VAPT for insurance companies is one of the most-checked controls in an IRDAI cyber audit, and it is stricter than most teams assume. Here is exactly how often you must test, who can test, how fast you must fix findings, and how a lean team stays ready.
The short answer
IRDAI VAPT requirements mandate vulnerability assessment and penetration testing at least twice a year on customer-facing systems and critical infrastructure, plus external penetration testing at least once every six months on internet-facing assets. As of 2026, that external test must be grey-box or white-box, not black-box only. All testing must be done by a CERT-In empanelled auditor, and findings are remediated by severity: critical in 30 days, high in 60, medium in 90, each confirmed by a retest. Applies to insurers and intermediaries alike.
On this page
What VAPT for insurance companies means
The IRDAI VAPT requirements sit inside the Insurance Regulatory and Development Authority of India Information and Cyber Security Guidelines, and they bind every regulated entity that handles policyholder data, insurers, reinsurers, and intermediaries such as brokers, corporate agents, web aggregators, and third-party administrators. Because insurance systems hold identity, financial, and often health data, IRDAI treats real security testing as proof that controls work, not a policy document that says they do. In an audit, the VAPT evidence is one of the first things examined.
How often VAPT for insurance companies must run
The first thing to get right about VAPT for insurance companies is frequency, because two testing rhythms run at once and one of them changed recently.
Vulnerability assessment and penetration testing must run at least twice a year on customer-facing systems and critical infrastructure. On top of that, external penetration testing on internet-facing assets is required at least once every six months. The 2026 update to the guidelines sharpened this: the external test must now be grey-box or white-box rather than black-box only, which means the tester works with more knowledge of the system and probes deeper. Annual-only testing does not meet the standard.
Who can perform the test
This is non-negotiable and catches teams out. The rules state that testing must be performed by a CERT-In empanelled audit firm, and the annual assurance audit by a qualified external auditor holding recognised certifications such as CISA, DISA, or CERT-In empanelment. A report from an internal team or a non-empanelled vendor will not stand up at an IRDAI inspection. A grounding in the types of VAPT helps you scope the engagement correctly before you commission it.
Remediation deadlines for insurance VAPT
Running the test is only half the job. The guidelines set hard, severity-based deadlines for closing what the test finds, and require proof of closure.
Critical findings must be remediated within thirty days, high findings within sixty, and medium findings within ninety. Gaps found in an internal vulnerability scan of ICT infrastructure must be closed immediately, and gaps in internet-facing applications closed within one month, followed by confirmatory testing to prove the fix. Any high-risk issue not resolved in time has to be escalated to the Board’s Risk Management Committee. Findings tracked to closure, with retest evidence, are the real substance of the rule.
The scope and the evidence
A test that only checks the marketing site does not satisfy the IRDAI VAPT requirements. The scope has to reach the systems an attacker would actually target, and the evidence has to be ready for inspection.
In practice the scope covers external-facing applications, internal network segmentation and database security, and API security for every API exposed to external parties such as agents, brokers, and aggregators, alongside the wider ICT infrastructure. Just as important, remediation evidence must be maintained in a format you can present to IRDAI during an inspection. Intermediaries submit their CERT-In empanelled audit compliance report within thirty days of the audit completing, so this is really an all-year discipline, not a single event.
How Osto helps you stay ready
Meeting VAPT for insurance companies, testing on two cadences, across web, network, and API, with severity-based remediation, retests, and audit-ready evidence, is a heavy lift for a lean insurance or intermediary team without a dedicated security function. Coordinating separate testers, trackers, and reporting is slow and easy to let slip. That is the gap Osto is built to close.
Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. Against these requirements, it runs VAPT across your applications, APIs, and infrastructure, categorises findings by severity, generates remediation and retest reports, and keeps organised, audit-ready evidence mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets you test-ready and keeps the evidence in order, so the audit becomes a verification rather than a scramble.
Stay IRDAI test-ready all year, without a big team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Run VAPT on the right cadence, remediate by severity, retest, and keep audit-ready evidence, on one platform. No security team required.
Book a Demo →Frequently asked questions
How often does IRDAI require VAPT?
The IRDAI VAPT requirements mandate vulnerability assessment and penetration testing at least twice a year on customer-facing systems and critical infrastructure, plus external penetration testing at least once every six months on internet-facing assets.
Does the external penetration test have to be black-box?
No. As of the 2026 update, external penetration testing must be grey-box or white-box, not black-box only, and conducted at least six-monthly by a CERT-In empanelled auditor. This gives the tester deeper visibility into the system.
Who can perform VAPT for IRDAI compliance?
Only a CERT-In empanelled audit firm. The annual assurance audit must be by a qualified external auditor holding certifications such as CISA, DISA, or CERT-In empanelment. Internal or non-empanelled reports are not accepted.
What are the VAPT remediation deadlines?
By severity: critical findings within thirty days, high within sixty, medium within ninety. Internal-scan gaps must be closed immediately, and internet-facing application gaps within one month, followed by confirmatory retesting to prove closure.
What must the VAPT scope cover?
External-facing applications, internal network segmentation, database security, and API security for every externally exposed API, plus the wider ICT infrastructure. Remediation evidence must be kept in an IRDAI-presentable format.
Do intermediaries also have to meet the IRDAI VAPT requirements?
Yes. Brokers, corporate agents, web aggregators, and TPAs are bound alongside insurers, and must submit their CERT-In empanelled audit compliance report within thirty days of the audit completing.

