BERRY9 IT SERVICES · B9ITS Book audit →
Home/Blog/Compliance
Compliance

SEBI Cybersecurity Framework: VAPT requirements for Indian stock brokers

B9ITS VAPT Practice 24 Feb 2026 12 min read Advanced

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF, August 2024) replaced and consolidated earlier broker/MII circulars. It defines a precise VAPT cadence per regulated-entity class. This is the operational summary.

The five regulated-entity classes under CSCRF

  1. Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations, depositories.
  2. Qualified Regulated Entities (QREs) — large brokers, AMCs, KRAs, RTAs above defined thresholds.
  3. Mid-sized REs — brokers and AMCs above the basic threshold.
  4. Small-sized REs — smaller brokers, depository participants, investment advisers above the entry threshold.
  5. Self-certifying REs — sub-broker / authorised person tier.

Each class has a different VAPT cadence and a different scope — and the framework explicitly maps to standards including ISO 27001, NIST CSF, and CIS Controls.

VAPT cadence by class

ClassExternal web/app VAPTInternal network VAPTConfiguration audit
MIIHalf-yearlyHalf-yearlyQuarterly
QREAnnual + on changeAnnualHalf-yearly
Mid REAnnualAnnualAnnual
Small REAnnualAnnual (managed-service acceptable)Annual
Self-certifyingAnnual via SEBI-empanelled vendor

Mandatory scope items

Vendor requirements

SEBI requires CERT-In empanelment for the VAPT vendor and explicit declarations of vendor independence. The framework calls out methodology — manual testing is required, scanner-only is not acceptable for the annual VAPT artifact.

Reporting and submission

VAPT reports must be presented to the Standing Committee on Cyber Security and submitted via the SEBI compliance portal at the prescribed cadence. Critical findings have explicit closure timelines — typically 30 days for QREs and MIIs, 45 days for mid-sized REs.

Practical scoping advice

Most Indian brokers we work with under CSCRF run a single combined VAPT engagement covering trading-platform web, mobile, API and back-office — with two engineer-pairs running in parallel — and split the deliverable into the artifacts SEBI expects. This is cheaper and faster than four separate engagements.

For the RBI equivalent, see VAPT for RBI-regulated entities.

Need a VAPT engagement scoped against this?

Tell us the asset and the compliance overlay. We will come back with a scope, timeline, and fixed-fee quote within 24 hours. Engagements start at USD 500. Free retest included.

Book a 20-minute call →
B9

BERRY9 IT SERVICES — VAPT Practice

Hyderabad-based ISO 27001 + 9001 certified offensive-security team. Since 2015 we have run 500+ engagements for 100+ clients across pharma, BFSI, healthcare, VFX, and enterprise SaaS. Every engagement includes a free retest.