VAPT for Insurance Companies

VAPT for insurance companies guide
VAPT for Insurance Companies: 6 Complete Rules | Osto

VAPT for insurance companies is one of the most-checked controls in an IRDAI cyber audit, and it is stricter than most teams assume. Here is exactly how often you must test, who can test, how fast you must fix findings, and how a lean team stays ready.

Osto Security Team9 min readIRDAI Compliance

The short answer

IRDAI VAPT requirements mandate vulnerability assessment and penetration testing at least twice a year on customer-facing systems and critical infrastructure, plus external penetration testing at least once every six months on internet-facing assets. As of 2026, that external test must be grey-box or white-box, not black-box only. All testing must be done by a CERT-In empanelled auditor, and findings are remediated by severity: critical in 30 days, high in 60, medium in 90, each confirmed by a retest. Applies to insurers and intermediaries alike.

What VAPT for insurance companies means

The IRDAI VAPT requirements sit inside the Insurance Regulatory and Development Authority of India Information and Cyber Security Guidelines, and they bind every regulated entity that handles policyholder data, insurers, reinsurers, and intermediaries such as brokers, corporate agents, web aggregators, and third-party administrators. Because insurance systems hold identity, financial, and often health data, IRDAI treats real security testing as proof that controls work, not a policy document that says they do. In an audit, the VAPT evidence is one of the first things examined.

How often VAPT for insurance companies must run

The first thing to get right about VAPT for insurance companies is frequency, because two testing rhythms run at once and one of them changed recently.

The cadence
How often testing has to happen
VAPT for insurance companies starts with frequency, and it is stricter than an annual check. Two rhythms run in parallel, and one of them changed in 2026.
How often you must test VAPT, twice a year At least two full assessments a year on customer-facing systems and critical infrastructure. External PT, six-monthly On internet-facing assets, now grey-box or white-box, not black-box only. By a CERT-In empanelled auditor.

Vulnerability assessment and penetration testing must run at least twice a year on customer-facing systems and critical infrastructure. On top of that, external penetration testing on internet-facing assets is required at least once every six months. The 2026 update to the guidelines sharpened this: the external test must now be grey-box or white-box rather than black-box only, which means the tester works with more knowledge of the system and probes deeper. Annual-only testing does not meet the standard.

Two clocks, not one
Teams often plan for a single annual test and fall short. The IRDAI VAPT requirements run two cadences in parallel: twice-yearly full VAPT, and six-monthly external penetration testing on anything internet-facing.

Who can perform the test

This is non-negotiable and catches teams out. The rules state that testing must be performed by a CERT-In empanelled audit firm, and the annual assurance audit by a qualified external auditor holding recognised certifications such as CISA, DISA, or CERT-In empanelment. A report from an internal team or a non-empanelled vendor will not stand up at an IRDAI inspection. A grounding in the types of VAPT helps you scope the engagement correctly before you commission it.

A scan is not a penetration test
The guidelines expect real, expert-led exploitation, not an automated scan. Business-logic and authentication flaws that matter in insurance systems are exactly what a scanner misses, our guide on VAPT versus vulnerability scanning explains the difference.

Remediation deadlines for insurance VAPT

Running the test is only half the job. The guidelines set hard, severity-based deadlines for closing what the test finds, and require proof of closure.

Remediation
Fixing findings is half the requirement
VAPT for insurance companies is as strict about closing findings as about finding them. Each severity has a deadline, and a retest has to prove the fix.
Remediation deadlines by severityCriticalFix within 30 daysHighFix within 60 daysMediumFix within 90 daysThen retestConfirmatory testproves closure

Critical findings must be remediated within thirty days, high findings within sixty, and medium findings within ninety. Gaps found in an internal vulnerability scan of ICT infrastructure must be closed immediately, and gaps in internet-facing applications closed within one month, followed by confirmatory testing to prove the fix. Any high-risk issue not resolved in time has to be escalated to the Board’s Risk Management Committee. Findings tracked to closure, with retest evidence, are the real substance of the rule.

The scope and the evidence

A test that only checks the marketing site does not satisfy the IRDAI VAPT requirements. The scope has to reach the systems an attacker would actually target, and the evidence has to be ready for inspection.

The scope
What a compliant test has to reach
A narrow test does not satisfy VAPT for insurance companies. The scope spans your external apps, network and databases, APIs, and the evidence you keep.
What the VAPT scope must coverExternal appsPublic-facing web andportalsNetwork and infraSegmentation anddatabasesAPIsAll externally exposedendpointsEvidenceFindings in anaudit-ready format

In practice the scope covers external-facing applications, internal network segmentation and database security, and API security for every API exposed to external parties such as agents, brokers, and aggregators, alongside the wider ICT infrastructure. Just as important, remediation evidence must be maintained in a format you can present to IRDAI during an inspection. Intermediaries submit their CERT-In empanelled audit compliance report within thirty days of the audit completing, so this is really an all-year discipline, not a single event.

How Osto helps you stay ready

Meeting VAPT for insurance companies, testing on two cadences, across web, network, and API, with severity-based remediation, retests, and audit-ready evidence, is a heavy lift for a lean insurance or intermediary team without a dedicated security function. Coordinating separate testers, trackers, and reporting is slow and easy to let slip. That is the gap Osto is built to close.

Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. Against these requirements, it runs VAPT across your applications, APIs, and infrastructure, categorises findings by severity, generates remediation and retest reports, and keeps organised, audit-ready evidence mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets you test-ready and keeps the evidence in order, so the audit becomes a verification rather than a scramble.

Stay IRDAI test-ready all year, without a big team.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Run VAPT on the right cadence, remediate by severity, retest, and keep audit-ready evidence, on one platform. No security team required.

Book a Demo →

Frequently asked questions

How often does IRDAI require VAPT?

The IRDAI VAPT requirements mandate vulnerability assessment and penetration testing at least twice a year on customer-facing systems and critical infrastructure, plus external penetration testing at least once every six months on internet-facing assets.

Does the external penetration test have to be black-box?

No. As of the 2026 update, external penetration testing must be grey-box or white-box, not black-box only, and conducted at least six-monthly by a CERT-In empanelled auditor. This gives the tester deeper visibility into the system.

Who can perform VAPT for IRDAI compliance?

Only a CERT-In empanelled audit firm. The annual assurance audit must be by a qualified external auditor holding certifications such as CISA, DISA, or CERT-In empanelment. Internal or non-empanelled reports are not accepted.

What are the VAPT remediation deadlines?

By severity: critical findings within thirty days, high within sixty, medium within ninety. Internal-scan gaps must be closed immediately, and internet-facing application gaps within one month, followed by confirmatory retesting to prove closure.

What must the VAPT scope cover?

External-facing applications, internal network segmentation, database security, and API security for every externally exposed API, plus the wider ICT infrastructure. Remediation evidence must be kept in an IRDAI-presentable format.

Do intermediaries also have to meet the IRDAI VAPT requirements?

Yes. Brokers, corporate agents, web aggregators, and TPAs are bound alongside insurers, and must submit their CERT-In empanelled audit compliance report within thirty days of the audit completing.