E-Governance
GIGW 3.0 Compliance Checklist for Government Websites
Affix Center · · 6 min read

Most government departments know their website must follow GIGW, but few have a clear view of what the latest version actually asks for. A GIGW 3.0 compliance checklist turns a long guideline document into tasks that a web team, a vendor and a nodal officer can track. Without one, compliance becomes a last-minute scramble before an audit, and the same issues come back every year.
The Guidelines for Indian Government Websites and Apps (GIGW) 3.0 were released in 2023. They raise the accessibility bar to WCAG 2.1 Level AA, cover mobile apps as well as websites, and add a cybersecurity chapter prepared with CERT-In. For a state department in Maharashtra, a municipal corporation in Thane or a PSU in Mumbai, this means older portals built to GIGW 2.0 are likely to have gaps. This article sets out a practical checklist you can use to find and close them.
What Changed in GIGW 3.0
GIGW 3.0 is not a small revision. The guidelines are organised around six areas of improvement:
- Structure: clearer roles and responsibilities for the people who own and run a website.
- Quality: better user interface, user experience and user-centred information architecture.
- Accessibility: conformance to WCAG 2.1 Level AA, which adds 17 success criteria over the WCAG 2.0 baseline used earlier.
- Cybersecurity: a dedicated chapter formulated by CERT-In covering websites, portals, web applications and mobile apps.
- Lifecycle management: policies to keep quality high after launch, not just on launch day.
- Risk and mitigation: each guideline is mapped to the risk it addresses.
The practical effect is that compliance is now continuous. A portal that passed an audit once can fall out of compliance through stale content, a broken form or an unpatched plugin.
GIGW 3.0 Compliance Checklist: Governance and Ownership
Start with people and policy. Many compliance failures are really ownership failures.
- Appoint a Web Information Manager. GIGW 3.0 expects a named officer responsible for the quality of the website across its lifecycle.
- Write down the website policies. Copyright, hyperlinking, privacy, terms of use, content contribution and archival policies should be published and current.
- Set a content review schedule. Decide who reviews each section, how often, and how outdated content is archived.
- Keep a contact and feedback mechanism. Citizens should be able to report problems, and someone must respond.
- Document your vendor responsibilities. If an agency maintains the site, the contract should state its compliance duties.
Accessibility Checklist for WCAG 2.1 Level AA
Accessibility is the area where most government sites fall short. It also has a legal basis: the Rights of Persons with Disabilities Act, 2016 requires accessible information and communication technology. Check the following:
Content and structure
- Every meaningful image has alternative text. Decorative images are marked so screen readers skip them.
- Pages use proper heading order, so a screen reader user can scan them.
- PDFs are tagged and readable, or the same content is also available as an HTML page.
- Link text makes sense on its own. Avoid a page full of "click here".
Visual and interaction
- Text meets colour contrast requirements against its background.
- Content reflows at 400 percent zoom without horizontal scrolling, a WCAG 2.1 addition that matters for mobile users.
- All functions work with a keyboard alone, with a visible focus indicator.
- Forms have labels, clear error messages and no time limits that cannot be extended.
- Videos have captions, and audio content has transcripts.
Language
- Bilingual or multilingual pages declare the correct language, so Marathi or Hindi text is read correctly by assistive tools.
Automated scanners catch some of these issues. Many others, such as sensible reading order or meaningful alt text, need manual testing with screen readers.
Security Checklist from the CERT-In Chapter
The cybersecurity chapter is where GIGW 3.0 overlaps with broader government security practice. A sound checklist includes:
- Security audit before hosting. Obtain a "safe to host" certificate from an auditor empanelled by CERT-In or STQC, or from STQC or NIC auditors.
- Re-audit after major changes. New modules, a new CMS version or a new payment integration should trigger fresh testing.
- HTTPS everywhere with valid certificates and secure configuration.
- Patch management for the CMS, plugins, frameworks, web server and database.
- Secure admin access through strong authentication, restricted IPs where possible and removal of unused accounts.
- Logging and monitoring so that incidents can be detected and reported on time.
- Backups that are tested, not just scheduled.
If your team needs support here, our cybersecurity services cover vulnerability assessment, hardening and monitoring for government applications.
Quality, Usability and Lifecycle Checks
GIGW 3.0 puts real weight on the citizen experience. These checks are often skipped because they seem cosmetic, but they affect compliance and public trust.
- Mobile readiness: the site works on common Android phones and slow connections.
- Search: an internal search that returns relevant results.
- Navigation: a sitemap, breadcrumb trail and consistent menus.
- Identity: the department name, emblem and ownership are clear on every page.
- Freshness: each page shows a last updated date, and tenders, circulars and notices are archived once expired.
- Performance: pages load quickly, with compressed images and caching.
- Monitoring: a dashboard or regular report flags broken links, downtime and non-conformities.
For mobile apps, apply the same thinking: accessibility, secure data storage, permissions limited to what the app needs and regular updates.
How to Run a GIGW 3.0 Gap Assessment
A structured gap assessment, run against a GIGW 3.0 compliance checklist like the one above, keeps the work manageable. A typical sequence looks like this:
- Inventory. List every website, sub-domain, portal and app your department owns. Forgotten microsites are a common risk.
- Automated scan. Run accessibility and security scans to find obvious issues quickly.
- Manual review. Test key user journeys, such as applying for a service or downloading a form, with keyboard and screen reader.
- Prioritise. Fix security issues and blockers for disabled users first, then usability and content gaps.
- Remediate and retest. Track each issue to closure with evidence.
- Audit and certify. Engage an empanelled auditor for security and, where required, apply for STQC website quality certification.
- Maintain. Add compliance checks to every release and content update.
Where the underlying platform is too old to fix economically, rebuilding on a modern, accessible CMS is often cheaper over time. Our e-governance services team can help decide between remediation and rebuild.
Frequently Asked Questions
Is GIGW 3.0 compliance mandatory?
GIGW applies to websites and apps of Indian government ministries, departments and organisations. Many departments also require compliance in tenders for portals built by vendors.
Which WCAG version does GIGW 3.0 follow?
GIGW 3.0 requires conformance to WCAG 2.1 Level AA. GIGW 2.0 was based on WCAG 2.0.
Does GIGW 3.0 apply to mobile apps?
Yes. The guidelines cover government websites and mobile apps, including their accessibility and security.
How long does GIGW 3.0 remediation take?
It depends on the size of the site, the age of the platform and the number of issues found. A small site may need a few weeks. A large portal with many services may need a phased plan.
How Affix Center Can Help
Affix Center works with government departments, PSUs and public bodies in Mumbai and across Maharashtra on portal development, accessibility remediation and security hardening. We can build a GIGW 3.0 compliance checklist for your portals, run a gap assessment, fix the issues we find and set up the processes that keep your site compliant after audit.
To discuss your website or app, contact our team.