The SEBI VAPT requirements for stock brokers decide how often you test, who can sign the report, and how fast you must fix what it finds. This guide breaks down the cadence, scope, and remediation rules, and how to meet them without a large security team.
TL;DR
The SEBI VAPT requirements for stock brokers are set by CSCRF. Most brokers run VAPT annually, but Qualified Stock Brokers and any broker offering internet or algo trading must test half-yearly, plus after every major system release. The test must be a real penetration test with manual exploitation by a CERT-In empanelled auditor, cover all critical systems and a sample of non-critical ones, and every finding must be remediated within three months, with high and critical issues re-tested within thirty days.
On this page
Why the SEBI VAPT requirements for stock brokers matter
A stock broker runs client money, trading systems, and sensitive market data, which makes it a high-value target and a focus of regulatory scrutiny. Under the Cybersecurity and Cyber Resilience Framework, the Securities and Exchange Board of India makes vulnerability assessment and penetration testing a core, testable control. The SEBI VAPT requirements for stock brokers are not a formality: they are one of the first things a CERT-In empanelled auditor checks, and getting the cadence, scope, or remediation wrong is a common reason brokers fall short at audit.
How often you must test
The first requirement is frequency, and it depends on your profile, not just your CSCRF category.
Most brokers run VAPT annually on their category cadence. But a large group must test half-yearly: Qualified Stock Brokers, and any broker offering Internet-Based Trading or algorithmic trading, fall into the twice-a-year bracket regardless of their broader category. On top of that, every broker must run a fresh VAPT after any major system release, and conduct quarterly vulnerability scans of internet-facing systems. If you offer online or algo trading, assume half-yearly is your baseline.
The core SEBI VAPT requirements for stock brokers
Beyond frequency, the rules fix who tests, what is covered, and how. These are the pillars an auditor will hold you to.
The test must be performed by a CERT-In empanelled information-security auditing organisation, this is non-negotiable, and the auditor is expected to have real BFSI audit experience. The scope must cover one hundred percent of your critical systems and at least a twenty-five percent sample of non-critical ones, and for dual-registered firms it covers the SEBI-regulated systems where they are properly segregated. The testing itself must involve manual exploitation, a genuine penetration test, and the findings must be reported in the CSCRF-specified format within the prescribed timelines. A grounding in the types of VAPT helps you scope this correctly.
Why a scan is not enough
The single most common failure here is treating an automated vulnerability scan as a penetration test. CSCRF explicitly expects manual exploitation, and interpreting annual VAPT as an automated scan is a mistake auditors flag.
A scanner checks your systems against a database of known issues. It is useful and should run, but it will not chain weaknesses into a real breach or understand your trading and settlement logic. A penetration test is a skilled professional attacking the way a real adversary would. Our guide on VAPT versus vulnerability scanning explains why a scan alone will never satisfy a SEBI cyber audit for a broker.
Fixing and re-testing
Here is the part brokers underestimate: under these rules, running the test is only half the job. SEBI is equally strict about closing what it finds.
Every vulnerability identified in a VAPT must be remediated within three months of the report submission date. Critical patch gaps carry the tightest deadline and must be fixed immediately, and high and critical findings must be re-tested within thirty days, with a re-test letter kept on file. Auditors have flagged brokers for the same critical vulnerability appearing in consecutive reports, precisely because remediation was never followed through. Findings tracked to closure, with evidence, are the real substance of the requirement.
The lean-team path to broker VAPT compliance
Meeting all of this, testing on the right cadence, with the right scope, manual exploitation of findings, remediation within tight timelines, and audit-ready evidence, is a heavy lift for a broking firm without a large security team. Coordinating separate testers, trackers, and reporting is slow and error-prone. The efficient path is one platform that runs the testing and organises the evidence together.
Meet the SEBI VAPT requirements for stock brokers, and stay audit-ready.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups and lean trading teams. Run VAPT on the right cadence, remediate, re-test, and keep the evidence, on one platform. No security team required.
Book a Demo →Frequently asked questions
How often must a stock broker run VAPT under SEBI?
Most brokers run VAPT annually, but Qualified Stock Brokers and any broker offering internet-based or algorithmic trading must test half-yearly. Every broker must also run a fresh VAPT after a major system release and conduct quarterly scans of internet-facing systems.
Who can perform a broker’s VAPT?
Only a CERT-In empanelled information-security auditing organisation, with real BFSI audit experience. A report from a non-empanelled firm will not be accepted at a SEBI cyber audit. This is a non-negotiable part of the SEBI VAPT requirements for stock brokers.
Is an automated scan enough to meet the requirement?
No. CSCRF expects manual exploitation, a real penetration test. Interpreting annual VAPT as an automated scan is a common mistake that auditors flag, because a scan misses the business-logic and chained vulnerabilities a broker faces.
What must a broker’s VAPT scope cover?
All critical systems and at least a twenty-five percent sample of non-critical systems. For firms registered under multiple regulators, the scope covers the SEBI-regulated systems where they are properly segregated.
How quickly must findings be fixed?
Every finding must be remediated within three months of the report submission date. Critical patch gaps must be fixed immediately, and high and critical findings re-tested within thirty days, with a re-test letter on file.
Can one VAPT cover both SEBI and RBI if we are dual-regulated?
Often yes. SEBI’s equivalence principle lets an RBI six-monthly vulnerability assessment meet or exceed the CSCRF VAPT minimum, provided the scope covers the SEBI-regulated systems and a CERT-In empanelled auditor performed the work.

