CERT-In's 15 Essential Cyber Security Controls for MSMEs: A Practical Implementation Guide
Introduction
Cybersecurity has become a business necessity for every organization. As cyber threats continue to evolve, many Indian small and medium enterprises (MSMEs) struggle to understand where to begin.
To help organizations strengthen their cyber resilience, the Indian Computer Emergency Response Team (CERT-In) has published the 15 Essential Cyber Security Controls for MSMEs. These controls provide practical guidance that organizations can adopt to improve their security posture without requiring large security teams or expensive technology.
This guide explains each control in simple language and provides practical recommendations for implementation.
What is CERT-In?
The Indian Computer Emergency Response Team (CERT-In) is the national agency responsible for responding to cybersecurity incidents and strengthening cyber resilience across India.
CERT-In regularly publishes advisories, best practices, vulnerability alerts, and security recommendations for government departments, enterprises, and MSMEs.
The 15 Essential Cyber Security Controls serve as a practical baseline that organizations can use to improve their cybersecurity maturity.
Are the 15 Controls Mandatory?
The 15 Essential Cyber Security Controls are recommended best practices, not a standalone law.
However, implementing these controls can help organizations:
-
Improve cyber resilience
-
Reduce operational risk
-
Prepare for customer security assessments
-
Support compliance with other regulations such as the Digital Personal Data Protection (DPDP) Act
-
Demonstrate good cybersecurity governance
Organizations operating in regulated sectors may also need to comply with additional industry-specific requirements.
CERT-In's 15 Essential Cyber Security Controls
1. Asset Inventory
Know what hardware, software, cloud services, and digital assets your organization owns.
Practical Steps
-
Maintain an inventory of laptops and servers.
-
Document software licenses.
-
Track cloud accounts.
-
Remove unused systems.
2. Identity and Access Management
Ensure that users have only the access they need.
Best Practices
-
Enable Multi-Factor Authentication (MFA)
-
Use strong passwords
-
Remove inactive accounts
-
Review user permissions regularly
3. Secure Configuration
Avoid using default configurations.
Examples include:
-
Disable unnecessary services
-
Change default passwords
-
Apply secure configuration baselines
-
Restrict administrative access
4. Patch Management
Keep operating systems and applications updated.
Organizations should:
-
Install security updates promptly
-
Prioritize critical vulnerabilities
-
Maintain an update schedule
5. Malware Protection
Deploy modern endpoint protection solutions.
Recommendations include:
-
Antivirus or Endpoint Detection and Response (EDR)
-
Email malware scanning
-
Web filtering
-
USB device controls
6. Backup and Recovery
Maintain secure backups of critical business data.
A good backup strategy includes:
-
Regular automated backups
-
Offline or immutable backups
-
Periodic recovery testing
7. Network Security
Protect internal and external network traffic.
Typical controls include:
-
Firewalls
-
Network segmentation
-
Secure Wi-Fi
-
VPN for remote access
8. Email Security
Email remains one of the primary attack vectors.
Organizations should implement:
-
SPF
-
DKIM
-
DMARC
-
Anti-phishing protection
-
Email filtering
9. Logging and Monitoring
Collect and review security logs to detect suspicious activity.
Monitor:
-
Login attempts
-
Administrative actions
-
Failed authentication
-
System changes
10. Vulnerability Assessment
Regularly identify security weaknesses.
This may include:
-
Vulnerability scanning
-
Configuration reviews
-
Cloud security assessments
11. Incident Response
Prepare for security incidents before they occur.
Every organization should have:
-
Incident response procedures
-
Contact lists
-
Escalation processes
-
Recovery plans
12. Employee Awareness
Human error remains one of the largest cybersecurity risks.
Conduct regular awareness training covering:
-
Phishing
-
Password hygiene
-
Safe internet practices
-
AI usage policies
13. Data Protection
Protect sensitive business and personal data.
Measures include:
-
Encryption
-
Access controls
-
Secure sharing
-
Data classification
14. Third-Party Risk Management
Assess the cybersecurity practices of vendors and service providers.
Review:
-
Cloud providers
-
Software vendors
-
Outsourced IT partners
15. Governance and Continuous Improvement
Cybersecurity should be reviewed continuously rather than treated as a one-time project.
Organizations should:
-
Review security posture regularly
-
Track improvement over time
-
Assign ownership
-
Measure cyber readiness
Practical Implementation Roadmap for MSMEs
Organizations do not need to implement all controls simultaneously.
A phased approach works best.
Phase 1 – Foundation
-
Asset Inventory
-
MFA
-
Backups
-
Antivirus
-
Email Security
Phase 2 – Strengthening
-
Patch Management
-
Vulnerability Assessment
-
Logging
-
Secure Configuration
Phase 3 – Governance
-
Incident Response
-
Vendor Risk
-
Data Protection
-
Security Awareness
-
Continuous Cyber Readiness Reviews
Common Challenges Faced by MSMEs
Many organizations struggle because they:
-
Have limited cybersecurity expertise
-
Use multiple disconnected security tools
-
Lack visibility into cloud environments
-
Cannot prioritize remediation efforts
-
Are unsure which controls need immediate attention
Rather than implementing controls in isolation, organizations benefit from understanding their overall cyber readiness and focusing on the most significant risks first.
How CyBelt Helps
CyBelt helps organizations continuously assess their cyber readiness by evaluating key security domains, identifying gaps aligned with recognized cybersecurity practices, and prioritizing remediation actions in clear business language.
Instead of generating lengthy technical reports, CyBelt provides actionable recommendations that help organizations improve security posture over time while supporting compliance initiatives.
Frequently Asked Questions
Does CERT-In require all MSMEs to implement these controls?
The controls are recommended best practices that provide a strong cybersecurity baseline. Organizations in regulated sectors may have additional mandatory requirements.
How often should these controls be reviewed?
Cybersecurity should be reviewed continuously. At a minimum, organizations should reassess their controls annually or whenever significant changes occur.
Are these controls sufficient for DPDP compliance?
The controls support stronger security practices but do not, by themselves, guarantee compliance with the Digital Personal Data Protection (DPDP) Act. Organizations should also address privacy governance, consent management, and other legal obligations.
Do I need expensive cybersecurity software?
Not necessarily. Many organizations can significantly improve their security posture through better configurations, strong identity management, timely patching, employee awareness, and regular assessments before investing in additional tools.


