Automated STQC & GIGW 3.0 Pre-Audit Readiness Suite
Eliminate audit rejections and win GeM tenders. Scan any Indian government or PSU portal in under 10 seconds for exact DOM element failures, security headers, and export a branded readiness PDF dossier.
< 10s
Execution Latency
High-speed AWS engine
WCAG 2.1 AA
RPwD Act 2016
Axe-Core DOM evaluator
CERT-In
Defensive Hardening
TLS 1.2/1.3 & HSTS matrix
1 Free Scan
Instant Onboarding
Full 15+ page PDF export
STQC Conformity Matrix
Four Modular Audit Engines Aligned With GIGW 3.0
Every machine-testable rule mandated for Indian public-sector deployments is verified in parallel.
Category 1: Cybersecurity & Server Hardening
Enforces CERT-In baseline security rules to protect portals against MitM and clickjacking.
- HTTP to HTTPS 301 redirection & TLS 1.2/1.3 cipher verification
- Defense headers: HSTS, CSP, X-Frame-Options, X-Content-Type
- Cookie governance: Secure, HttpOnly, and SameSite validation
- Server banner leakage & exposed dotfiles (/.git/, /.env) check
Category 2: Digital Accessibility (WCAG 2.1 AA)
RPwD Act 2016 statutory compliance powered by headless Axe-Core DOM inspection.
- Color contrast ratios (≥4.5:1 for regular text, ≥3:1 for large text)
- Headings hierarchy (<h1>–<h6>) and landmark region validation
- Descriptive alt tags on visual assets & skip navigation links
- Programmatic <label> association for form controls & focus indicators
Category 3: Mandatory GIGW Governance Elements
Detects required policies and statutory features unique to Indian Government sites.
- Mandatory policy links: Privacy, Hyperlinking, Copyright, Terms, CMP
- Designated Web Information Manager (WIM) contact & ownership statements
- Explicit Screen Reader Access page & text resizing utility (A-, A, A+)
- Bilingual / Hindi language switcher & Last Updated timestamp
Category 4: Performance, Mobile & Quality Baseline
Ensures portals deliver fast responsiveness and accessible tender documents.
- Core Web Vitals estimation (LCP, FID/INP, CLS) on 4G network profiles
- Automated scanning for broken 404/500 hyperlinks across menus
- Document flagging for un-tagged / non-OCR .pdf / .docx tenders
- Inline script payload optimization to avoid main thread blocking
Target Personas
Engineered For The GovTech Procurement Lifecycle
Agency Tech Lead / Bidder
GeM Tender RFP Submissions
Generate an official, branded GIGW 3.0 / STQC Readiness PDF within 60 seconds to attach to mandatory GeM tender technical proposals.
GovTech Developer
Pre-STQC Code Remediation
Pinpoint exact DOM selectors, failing HTML lines, missing headers, and copy-pasteable Nginx/Apache/HTML remediation snippets before audit submission.
Web Information Manager (WIM)
Accountable Government Officer
Non-technical executive scorecards verifying whether the contracted IT vendor actually delivered a secure, compliant, and accessible portal.
Complete Guide to GIGW 3.0, STQC Certification & GeM Tender Audit Readiness
Under directives issued by the Ministry of Electronics and Information Technology (MeitY), all Indian government portals, Public Sector Undertakings (PSUs), autonomous bodies, and GeM RFP bidders must achieve full conformity with the Guidelines for Indian Government Websites (GIGW 3.0) and obtain STQC Website Quality Certification (CQW).
1. CERT-In Cybersecurity Baseline
Mandatory defense-in-depth posture: automated inspection of TLS 1.2/1.3 protocol ciphers, HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), anti-clickjacking headers (X-Frame-Options), secure cookie flags (HttpOnly, Secure, SameSite), and server version token suppression to prevent banner grabbing.
2. WCAG 2.1 AA & RPwD Act 2016
Legal mandate under Section 42 of the Rights of Persons with Disabilities Act 2016: headless DOM element auditing via Axe-Core engine, verifying color contrast thresholds (≥4.5:1), ARIA landmarks, form input labeling, descriptive link anchors, skip-to-content links, and complete keyboard navigability.
3. Mandatory GIGW 3.0 Governance
Administrative conformity required by STQC: presence of designated Web Information Manager (WIM) with contact details, active bilingual language switcher (English & Hindi), dedicated Screen Reader Access portal, and statutory policy pages (Privacy, Terms, Copyright, and Hyperlinking).
GIGW 3.0 Statutory Requirements vs. GovAudit 3.0 Automated Inspection
| Compliance Domain | Governing Standard / Clause | Mandatory Requirement | GovAudit 3.0 Automated Engine |
|---|---|---|---|
| Cybersecurity | CERT-In / GIGW 3.0 Clause 6.1 | HTTPS enforcement, TLS 1.2/1.3, HSTS header, Secure cookies | Automated parallel SSL/TLS handshake & header analyzer |
| Accessibility | WCAG 2.1 Level AA / RPwD Act | Contrast ≥ 4.5:1, Alt tags, Keyboard focus, ARIA labels | Headless Axe-Core Playwright DOM rule verification |
| Governance | GIGW 3.0 Clause 5.2 - 5.5 | Web Information Manager (WIM), Bilingual toggle, Policies | Semantic DOM & anchor link scraper for required pages |
| Performance | GIGW 3.0 Clause 7.2 | Core Web Vitals, accessible PDF/Word tenders, no 404 links | Lighthouse CWV profiler & broken link detector |
Frequently Asked Questions About GIGW 3.0 & STQC Audits
Everything you need to know about Indian government website compliance, STQC certification, and GeM procurement.
What is GIGW 3.0 compliance and who is required to adhere to it?
The Guidelines for Indian Government Websites (GIGW 3.0), formulated by the Ministry of Electronics and Information Technology (MeitY) and the National Informatics Centre (NIC), establish mandatory design, accessibility, security, and governance standards. All Central Ministries, State Government departments, PSUs, judicial portals, and IT vendors bidding on Government e-Marketplace (GeM) tenders must comply with GIGW 3.0.
How does GovAudit 3.0 help achieve STQC Website Quality Certification (CQW)?
STQC (Standardisation Testing and Quality Certification) Directorate evaluates government websites before awarding the official Certified Quality Website (CQW) seal. GovAudit 3.0 replicates STQC’s automated testing protocol, detecting non-compliant HTML elements, missing security headers, and accessibility violations in under 10 seconds, and generates an actionable remediation PDF dossier with exact code patches.
What are the mandatory CERT-In cybersecurity baseline checks?
Under CERT-In advisories and GIGW 3.0 Section 6, government websites must enforce strict HTTPS with TLS 1.2 or TLS 1.3 ciphers, implement HTTP Strict Transport Security (HSTS) with subdomains, deploy Content Security Policy (CSP), prevent clickjacking via X-Frame-Options, secure cookies with HttpOnly and Secure flags, and disable server identification headers (server tokens).
How does GovAudit test for WCAG 2.1 Level AA and RPwD Act 2016?
Section 42 of the Rights of Persons with Disabilities (RPwD) Act 2016 legally requires all electronic content and websites to be accessible to persons with disabilities. GovAudit 3.0 executes an automated Axe-Core inspection engine on headless browsers to test color contrast (minimum 4.5:1 ratio), image alternate text, keyboard-only tab order, ARIA landmark roles, and screen reader compatibility.
Can GovAudit 3.0 audit reports be submitted with GeM tender technical proposals?
Yes. GeM (Government e-Marketplace) tenders for website development, portal modernization, and annual maintenance contracts (AMC) frequently require bidders to demonstrate pre-audit readiness. GovAudit 3.0 generates an official, timestamped STQC Pre-Audit Readiness PDF Dossier complete with executive scores, category breakdowns, and compliance checklists suitable for technical RFP bid attachments.
What is the difference between GIGW 2.0 and GIGW 3.0?
While GIGW 2.0 focused primarily on static desktop accessibility and basic security, GIGW 3.0 introduces mobile-first responsive guidelines, Core Web Vitals performance benchmarks, modern cyber defense headers (CSP, HSTS), bilingual content mandates, lifecycle governance, and integration readiness for public digital platforms (India Stack).
What is a Web Information Manager (WIM) and why is it mandatory?
Under GIGW 3.0 Clause 5.2, every government department must officially nominate a Web Information Manager (WIM)—an officer responsible for content accuracy, currency, and statutory compliance. The WIM’s name, official email, phone number, and postal address must be prominently displayed on the website.
How long does an audit scan take and what is included in the free tier?
GovAudit 3.0 completes a multi-category audit scan in under 10 seconds using distributed cloud workers. Every new user receives 1 Free Full Category Audit upon sign in, including interactive web findings, code remediation snippets, and full downloadable report export.