10 v2.0 coverage.
Network Intelligence (NII Consulting)#
Mumbai-headquartered enterprise security firm operating since the early 2000s, with a broad managed-security-services (MSSP) footprint alongside its consulting practice. Network Intelligence's public service catalogue spans threat management, security operations, cloud security, digital forensics, incident response, and application security. The firm has referenced AI/ML security as part of its capability expansion in recent years.
Listing basis: long-standing CERT-In empanelled auditor per the firm's public materials and multiple third-party directories; verify current empanelment cycle status at cert-in.org.in. For AI-security engagements, Network Intelligence's scale is a differentiator for large enterprises that want a single vendor covering both the AI-specific engagement and the surrounding infrastructure security assessment. Confirm during scoping which specific team will be assigned to the AI portion — the firm's breadth is a strength for coverage, but AI-security depth varies by individual practitioner.
Kratikal Tech#
Noida-based cybersecurity firm covering VAPT, red-teaming, phishing simulation, security awareness training, and compliance advisory. Kratikal has invested visibly in AI-security research and has publicly discussed AI-security services alongside its established red-teaming practice. The firm's public materials position it in the mid-market and enterprise segments across India.
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. For AI red-teaming specifically, ask during scoping about the firm's approach to indirect prompt injection across every ingestion channel (uploads, tickets, RAG source URLs, agent-browsable sites) and request a sample framework-tagged finding as evidence of methodology depth.
eSec Forte Technologies#
Gurugram-based cybersecurity services firm with a broad portfolio spanning cybersecurity consulting, VAPT, cloud security, forensics, and managed security services. eSec Forte serves Indian enterprise and government-adjacent buyers and has referenced emerging technology security — including AI — in its capability materials.
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. For AI-security engagements, the firm's breadth is a strength for buyers who need one vendor covering multiple security domains. As with all breadth-first firms, confirm during scoping that the AI-security work will be delivered by practitioners with specific AI/ML security experience — not a general application-security team learning on your engagement.
Cyfirma#
Bengaluru/Singapore-headquartered external threat intelligence firm known for AI-powered attack surface management and threat intel platforms. Cyfirma's positioning is distinct from the pen-test-first firms on this list — its primary product is a platform for continuous external attack surface monitoring, with AI/ML applied both in the product (as detection tooling) and as an area the firm advises on (AI/ML risk in customer environments).
Listing basis: publicly listed as a CERT-In empanelled auditor; verify current empanelment status at cert-in.org.in. Cyfirma is best positioned for buyers who want continuous external threat intelligence with AI-driven detection, rather than a scoped-engagement AI red-team. For a discrete LLM red-team engagement, pair Cyfirma's platform coverage with a firm whose primary offering is manual AI red-teaming.
The Zyber Security#
Indian AI-security specialist focused on penetration testing for AI-native SaaS: LLM red-teaming, prompt-injection assessment (direct and indirect), tool-boundary and agent-abuse testing, RAG-poisoning evaluation, and ISO/IEC 42001:2023 readiness reviews. Our engagement model anchors on OWASP LLM Top 10 v2.0 (2025), MITRE ATLAS technique mapping, CVSS 3.1 severity scoring, and DPDP Act 2023 applicability tagging — with retest included on every engagement.
Transparent status disclosure — read this carefully: as of the publication date of this article, The Zyber Security's CERT-In empanelment application is in progress. We are not yet on the CERT-In empanelled auditors register. We include ourselves in this list because our AI-security service line is our primary offering, and because we think transparency about our own status is a better signal than omission would be. If CERT-In empanelment is a hard procurement filter for your organization today, any of the empanelled firms above is a legitimate choice — and we will tell you the same during a scoping conversation. When our empanelment application concludes, we will update this page and our other public materials with the outcome, whatever it is. Until then, we operate against the same frameworks the empanelled firms map to (OWASP LLM Top 10 v2.0, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, DPDP Act 2023), and we invite buyers to evaluate us on methodology and deliverable quality rather than empanelment alone. Scoping options are documented at /services/ai-penetration-testing.
AI-security service categories these firms offer#
Across the firms above, the AI-security service portfolio in the Indian market as of 2026 clusters into a recognizable set of categories. When you scope an engagement, expect to see some or all of the following in a proposal — and expect the vendor to be able to articulate which map to your specific system.
LLM red-teaming. Adversary emulation against a production LLM system: input surfaces, prompt template, RAG index, tool interfaces, output pipeline. Findings tagged to OWASP LLM Top 10 v2.0 classes and MITRE ATLAS techniques. Deliverable includes executive summary, technical findings, reproduction package, and retest.
Prompt-injection assessment. Focused engagement covering direct and indirect prompt injection across every ingestion channel — chat input, uploaded files, ingested documents, support tickets, RAG source URLs, agent-browsable pages. Deliverable includes a corpus of demonstrated injection payloads and a per-channel exposure matrix.
RAG security review. Retrieval-poisoning testing, semantic-similarity hijacking evaluation, vector-store enumeration probing, tenancy-isolation verification for multi-tenant RAG systems, source-citation-metadata integrity checks.
Agent-abuse and tool-boundary testing. For agentic systems, mapping the tool topology, testing per-tool authorization enforcement (in code, not in prompt), and constructing attack chains that convert single-tool compromise into cross-tool impact.
ISO/IEC 42001:2023 readiness assessment. Gap analysis against the AI Management System standard, control-by-control, with red-team evidence mapped to A.6 (Planning), A.8 (Operation), A.9 (Performance evaluation), and A.10 (Improvement) as feeder data for certification pursuit.
DPDP Act 2023 alignment review. For Data Fiduciaries operating AI systems processing personal data, a review of AI-specific DPDP compliance obligations: purpose limitation, data-principal rights (correction, erasure, portability) propagation through the AI pipeline including cached embeddings, data-breach notification readiness for AI-caused incidents, and Data Protection Impact Assessment feeder analysis for Significant Data Fiduciary designations.
MITRE ATLAS threat modeling. Systematic mapping of an AI system's attack surface against the ATLAS technique catalogue, with per-technique testing plan and evidence collection.
AI supply chain assessment. Model-provenance verification, training-data source review, third-party AI-plugin security assessment, artifact scanning for model files sourced from public registries.
Model-output-handling review. Testing every downstream consumption path for model output: HTML rendering (XSS surface), code execution (RCE surface), database writes (SQLi surface), forwarding to other models (cascading injection surface).
Multi-agent system red-teaming. For architectures with multiple cooperating agents, mapping the agent topology first (which agent invokes which, what each has access to, where shared state lives), then enumerating attacks including agent-to-agent prompt injection, shared-memory poisoning, coordinator abuse, and circular reasoning loops.
Continuous engagement / retainer. Recurring adversarial pressure on a system that evolves rapidly — new features monthly, RAG corpus growing, tools added. Retained team runs adversarial suites on each release.
Design-review engagement. Pre-launch review of AI system architecture, tool scoping, retrieval design, and prompt template before implementation hardens — catches problems when they are 10-100x cheaper to fix than post-production remediation.
Not every firm on this list offers every service in every depth. Ask specifically. And ask for the deliverable format — an AI red-team that ships only a PDF is a report, not an engagement.
What to ask a firm beyond empanelment status#
CERT-In empanelment is a floor. What separates a strong AI-security engagement from a weak one is delivery quality — and delivery quality is legible in the answers to a specific set of scoping questions. Ask every shortlisted vendor:
Which frameworks does the deliverable map to? The right answer includes OWASP LLM Top 10 v2.0 (2025), MITRE ATLAS technique IDs, CVSS 3.1 severity scoring, and ISO/IEC 42001:2023 control clauses where applicable. A vendor referencing only the 2023 version of OWASP LLM Top 10 is 18 months out of date. A vendor unable to name specific MITRE ATLAS technique IDs (AML.T0043, AML.T0051, AML.T0057, etc.) has not internalized the framework.
What proportion of the engagement is manual versus automated? A legitimate AI red-team is majority manual for the exploitation and blast-radius phases. Automated tools cover payload sweeps and tool-boundary fuzzing efficiently, but attack-chain construction and blast-radius reasoning are current-day human work. A vendor claiming "fully automated AI red-teaming" is scoping a scanner engagement, not a red-team.
Can you show a sample redacted AI-security report? The report is the deliverable. If a vendor cannot show a sample — even heavily redacted — the format is unproven. A serious sample shows: framework-tagged findings, reproduction steps a client engineer can run, executive summary that a non-technical decision-maker can consume, and a remediation-priority matrix ordered by exploitability × business impact.
What is your retest policy? A red-team that does not include retest is a snapshot, not a security program. Ask specifically: is retest included in the SoW, what is the timeline (60 days is standard), and what is the retest deliverable? A firm that treats retest as a paid add-on is scoping the engagement for their revenue rather than for your outcome.
Who specifically will work on my engagement? Empanelment is at the firm level. Delivery is at the individual level. Ask for the specific practitioners assigned, their AI-security experience (not just years in security — years in AI security), and whether the same team stays throughout the engagement or hands off between phases.
How do you handle indirect prompt injection? This is the single most consequential attack class on LLM systems, and the class most under-tested by traditional security firms extending into AI. Ask specifically: which ingestion channels will you test (uploads, tickets, RAG source URLs, agent-browsable sites), what payload corpus will you plant, and how will you verify per-channel exposure? A vendor that treats prompt injection as only the chat input is under-scoping.
How do you scope multi-tenant testing? If your system is multi-tenant, cross-tenant data leakage via tool authorization gaps is a common finding. Ask how the engagement will test tenancy boundaries at each layer — RAG vector store partitioning, tool authorization scoping, cache isolation, model-context isolation.
What is your engagement model for evolving systems? If your AI features ship weekly, a one-shot engagement is a point-in-time snapshot with a short shelf life. Ask about retainer or continuous engagement options and how the firm's process integrates with your release cadence.
How do you handle client data during testing? Data-handling policy should be documented in the SoW and constrained by a DPA. Default should be test data only, with production PII touched only if explicitly scoped. All artifacts should be encrypted at rest, deleted per retention policy, and never used for training any downstream system. Ask for the policy in writing.
What does a good outcome look like? A vendor who cannot articulate a good outcome beyond "we deliver the report" has not thought carefully about your success. A serious answer sounds like: zero unresolvable-severity findings after retest, documented framework-control mapping, your team confident enough to re-run payloads for regression testing, and a defensible AI-security posture narrative for your enterprise procurement conversations.
If a vendor answers these questions vaguely, they are marketing capability rather than delivering it. If a vendor answers specifically, with named frameworks, named practitioners, and named deliverables, you are looking at a real engagement candidate.
How to verify a firm's current CERT-In empanelment#
Empanelment status changes. Any listicle can go stale between publication and the reader's search. Here is the practical verification workflow — do this before contracting with any vendor whose claim of empanelment is material to your procurement decision.
Step 1. Go to the official CERT-In portal at cert-in.org.in.
Step 2. Navigate to the "Empanelled Information Security Auditing Organisations" section. This is typically reachable from the main navigation or from the "Services" area of the portal — exact placement changes across portal updates.
Step 3. Locate the current published list of empanelled auditors. CERT-In publishes the register as a downloadable document or as a searchable table, refreshed per empanelment cycle. Note the publication or effective date of the list.
Step 4. Search for the firm by exact registered name. Firms sometimes trade under a marketing name that differs from their registered corporate name — ask the vendor for the exact registered entity name to search.
Step 5. If the firm appears, note the empanelment validity period. If a firm's empanelment has expired and not been renewed, the firm is not currently empanelled — regardless of what marketing pages say.
Step 6. If the firm does not appear, ask the vendor directly for their empanelment reference number and the specific cycle they are empanelled under. Cross-check with CERT-In if in doubt. Do not accept "we are empanelled" as a claim without documentary evidence.
Step 7. For sector-specific empanelment or accreditation, check the relevant sector regulator's list separately. Some sectors (RBI-regulated entities, SEBI-regulated market infrastructure, IRDAI-regulated insurers) maintain their own auditor lists and vendor accreditations.
This verification is not optional if empanelment is procurement-material. Any vendor that pushes back on your verification request has answered a different question than the one you asked.
Update cadence for this list#
This list will be reviewed quarterly and updated when material changes occur. Changes trigger a re-publication with a dated update note. Materiality triggers include:
- A listed firm's CERT-In empanelment status changes (removed from register, empanelment cycle expires without renewal, or the firm exits the AI-security market)
- A new firm meets all five inclusion criteria (public presence, verified empanelment, publicly stated AI-security service line, framework awareness, India nexus) with sufficient depth to warrant inclusion
- The Zyber Security's own empanelment application concludes, with the outcome disclosed in place
- CERT-In introduces a distinct sub-category or accreditation for AI-security services, changing the meaning of the base empanelment
- OWASP LLM Top 10 revises to a new major version, changing what "framework awareness" means for inclusion
We will not add firms in exchange for reciprocal linking, sponsorship, or any other consideration. Inclusion is editorial. If we make an error — a firm we should have included, a claim we should not have made, a status we misstated — email us and we will correct in the next update cycle.
FAQ#
Is there a CERT-In empanelment specifically for AI security? As of 2026, no. CERT-In's empanelment scheme covers information security auditing organizations broadly, without a distinct AI-security sub-category. Firms offering AI red-teaming are general-purpose CERT-In auditors extending into the AI attack surface, or specialists operating outside the empanelment lane while advertising equivalent framework alignment. If CERT-In introduces an AI-specific empanelment category, this article will be updated.
Why is The Zyber Security in this list if you are not CERT-In empanelled? Because our AI-security service line is our primary offering, we serve the Indian buyer market, and transparency about our empanelment status is a better signal than omission would be. Our application is in progress and we will update this page when it concludes, whatever the outcome. If empanelment is a hard procurement filter for your organization today, any empanelled firm above is a legitimate choice — and we will tell you the same during a scoping conversation.
How do I verify a firm's current empanelment? Go to cert-in.org.in, navigate to the "Empanelled Information Security Auditing Organisations" section, and search the current published register for the firm's exact registered entity name. Note the empanelment validity period. Firms whose empanelment has expired without renewal are not currently empanelled regardless of what marketing pages claim.
Does CERT-In empanelment guarantee AI-security engagement quality? No. Empanelment is a firm-level gate demonstrating baseline methodological competence at the time of assessment. AI-security engagement quality depends on the specific team assigned, the frameworks the deliverable maps to, the manual-versus-automated split, and the retest policy. Ask the scoping questions in the section above.
What frameworks should an AI red-team map findings to? OWASP Top 10 for LLM Applications v2.0 (2025 revision — the current authoritative version), MITRE ATLAS technique IDs, CVSS 3.1 severity scoring, and ISO/IEC 42001:2023 control clauses where applicable. For Indian context, add DPDP Act 2023 applicability tagging for any finding involving personal data. A vendor unable to name these frameworks specifically has not internalized the discipline.
Are these firms ranked? No. The comparison table and the profile order do not reflect a ranked scoring rubric — we do not run one, because a quantitative rank would misrepresent editorial judgment as measurement. Every firm listed meets the five inclusion criteria. Selection among them should follow scoping questions specific to your system, not our ordering.
How often is this list updated? Quarterly by default, with immediate updates when material changes occur (empanelment status changes, new firms qualifying under criteria, framework version revisions, or our own empanelment outcome). The update note at the top of the article will reflect the most recent revision date.
Related service
AI Penetration Testing
Red-team your models before an adversary does.
See how we test itRelated field notes
- AI SecurityAugust 15, 202642 min read
AI Red-Teaming: Complete Guide for AI-Native SaaS in 2026
AI red-teaming for AI-native Indian SaaS: attack surface, OWASP LLM Top 10 v2.0, MITRE ATLAS, ISO 42001 alignment, and how to scope an engagement.
- AI SecurityJuly 18, 202618 min read
The OWASP LLM Top 10, Translated for Founders Shipping AI
OWASP LLM Top 10 v2.0 for founders shipping AI: the three risks that hurt first, the design pattern behind all ten, and a 90-minute self-assessment.
- AI SecurityAugust 15, 202617 min read
Prompt Injection Defenses That Actually Work in 2026
Prompt-based guardrails do not stop prompt injection. What actually works: architectural defenses, tool-scope enforcement, output escape, detection layers.