Home / Services / MSME CERT-In Guideline Assessment
Services
MSME CERT-In Guideline Assessment
A practical route to the 15 baseline cyber defence controls that CERT-In has set out for MSMEs.

Overview
What it is and who needs it
In September 2025 the Indian Computer Emergency Response Team (CERT-In) published “15 Elemental Cyber Defense Controls for MSMEs” (version 1.0). It sets a baseline for micro, small and medium enterprises: 15 control areas supported by 45 recommendations.
In plain language, the guideline asks an MSME to know what assets it has, keep them configured and patched, control who has access, protect email, endpoints and data, train staff, keep logs, manage suppliers and be ready to handle an incident. CERT-In’s guidance is that these baseline controls are audited at least once a year by a CERT-In empanelled auditing organisation.
Who needs it
- MSMEs that supply larger enterprises or government bodies
- MSMEs preparing for their first annual baseline audit
- Owners who want a clear, affordable security baseline
- IT service providers supporting MSME customers

Scope
What the service covers
Gap assessment
Your current practices compared with each of the 15 controls and 45 recommendations.
Prioritised roadmap
A remediation plan ordered by risk, effort and cost, with a named owner for each action.
Implementation help
Hands-on support with policies, configurations, backups, logging and staff training.
Audit readiness
A pre-audit review and an evidence pack ready for the annual baseline audit.
The guideline at a glance
The 15 control areas
Each control area carries specific recommendations. We assess every one.
01
Effective Asset Management
02
Network and Email Security
03
Endpoint and Mobile Security
04
Secure Configurations
05
Patch Management
06
Incident Management
07
Logging and Monitoring
08
Awareness and Training
09
Third Party Risk Management
10
Data Protection, Backup and Recovery
11
Governance and Compliance
12
Robust Password Policy
13
Access Control and Identity Management
14
Physical Security
15
Vulnerability Audits and Assessments
Control names follow CERT-In’s document, version 1.0 dated 1 September 2025.
Our approach
How we work, step by step
01
Kick-off
We confirm the business units, locations and systems in scope and who will take part.
02
Gap assessment
Interviews, configuration reviews and evidence sampling against each control.
03
Roadmap
Findings are turned into a prioritised plan that you review and approve.
04
Implementation support
We help your team or IT vendor close the gaps and document what was done.
05
Audit readiness
A final review confirms each control is in place and the evidence is in order.
Deliverables
What you receive
- Gap assessment report scored control by control
- Prioritised remediation roadmap with owners and effort
- Policy and procedure templates adapted to your business
- Evidence pack mapped to the 45 recommendations
- Readiness review before the annual audit

Why iSecurify
Three reasons customers choose us
01
Sized for an MSME
The work is scoped for small teams and limited budgets, with no enterprise overhead.
02
Plain-language guidance
You get clear actions, not a list of clause numbers.
03
From gaps to closure
We help to fix what we find and stay until you are ready for audit.
Questions
Frequently asked questions
Is the guideline mandatory for my business?
The document sets the baseline CERT-In expects MSMEs to have in place and is read alongside CERT-In’s wider directions and audit guidelines. How it applies can depend on your sector, your customers and your contracts. We help you confirm what applies to you at the start.
Who carries out the annual audit?
CERT-In’s guidance refers to baseline audits by CERT-In empanelled auditing organisations. iSecurify prepares you for that audit. [Empanelment status to be confirmed]
How long does the assessment take?
For a typical small business the gap assessment takes one to two weeks. Remediation time depends on the gaps found.
We do not have an IT team. Can we still do this?
Yes. Many MSMEs rely on an outside IT vendor or a single administrator. We work with whoever manages your IT and keep the actions practical.
Does this help with ISO 27001 later?
Yes. The 15 controls overlap with ISO 27001, so the policies, asset records and evidence you build here are a head start.
Customer stories
What our customers say
-
Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.
Swapon Adhikary
Director · The Hird
-
Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.
Krutarth Pandya
-
We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.
Nandeep Mehta
Organisations we work with
Talk to us about MSME CERT-In Guideline Assessment.
Share a few details and a consultant will come back with a scope and next steps.
