Skip to main content
State Emblem of India & Departmental Crest
CyberCheckIndia

GIGW 3.0 & STQC Pre-Audit Suite

GIGW 3.0 • WCAG 2.1 AA • CERT-In Baseline

Automated STQC & GIGW 3.0 Pre-Audit Readiness Suite

Eliminate audit rejections and win GeM tenders. Scan any Indian government or PSU portal in under 10 seconds for exact DOM element failures, security headers, and export a branded readiness PDF dossier.

Free Webmaster Tools: Instant CT Log Subdomain Discovery & Global DNS PropagationAll Tools Directory
Quick Test Samples:

< 10s

Execution Latency

High-speed AWS engine

WCAG 2.1 AA

RPwD Act 2016

Axe-Core DOM evaluator

CERT-In

Defensive Hardening

TLS 1.2/1.3 & HSTS matrix

1 Free Scan

Instant Onboarding

Full 15+ page PDF export

STQC Conformity Matrix

Five Modular Audit Engines Aligned With GIGW 3.0 & CERT-In VAPT

Every machine-testable rule mandated for Indian public-sector deployments is verified in parallel.

Category 1: Cybersecurity & Server Hardening (12 Tests)

Enforces CERT-In baseline security rules, modern cryptographic ciphers, and defensive headers.

  • TLS 1.2/1.3, Perfect Forward Secrecy (PFS) & cipher hardening
  • Certificate key length (≥2048-bit) & DNS CAA authorization record
  • Deep HSTS (1-year max-age, subdomains, preload) & COOP/COEP isolation
  • Server banner leakage, cloud credentials & exposed dotfiles detection

Category 2: Digital Accessibility (12 WCAG 2.1 AA Tests)

RPwD Act 2016 statutory compliance powered by Axe-Core and automated DOM checks.

  • Document language (lang), descriptive page <title> & contrast ratios
  • Viewport zoom scalability (blocks user-scalable=no) & skip links
  • HTML5 landmarks (<main>), headings & keyboard positive tabindex traps
  • Table headers (<th scope>), form labels & unmuted autoplay hazards

Category 3: Mandatory GIGW 3.0 Governance (15 Checks)

Detects required policies and statutory features unique to Indian Government sites.

  • Mandatory policy links: Privacy, Hyperlinking, Copyright, Terms, CMP
  • Designated Web Information Manager (WIM) & official ownership
  • State Emblem alt compliance, HTML Sitemap & CPGRAMS grievance link
  • Bilingual toggle, physical address PIN code & .gov.in domain check

Category 4: Performance, Mobile & Quality (10 Benchmarks)

Ensures portals deliver fast responsiveness, modern compression, and accessible documents.

  • Core Web Vitals (LCP/CLS) & Brotli/Gzip payload compression
  • Image explicit dimensions (CLS prevention) & native lazy loading
  • Modern HTTP/2 multiplexing & render-blocking CSS elimination
  • OCR tender document accessibility & download file size transparency

Category 5: VAPT & Web Penetration Testing (20 Vectors)

Advanced 20-vector non-destructive vulnerability assessment based on OWASP Top 10, ASVS Level 2, and CERT-In VAPT guidelines.

  • XSS sinks, SQLi error disclosure & CSP unsafe-inline / eval analysis
  • Exposed admin portals, GraphQL introspection & sensitive backup leaks
  • DNS email spoofing defense (SPF & DMARC) & cross-origin isolation (COOP/COEP)
  • Permissions-Policy, cookie hardening (__Host-), CORS reflection & security.txt
100% Free Public Webmaster Tools

DNS & Subdomain Reconnaissance Suite

Complement your GIGW 3.0 & STQC audit with free, zero-login network intelligence. Enumerate Certificate Transparency logs, uncover shadow IT subdomains, and verify global DNS propagation in real-time.

Explore All Free Tools
Unlimited & Free

Subdomain Finder & CT Log Enumerator

Discover all active and historical subdomains for any apex domain using public Certificate Transparency (CT) logs. Uncover exposed departmental staging portals, legacy servers, and API gateways before external audits.

Instant CT log indexing via crt.sh & crt.name
Live DNS reachability resolution (IPv4 & IPv6 A/AAAA records)
1-Click CyberCheck Pre-Audit Scan handoff & CSV/JSON export
Launch Subdomain FinderZero Sign-Up Needed
16+ Global Resolvers

Global DNS Propagation Checker

Verify DNS propagation across 16+ authoritative DNS resolvers across India (Mumbai, Delhi), US, Europe, Singapore, and Australia. Track TTL updates and diagnose misconfigured NS, MX, TXT, CAA, or A records in real-time.

Queries 16+ global servers: Google, Cloudflare, Quad9, OpenDNS, Level3
Supports 9 DNS record types: A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, PTR
Propagation match percentage gauge & millisecond latency timing
Check DNS PropagationLive Global Nodes

Why Subdomain Enumeration Matters for GIGW 3.0

Government portals frequently deploy unmanaged subdomains for tenders, employee portals, or temporary schemes. Under CERT-In guidelines, forgotten subdomains running legacy software represent high-risk attack surfaces. Our CT log enumerator surfaces every issued certificate so administrators can audit every public asset.

Why Global DNS Propagation Verification is Critical

When migrating to secure NIC cloud environments or rolling out DNSSEC / CAA policies, nameserver caching delays can cause localized outages. CyberCheck India checks DNS propagation across worldwide points of presence so webmasters can verify global resolution with 100% confidence.

Target Personas

Engineered For The GovTech Procurement Lifecycle

Agency Tech Lead / Bidder

GeM Tender RFP Submissions

Generate an official, branded GIGW 3.0 / STQC Readiness PDF within 60 seconds to attach to mandatory GeM tender technical proposals.

GovTech Developer

Pre-STQC Code Remediation

Pinpoint exact DOM selectors, failing HTML lines, missing headers, and copy-pasteable Nginx/Apache/HTML remediation snippets before audit submission.

Web Information Manager (WIM)

Accountable Government Officer

Non-technical executive scorecards verifying whether the contracted IT vendor actually delivered a secure, compliant, and accessible portal.

Statutory Compliance Architecture

Complete Guide to GIGW 3.0, STQC Certification & GeM Tender Audit Readiness

Under directives issued by the Ministry of Electronics and Information Technology (MeitY), all Indian government portals, Public Sector Undertakings (PSUs), autonomous bodies, and GeM RFP bidders must achieve full conformity with the Guidelines for Indian Government Websites (GIGW 3.0) and obtain STQC Website Quality Certification (CQW).

1. CERT-In Cybersecurity Baseline

Mandatory defense-in-depth posture: automated inspection of TLS 1.2/1.3 protocol ciphers, HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), anti-clickjacking headers (X-Frame-Options), secure cookie flags (HttpOnly, Secure, SameSite), and server version token suppression to prevent banner grabbing.

2. WCAG 2.1 AA & RPwD Act 2016

Legal mandate under Section 42 of the Rights of Persons with Disabilities Act 2016: headless DOM element auditing via Axe-Core engine, verifying color contrast thresholds (≥4.5:1), ARIA landmarks, form input labeling, descriptive link anchors, skip-to-content links, and complete keyboard navigability.

3. Mandatory GIGW 3.0 Governance

Administrative conformity required by STQC: presence of designated Web Information Manager (WIM) with contact details, active bilingual language switcher (English & Hindi), dedicated Screen Reader Access portal, and statutory policy pages (Privacy, Terms, Copyright, and Hyperlinking).

GIGW 3.0 Statutory Requirements vs. CyberCheck India Automated Inspection

Compliance DomainGoverning Standard / ClauseMandatory RequirementCyberCheck India Automated Engine
CybersecurityCERT-In / GIGW 3.0 Clause 6.1HTTPS enforcement, TLS 1.2/1.3, HSTS header, Secure cookiesAutomated parallel SSL/TLS handshake & header analyzer
AccessibilityWCAG 2.1 Level AA / RPwD ActContrast ≥ 4.5:1, Alt tags, Keyboard focus, ARIA labelsHeadless Axe-Core Playwright DOM rule verification
GovernanceGIGW 3.0 Clause 5.2 - 5.5Web Information Manager (WIM), Bilingual toggle, PoliciesSemantic DOM & anchor link scraper for required pages
PerformanceGIGW 3.0 Clause 7.2Core Web Vitals, accessible PDF/Word tenders, no 404 linksLighthouse CWV profiler & broken link detector
VAPT & PenetrationCERT-In VAPT / OWASP Top 10Non-destructive OWASP checks, sensitive exposures, admin portal protectionAutomated 12-vector OWASP penetration testing engine
Knowledge Base & FAQs

Frequently Asked Questions About GIGW 3.0 & STQC Audits

Everything you need to know about Indian government website compliance, STQC certification, and GeM procurement.

What is GIGW 3.0 compliance and who is required to adhere to it?

The Guidelines for Indian Government Websites (GIGW 3.0), formulated by the Ministry of Electronics and Information Technology (MeitY) and the National Informatics Centre (NIC), establish mandatory design, accessibility, security, and governance standards. All Central Ministries, State Government departments, PSUs, judicial portals, and IT vendors bidding on Government e-Marketplace (GeM) tenders must comply with GIGW 3.0.

How does CyberCheck India help achieve STQC Website Quality Certification (CQW)?

STQC (Standardisation Testing and Quality Certification) Directorate evaluates government websites before awarding the official Certified Quality Website (CQW) seal. CyberCheck India replicates STQC’s automated testing protocol, detecting non-compliant HTML elements, missing security headers, and accessibility violations in under 10 seconds, and generates an actionable remediation PDF dossier with exact code patches.

What are the mandatory CERT-In cybersecurity baseline checks?

Under CERT-In advisories and GIGW 3.0 Section 6, government websites must enforce strict HTTPS with TLS 1.2 or TLS 1.3 ciphers, implement HTTP Strict Transport Security (HSTS) with subdomains, deploy Content Security Policy (CSP), prevent clickjacking via X-Frame-Options, secure cookies with HttpOnly and Secure flags, and disable server identification headers (server tokens).

How does CyberCheck India test for WCAG 2.1 Level AA and RPwD Act 2016?

Section 42 of the Rights of Persons with Disabilities (RPwD) Act 2016 legally requires all electronic content and websites to be accessible to persons with disabilities. CyberCheck India executes an automated Axe-Core inspection engine on headless browsers to test color contrast (minimum 4.5:1 ratio), image alternate text, keyboard-only tab order, ARIA landmark roles, and screen reader compatibility.

Can CyberCheck India audit reports be submitted with GeM tender technical proposals?

Yes. GeM (Government e-Marketplace) tenders for website development, portal modernization, and annual maintenance contracts (AMC) frequently require bidders to demonstrate pre-audit readiness. CyberCheck India generates an official, timestamped STQC Pre-Audit Readiness PDF Dossier complete with executive scores, category breakdowns, and compliance checklists suitable for technical RFP bid attachments.

What is the difference between GIGW 2.0 and GIGW 3.0?

While GIGW 2.0 focused primarily on static desktop accessibility and basic security, GIGW 3.0 introduces mobile-first responsive guidelines, Core Web Vitals performance benchmarks, modern cyber defense headers (CSP, HSTS), bilingual content mandates, lifecycle governance, and integration readiness for public digital platforms (India Stack).

What is a Web Information Manager (WIM) and why is it mandatory?

Under GIGW 3.0 Clause 5.2, every government department must officially nominate a Web Information Manager (WIM)—an officer responsible for content accuracy, currency, and statutory compliance. The WIM’s name, official email (info@abhixtechlabs.com), phone number (+91 95992 27596), and postal address must be prominently displayed on the website.

How long does an audit scan take and what is included in the free tier?

CyberCheck India completes a multi-category audit scan in under 10 seconds using distributed cloud workers. Every new user receives 1 Free Full Category Audit upon sign in, including interactive web findings, code remediation snippets, and full downloadable report export.

Is the CyberCheck Subdomain Finder free and how does Certificate Transparency work?

Yes, our Free Subdomain Finder is completely free with no registration required. It queries public, tamper-evident Certificate Transparency (CT) logs via crt.sh and crt.name. Because all public SSL/TLS certificates must be logged cryptographically, this tool surfaces departmental subdomains, forgotten staging environments, and API endpoints, while simultaneously verifying live IPv4/IPv6 reachability.

How does the Global DNS Propagation Checker verify DNS records?

Our Global DNS Propagation Checker performs non-cached lookups across 16+ geographic DNS resolvers worldwide, including nodes in Mumbai, Delhi, Singapore, Frankfurt, London, New York, San Francisco, and Sydney. It tests 9 critical record types (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, PTR) and computes live propagation percentages and query latencies.