Picture this – your cyber audit report is complete, signed and ready for submission to your exchange or depository. Then someone checks the auditor’s empanelment status and finds it lapsed two months ago. The report cannot be used and the clock on your SEBI CSCRF deadline keeps running.
This is not a rare slip. Empanelment status changes, engagement caps expire and cooling-off periods apply. Getting these details wrong may cost time you do not have.
Choosing a CERT-In empanelled auditor for compliance can turn out to be a good investment as it is not just about ticking the empanelment box. SEBI has laid out specific selection norms on top of it. This guide walks you through how to choose a CERT-In empanelled auditor for SEBI CSCRF and what actually matters when you shortlist and engage one.
Why CERT-In Empanelment Alone Is Not Enough
SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) requires every cyber audit to be carried out by a CERT-In empanelled information security auditing organisation. That is the baseline. But SEBI’s CSCRF circular and its subsequent FAQs go further, setting out auditor selection norms that regulated entities (REs) must apply before engaging a firm.
The auditor should preferably carry at least three years of IT audit experience in banking and financial services, with direct exposure to the securities market. Experience with ISO 27001 frameworks counts as an advantage, particularly for market infrastructure institutions (MIIs) and Qualified REs, where ISO 27001 evidence is often required alongside the audit.
The firm should also have certified professionals on the engagement, holding credentials such as CISA, CISM, GSNA or CISSP, and should follow an ISMS or IT governance methodology aligned with recognised practices like COBIT. Independence matters just as much. SEBI requires that the auditor have no conflict of interest and should not have delivered consulting work to the RE’s relevant departments in the last two years.
There is also a tenure rule to watch. An RE can engage the same CERT-In empanelled auditor for a maximum of three consecutive years. After that, a two-year cooling-off period applies before the same firm becomes eligible again.
Steps to Choose the Right CERT-In Empanelled Auditor for SEBI CSCRF
Selecting an auditor is easier when you work through it as a checklist. Here is a practical sequence to follow.
- Verify empanelment status directly: Confirm the firm’s name and validity period on the current CERT-In empanelment list rather than relying on a vendor’s website claim.
- Match sector experience to your entity type: Ask for references from securities market engagements, not just generic IT audits, since CSCRF scope and terminology differ from other frameworks.
- Check certifications and methodology: Confirm the audit team includes CISA, CISM, GSNA or CISSP-certified professionals and that the firm’s approach maps to COBIT or an equivalent governance standard.
- Screen for independence: Rule out any firm that has provided consulting services to the audited departments within the last two years.
- Confirm the tenure clock: If you have worked with this auditor before, check how many consecutive years they have already audited you, so you do not breach the three-year cap.
Red Flags to Watch for When Shortlisting an Auditor
Some warning signs are easy to miss until it is too late. Keep an eye out for these before you decide to work with a firm:
- Empanelment nearing expiry: An auditor whose empanelment expires before your audit cycle ends creates a report you cannot submit.
- Generalist positioning with no securities-market work: Empanelment alone does not guarantee familiarity with CSCRF’s specific control areas or reporting formats.
- Unclear independence history: A firm that has recently advised your IT or risk teams may not meet SEBI’s conflict-of-interest requirement.
- Silence on the tenure cap: An auditor unaware of the three-year engagement limit and two-year cooling-off rule is a sign of limited CSCRF-specific experience.
- Vague scope definitions: SEBI requires cyber audits to cover all critical systems and a defined sample of non-critical systems. An auditor who cannot explain this scope clearly is not ready for a CSCRF engagement.
Conclusion
Getting your SEBI CSCRF cyber audit right starts before the audit itself – with how you choose your auditor. Empanelment confirms eligibility. Sector experience, certifications, independence and tenure history – confirm your readiness. Missing any one of these can turn a completed audit into a report you cannot use.
If you are working through how to choose a CERT-In empanelled auditor for SEBI CSCRF, connect with our experts at CyberNX. Our team brings CERT-In empanelment together with dedicated securities and market audit experience, so your compliance timeline stays on track.
How to Choose a CERT-In Empanelled Auditor for SEBI CSCRF FAQs
Is CERT-In empanelment mandatory for every SEBI CSCRF cyber audit?
Yes. SEBI’s CSCRF circular requires cyber audits to be carried out only by CERT-In empanelled information security auditing organisations, across all applicable regulated entity categories.
Can we reappoint the same CERT-In empanelled auditor every year?
An RE can engage the same auditor for a maximum of three consecutive years. After that, a two-year cooling-off period applies before the firm is eligible again.
What certifications should the auditor’s team hold?
SEBI’s selection norms point to credentials such as CISA, CISM, GSNA or CISSP, along with a methodology aligned to recognised IT governance frameworks like COBIT.




