Alastor InfoSec
← Back to Blog
Compliance

July 31, 2026 · Alastor InfoSec Team

CERT-IN AI Cybersecurity Guidelines 2026: What Indian OEMs and Tech Providers Must Implement Now

India's cybersecurity regulator moved decisively in June 2026. The Indian Computer Emergency Response Team (CERT-IN) issued formal guidelines requiring all Original Equipment Manufacturers (OEMs) and technology providers operating in India to implement AI-accelerated vulnerability protection programmes — covering AI-assisted security testing, continuous monitoring, automated patch management, and structured incident response frameworks. This is not an advisory. It is a regulatory direction backed by CERT-IN's enforcement posture, which has shifted sharply from guidance to formal proceedings over the past eighteen months.

For Indian OEMs, SaaS platforms, infrastructure vendors, and technology service providers, June 2026 marks the point at which AI security testing stopped being an optional enhancement and became a compliance baseline.

What Triggered the New Guidelines

The guidelines emerged from a pattern CERT-IN documented across the first half of 2026: AI-driven threat actors compressing exploit timelines to windows that traditional patch management cannot meet. While CERT-IN has long mandated incident reporting within six hours and patching of critical internet-facing flaws within twelve hours, the underlying problem is that vulnerabilities are now being discovered, weaponised, and deployed by adversaries using the same AI tools that defenders have only recently begun to adopt.

CERT-IN conducted ten tailored cybersecurity exercises during June and July 2026 specifically themed around "Building Resilience against Frontier AI-driven Cyber Threats." The findings from those exercises directly informed the June guidance. The regulator also deployed AI-driven situational awareness systems internally to detect malicious domains and phishing activity, and extended AI-enabled vulnerability assessments for public-facing government digital assets in a sandbox environment. The June guidelines effectively ask the private sector to match this posture.

What the Guidelines Require

The June 2026 CERT-IN directive covers four operational domains for OEMs and technology providers.

AI-Assisted Security Testing means organisations can no longer rely solely on annual penetration testing or periodic vulnerability scans. The guidelines require that security testing programmes incorporate automated, continuous assessment capabilities. This means deploying tools capable of testing against the latest threat intelligence rather than only against a fixed vulnerability database refreshed quarterly.

Continuous Monitoring goes beyond traditional SIEM implementation. CERT-IN expects technology providers to operate real-time asset visibility covering internet-facing infrastructure, supply chain integrations, and third-party API connections. Shadow IT and undiscovered assets are explicitly called out as a risk category that continuous monitoring must address.

Patch Management with AI-Prioritised Timelines reflects the twelve-hour patching mandate CERT-IN issued earlier in 2026 for critical internet-facing flaws. The June guidelines extend this with an expectation that OEMs use automated vulnerability correlation to identify which flaws in their product lines are being actively exploited in the wild, and push patches through customer update channels within those compressed timelines.

Incident Response Frameworks must now be tested at least annually and must specifically address AI-driven threat scenarios — including synthetic phishing, automated credential stuffing, and AI-generated malware variants. The framework must demonstrate documented playbooks, a tested communication chain, and defined notification timelines aligned to CERT-IN's six-hour reporting requirement.

The Connection to DPDPA Enforcement

The June 2026 CERT-IN guidelines land fifteen weeks before DPDPA Phase 2 enforcement begins on November 13, 2026. The overlap is not coincidental. CERT-IN's mandate for continuous monitoring and AI-assisted security testing directly addresses one of the primary obligations Data Fiduciaries face under the Digital Personal Data Protection Act: the requirement to implement appropriate technical and organisational measures to protect personal data.

Under DPDPA, a data breach that was preventable — meaning one where known vulnerabilities in public-facing systems went unpatched — carries a penalty of up to ₹250 crore per violation from the Data Protection Board of India (DPBI), which is now actively being staffed. Demonstrating that your security programme meets CERT-IN's AI-assisted testing standard is the fastest way to show the DPBI that you took reasonable measures. Conversely, organisations that cannot document continuous monitoring and vulnerability assessment at the time of a breach will face compounded regulatory exposure from both CERT-IN and the DPBI.

What Good Looks Like in Practice

Building the capability CERT-IN now requires does not mean replacing your security team with AI. It means instrumenting your environment so that AI handles the volume problem — continuous discovery, correlation of threat intelligence with your specific asset inventory, and prioritised patch queuing — while human security engineers focus on validation, complex finding assessment, and the judgement calls that automated systems still cannot make reliably.

Practically, this means three things for OEMs and technology providers. First, attack surface discovery needs to run continuously, not as a point-in-time exercise. Your external-facing asset inventory must be updated in real time as new subdomains, APIs, and cloud resources are provisioned. Second, vulnerability assessment must be correlated against live exploit intelligence — a CVE with a CVSS 9.8 score that has no known public exploit is materially different from a CVE with a CVSS 6.5 score that CISA added to its Known Exploited Vulnerabilities catalog yesterday. Third, evidence of all of this activity must be collected, timestamped, and stored in a format that can be presented to CERT-IN or the DPBI during an investigation.

The Space Sector and Joint Guidelines

One specific vertical worth noting: CERT-IN also issued joint guidelines with the Satcom Industry Association (SIA-India) in 2026 specifically addressing cybersecurity for India's space sector. With India's commercial space sector growing rapidly, OEMs supplying hardware and software to satellite operators and ground station infrastructure now face a distinct compliance layer on top of the general June 2026 guidance. If your organisation touches space or critical national infrastructure, the SIA-India joint guidelines apply alongside the broader CERT-IN OEM directive.

How Alastor InfoSec Maps to the Requirement

Alastor InfoSec's Enforster AI platform is built precisely for the compliance profile CERT-IN's June 2026 guidelines describe. Enforster AI combines AI-powered SAST, DAST, dark web monitoring, MCP security scanning, and GitHub leak detection into a continuous assessment engine that runs without human intervention between formal testing cycles. When a new exploit is added to the CISA KEV catalog or CERT-IN issues an advisory, Enforster AI correlates that intelligence against your specific asset inventory immediately.

Alastor Shield provides the compliance evidence layer: every scan, finding, and remediation action is automatically mapped to CERT-IN obligations, DPDPA controls, ISO 27001 clauses, and SOC 2 criteria. This means when CERT-IN asks your organisation to demonstrate compliance with the June 2026 AI vulnerability protection mandate, the evidence package is already assembled.

For OEMs and technology providers who need to meet the continuous monitoring and AI-assisted testing standard before November 2026, we can have Enforster AI operational against your environment within days — not months. Reach out to [email protected] or visit /products/enforster-ai to start.


CERT-IN's June 2026 AI cybersecurity guidelines establish continuous monitoring and AI-assisted security testing as the new compliance baseline for Indian OEMs and technology providers — organisations that cannot demonstrate this posture by November 2026 face compounded exposure from both CERT-IN and the DPBI under DPDPA.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.