Home / Services / MSME CERT-In Guideline Assessment

Services

MSME CERT-In Guideline Assessment

A practical route to the 15 baseline cyber defence controls that CERT-In has set out for MSMEs.

Consultant walking a small business owner through a checklist
Image placeholder: Consultant walking a small business owner through a checklist

Overview

What it is and who needs it

In September 2025 the Indian Computer Emergency Response Team (CERT-In) published “15 Elemental Cyber Defense Controls for MSMEs” (version 1.0). It sets a baseline for micro, small and medium enterprises: 15 control areas supported by 45 recommendations.

In plain language, the guideline asks an MSME to know what assets it has, keep them configured and patched, control who has access, protect email, endpoints and data, train staff, keep logs, manage suppliers and be ready to handle an incident. CERT-In’s guidance is that these baseline controls are audited at least once a year by a CERT-In empanelled auditing organisation.

Who needs it

  • MSMEs that supply larger enterprises or government bodies
  • MSMEs preparing for their first annual baseline audit
  • Owners who want a clear, affordable security baseline
  • IT service providers supporting MSME customers
Small office team at their desks
Image placeholder: Small office team at their desks

Scope

What the service covers

Gap assessment

Your current practices compared with each of the 15 controls and 45 recommendations.

Prioritised roadmap

A remediation plan ordered by risk, effort and cost, with a named owner for each action.

Implementation help

Hands-on support with policies, configurations, backups, logging and staff training.

Audit readiness

A pre-audit review and an evidence pack ready for the annual baseline audit.

The guideline at a glance

The 15 control areas

Each control area carries specific recommendations. We assess every one.

01

Effective Asset Management

02

Network and Email Security

03

Endpoint and Mobile Security

04

Secure Configurations

05

Patch Management

06

Incident Management

07

Logging and Monitoring

08

Awareness and Training

09

Third Party Risk Management

10

Data Protection, Backup and Recovery

11

Governance and Compliance

12

Robust Password Policy

13

Access Control and Identity Management

14

Physical Security

15

Vulnerability Audits and Assessments

Control names follow CERT-In’s document, version 1.0 dated 1 September 2025.

Our approach

How we work, step by step

01

Kick-off

We confirm the business units, locations and systems in scope and who will take part.

02

Gap assessment

Interviews, configuration reviews and evidence sampling against each control.

03

Roadmap

Findings are turned into a prioritised plan that you review and approve.

04

Implementation support

We help your team or IT vendor close the gaps and document what was done.

05

Audit readiness

A final review confirms each control is in place and the evidence is in order.

Deliverables

What you receive

  • Gap assessment report scored control by control
  • Prioritised remediation roadmap with owners and effort
  • Policy and procedure templates adapted to your business
  • Evidence pack mapped to the 45 recommendations
  • Readiness review before the annual audit
Gap assessment scorecard for the 15 controls
Image placeholder: Gap assessment scorecard for the 15 controls

Why iSecurify

Three reasons customers choose us

01

Sized for an MSME

The work is scoped for small teams and limited budgets, with no enterprise overhead.

02

Plain-language guidance

You get clear actions, not a list of clause numbers.

03

From gaps to closure

We help to fix what we find and stay until you are ready for audit.

Questions

Frequently asked questions

Is the guideline mandatory for my business?

The document sets the baseline CERT-In expects MSMEs to have in place and is read alongside CERT-In’s wider directions and audit guidelines. How it applies can depend on your sector, your customers and your contracts. We help you confirm what applies to you at the start.

Who carries out the annual audit?

CERT-In’s guidance refers to baseline audits by CERT-In empanelled auditing organisations. iSecurify prepares you for that audit. [Empanelment status to be confirmed]

How long does the assessment take?

For a typical small business the gap assessment takes one to two weeks. Remediation time depends on the gaps found.

We do not have an IT team. Can we still do this?

Yes. Many MSMEs rely on an outside IT vendor or a single administrator. We work with whoever manages your IT and keep the actions practical.

Does this help with ISO 27001 later?

Yes. The 15 controls overlap with ISO 27001, so the policies, asset records and evidence you build here are a head start.

Customer stories

What our customers say

  • Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.

    Swapon Adhikary

    Director · The Hird

  • Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.

    Krutarth Pandya

  • We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.

    Nandeep Mehta

Organisations we work with

Talk to us about MSME CERT-In Guideline Assessment.

Share a few details and a consultant will come back with a scope and next steps.

info@isecurify.co