MSMEs Face Mandatory Annual Cyber Audits: CERT-In's Bold Move



Quick Summary
The Indian Computer Emergency Response Team (CERT-In) has introduced a new mandate requiring all Micro, Small, and Medium Enterprises (MSMEs) to undergo annual cybersecurity audits. This move shifts compliance from voluntary to mandatory, aiming to protect MSMEs, which are frequent targets for cybercriminals due to limited resources. The audits will cover network, application, and data security, as well as incident response plans, with findings needing to be reported to CERT-In.

In a significant move to bolster India's digital security, the Indian Computer Emergency Response Team (CERT-In) has announced a new mandate making annual cybersecurity audits compulsory for Micro, Small, and Medium Enterprises (MSMEs). This regulation, which came into effect recently, marks a pivotal shift from a voluntary to a mandatory compliance framework, underscoring the government's commitment to safeguarding this critical sector of the economy.

Mandatory Cyber Audits for Indian MSMEs by CERT-In

Need and Importance

MSMEs, often operating with limited resources and less sophisticated IT infrastructure, have become increasingly attractive targets for cybercriminals. Their vulnerabilities are exploited for various malicious activities, including data theft, financial fraud, and as entry points to larger supply chains.

The repercussions of a cyberattack on an MSME can be devastating, leading to significant financial losses, reputational damage, and operational disruption. CERT-In's new directive aims to proactively address these risks by ensuring that MSMEs regularly assess their cyber resilience and rectify any weaknesses.

 

What Does the Mandate Entail?

Under the new regulations, all MSMEs are required to conduct a comprehensive cybersecurity audit at least once a year. This audit must be carried out by CERT-In empaneled auditors who will evaluate the organization's security posture against a predefined set of guidelines. The audit scope includes:

  • Network Security: Assessing firewalls, intrusion detection systems, and network access controls.
  • Application Security: Reviewing web and mobile applications for vulnerabilities.
  • Data Security: Checking data encryption, access permissions, and data backup procedures.
  • Incident Response Plan: Evaluating the readiness of the organization to handle a cyber incident.

Following the audit, the MSME must submit a report to CERT-In, detailing the findings and the measures taken to address any identified vulnerabilities.

Framework

Instead of hitting small businesses with a complex, overwhelming list of rules, CERT-In's September 1 guidelines are more of a guided tour into the world of cybersecurity. They've crafted a blueprint built on 15 fundamental defense principles, each with a few simple, actionable steps, adding up to a total of 45 clear recommendations.

 

Conclusion

India's cybersecurity landscape is undergoing a significant transformation, with the Indian Computer Emergency Response Team (CERT-In) now making annual cybersecurity audits mandatory for all Micro, Small, and Medium Enterprises (MSMEs). This landmark directive, which became effective on September 1, 2025, extends a broader framework introduced in July 2025 that initially applied to large public and private organizations. The goal is to establish a cybersecurity baseline for MSMEs, which have become prime targets for cyberattacks due to their often limited resources and less mature IT security practices.

Disclaimer: Every effort has been made to avoid errors or omissions in this material. In spite of this, errors may creep in. Any mistake, error or discrepancy noted may be brought to our notice which shall be taken care of in the next edition. In no event the author shall be liable for any direct, indirect, special or incidental damage resulting from or arising out of or in connection with the use of this information.

FAQ :

CERT-In has made annual cybersecurity audits mandatory for all Micro, Small, and Medium Enterprises (MSMEs) in India, effective from September 1, 2025.

MSMEs are increasingly targeted by cybercriminals due to their often limited resources and less sophisticated IT infrastructure. These audits aim to proactively address these risks and bolster their cyber resilience.

The audits evaluate Network Security, Application Security, Data Security, and the organization's Incident Response Plan.

The annual cybersecurity audits must be carried out by auditors who are empaneled by CERT-In.

Following the audit, the MSME must submit a report to CERT-In, detailing the findings and the measures taken to address any identified vulnerabilities.




About the Author

Company Secretary

Company Secretary having 8+ years of post qualification experience in the Compliance Management Services industry by serving Corporates including Listed Companies, Corporate Secretarial Firms and LLP. Have a keen interest in the Corporate Governance and Compliance Management and the soaring craving to learn everyday. A ... Read more

Click here to Login and post comments    OR


Related Articles


Loading


Popular Articles





CCI Pro

CCI Articles

submit article


Company
Featured 18 July 2026
Senior Manager- Finance & Accounts

apricus india

Ahmedabad

CA

View Details
Company
23 July 2026
Semi qualified CA

Garg Bros & Associate CA

New Delhi

CA Inter

View Details
Company
05 July 2026
Financial Controller

NovumLake Partners

Mumbai

CA

View Details
Company
Featured 16 July 2026
Semi Qualified Company Secretary

Vakilsearch.com

Chennai

CS

View Details
Company
06 July 2026
Senior Accountant

Arvindkumar Maniar & Co.

Rajkot

CA

View Details
Company
06 July 2026
Chartered Accountant (Indirect Taxation)

Gowra Ventures Pvt Ltd

Hyderabad

CA

View Details
Company
ARTICLESHIP 28 July 2026
Article/Intern/Semi-Qualified/Fresher B.Com

VNSS & Co

Mumbai

Others

View Details
Company
ARTICLESHIP 16 July 2026
Article Assistant

Sahil Agarwal & Company

Mumbai

CA Inter

View Details