VAPT is one of the most important parts of any cybersecurity program. It finds the weak spots in your cybersecurity systems before an attacker does. But running the test and getting a report is not enough. What matters is whether every finding gets fixed, on time, with proof to show for it.
For SEBI-regulated entities, that gap has become even harder to ignore. Recent SEBI and depository communications have focused on the submission of proof showing that VAPT findings have been remediated, not just identified. If you handle IT, compliance or risk at a stockbroker, depository participant, mutual fund or any other SEBI-regulated entity, this is the part many teams miss.
VAPT requirements under SEBI CSCRF cover a lot more than just a yearly scan. They set how often you test, what you must check, who can run the test, and how fast you must fix what you find. Skip any of these, and even a clean report will not help you at audit time. This blog explains what SEBI expects from you, in simple terms.
What VAPT means under SEBI CSCRF
Vulnerability Assessment and Penetration Testing (VAPT) is a two-part exercise.
- Vulnerability assessment scans your systems for known weaknesses.
- Penetration testing goes further. It simulates a real attack to check if those weaknesses can actually be exploited.
Under the Cybersecurity and Cyber Resilience Framework (CSCRF), SEBI folds VAPT into a broader assurance cycle. Cyber audits, threat hunting, red teaming and Cyber Capability Index assessments all sit alongside VAPT. Together, they confirm your controls actually work the way they are supposed to.
How often you need to run VAPT
VAPT requirements under SEBI CSCRF are tied directly to your entity classification. There is no fixed calendar date.
Market Infrastructure Institutions (MIIs), Qualified Stockbrokers (QSBs) and entities classified as Protected Systems or Critical Information Infrastructure (CII), where applicable, follow a half-yearly VAPT cycle. Qualified REs outside this group typically work on an annual VAPT cycle, while self-assessment categories follow lighter timelines based on their tier.
Key registration authorities were recently re-categorised from MII to Qualified RE status. That change brought VAPT, cyber audit and IT committee obligations they did not carry before, so if your entity type has shifted, check your current tier before assuming your old schedule still applies.
What the VAPT scope must cover
The VAPT requirements under SEBI CSCRF do not leave scope open to interpretation. Annexure-L of the framework lays out the testing methodology, and it expects coverage across:
- Network infrastructure: routers, firewalls, servers and anything reachable over WAN or LAN
- Web and mobile applications: including systems exposed through public IP addresses
- Cloud environments: workloads and configurations hosted on third-party cloud platforms
- Databases and endpoints: systems that store or process regulated data
If your business runs activities outside SEBI’s purview, audit scope stays limited to SEBI-linked infrastructure, unless those systems are interconnected with the rest of your environment.
Closing VAPT findings on time
Running the test is only half the job. SEBI CSCRF is equally strict about how quickly you act on what the test finds. Here is what the closure process looks like in practice.
- Get the report from a CERT-In empanelled auditor: VAPT under SEBI CSCRF must be performed by an Information Security auditing organisation empanelled with CERT-In. This is non-negotiable for all regulated entities.
- Fix critical patch gaps immediately: High-severity vulnerabilities that exist because a patch was not applied carry the tightest deadline in the framework.
- Close all findings within three months: Every vulnerability identified during a VAPT activity should be remediated within three months of the report submission date.
- Escalate open items to your IT Committee: Anything still open after three months needs formal IT Committee approval and documented justification.
Recent regulatory clarifications also introduced a condensed VAPT report format, instead of lengthy multi-document submissions toward a single, standardised deliverable. This makes it easier for auditors and IT committees to track closure status without digging through paperwork.
Why this matters beyond compliance
Meeting VAPT requirements under SEBI CSCRF is not just about avoiding penalties. Stockbrokers, depositories and mutual funds hold sensitive financial data for millions of investors. A missed patch or an unclosed vulnerability is a real risk to that data, not just a line item in an audit report.
Treating VAPT as a continuous discipline, backed by clear ownership and tracked deadlines, keeps your organisation both compliant and genuinely harder to breach.
Conclusion
VAPT requirements under SEBI CSCRF consists of more than running a scan once a year. They demand the right auditor, the right scope and fast, documented closure of every finding. Getting this rhythm right protects your organisation from both regulatory action and real cyber risk.
CyberNX helps SEBI regulated entities plan and execute VAPT requirements under SEBI CSCRF, from CERT-In empanelled testing to closure tracking and IT Committee reporting. Connect with our SEBI CSCRF experts to build a compliance roadmap that works for you at audit time.
VAPT Requirements Under SEBI CSCRF FAQs
What is VAPT under SEBI CSCRF?
It is a mandatory security exercise for applicable SEBI-regulated entities under CSCRF that combines vulnerability assessment and penetration testing. It checks whether your systems have exploitable weaknesses and must be performed by a CERT-In empanelled auditor.
How often should VAPT be conducted for SEBI regulated entities?
Market Infrastructure Institutions and Qualified Stockbrokers must run VAPT half-yearly. Most other regulated entities follow an annual cycle, based on their assigned tier.
What is the timeline to close VAPT findings?
High-severity vulnerabilities from unapplied patches must be fixed within one week. All other identified vulnerabilities should be closed within three months of the report.
Who can conduct VAPT for SEBI CSCRF compliance?
Only Information Security auditing organisations empanelled with CERT-In are authorised to conduct VAPT under the SEBI CSCRF framework.




