VAPT for SEBI Regulated Entities: Scope, Timelines and Compliance

SEBI VAPT requirements covering testing scope, reporting timelines, remediation and verified closure

In the SEBI context, VAPT is the prescribed security-testing cycle that finds vulnerabilities, proves exploitable risk, records remediation and verifies that fixes actually work.

  • Glossary
  • SEBI compliance
  • Security testing

The short answer

VAPT stands for Vulnerability Assessment and Penetration Testing. Under SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF), covered regulated entities must test a comprehensive scope through the applicable CERT-In-empanelled audit route, submit the approved report to the prescribed authority, close findings using a severity-based approach and complete revalidation. A scanner-only output is not the full SEBI VAPT cycle.

SEBI treats VAPT as a governed assurance process, not a once-a-year technical scan. Scope, auditor independence, management ownership, reporting, remediation, risk acceptance and revalidation all form part of the evidence.

What VAPT means in the SEBI context

Discover

Vulnerability assessment

Identify weaknesses broadly across every in-scope asset and classify them by severity.

Demonstrate

Penetration testing

Simulate attacks to show which weaknesses are exploitable and what an attacker could reach.

Validate

Closure and retest

Track remediation, retest the affected paths and preserve evidence that the fix is effective.

The general meaning of VAPT is breadth plus proof. SEBI adds a regulated operating layer: transparent scope, prescribed reporting, IT Committee oversight, defined closure expectations and revalidation.

A clean scan is not automatically a compliant VAPT

The evidence should show what was tested, how it was tested, which vulnerabilities were confirmed, how each was handled and whether remediation passed revalidation.

Vulnerability assessment versus penetration testing

DimensionVulnerability assessmentPenetration testing
QuestionWhich weaknesses may exist?What can an attacker actually exploit?
ApproachBroad, repeatable discovery using tools plus expert validation.Targeted simulations, manual testing and chained attack paths.
Typical outputAsset-level findings, severity, evidence and affected components.Reproduction steps, exploit evidence, impact and attack narrative.
Primary valueCoverage across the full environment.Proof and prioritisation based on real exploitability.

Both halves matter. Automated assessment finds known weaknesses efficiently; manual testing finds context-dependent issues such as broken authorisation, business-logic abuse and attack chains. This is especially important for API security, where a harmful request may be technically valid.

What SEBI expects the VAPT scope to cover

SEBI VAPTall critical assetsInfrastructureApplicationsAPIsMobile appsCloudWi-FiSegmentationOS &databasesConfigurationaudit
Swipe to see the full diagram. Annexure L expects transparent coverage of critical assets and infrastructure, not only the public website.
Scope areaExamples of what should be tested
InfrastructureInternal and external systems, servers, network devices, security devices and internet-facing IPs.
Applications and APIsAuthentication, authorisation, sessions, inputs, sensitive functions, integrations and exposed endpoints.
Mobile applicationsAndroid and iOS packages, local storage, transport, authentication and backend interaction.
CloudCloud deployments, identity permissions, public exposure, network controls and configuration posture, supported by ongoing CSPM.
Network and Wi-FiSegmentation, wireless security, accessible services, trust boundaries and lateral-movement paths.
Operating systems and databasesPatching, hardening, authentication, privileges, exposed services and insecure defaults.
ConfigurationSecurity settings across the in-scope technology stack and deviations from approved baselines.

Scope transparency is a control

An RE should reconcile the VAPT scope against its current asset inventory and criticality classification. Unexplained exclusions create an assurance gap even if every tested asset passes.

How often SEBI REs must conduct VAPT

Regulated entityCSCRF periodicity
REs identified as protected systems and/or Critical Information Infrastructure by NCIIPCAt least twice. One complete VAPT cycle—including report submission, closure and revalidation—must be completed in each half of the financial year.
Rest of the covered REsAt least once. The VAPT activity must commence in the first quarter of the financial year.

REs should plan VAPT at the beginning of the financial year. A category change must not leave an audit cycle uncovered; any unaudited period is included in the current cycle.

Annual is the regulatory floor, not a release strategy

A significant new application, API, mobile release, cloud migration or architectural change can create exposure long before the next scheduled engagement. Continuous assessment and change-triggered testing help manage the interval.

Report, closure and revalidation timeline

CompleteVAPT activitystart the clocks1 monthIT Committee approvalsubmit report3 monthsafter report submissionclose findings5 monthsafter VAPT completionfinish revalidationOpen items require governance; revalidation proves whether remediation worked.
Swipe to see the full timeline. The three deadlines use different starting points, so each should be tracked separately.
ActivityRequired timeline
VAPT report submission1 month Submit within one month of VAPT completion, after approval by the respective IT Committee for REs.
Closure of findings3 months Close within three months of report submission using a graded approach based on criticality.
Revalidation5 months Complete within five months of VAPT completion.

The IT Committee must regularly track vulnerability closure. Open vulnerabilities after the relevant period require documented governance, and the revalidation report and open observations must be placed before the Committee for direction.

Who can conduct SEBI-context VAPT?

Unless otherwise specified, CSCRF audits must use a CERT-In-empanelled information-security auditing organisation. SEBI’s audit guidelines also address experience, resources, independence, use of licensed tools, confidentiality and data handling.

Selection checkWhat to verify
EmpanelmentCERT-In empanelment is current for the full engagement period.
Relevant capabilityThe team has direct experience across the technologies and VAPT areas in the agreed scope.
IndependenceConflicts of interest and recent consulting relationships are assessed against the CSCRF selection norms.
Tools and methodLicensed tools and recognised testing methodologies are used, with manual depth beyond scanner output.
ConfidentialityAn NDA is signed and audit information is handled according to the prescribed jurisdictional safeguards.

What a defensible VAPT report must prove

  1. Entity and category. Identify the regulated entity, entity type, CSCRF category and rationale.
  2. Audit identity. Record the auditing organisation, empanelment details, period and independence declaration.
  3. Exact scope. List asset counts, IPs, applications, APIs, mobile packages, cloud environments and other tested components.
  4. Methodology. Explain the tools, manual testing, attack simulations and reference standards used.
  5. Finding quality. Give severity, affected asset, evidence, reproduction steps, impact and actionable remediation.
  6. Management ownership. Include the prescribed declaration and IT Committee review or approval evidence.
  7. Closure trail. Connect each finding to an owner, fix, date, supporting evidence and risk decision.
  8. Revalidation result. State whether the original exploit path is closed and identify anything that remains open.

VAPT findings should feed the organisation’s risk assessment and risk register. A finding is technical evidence; the risk register adds business consequence, ownership and the decision to remediate, mitigate or accept.

SEBI VAPT readiness checklist

  1. Confirm the RE type, CSCRF category, reporting authority and required frequency.
  2. Schedule the cycle at the beginning of the financial year and work backwards from reporting and revalidation deadlines.
  3. Reconcile the scope against the full asset inventory and critical-system classification.
  4. Include infrastructure, applications, APIs, mobile, cloud, Wi-Fi, segmentation, OS, databases and configuration where applicable.
  5. Resolve auditor empanelment, independence, NDA and data-handling requirements before testing.
  6. Create safe testing rules, escalation contacts, credentials, maintenance windows and evidence-handling procedures.
  7. Triage findings promptly and prioritise confirmed exploit paths rather than relying only on scanner severity.
  8. Track remediation through the IT Committee and record approved handling for open observations.
  9. Complete revalidation on time and preserve the report, proof of closure and residual-risk decisions.
  10. Use continuous scanning, DAST, code security and monitoring between formal VAPT cycles.

How Osto supports SEBI VAPT readiness

Osto combines broad automated assessment with expert-led penetration testing across web applications, APIs, mobile apps, cloud and infrastructure. Findings are categorised, assigned, tracked through remediation and carried into retesting in the same platform.

Because VAPT sits alongside WAF, API protection, CSPM, code security, endpoint controls and SIEM, the RE can connect a confirmed finding to its protective control, remediation owner and closure evidence without rebuilding the trail from separate systems.

SEBI VAPT readiness

Move from findings to verified closure

Cover the full attack surface, manage remediation and keep the evidence required for review and revalidation.

Get a free security assessment

Automated breadth · Expert-led depth · One platform, everything

Frequently asked questions

What does VAPT stand for in SEBI compliance?

VAPT stands for Vulnerability Assessment and Penetration Testing. It combines broad weakness discovery with attack simulation to confirm exploitability, followed by remediation and revalidation.

Is VAPT mandatory for SEBI Regulated Entities?

CSCRF prescribes VAPT for covered SEBI REs. The exact route, frequency and reporting authority depend on the entity and any applicable designation.

How often must a SEBI RE conduct VAPT?

Most covered REs conduct it at least once, commencing in the first quarter of the financial year. REs identified as protected systems and/or CII by NCIIPC complete one full cycle in each half of the financial year.

Must the VAPT auditor be CERT-In empanelled?

Unless otherwise specified, CSCRF audits must be conducted by a CERT-In-empanelled information-security auditing organisation. Auditor selection must also address capability, independence, tools and confidentiality.

What systems must be included in SEBI VAPT?

The comprehensive scope includes critical assets and infrastructure such as internal and external infrastructure, applications, APIs, mobile applications, cloud deployments, Wi-Fi, network segmentation, operating systems, databases and configuration.

When must the VAPT report be submitted?

After approval by the respective IT Committee for REs, the report must be submitted within one month of completing the VAPT activity.

How quickly must VAPT findings be closed?

CSCRF sets a three-month period from report submission, using a graded approach based on the criticality of observations. Open items require appropriate governance and tracking.

When is VAPT revalidation due?

Revalidation must be completed within five months of the original VAPT completion. Its purpose is to confirm that the identified exploit paths have actually been fixed.

Is automated vulnerability scanning enough?

No. Scanning supports the vulnerability-assessment half, but the prescribed scope calls for in-depth evaluation and simulations of actual attacks. Manual penetration testing and verified revalidation remain essential.

Is VAPT the same as a CSCRF cyber audit?

No. VAPT tests vulnerabilities and exploitability. A cyber audit evaluates compliance with the broader CSCRF standards and mandatory guidelines. They are distinct assurance activities with their own scope and timelines.