
The CERT-In empanelled security audit IRDAI requires before your insurance e-commerce platform goes live, and the annual review that keeps it compliant.
An Insurance Self-Network Platform (ISNP) is the electronic platform, a website, a mobile app, or both, through which an insurer or intermediary conducts insurance e-commerce. It can only operate with IRDAI’s prior permission, and under the Authority’s insurance e-commerce guidelines (IRDA/INT/GDU/ECM/055/03/2017), the platform’s controls, systems, procedures and safeguards must be independently reviewed.
Crucially, the platform cannot mark its own homework. IRDAI requires the assessment to come from outside the organisation, from a CERT-In empanelled auditing firm, or a professional holding an equivalent CISA or DISA (ICAI) qualification. It is required once before the platform opens for business, and then on a recurring annual basis for as long as it operates. What the auditor produces does not stop at the engineering team either: it travels up to the Board, or the sub-committee acting for it. As a CERT-In empanelled auditing organisation, SICHERTEN runs the assessment end to end and writes it up for both destinations, the regulator and the boardroom.
Full vulnerability assessment and penetration testing of the platform, web portal, mobile app and APIs, against the OWASP Top 10.
Payment-gateway integration, premium collection, refunds and the security of transaction and settlement paths.
Protection of proposal, KYC, medical, financial and policy data, in transit and at rest, with access controls and encryption.
Whether the platform can actually see what its own data-processing systems are doing, logging, alerting and an audit trail that would stand up to scrutiny.
Network architecture, server and cloud hardening, exposed services, security headers and configuration review.
Information security management system, policies, logging, incident response and business continuity, aligned to ISO/IEC 27001.
Any entity operating, or applying to operate, an insurance e-commerce platform under IRDAI permission.
IRDAI’s guidelines on insurance e-commerce set out what an ISNP must have in place, and who may attest to it. Requirements are updated by the Authority from time to time, so we confirm the current scope against the applicable circulars for your entity type before the engagement begins.
A structured audit lifecycle that satisfies the regulator and gives your engineers something they can act on.
A structured intake defines the boundary, every portal, app, API, database and third-party integration in scope.
Automated, breadth-first discovery across the application, network, infrastructure and cloud layers.
Manual, business-logic testing, policy purchase and servicing flows, premium payment, access control and policyholder-data exposure.
Verification of internal monitoring controls, access management, encryption, logging, BCP and ISO 27001 alignment.
Risk-rated findings with evidence, business impact and prioritised remediation guidance, written for both engineers and the Board.
Support through closure of critical and high findings, then independent retesting and the final signed audit certificate.
The audit is anchored to the regulator’s expectations and the standards the platform is measured against.
What to have in place before the audit begins.
Cybersecurity audits for insurers and intermediaries.
Learn more →Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Back to the full pillar.
View pillar →Tell us about your platform and we’ll scope the audit with you, and get you to a board-ready report.