Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • Contact

VAPT Requirements under SEBI CSCRF: What Regulated Entities Must Know

4 min read
7 Views
  • SEBI CSCRF

VAPT is one of the most important parts of any cybersecurity program. It finds the weak spots in your cybersecurity systems before an attacker does. But running the test and getting a report is not enough. What matters is whether every finding gets fixed, on time, with proof to show for it.

For SEBI-regulated entities, that gap has become even harder to ignore. Recent SEBI and depository communications have focused on the submission of proof showing that VAPT findings have been remediated, not just identified. If you handle IT, compliance or risk at a stockbroker, depository participant, mutual fund or any other SEBI-regulated entity, this is the part many teams miss.

VAPT requirements under SEBI CSCRF cover a lot more than just a yearly scan. They set how often you test, what you must check, who can run the test, and how fast you must fix what you find. Skip any of these, and even a clean report will not help you at audit time. This blog explains what SEBI expects from you, in simple terms.

Table of Contents

What VAPT means under SEBI CSCRF

Vulnerability Assessment and Penetration Testing (VAPT) is a two-part exercise.

  • Vulnerability assessment scans your systems for known weaknesses.
  • Penetration testing goes further. It simulates a real attack to check if those weaknesses can actually be exploited.

Under the Cybersecurity and Cyber Resilience Framework (CSCRF), SEBI folds VAPT into a broader assurance cycle. Cyber audits, threat hunting, red teaming and Cyber Capability Index assessments all sit alongside VAPT. Together, they confirm your controls actually work the way they are supposed to.

How often you need to run VAPT

VAPT requirements under SEBI CSCRF are tied directly to your entity classification. There is no fixed calendar date.

Market Infrastructure Institutions (MIIs), Qualified Stockbrokers (QSBs) and entities classified as Protected Systems or Critical Information Infrastructure (CII), where applicable, follow a half-yearly VAPT cycle. Qualified REs outside this group typically work on an annual VAPT cycle, while self-assessment categories follow lighter timelines based on their tier.

Key registration authorities were recently re-categorised from MII to Qualified RE status. That change brought VAPT, cyber audit and IT committee obligations they did not carry before, so if your entity type has shifted, check your current tier before assuming your old schedule still applies.

What the VAPT scope must cover

The VAPT requirements under SEBI CSCRF do not leave scope open to interpretation. Annexure-L of the framework lays out the testing methodology, and it expects coverage across:

  • Network infrastructure: routers, firewalls, servers and anything reachable over WAN or LAN
  • Web and mobile applications: including systems exposed through public IP addresses
  • Cloud environments: workloads and configurations hosted on third-party cloud platforms
  • Databases and endpoints: systems that store or process regulated data

If your business runs activities outside SEBI’s purview, audit scope stays limited to SEBI-linked infrastructure, unless those systems are interconnected with the rest of your environment.

Closing VAPT findings on time

Running the test is only half the job. SEBI CSCRF is equally strict about how quickly you act on what the test finds. Here is what the closure process looks like in practice.

4 Steps to Close VAPT Findings under SEBI CSCRF

  • Get the report from a CERT-In empanelled auditor: VAPT under SEBI CSCRF must be performed by an Information Security auditing organisation empanelled with CERT-In. This is non-negotiable for all regulated entities.
  • Fix critical patch gaps immediately: High-severity vulnerabilities that exist because a patch was not applied carry the tightest deadline in the framework.
  • Close all findings within three months: Every vulnerability identified during a VAPT activity should be remediated within three months of the report submission date.
  • Escalate open items to your IT Committee: Anything still open after three months needs formal IT Committee approval and documented justification.

Recent regulatory clarifications also introduced a condensed VAPT report format, instead of lengthy multi-document submissions toward a single, standardised deliverable. This makes it easier for auditors and IT committees to track closure status without digging through paperwork.

Why this matters beyond compliance

Meeting VAPT requirements under SEBI CSCRF is not just about avoiding penalties. Stockbrokers, depositories and mutual funds hold sensitive financial data for millions of investors. A missed patch or an unclosed vulnerability is a real risk to that data, not just a line item in an audit report.

Treating VAPT as a continuous discipline, backed by clear ownership and tracked deadlines, keeps your organisation both compliant and genuinely harder to breach.

Conclusion

VAPT requirements under SEBI CSCRF consists of more than running a scan once a year. They demand the right auditor, the right scope and fast, documented closure of every finding. Getting this rhythm right protects your organisation from both regulatory action and real cyber risk.

CyberNX helps SEBI regulated entities plan and execute VAPT requirements under SEBI CSCRF, from CERT-In empanelled testing to closure tracking and IT Committee reporting. Connect with our SEBI CSCRF experts to build a compliance roadmap that works for you at audit time.

VAPT Requirements Under SEBI CSCRF FAQs

What is VAPT under SEBI CSCRF?

It is a mandatory security exercise for applicable SEBI-regulated entities under CSCRF that combines vulnerability assessment and penetration testing. It checks whether your systems have exploitable weaknesses and must be performed by a CERT-In empanelled auditor.

How often should VAPT be conducted for SEBI regulated entities?

Market Infrastructure Institutions and Qualified Stockbrokers must run VAPT half-yearly. Most other regulated entities follow an annual cycle, based on their assigned tier.

What is the timeline to close VAPT findings?

High-severity vulnerabilities from unapplied patches must be fixed within one week. All other identified vulnerabilities should be closed within three months of the report.

Who can conduct VAPT for SEBI CSCRF compliance?

Only Information Security auditing organisations empanelled with CERT-In are authorised to conduct VAPT under the SEBI CSCRF framework.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Data Localisation under SEBI CSCRF: A Compliance Snapshot

Data Localisation under SEBI CSCRF: Why the Mandate is Still in Abeyance

Where your data is stored is as important as how well it is protected. Across the world, regulators are introducing

SEBI CSCRF for KRAs and QRTAs: Key Changes You Must Know

SEBI CSCRF for KRAs & QRTAs: What Changed and What You Must Do Now

Every time an investor opens a demat account, a mutual fund folio or a trading account in India, their record

Incident Response under SEBI CSCRF: A Compliance Guide

Incident Response under SEBI CSCRF: A Practical Guide for Regulated Entities

CERT-In gives regulated entities six hours to report a cyber incident once it is detected. For SEBI-regulated firms, that clock

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.