{"id":1019,"date":"2026-08-24T19:51:00","date_gmt":"2026-08-24T19:51:00","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1019"},"modified":"2026-08-24T19:51:00","modified_gmt":"2026-08-24T19:51:00","slug":"resources-glossary-sebi-vapt-requirements","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-sebi-vapt-requirements\/","title":{"rendered":"VAPT for SEBI Regulated Entities: Scope, Timelines and Compliance"},"content":{"rendered":"\n<!-- OSTO GLOSSARY: VAPT in the SEBI context. Paste into one Custom HTML block. Page title is intentionally excluded. -->\n<style>\n.og{--navy:#1c267a;--text:#0f1538;--line:#eceef5;--white:#fff;--blue0:#f4f5fd;--blue1:#e9ecfa;--blue2:#cfd5f2;--blue7:#4a52a8;--sage0:#f2f8f5;--sage1:#e3f0e9;--sage2:#c3ddce;--sage7:#3a6f5d;--apri0:#fdf6f0;--apri1:#fbe9dc;--apri2:#f2cdb2;--apri7:#a2603a;--sky0:#f1f7fb;--sky1:#e2eff7;--sky2:#bfd9e9;--sky7:#2f6a89;--shadow:0 6px 22px rgba(15,21,56,.05);font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-size:17px;line-height:1.75;color:var(--text)}\n.og p{margin:0 0 22px}.og h2{font:700 clamp(25px,3vw,31px)\/1.25 'Inter',sans-serif;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}.og h2:after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--blue2)}.og h2.sage:after{background:var(--sage2)}.og h2.apri:after{background:var(--apri2)}.og h2.sky:after{background:var(--sky2)}.og h3{font:700 20px\/1.4 'Inter',sans-serif;color:var(--navy);margin:28px 0 8px}.og ul,.og ol{padding-left:22px;margin:0 0 24px}.og li{margin-bottom:9px}.og strong{font-weight:600}.og a{color:var(--navy);text-underline-offset:3px}\n.og .dek{font-size:20px;line-height:1.6;margin:0 0 18px}.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}.og .tags li{margin:0}.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}.og .tb{background:var(--blue1);color:var(--blue7)}.og .ts{background:var(--sage1);color:var(--sage7)}.og .ta{background:var(--apri1);color:var(--apri7)}\n.og .short{background:linear-gradient(135deg,var(--blue1),var(--sage1));border-radius:22px;padding:28px 32px;margin:0 0 30px}.og .short .k,.og .toc .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--blue7);margin:0 0 10px}.og .short p{font-size:19px;line-height:1.65;margin:0}.og .toc{background:var(--blue0);border-radius:20px;padding:24px 28px;margin:0 0 34px}.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}.og .toc a{text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n.og .callout{padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy);border-radius:4px}.og .callout.soft{border:none;border-radius:20px;background:var(--blue0)}.og .callout.apricot{border:none;border-radius:20px;background:var(--apri0)}.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}.og .callout.apricot .k{color:var(--apri7)}.og .callout p:last-child{margin-bottom:0}\n.og figure{margin:0 0 30px}.og .sx{overflow-x:auto;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}.og .sx svg{display:block;width:100%;height:auto;min-width:650px}.og figcaption{font-size:14px;line-height:1.6;margin-top:12px}.og .swipe{display:none}\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}.og td{border-bottom:1px solid var(--line);padding:13px 16px;vertical-align:top;line-height:1.6}.og tr:last-child td{border-bottom:none}.og .hb th{background:var(--blue1);color:var(--blue7)}.og .hs th{background:var(--sage1);color:var(--sage7)}.og .ha th{background:var(--apri1);color:var(--apri7)}\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}.og .card{border-radius:18px;padding:20px 22px}.og .card .n{font-size:16px;font-weight:700;margin:0 0 4px}.og .card .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}.og .card p{font-size:14px;line-height:1.55;margin:0}.og .card.a{background:var(--sky0)}.og .card.a .n,.og .card.a .g{color:var(--sky7)}.og .card.b{background:var(--sage0)}.og .card.b .n,.og .card.b .g{color:var(--sage7)}.og .card.c{background:var(--blue0)}.og .card.c .n,.og .card.c .g{color:var(--navy)}\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}.og .p1{background:var(--blue1);color:var(--navy)}.og .p3{background:var(--apri1);color:var(--apri7)}.og .p5{background:var(--sage1);color:var(--sage7)}\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px}.og summary::-webkit-details-marker{display:none}.og summary:after{content:\"+\";font-size:22px;line-height:1;color:var(--blue7)}.og details[open] summary:after{content:\"\\2013\"}.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}.og .related{font-size:15px;border-top:1px solid var(--line);padding-top:22px;margin-top:40px}\n@media(max-width:700px){.og{font-size:16px}.og .dek{font-size:18px}.og .short p{font-size:17px}.og .short,.og .toc,.og .callout{padding:22px 20px}.og .toc ol{columns:1}.og .trio{grid-template-columns:1fr}.og .swipe{display:inline;font-weight:600;color:var(--blue7)}.og table{font-size:14px}.og th,.og td{padding:11px 12px}}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">In the SEBI context, VAPT is the prescribed security-testing cycle that finds vulnerabilities, proves exploitable risk, records remediation and verifies that fixes actually work.<\/p>\n<ul class=\"tags\"><li><span class=\"tag tb\">Glossary<\/span><\/li><li><span class=\"tag ts\">SEBI compliance<\/span><\/li><li><span class=\"tag ta\">Security testing<\/span><\/li><\/ul>\n<div class=\"short\"><p class=\"k\">The short answer<\/p><p><strong>VAPT stands for Vulnerability Assessment and Penetration Testing.<\/strong> Under SEBI\u2019s Cybersecurity and Cyber Resilience Framework (CSCRF), covered regulated entities must test a comprehensive scope through the applicable CERT-In-empanelled audit route, submit the approved report to the prescribed authority, close findings using a severity-based approach and complete revalidation. A scanner-only output is not the full SEBI VAPT cycle.<\/p><\/div>\n<p>SEBI treats VAPT as a governed assurance process, not a once-a-year technical scan. Scope, auditor independence, management ownership, reporting, remediation, risk acceptance and revalidation all form part of the evidence.<\/p>\n<div class=\"toc\"><p class=\"k\">On this page<\/p><ol><li><a href=\"#meaning\">What VAPT means<\/a><\/li><li><a href=\"#difference\">VA versus penetration testing<\/a><\/li><li><a href=\"#scope\">SEBI\u2019s VAPT scope<\/a><\/li><li><a href=\"#frequency\">Frequency and applicability<\/a><\/li><li><a href=\"#timeline\">Reporting and closure timeline<\/a><\/li><li><a href=\"#auditor\">Auditor requirements<\/a><\/li><li><a href=\"#evidence\">What the report must prove<\/a><\/li><li><a href=\"#checklist\">Readiness checklist<\/a><\/li><li><a href=\"#osto\">How Osto supports VAPT<\/a><\/li><li><a href=\"#faq\">FAQ<\/a><\/li><\/ol><\/div>\n\n<h2 id=\"meaning\">What VAPT means in the SEBI context<\/h2>\n<div class=\"trio\"><div class=\"card a\"><p class=\"n\">Discover<\/p><p class=\"g\">Vulnerability assessment<\/p><p>Identify weaknesses broadly across every in-scope asset and classify them by severity.<\/p><\/div><div class=\"card b\"><p class=\"n\">Demonstrate<\/p><p class=\"g\">Penetration testing<\/p><p>Simulate attacks to show which weaknesses are exploitable and what an attacker could reach.<\/p><\/div><div class=\"card c\"><p class=\"n\">Validate<\/p><p class=\"g\">Closure and retest<\/p><p>Track remediation, retest the affected paths and preserve evidence that the fix is effective.<\/p><\/div><\/div>\n<p>The general meaning of <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> is breadth plus proof. SEBI adds a regulated operating layer: transparent scope, prescribed reporting, IT Committee oversight, defined closure expectations and revalidation.<\/p>\n<div class=\"callout soft\"><p class=\"k\">A clean scan is not automatically a compliant VAPT<\/p><p>The evidence should show what was tested, how it was tested, which vulnerabilities were confirmed, how each was handled and whether remediation passed revalidation.<\/p><\/div>\n\n<h2 id=\"difference\" class=\"sky\">Vulnerability assessment versus penetration testing<\/h2>\n<table class=\"hb\"><thead><tr><th>Dimension<\/th><th>Vulnerability assessment<\/th><th>Penetration testing<\/th><\/tr><\/thead><tbody><tr><td><strong>Question<\/strong><\/td><td>Which weaknesses may exist?<\/td><td>What can an attacker actually exploit?<\/td><\/tr><tr><td><strong>Approach<\/strong><\/td><td>Broad, repeatable discovery using tools plus expert validation.<\/td><td>Targeted simulations, manual testing and chained attack paths.<\/td><\/tr><tr><td><strong>Typical output<\/strong><\/td><td>Asset-level findings, severity, evidence and affected components.<\/td><td>Reproduction steps, exploit evidence, impact and attack narrative.<\/td><\/tr><tr><td><strong>Primary value<\/strong><\/td><td>Coverage across the full environment.<\/td><td>Proof and prioritisation based on real exploitability.<\/td><\/tr><\/tbody><\/table>\n<p>Both halves matter. Automated assessment finds known weaknesses efficiently; manual testing finds context-dependent issues such as broken authorisation, business-logic abuse and attack chains. This is especially important for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a>, where a harmful request may be technically valid.<\/p>\n\n<h2 id=\"scope\" class=\"sage\">What SEBI expects the VAPT scope to cover<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 400\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SEBI VAPT scope across infrastructure, applications, APIs, mobile, cloud, Wi-Fi, segmentation, operating systems, databases and configuration.\"><circle cx=\"390\" cy=\"192\" r=\"76\" fill=\"#1c267a\"\/><text x=\"390\" y=\"185\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"23\" font-weight=\"700\" fill=\"#fff\">SEBI VAPT<\/text><text x=\"390\" y=\"211\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"12\" fill=\"#dfe2f4\">all critical assets<\/text><g font-family=\"Inter\" font-size=\"12\" text-anchor=\"middle\"><rect x=\"45\" y=\"48\" width=\"145\" height=\"56\" rx=\"16\" fill=\"#e9ecfa\"\/><text x=\"117\" y=\"81\" fill=\"#1c267a\" font-weight=\"700\">Infrastructure<\/text><rect x=\"213\" y=\"48\" width=\"145\" height=\"56\" rx=\"16\" fill=\"#e2eff7\"\/><text x=\"285\" y=\"81\" fill=\"#2f6a89\" font-weight=\"700\">Applications<\/text><rect x=\"422\" y=\"48\" width=\"145\" height=\"56\" rx=\"16\" fill=\"#e3f0e9\"\/><text x=\"494\" y=\"81\" fill=\"#3a6f5d\" font-weight=\"700\">APIs<\/text><rect x=\"590\" y=\"48\" width=\"145\" height=\"56\" rx=\"16\" fill=\"#fbe9dc\"\/><text x=\"662\" y=\"81\" fill=\"#a2603a\" font-weight=\"700\">Mobile apps<\/text><rect x=\"35\" y=\"300\" width=\"130\" height=\"56\" rx=\"16\" fill=\"#f1f7fb\"\/><text x=\"100\" y=\"333\" fill=\"#2f6a89\" font-weight=\"700\">Cloud<\/text><rect x=\"180\" y=\"300\" width=\"130\" height=\"56\" rx=\"16\" fill=\"#f4f5fd\"\/><text x=\"245\" y=\"333\" fill=\"#1c267a\" font-weight=\"700\">Wi-Fi<\/text><rect x=\"325\" y=\"300\" width=\"130\" height=\"56\" rx=\"16\" fill=\"#e3f0e9\"\/><text x=\"390\" y=\"333\" fill=\"#3a6f5d\" font-weight=\"700\">Segmentation<\/text><rect x=\"470\" y=\"300\" width=\"130\" height=\"56\" rx=\"16\" fill=\"#fbe9dc\"\/><text x=\"535\" y=\"326\" fill=\"#a2603a\" font-weight=\"700\">OS &amp;<\/text><text x=\"535\" y=\"342\" fill=\"#a2603a\" font-weight=\"700\">databases<\/text><rect x=\"615\" y=\"300\" width=\"130\" height=\"56\" rx=\"16\" fill=\"#e9ecfa\"\/><text x=\"680\" y=\"326\" fill=\"#1c267a\" font-weight=\"700\">Configuration<\/text><text x=\"680\" y=\"342\" fill=\"#1c267a\" font-weight=\"700\">audit<\/text><\/g><g stroke=\"#cfd5f2\" stroke-width=\"2\"><line x1=\"117\" y1=\"104\" x2=\"329\" y2=\"144\"\/><line x1=\"285\" y1=\"104\" x2=\"354\" y2=\"122\"\/><line x1=\"494\" y1=\"104\" x2=\"426\" y2=\"122\"\/><line x1=\"662\" y1=\"104\" x2=\"451\" y2=\"144\"\/><line x1=\"100\" y1=\"300\" x2=\"326\" y2=\"244\"\/><line x1=\"245\" y1=\"300\" x2=\"351\" y2=\"261\"\/><line x1=\"390\" y1=\"300\" x2=\"390\" y2=\"268\"\/><line x1=\"535\" y1=\"300\" x2=\"429\" y2=\"261\"\/><line x1=\"680\" y1=\"300\" x2=\"454\" y2=\"244\"\/><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Annexure L expects transparent coverage of critical assets and infrastructure, not only the public website.<\/figcaption><\/figure>\n<table class=\"hs\"><thead><tr><th>Scope area<\/th><th>Examples of what should be tested<\/th><\/tr><\/thead><tbody><tr><td><strong>Infrastructure<\/strong><\/td><td>Internal and external systems, servers, network devices, security devices and internet-facing IPs.<\/td><\/tr><tr><td><strong>Applications and APIs<\/strong><\/td><td>Authentication, authorisation, sessions, inputs, sensitive functions, integrations and exposed endpoints.<\/td><\/tr><tr><td><strong>Mobile applications<\/strong><\/td><td>Android and iOS packages, local storage, transport, authentication and backend interaction.<\/td><\/tr><tr><td><strong>Cloud<\/strong><\/td><td>Cloud deployments, identity permissions, public exposure, network controls and configuration posture, supported by ongoing <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a>.<\/td><\/tr><tr><td><strong>Network and Wi-Fi<\/strong><\/td><td>Segmentation, wireless security, accessible services, trust boundaries and lateral-movement paths.<\/td><\/tr><tr><td><strong>Operating systems and databases<\/strong><\/td><td>Patching, hardening, authentication, privileges, exposed services and insecure defaults.<\/td><\/tr><tr><td><strong>Configuration<\/strong><\/td><td>Security settings across the in-scope technology stack and deviations from approved baselines.<\/td><\/tr><\/tbody><\/table>\n<div class=\"callout\"><p class=\"k\">Scope transparency is a control<\/p><p>An RE should reconcile the VAPT scope against its current asset inventory and criticality classification. Unexplained exclusions create an assurance gap even if every tested asset passes.<\/p><\/div>\n\n<h2 id=\"frequency\" class=\"apri\">How often SEBI REs must conduct VAPT<\/h2>\n<table class=\"ha\"><thead><tr><th>Regulated entity<\/th><th>CSCRF periodicity<\/th><\/tr><\/thead><tbody><tr><td><strong>REs identified as protected systems and\/or Critical Information Infrastructure by NCIIPC<\/strong><\/td><td><strong>At least twice.<\/strong> One complete VAPT cycle\u2014including report submission, closure and revalidation\u2014must be completed in each half of the financial year.<\/td><\/tr><tr><td><strong>Rest of the covered REs<\/strong><\/td><td><strong>At least once.<\/strong> The VAPT activity must commence in the first quarter of the financial year.<\/td><\/tr><\/tbody><\/table>\n<p>REs should plan VAPT at the beginning of the financial year. A category change must not leave an audit cycle uncovered; any unaudited period is included in the current cycle.<\/p>\n<div class=\"callout apricot\"><p class=\"k\">Annual is the regulatory floor, not a release strategy<\/p><p>A significant new application, API, mobile release, cloud migration or architectural change can create exposure long before the next scheduled engagement. Continuous assessment and change-triggered testing help manage the interval.<\/p><\/div>\n\n<h2 id=\"timeline\">Report, closure and revalidation timeline<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 270\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SEBI VAPT timeline from completion through report submission, finding closure and revalidation.\"><line x1=\"86\" y1=\"130\" x2=\"694\" y2=\"130\" stroke=\"#cfd5f2\" stroke-width=\"6\" stroke-linecap=\"round\"\/><g font-family=\"Inter\" text-anchor=\"middle\"><circle cx=\"94\" cy=\"130\" r=\"16\" fill=\"#1c267a\"\/><text x=\"94\" y=\"75\" font-size=\"18\" font-weight=\"700\" fill=\"#1c267a\">Complete<\/text><text x=\"94\" y=\"99\" font-size=\"11.5\" fill=\"#0f1538\">VAPT activity<\/text><text x=\"94\" y=\"178\" font-size=\"11.5\" fill=\"#0f1538\">start the clocks<\/text><circle cx=\"292\" cy=\"130\" r=\"16\" fill=\"#4a52a8\"\/><text x=\"292\" y=\"75\" font-size=\"21\" font-weight=\"700\" fill=\"#1c267a\">1 month<\/text><text x=\"292\" y=\"99\" font-size=\"11.5\" fill=\"#0f1538\">IT Committee approval<\/text><text x=\"292\" y=\"178\" font-size=\"11.5\" fill=\"#0f1538\">submit report<\/text><circle cx=\"496\" cy=\"130\" r=\"16\" fill=\"#a2603a\"\/><text x=\"496\" y=\"75\" font-size=\"21\" font-weight=\"700\" fill=\"#a2603a\">3 months<\/text><text x=\"496\" y=\"99\" font-size=\"11.5\" fill=\"#0f1538\">after report submission<\/text><text x=\"496\" y=\"178\" font-size=\"11.5\" fill=\"#0f1538\">close findings<\/text><circle cx=\"690\" cy=\"130\" r=\"16\" fill=\"#3a6f5d\"\/><text x=\"690\" y=\"75\" font-size=\"21\" font-weight=\"700\" fill=\"#3a6f5d\">5 months<\/text><text x=\"690\" y=\"99\" font-size=\"11.5\" fill=\"#0f1538\">after VAPT completion<\/text><text x=\"690\" y=\"178\" font-size=\"11.5\" fill=\"#0f1538\">finish revalidation<\/text><text x=\"390\" y=\"231\" font-size=\"12.5\" fill=\"#0f1538\">Open items require governance; revalidation proves whether remediation worked.<\/text><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full timeline. <\/span>The three deadlines use different starting points, so each should be tracked separately.<\/figcaption><\/figure>\n<table class=\"hb\"><thead><tr><th>Activity<\/th><th>Required timeline<\/th><\/tr><\/thead><tbody><tr><td><strong>VAPT report submission<\/strong><\/td><td><span class=\"pill p1\">1 month<\/span> Submit within one month of VAPT completion, after approval by the respective IT Committee for REs.<\/td><\/tr><tr><td><strong>Closure of findings<\/strong><\/td><td><span class=\"pill p3\">3 months<\/span> Close within three months of report submission using a graded approach based on criticality.<\/td><\/tr><tr><td><strong>Revalidation<\/strong><\/td><td><span class=\"pill p5\">5 months<\/span> Complete within five months of VAPT completion.<\/td><\/tr><\/tbody><\/table>\n<p>The IT Committee must regularly track vulnerability closure. Open vulnerabilities after the relevant period require documented governance, and the revalidation report and open observations must be placed before the Committee for direction.<\/p>\n\n<h2 id=\"auditor\" class=\"sage\">Who can conduct SEBI-context VAPT?<\/h2>\n<p>Unless otherwise specified, CSCRF audits must use a <strong>CERT-In-empanelled information-security auditing organisation<\/strong>. SEBI\u2019s audit guidelines also address experience, resources, independence, use of licensed tools, confidentiality and data handling.<\/p>\n<table class=\"hs\"><thead><tr><th>Selection check<\/th><th>What to verify<\/th><\/tr><\/thead><tbody><tr><td><strong>Empanelment<\/strong><\/td><td>CERT-In empanelment is current for the full engagement period.<\/td><\/tr><tr><td><strong>Relevant capability<\/strong><\/td><td>The team has direct experience across the technologies and VAPT areas in the agreed scope.<\/td><\/tr><tr><td><strong>Independence<\/strong><\/td><td>Conflicts of interest and recent consulting relationships are assessed against the CSCRF selection norms.<\/td><\/tr><tr><td><strong>Tools and method<\/strong><\/td><td>Licensed tools and recognised testing methodologies are used, with manual depth beyond scanner output.<\/td><\/tr><tr><td><strong>Confidentiality<\/strong><\/td><td>An NDA is signed and audit information is handled according to the prescribed jurisdictional safeguards.<\/td><\/tr><\/tbody><\/table>\n\n<h2 id=\"evidence\" class=\"sky\">What a defensible VAPT report must prove<\/h2>\n<ol><li><strong>Entity and category.<\/strong> Identify the regulated entity, entity type, CSCRF category and rationale.<\/li><li><strong>Audit identity.<\/strong> Record the auditing organisation, empanelment details, period and independence declaration.<\/li><li><strong>Exact scope.<\/strong> List asset counts, IPs, applications, APIs, mobile packages, cloud environments and other tested components.<\/li><li><strong>Methodology.<\/strong> Explain the tools, manual testing, attack simulations and reference standards used.<\/li><li><strong>Finding quality.<\/strong> Give severity, affected asset, evidence, reproduction steps, impact and actionable remediation.<\/li><li><strong>Management ownership.<\/strong> Include the prescribed declaration and IT Committee review or approval evidence.<\/li><li><strong>Closure trail.<\/strong> Connect each finding to an owner, fix, date, supporting evidence and risk decision.<\/li><li><strong>Revalidation result.<\/strong> State whether the original exploit path is closed and identify anything that remains open.<\/li><\/ol>\n<p>VAPT findings should feed the organisation\u2019s <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment and risk register<\/a>. A finding is technical evidence; the risk register adds business consequence, ownership and the decision to remediate, mitigate or accept.<\/p>\n\n<h2 id=\"checklist\" class=\"apri\">SEBI VAPT readiness checklist<\/h2>\n<ol><li>Confirm the RE type, CSCRF category, reporting authority and required frequency.<\/li><li>Schedule the cycle at the beginning of the financial year and work backwards from reporting and revalidation deadlines.<\/li><li>Reconcile the scope against the full asset inventory and critical-system classification.<\/li><li>Include infrastructure, applications, APIs, mobile, cloud, Wi-Fi, segmentation, OS, databases and configuration where applicable.<\/li><li>Resolve auditor empanelment, independence, NDA and data-handling requirements before testing.<\/li><li>Create safe testing rules, escalation contacts, credentials, maintenance windows and evidence-handling procedures.<\/li><li>Triage findings promptly and prioritise confirmed exploit paths rather than relying only on scanner severity.<\/li><li>Track remediation through the IT Committee and record approved handling for open observations.<\/li><li>Complete revalidation on time and preserve the report, proof of closure and residual-risk decisions.<\/li><li>Use continuous scanning, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a>, code security and monitoring between formal VAPT cycles.<\/li><\/ol>\n\n<h2 id=\"osto\" class=\"sage\">How Osto supports SEBI VAPT readiness<\/h2>\n<p>Osto combines broad automated assessment with expert-led penetration testing across web applications, APIs, mobile apps, cloud and infrastructure. Findings are categorised, assigned, tracked through remediation and carried into retesting in the same platform.<\/p>\n<p>Because VAPT sits alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a>, API protection, CSPM, code security, endpoint controls and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a>, the RE can connect a confirmed finding to its protective control, remediation owner and closure evidence without rebuilding the trail from separate systems.<\/p>\n<p class=\"related\"><strong>Primary source:<\/strong> <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI Cybersecurity and Cyber Resilience Framework, 20 August 2024<\/a>, including Part I section 4.3 and Annexures A, D and L. This glossary is an operational overview, not legal advice.<\/p>\n\n<div style=\"background:#1C267A;border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.22);text-align:center\"><p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#fff;font:700 11px Inter,sans-serif;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px\">SEBI VAPT readiness<\/p><p style=\"color:#fff;font:700 26px\/1.3 Inter,sans-serif;letter-spacing:-.4px;margin:0 0 12px\">Move from findings to verified closure<\/p><p style=\"color:#dfe2f4;font:16px\/1.65 Inter,sans-serif;margin:0 auto 26px;max-width:540px\">Cover the full attack surface, manage remediation and keep the evidence required for review and revalidation.<\/p><a href=\"https:\/\/www.osto.one\/contact\" style=\"display:inline-block;background:#fff;color:#1c267a;font:700 16px Inter,sans-serif;text-decoration:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px\" target=\"_blank\" rel=\"noopener\">Get a free security assessment<\/a><p style=\"color:#cfd3ea;font:13px Inter,sans-serif;margin:14px 0 0\">Automated breadth \u00b7 Expert-led depth \u00b7 One platform, everything<\/p><\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details><summary>What does VAPT stand for in SEBI compliance?<\/summary><p>VAPT stands for Vulnerability Assessment and Penetration Testing. It combines broad weakness discovery with attack simulation to confirm exploitability, followed by remediation and revalidation.<\/p><\/details>\n<details><summary>Is VAPT mandatory for SEBI Regulated Entities?<\/summary><p>CSCRF prescribes VAPT for covered SEBI REs. The exact route, frequency and reporting authority depend on the entity and any applicable designation.<\/p><\/details>\n<details><summary>How often must a SEBI RE conduct VAPT?<\/summary><p>Most covered REs conduct it at least once, commencing in the first quarter of the financial year. REs identified as protected systems and\/or CII by NCIIPC complete one full cycle in each half of the financial year.<\/p><\/details>\n<details><summary>Must the VAPT auditor be CERT-In empanelled?<\/summary><p>Unless otherwise specified, CSCRF audits must be conducted by a CERT-In-empanelled information-security auditing organisation. Auditor selection must also address capability, independence, tools and confidentiality.<\/p><\/details>\n<details><summary>What systems must be included in SEBI VAPT?<\/summary><p>The comprehensive scope includes critical assets and infrastructure such as internal and external infrastructure, applications, APIs, mobile applications, cloud deployments, Wi-Fi, network segmentation, operating systems, databases and configuration.<\/p><\/details>\n<details><summary>When must the VAPT report be submitted?<\/summary><p>After approval by the respective IT Committee for REs, the report must be submitted within one month of completing the VAPT activity.<\/p><\/details>\n<details><summary>How quickly must VAPT findings be closed?<\/summary><p>CSCRF sets a three-month period from report submission, using a graded approach based on the criticality of observations. Open items require appropriate governance and tracking.<\/p><\/details>\n<details><summary>When is VAPT revalidation due?<\/summary><p>Revalidation must be completed within five months of the original VAPT completion. Its purpose is to confirm that the identified exploit paths have actually been fixed.<\/p><\/details>\n<details><summary>Is automated vulnerability scanning enough?<\/summary><p>No. Scanning supports the vulnerability-assessment half, but the prescribed scope calls for in-depth evaluation and simulations of actual attacks. Manual penetration testing and verified revalidation remain essential.<\/p><\/details>\n<details><summary>Is VAPT the same as a CSCRF cyber audit?<\/summary><p>No. VAPT tests vulnerabilities and exploitability. A cyber audit evaluates compliance with the broader CSCRF standards and mandatory guidelines. They are distinct assurance activities with their own scope and timelines.<\/p><\/details>\n<p class=\"related\"><strong>Continue reading:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/blog\/what-is-vapt\/\">What Is VAPT?<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In the SEBI context, VAPT is the prescribed security-testing cycle that finds vulnerabilities, proves exploitable risk, records remediation and verifies\u2026<\/p>\n","protected":false},"author":8,"featured_media":1020,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[470,471,469],"class_list":["post-1019","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sebi-vapt","tag-sebi-vapt-guidelines","tag-vapt-for-sebi-regulated-entities"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1019"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1019\/revisions"}],"predecessor-version":[{"id":1021,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1019\/revisions\/1021"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1020"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}