CERT-In Guidelines on AI-Accelerated Vulnerability Protection and Response Requirements for OEMs and Technology Providers

Jun 16, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Indian Computer Emergency Response Team (CERT-In) on June 10, 2026, has issued Guidelines on AI-Accelerated Vulnerability Protection and Response Requirements for Original Equipment Manufacturers (OEMs) and Technology Providers in view of the evolving cybersecurity threat landscape driven by artificial intelligence and automated exploitation techniques. Recognising the increasing use of AI-enabled tools by threat actors for vulnerability discovery, exploit generation, reconnaissance, and cyberattacks, the guidelines prescribe enhanced cybersecurity practices for OEMs, software vendors, hardware manufacturers, cloud service providers, managed service providers, system integrators, and other technology providers operating in India.

The following has been stated:

The guidelines require OEMs and technology providers to establish comprehensive cybersecurity governance, secure development practices, and continuous vulnerability management mechanisms. Organizations are advised to conduct both traditional and AI-assisted security testing, maintain updated hardware and software bills of materials (including Software Bills of Materials (SBOMs)), assess risks associated with AI-enabled services, and implement appropriate safeguards to prevent misuse of AI systems. Specific obligations include continuous vulnerability assessments, immediate disclosure of critical and high-severity vulnerabilities and zero-day exploits to affected entities and CERT-In, and maintenance of evidence demonstrating AI-assisted security testing and certification.

The guidelines further prescribe accelerated patch management timelines based on the severity and exploitability of vulnerabilities, while requiring OEMs to provide interim mitigation measures where immediate patching is not feasible. They also mandate implementation of Secure Development Lifecycle (SDL) practices, robust credential and access management controls, formal incident response and vulnerability disclosure processes, and timely reporting of cyber incidents in accordance with CERT-In directions. In addition, OEMs and technology providers are required to maintain security posture assessments, remediation action plans, compliance commitments, continuous security assessment reports, and SDL compliance certifications. The guidelines also empower Indian organizations and CERT-In to conduct independent security assessments, request security documentation, and verify compliance. Overall, the framework aims to strengthen cybersecurity resilience, improve vulnerability management, and ensure rapid response to AI-assisted cyber threats across India's digital ecosystem.


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT