Timeline for audit request processing¶
(With effect from 1-Jan-2019)
On receipt of audit request
For in-house or NIC coordinated dynamic websites¶
Assigning to auditor – same day.
Acceptance by auditor – same day.
Information to developer / coordinator – same day.
After receipt of source code in sFTP server start of source code analysis – within one day.
Source code analysis report preparation and submission to developer – within two days.
Blackbox audit report preparation and submission to developer – three to five days.
Manual audit first report preparation and submission to developer – five to fifteen days.
Manual audit subsequent report preparation and submission to developer – three to ten days.
Issue of clearance note after receipt of report from auditor as “safe to host” – same day.
For static websites with self-certificate¶
Issue of clearance note with no issues – same day.
For websites audited by CERT-IN empanelled auditor¶
Issue of clearance note with no issues – within two days.
For replica websites¶
Issue of clearance note for replica websites with valid audit clearance of original website – within one day.
sFTP Server user account authorization¶
Authorization of user for uploading source code in sFTP server on receipt of public key – same day.
Reminder to coordinator for response¶
Static websites – reminder to be sent if no response is received within 7 days.
Dynamic websites – reminder to be sent if no response is received within 15 days.
Third party audited websites - reminder to be sent if no response is received within 15 days.