Insights

GIGW 3.0, explained for department heads

If you are responsible for a government or PSU website — as a department head, a web information manager, or the officer whose name is on the compliance file — GIGW is the standard you will be audited against. GIGW stands for Guidelines for Indian Government Websites, published under MeitY, and version 3.0 extends it beyond websites to apps and citizen services. Conformance is verified through an STQC audit, and this article explains what that actually involves.

What GIGW 3.0 covers

The guidelines group into three broad areas. First, quality and accessibility: the site must work for every citizen, including those using screen readers or keyboard navigation — this is where WCAG 2.1 requirements like alt text, proper headings, skip links and a Screen Reader Access page come in. Second, mandatory elements: content in Hindi or the regional language, a contact and feedback mechanism, published website policies (privacy, copyright, hyperlinking), clear ownership, and a visible last-updated date. Third, hosting and security norms: HTTPS everywhere, security headers, and hosting practices aligned with CERT-In guidance.

How the STQC audit works

STQC — the Standardisation Testing and Quality Certification directorate — audits the website against a detailed checklist derived from the guidelines. Some checks are automated; many are manual, covering document accessibility (yes, your PDFs count), content quality, and process evidence such as a content review policy. Sites that fail receive findings and return for rework, which is where most timelines slip: fixing accessibility across an old CMS is slower than building it in from the start.

The mistakes that cost the most time

In our audit-preparation work, the same gaps repeat. Language versions exist but are outdated or partial. The Screen Reader Access page is missing entirely. Policies are copied from another department's site with the wrong department name still in them. Homepages weigh several megabytes and time out on rural connections. Security headers — free, ten-minute DNS-level or server-level fixes — are absent. None of these are hard to fix; they are simply invisible until an audit or a citizen complaint makes them visible.

Where to start

Start with a baseline: run your site through an automated GIGW check to see the machine-verifiable gaps in sixty seconds, then plan the manual work — content, documents, language — around a realistic timeline. Our free checker at karleesh.com/tools/gigw-check runs the automatable portion of GIGW 3.0 and gives you a weighted score with a prioritised gap list. And if you want the full picture, this article is from Issue 01 of The Karleesh Quarterly — the complete issue, including the seven gaps that fail most STQC audits and a pre-audit checklist, is a free download at karleesh.com/insights/magazine.

Free download

Website Security Checklist (PDF)

25 practical checks every business website should pass — from our security team.

← All articles