1. Overview
We will rebuild ccrhindia.ayush.gov.in as a bilingual (English and Hindi) website on an open-source CMS, compliant with GIGW 3.0, DBIM and WCAG 2.1 AA. The site goes live within 20 weeks of the work order with CERT-In Safe-to-Host and STQC Certified Quality Website (CQW) certificates, and we then host and run it on a MeitY-empanelled cloud in India for 5 years.
Working prototype of the new website: https://vedanshugoyal.github.io/ccrh-prototype/ (28 pages in English and Hindi, built with CCRH's own public content). More design concepts and colour options can be provided on request.
- A new DBIM-based design with navigation built around visitors; every key service within 3 clicks.
- All existing content, documents, media and data migrated without loss; every old link keeps working.
- WCAG 2.1 AA, CERT-In Safe-to-Host and STQC CQW cleared before launch.
- Hosting on a MeitY-empanelled cloud in India at 99.9% uptime; no data stored or routed abroad.
- 5 years of operation: content updates, annual CERT-In audit, STQC renewal, EV SSL, patching and backups.
- 100% ownership of source code, database and documentation transferred to CCRH.
2. What we found on the current website
We studied the public pages of ccrhindia.ayush.gov.in on 8 October 2026 (181 menu pages in both languages; no logins, no scans).
| Area | Finding | What the new website does |
|---|---|---|
| Platform | Drupal 10, whose security support ends on 9 December 2026 | Moves to a supported Drupal version, with database-level migration |
| Speed | Pages take about 6.7 seconds to build; the home page is about 9.4 MB | Home page about 140 KB in the prototype; optimised images; caching |
| Hindi and English | Two separate page trees; menus differ (94 vs 87 links); 169 documents in one language only | One item holds both languages; the language switch keeps you on the same page |
| Accessibility | Same title on all 181 pages; no high-contrast option; scrolling text cannot be paused; missing alt text | Unique titles; contrast and text-size options; pausable ticker; alt text required |
| Security | Plain HTTP not redirected to HTTPS; no Content-Security-Policy; server versions disclosed | HTTPS only, security headers, WAF, hardened servers |
| Data sovereignty | Google Maps embedded on about 34 pages | No third-party calls; India-hosted maps |
| Documents | 424+ PDFs, most without file size; some over 100 MB | Type and size on every download; large files flagged and compressed |
3. Approach and technology
| Layer | Choice |
|---|---|
| CMS | Drupal (open source), the same CMS as today, upgraded through supported versions at our cost |
| Servers | Web server and database server as specified in §4.3 (4 vCPU, 32 GB RAM, 300 GB SSD each), Linux with enterprise support |
| Network | Two-tier: only the web server is public (ports 80/443 behind the WAF); the database has no public route |
| Security | Web Application Firewall with rate limiting and virtual patching, no CAPTCHAs; admin access only from whitelisted IPs |
| Data in India | Hosting, backups, logs and firewall all in Indian regions of a MeitY-empanelled cloud; logs kept 180 days (CERT-In directions) |
| Ownership | Code in a repository owned by CCRH; infrastructure scripted so it can be rebuilt and handed over |
4. New website structure
Eight sections replace ten, each built around one group of visitors:
| Section | Main pages |
|---|---|
| About CCRH | The Council, objectives, governance, citizen charter, annual reports |
| Research | 8 research areas, public health programmes, Extra Mural Research, collaborations |
| Our Network | Centre finder for all 33 institutes and units with address and phone, by state and type |
| Publications | Standard Treatment Guidelines, IJRH, annual reports, newsletter, books, IEC material |
| Opportunities | Vacancies, results, recruitment rules, scholarships |
| Tenders | Open, recently closed and archived tenders, with corrigenda under each tender |
| Media | News and updates, photo and video galleries |
| Help and Contact | Contact details, RTI, grievances (CPGRAMS), FAQ, feedback |
5. Data migration
- Take a database and file export of the current site (week 1) and list every page, file and URL.
- Pair every English page with its Hindi page; flag documents that exist in one language only.
- Agree a mapping of old content to new content types with CCRH (week 3).
- Run two trial migrations on staging (weeks 13–14) with a reconciliation report: item counts, file checksums, links, translations.
- Final migration at go-live after a 48-hour content freeze; every old URL redirects to its new page.
- Keep the old site read-only for 30 days as a fallback.
6. Certification plan
| Certificate | Issued by | When |
|---|---|---|
| WCAG 2.1 AA (internal check) | Our testing on every build | Weeks 7–14 |
| CERT-In Safe-to-Host | CERT-In empanelled auditor (booked in week 8) | Certificate by week 18; renewed every year |
| STQC Certified Quality Website | STQC Directorate, MeitY (applied in week 14) | Certificate by week 18; renewed in year 3 |
Production servers are built early (weeks 11–12, at our cost, as allowed by Corrigendum 1), so the audits test the environment that actually goes live.
7. Timeline (20 weeks)
| Phase | Weeks | Deliverables | CCRH sign-off |
|---|---|---|---|
| 1. Discovery | 1–3 | Requirements, current-site assessment, information architecture, project plan, migration strategy | Project plan |
| 2. Design | 4–6 | Wireframes, 3 DBIM design concepts, interactive prototype | M1: final design |
| 3. Build | 7–12 | Website, CMS, responsive layouts, GIGW and DBIM compliance; production servers built | Demo every 2 weeks |
| 4. Test | 13–14 | Two trial migrations; functional, accessibility, performance and browser testing | M2: staging ready |
| 5. Certify | 15–18 | CERT-In audit and fixes; STQC testing; both certificates | M3: certificates |
| 6. Harden | 19 | WAF rules, EV SSL, network rules, control panel, backup restore test | M4: production ready |
| 7. Launch | 20 | Final migration, UAT, go-live, credentials, first backup, training | M5: go-live; 5-year AMC starts |
8. Operations and support for 5 years
- Response: within 30–60 minutes in working hours and 2–4 hours otherwise (Corrigendum 1). No onsite staff needed.
- Content updates: published within 1 working day; urgent notices within 2 hours.
- Security: Drupal security patches within 48 hours (24 hours if critical); monthly OS patching; incidents reported to CERT-In within 6 hours.
- Uptime: 99.9% per year, checked every minute from India; monthly uptime report with each quarterly invoice.
- Backups: daily, kept in a second Indian region; full encrypted backup delivered to CCRH every quarter and at each year-end, restore-tested.
- Credentials: full set handed to CCRH at go-live; any change shared within 24 hours.
- Yearly: CERT-In audit, EV SSL renewal, performance review; STQC renewal in year 3.
- Training: CMS training for CCRH staff at go-live and yearly, with user manual and SOPs.
- Exit: complete handover of code, data, credentials and documentation, with knowledge transfer, before any final payment.
9. Points we will confirm with CCRH at kick-off
- Access to a database and file export of the current website.
- Who provides Hindi translations of new content.
- Whether institute and unit staff will edit their own pages.
- Whether the website should open in Hindi or English by default.
- Which officer will act as Web Information Manager.
Team
Two Computer Science graduates of IIT Jodhpur with private-sector experience building and running websites and large software systems.
Vedanshu Goyal, Proprietor and Project Lead (hosting, performance, security)
- B.Tech, Computer Science and Engineering, IIT Jodhpur. ICPC World Finalist 2023, an international programming contest.
- Software Development Engineer, Live Your Best Life (lybl.com) (Jan – Jul 2023): built the online booking system and a community forum for the LYBL website.
- Software Engineer, Qi-CAP, Bangalore (Aug 2023 – Jun 2026), a stock-market trading technology company.
- Built software that handles about 10 lakh stock-market updates every second.
- Made the company's trading systems more than 70% faster, and kept them steady at the busiest times of the day.
- Worked on storing and retrieving large amounts of data quickly and safely, which is also what keeps a busy website fast and available.
Sarthak Kumar Singh, Web Development Lead
- B.Tech, Computer Science and Engineering, IIT Jodhpur.
- Full Stack Engineer, Regie.ai (Apr 2026 – Jun 2026). Earlier SDE I and SDE II at ConveGenius.ai (May 2023 – Mar 2026), promoted within 2 years.
- Built and ran web systems used by over 10 crore people, available 99.9% of the time and handling about 5,000 requests every second.
MOJUD | 397, Green Park Colony, Bistan Road, Khargone, Madhya Pradesh 451001 | +91-9425326724 | team@mojud.life