Most cybersecurity blogs about CERT-In compliance are written by people who read the framework.
This one is written by a team that helped shape it.
CERT-In compliance is now a legal requirement for every MSME in India — not a best practice, not a recommendation.
xIoTz contributed directly to developing India’s CERT-In MSME Cybersecurity Framework — the 15 Elemental Cyber Defense Controls that every Micro, Small, and Medium Enterprise in India is now required to implement.
We didn’t read about the incidents that informed each control.
We responded to them.
We know where businesses fail audits — because we’ve watched it happen, and we’ve helped them recover.
This is not a summary of a official PDF. This is the practitioner’s guide.
“Small businesses aren’t ignored by attackers. They’re preferred. They’re easier. They’re faster. And they almost never survive.”
Over 40% of all cyber incidents hit small and medium businesses — not because attackers got lucky, but because basic protections were never in place.
India’s MSMEs are the backbone of the economy.
They’re also the most under protected segment in it.
One breach.
That’s all it takes.
Operational shutdown. Financial damage. Customer trust gone overnight.
For most MSMEs, there is no recovery plan. There’s just the aftermath.
Before the controls — here’s what compliance means in practice. These are not optional guidelines. They are legal requirements under India’s IT Act and CERT-In directives, enforceable against your business today.
Most businesses fail audits not because of a sophisticated breach. They fail because nobody implemented the basics consistently — strong passwords, access controls, system monitoring, configuration standards. Things that should have been standard practice and weren’t.
Non-compliance is not just an audit failure. Under India’s IT Act and CERT-In directives, the consequences are direct and severe.
Responsible officers — including directors and CEOs — can face personal imprisonment for failure to report incidents or maintain required logs.
For an MSME, a ₹1 crore penalty isn’t a setback. It’s a shutdown.
At their core, the 15 controls focus on four things: knowing what systems your business runs on, controlling who can access them, watching for anything unusual, and being ready to respond when something goes wrong. Everything else is detail.
xIoTz was in the room when these controls were being defined. We brought incident data from real MSME breaches — the patterns we kept seeing across sectors, the gaps that kept getting exploited, the controls that kept being skipped. The framework reflects that input. Which is also why we know exactly how auditors interpret each one.
| No. | Control Area | Description |
|---|---|---|
| 01 | Effective Asset Management | Know every device, software, and data asset in your business. Track them from day one to secure disposal. Nothing unknown should exist on your network. |
| 02 | Network & Email Security | Proper firewalls. Secure Wi-Fi (WPA2/WPA3). VPN and MFA for remote access. Email protection via SPF, DKIM, DMARC — the front line against phishing. |
| 03 | Endpoint & Mobile Security | Licensed EDR on every device. No pirated software. USB restrictions. Built-in OS security features switched on — no exceptions. |
| 04 | Secure Configurations | Configure every server, endpoint, and application securely before it goes live. Disable what you don’t use. Default settings are not safe settings. |
| 05 | Patch Management | Update regularly — operating systems, applications, firmware. Unpatched systems are open doors. Attackers scan for known vulnerabilities within hours of public disclosure. |
| 06 | Incident Management | Have a plan before you need one. Detection, response, investigation, recovery — all mapped out. Major incidents must be reported within 6 hours of detection. |
| 07 | Logging & Monitoring | Record system activities. Monitor anomalies. Retain logs for 180 days within India — a mandatory legal requirement. |
| 08 | Awareness & Training | Train employees at least twice a year on phishing, passwords, data protection, and social engineering. |
| 09 | Third-Party Risk Management | Evaluate vendor security posture. Enforce security standards contractually. Your vendors inherit your risk. |
| 10 | Data Protection, Backup & Recovery | Use encrypted backups stored offline/offsite. Test recovery regularly. If you can’t restore it, it doesn’t count. |
| 11 | Governance & Compliance | Assign cybersecurity ownership. Maintain approved policies. Follow regulatory guidelines — accountability is critical. |
| 12 | Robust Password Policy | Enforce strong passwords, account lockouts, and MFA. Avoid password reuse at all costs. |
| 13 | Access Control & Identity Management | Use unique user IDs, role-based access, and regular permission reviews. Revoke access immediately on role change or exit. |
| 14 | Physical Security | Secure server rooms and infrastructure with controlled access, CCTV, badges, and biometrics where required. |
| 15 | Vulnerability Audits & Assessments | Conduct annual audits via certified auditors. Focus on remediation — not just assessment. |
Use this MSME compliance checklist to run an honest check against all 15 controls. Most MSMEs find critical gaps in logging, third-party risk, and incident response. Find yours before your auditor does.
Download the free CERT-In MSME self-assessment checklistThe controls make sense. Implementation is where it breaks down — not from lack of intent, but from the natural constraints of running a business without a dedicated security team.
At xIoTz, we’ve worked with MSMEs across manufacturing, fintech, logistics, healthcare, and retail. The failure patterns are remarkably consistent — regardless of sector, size, or how long a business has been operating.
Security responsibilities get distributed across whoever is available. No single person tracks whether patches are applied, logs are retained, or access permissions were reviewed this quarter.
Antivirus on one system. Firewall managed separately. Backups handled by someone else. Each piece works in isolation — and the gaps between tools are exactly where attacks happen.
Many businesses can’t tell you every device connected to their network right now. Shadow IT — personal phones, unregistered laptops, unauthorized cloud apps — creates exposure nobody is tracking.
Something breaks, someone responds. Nothing breaks, nothing changes. The industry average for breach discovery is still six months — and the damage is done long before detection.
What xIoTz found across MSME audits:
The most common gap isn’t a missing firewall or weak password.
It’s the absence of a single owner.
When nobody is personally accountable for cybersecurity, every control slowly drifts — patches slip, logs fill up and get ignored, access permissions accumulate like clutter.
That’s the problem xIoTz Unified Cyber Assurance was built to solve.
Most businesses treat compliance like an annual event. Prepare for the audit. Pass the audit. Forget about it until next year.
That is not how cybersecurity works.
The NIST Cybersecurity Framework defines cybersecurity as a continuous cycle: Identify, Protect, Detect, Respond, Recover.
India’s own National Cyber Security Policy reinforces the same principle — ongoing vigilance, not periodic checkbox exercises.
Threats don’t pause between audits.
Attackers don’t wait for your preparation window.
The six-month problem:
The industry average time to detect a breach is still six months.
If your monitoring only runs during audit prep, you are effectively blind for most of the year — and the damage accumulates silently the entire time.
Continuous compliance means monitoring runs 24/7.
Logs are retained automatically.
Configuration drift is flagged in real time.
When an audit arrives, the evidence is already there — timestamped, organized, and ready.
This is exactly how xIoTz Unified Cyber Assurance works.
Because we helped design the CERT-In standard, we built the platform around it — not retrofitted it after the fact.
Every one of the 15 controls maps directly to a function in our platform. NOC, SOC, TOC, CSPM, and Compliance run as a single integrated layer, deployed in under 2 hours, at 90% less than traditional enterprise security costs.
Compliance stops being an event. It becomes the natural outcome of simply running your business securely.
This is not about passing an audit. Here’s what actually changes for your business:
Most breaches exploit basic, preventable gaps. Close the gaps.
Remove the easiest attack paths. The majority of attackers are opportunistic — they move to easier targets when yours is hardened.
With monitoring in place and an incident response plan ready, you contain damage in hours — not months.
The 6-hour CERT-In reporting window is only possible if you’re already watching.
Enterprise clients ask about your security posture before signing contracts.
Regulators expect it.
Customers are increasingly aware of it.
Strong cybersecurity is now a competitive differentiator — not just a compliance checkbox.
Organizations with tested backups, recovery plans, and active monitoring get back on their feet after an incident.
Those without them often don’t.
It is that simple.
There are dozens of cybersecurity vendors who will sell you a CERT-In compliance solution.
Very few of them were involved in building the standard they’re selling against. xIoTz was.
That distinction matters — not as a marketing claim, but as a practical advantage.
When our platform maps to Control 7 (Logging & Monitoring) or Control 6 (Incident Management), it does so because we understand how CERT-In auditors interpret those controls, what evidence they look for, and what “compliant” actually means in practice versus on paper.
We also built xIoTz for the reality of running an MSME — not for the fantasy of having a 10-person security team.
Two-hour deployment.
No specialist required.
30+ security products unified into one platform.
Continuous monitoring so your compliance evidence is always ready, not assembled in a panic before the audit.
The businesses that survive incidents aren’t the ones who prepared for the audit.
They’re the ones who never stopped being secure.
xIoTz helped define the CERT-In MSME standard. We also built a platform to help you meet it — deployed in 2 hours, at 90% less cost than enterprise alternatives, with continuous compliance built in from day one.
Book ConsultationLearn CERT-In Compliance
xIoTz helped shape India's CERT-In compliance framework. Here's the practitioner's checklist — all 15 controls, the penalties most businesses don't know about, and how to...

India's 63 million MSMEs finally have a cybersecurity baseline. xIoTz has contributed to the National Cybersecurity Framework for MSMEs — specifically the 15 Elemental Cyber...

xIoTz Private Limited has been named the winner of a national defence innovation challenge for developing an indigenous Security Information and Event Management (SIEM) solution...
xIoTz UCAP is a self-healing military grade solution built on an Edge-Cloud platform providing 30+ Security Products built-in & integrated with SIEM enabling cyber safety & data assurance.
xIoTz Private Limited © 2026 | All Rights Reserved