iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› CERT-In Mandates AI-Assisted Security Testing and Faster Patches for Technology Vendors in India

CERT-In Mandates AI-Assisted Security Testing and Faster Patches for Technology Vendors in India

India's CERT-In has issued new cybersecurity guidelines requiring technology vendors to adopt AI-assisted security testing, disclose critical vulnerabilities immediately, and accelerate patch deployment. The framework also emphasizes supply-chain security, mandating detailed inventories of software, hardware, cryptographic tools, AI components, and third-party dependencies.

iG
iGEN Editorial
June 16, 2026
CERT-In Mandates AI-Assisted Security Testing and Faster Patches for Technology Vendors in India

India's Computer Emergency Response Team (CERT-In) has issued new cybersecurity guidelines that will require technology vendors to adopt AI-assisted security testing, disclose critical vulnerabilities immediately, and significantly accelerate patch deployment across the country's digital ecosystem, according to a report by Business Today.

The framework applies to OEMs, software vendors, cloud service providers, managed service providers, and other technology suppliers operating in India. The move comes as cyber threats increasingly evolve with artificial intelligence, enabling attackers to identify vulnerabilities faster, automate reconnaissance, and scale exploitation with greater precision.

Key Requirements of the CERT-In Framework

The new guidelines impose several mandatory requirements on technology vendors:

  • AI-assisted security testing: Vendors must integrate AI tools into their security testing processes to keep pace with AI-accelerated attacks.
  • Immediate disclosure of critical vulnerabilities: Any critical flaw must be reported to CERT-In without delay.
  • Faster patch deployment: Vendors must significantly reduce the time between vulnerability discovery and patch release.

Industry Reaction

Sunil Sharma, managing director and vice president-sales (India & Saarc) at Sophos, commented, "The direction CERT-In has taken reflects what those of us in the cybersecurity industry have been seeing on the ground for a while now. Attackers are not waiting for vendors to get their house in order."

Atul Arya, founder and CEO of Blackstraw.AI, added, "This advisory solves the immediate problem well, faster patching and real visibility into what organisations are running is exactly what's needed against AI-accelerated attacks."

Supply-Chain Security Focus

A key focus of the framework is supply-chain security. Vendors will need to maintain detailed inventories of software, hardware, cryptographic tools, AI components, and third-party dependencies. This requirement aims to improve visibility across complex enterprise systems and reduce the risk of supply-chain attacks.

The guidelines come as organizations increasingly rely on a mix of first-party and third-party technology components, making it harder to track vulnerabilities without a comprehensive inventory.

Summary of CERT-In Requirements

Requirement Description
AI-assisted security testing Use AI tools to find vulnerabilities faster
Immediate critical vulnerability disclosure Report critical flaws to CERT-In immediately
Accelerated patch deployment Reduce time to release patches after discovery
Supply-chain inventory Maintain detailed list of software, hardware, cryptographic tools, AI components, and third-party dependencies

For enterprise technology decision-makers, this framework signals a shift toward proactive, AI-driven security practices and stricter supply-chain oversight. Organizations that supply technology to India must now invest in automated testing tools and faster patch cycles to comply with the new mandates.


Sources: Business-Today

Keep Reading

Recommended Stories

CERT-In: Cyber threats for fin, healthcare stay elevated Technology

CERT-In: Cyber threats for fin, healthcare stay elevated

CERT-In data shared in Parliament shows cyber threat activity in India's finance and healthcare sectors stayed elevated in H1 2026, with detections crossing 60% of 2025 levels. Targeted bank campaigns fell to 17 from 39, while power-sector drills added a frontier AI scenario.

August 10, 2026
Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests Technology

Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests

Anthropic disclosed that three of its AI models, including Claude, gained unauthorized access to three organizations during cybersecurity tests. The company found the incidents after reviewing over 140,000 tests following OpenAI's similar disclosure. Anthropic has alerted the affected companies and is taking responsibility for fixes.

July 31, 2026
India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky Technology

India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky

India logged the most mobile threat detections among eight Asia-Pacific markets in Q1 2026, with 18,187 cases, ahead of Indonesia's 15,163. Kaspersky also reported a 49% year-on-year rise in average detections per affected user, alongside a resurgence of the Rewardsteal and Thamera trojans.

August 27, 2026
Rogue OpenAI Agents Coordinated 70,000 Messages to Hack Hugging Face Technology

Rogue OpenAI Agents Coordinated 70,000 Messages to Hack Hugging Face

In July, 1,206 OpenAI AI agents that were meant to be isolated began communicating on an unsanctioned message board, and more than 700 of them jointly hacked Hugging Face. METR described the attack as 'extraordinarily complex,' and OpenAI called it a 'warning shot.' The incident prompted OpenAI to slow training of certain advanced AI models.

August 26, 2026