Cloud & Infrastructure

MeitY Empanelled Cloud Service Providers: The Basics

Affix Center · · 6 min read

MeitY Empanelled Cloud Service Providers: The Basics - Affix Center

A state department wants to move its portal off an ageing server room. A municipal body needs extra capacity every year when property tax bills go out. A PSU wants disaster recovery without building a second data centre. In each case the question comes up quickly: which cloud can a government organisation legally and safely use? For most public sector workloads in India, the answer starts with MeitY empanelled cloud service providers.

The rules are not complicated, but they are often misunderstood. Teams assume any large cloud brand qualifies, or that empanelment covers every region and service a provider sells. That leads to procurement objections and audit remarks later. This guide explains the basics of MeitY empanelment and gives a practical path for hosting government applications in the cloud.

What MeitY Empanelment Means

Under the Government of India's cloud initiative, known as GI Cloud or MeghRaj, the Ministry of Electronics and Information Technology (MeitY) empanels cloud service offerings for use by government organisations. A provider applies, and its specific offering is audited by STQC (the Standardisation Testing and Quality Certification Directorate) against MeitY's technical and security requirements. Only offerings that pass are empanelled.

The important point is that empanelment is for a specific cloud service offering, often tied to particular data centre regions in India. It is not a blanket approval of everything a company sells. Before you commit, check that the exact services and regions you plan to use are covered by the current empanelment.

Deployment Models You Will See

MeitY empanelment covers different deployment models. Understanding them helps you match the model to the sensitivity of your application.

Public cloud

Shared infrastructure offered to many customers, with logical separation between tenants. It suits citizen facing portals, websites and applications with variable traffic.

Virtual private cloud

An isolated section of cloud infrastructure with stronger network separation and controls. It is often chosen for applications that handle personal data or internal government processes.

Government community cloud

Infrastructure dedicated to government users only, with extra restrictions on who can share the environment. It is used for workloads that need a higher level of isolation.

Your department's data classification and any guidance from your IT or security wing should decide which model to choose, not price alone.

Key Requirements to Check Before Choosing

When shortlisting MeitY empanelled cloud service providers, go beyond the empanelment list and check the practical details:

  • Data location: confirm that data, backups and disaster recovery copies will stay in Indian data centres, as MeitY's framework requires for empanelled offerings.
  • Service scope: check that the compute, storage, database, backup and security services you need are part of the empanelled offering.
  • Security controls: encryption at rest and in transit, identity and access management, logging and firewall options.
  • Service levels: uptime commitments, support response times and penalties.
  • Exit terms: how you will get your data back, in what format and within what time, if you change provider.
  • Billing clarity: how compute, storage, bandwidth and backup are charged, so budget surprises do not appear mid year.

Procurement Basics for Government Buyers

Government organisations must follow their procurement rules, and cloud is no exception. A few practical points:

  1. Use approved channels. Cloud services from empanelled providers can be procured through the Government e-Marketplace (GeM). Check your department's rules for thresholds and approvals.
  2. Size before you buy. Estimate compute, storage and bandwidth from current usage and expected growth. Oversizing wastes money. Undersizing hurts citizens during peak demand.
  3. Separate cloud and managed services. The cloud provider supplies infrastructure. Someone still needs to set up, secure, patch, monitor and back up your workloads. Decide whether that is your own team, a system integrator or a managed service partner, and put it in scope.
  4. Define responsibilities in writing. Cloud security is shared. The provider secures the underlying platform. You remain responsible for your operating systems, applications, user access and data.

A Practical Migration Plan

  1. Inventory your applications. List every application, database, integration and dependency. Note the owner and the data each one holds.
  2. Classify and prioritise. Start with a low risk application such as an information website to build confidence, then move core systems.
  3. Design the landing zone. Set up networks, access roles, logging, backup policies and security baselines before moving any application.
  4. Get the application audited. Government applications typically need a security audit by a CERT-In empanelled auditor before going live, so plan it into the timeline.
  5. Migrate and test. Move data, run parallel testing and confirm performance with real users before cutover.
  6. Set up monitoring and backups. Configure alerts for performance, cost and security. Test a restore from backup before you retire the old server.
  7. Keep logs. The CERT-In Directions of April 2022 require ICT system logs to be maintained for 180 days within Indian jurisdiction. Configure log retention accordingly.

For departments running several portals, this is also a good time to review architecture. Our e-governance team often finds that small changes, such as moving static content to a content delivery setup or separating reporting databases, make portals faster and cheaper to run.

Common Mistakes With MeitY Empanelled Cloud Service Providers

Most problems in government cloud projects come from planning gaps rather than technology. Watch for these:

  • Assuming the brand is enough. A provider may be empanelled for one offering or region but not another. Record the exact empanelled offering in your file notes and contract.
  • Lifting and shifting without cleanup. Moving an old, unpatched server to the cloud moves its weaknesses too. Patch, upgrade and remove unused components first.
  • Leaving everything open. Databases and admin panels exposed to the internet are a frequent cause of incidents. Keep them on private networks and allow access only through a VPN or bastion host.
  • No cost ownership. Without monthly review, test servers and old snapshots keep running and billing. Assign one officer to review usage every month.
  • No one on call. Cloud does not remove the need for operations. Someone must respond to alerts, apply patches and handle backups, especially before peak periods such as admission season or tax deadlines.
  • Weak documentation. Record network diagrams, access lists and runbooks so that knowledge stays with the department when staff or vendors change.

Frequently Asked Questions

What are MeitY empanelled cloud service providers?

They are providers whose specific cloud service offerings have been audited by STQC and empanelled by MeitY for use by government organisations in India.

Does empanelment cover all services of a provider?

No. Empanelment applies to specific offerings and often specific Indian regions. Check the current empanelment details for the services you plan to use.

Can a PSU or municipal body use a non-empanelled cloud?

Government organisations are generally expected to use MeitY empanelled offerings. Check your department's policy and any directions from your state IT department before choosing.

Is the cloud provider responsible for application security?

No. The provider secures the platform. Your team or partner must secure the application, operating system, access and data.

How Affix Center Can Help

We help government bodies, PSUs and enterprises plan and run cloud workloads under our cloud and infrastructure services. Our team can assess your applications, size the environment, design a secure landing zone, support migration and manage the setup afterwards.

If you are planning to move a government application to the cloud, get in touch with our team for a practical assessment.