Insights
SEBI CSCRF and VAPT: What Regulated Entities Must Do
A New Framework, Not Just a New Circular
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) consolidates and replaces the separate cybersecurity circulars that stock exchanges, depositories, mutual funds, stockbrokers, KRAs and other market infrastructure participants previously followed. For security teams inside regulated entities, the practical effect is that VAPT is no longer a once-a-year checkbox — it is one strand of an ongoing cyber resilience obligation that regulators expect to see evidenced, not just claimed.
That shift matters because CSCRF ties an entity's compliance posture to a self-declared category — based on size, criticality and the nature of the systems it runs — and each category carries a different cadence and depth of assessment. A qualified regulated entity or market infrastructure institution is expected to run VAPT more frequently and more rigorously than a small-size RE, but every category is expected to demonstrate a defensible, repeatable process rather than a one-off report filed to satisfy an auditor.
What CSCRF Changes for VAPT Specifically
- Scope beyond the perimeter. CSCRF's VAPT expectations extend to APIs, mobile applications, cloud-hosted infrastructure and third-party/vendor-connected systems — not just the traditional network perimeter that older circulars focused on.
- Documented remediation, not just findings. A VAPT report that lists vulnerabilities without a tracked closure timeline and verified re-test does not satisfy the framework's intent. Regulators increasingly expect proof that critical and high findings were actually fixed, with evidence.
- Board and senior management visibility. CSCRF pushes cyber resilience reporting up to leadership level — VAPT outcomes need to be summarised in language a board can act on, not buried in a technical appendix nobody outside IT reads.
- Incident and threat-intel integration. VAPT findings are expected to feed into the entity's broader incident-response and threat-intelligence posture, aligning with CERT-In reporting timelines rather than sitting in a separate compliance silo.
Where Entities Get Caught Out
The most common gap we see is not a missing VAPT — most regulated entities already run one. It's a VAPT that was scoped narrowly around what was easy to test (the corporate website, the core trading or transaction application) while newer surfaces — a partner-facing API, a mobile app released mid-year, a cloud workload spun up outside the original architecture review — were never brought into scope. CSCRF's audit expectations are explicit about covering the entity's actual technology footprint, not the footprint as it existed when the last VAPT contract was signed.
The second common gap is cadence drift: an annual VAPT that technically satisfies a once-a-year requirement but leaves a ten-to-eleven-month window where a newly disclosed CVE or a code change introduces exposure nobody is actively testing for. For entities in the higher CSCRF categories, that gap is itself a finding waiting to happen at the next audit cycle.
How to Approach a CSCRF-Aligned VAPT Programme
- Confirm your category and its cadence first. The assessment frequency and depth SEBI expects depends on how your entity is classified — get that right before scoping the engagement, not after.
- Scope to the real estate. Include every internet-facing and partner-facing system currently in production — web applications, APIs, mobile apps and cloud infrastructure — not just what was tested last time.
- Build in re-testing. A finding is not closed until it has been independently re-tested and verified fixed. Budget and schedule for that step up front rather than treating it as optional.
- Keep evidence audit-ready. Scope documents, findings, remediation tracking and re-test sign-off should be organised so they can be produced quickly when a SEBI or exchange audit asks for them.
eNeoteric runs VAPT engagements across India for BFSI and market-regulated entities, scoped around web applications, APIs, mobile apps and cloud infrastructure, with documented remediation tracking and re-test sign-off built into every engagement. If your entity is preparing for a CSCRF-aligned assessment cycle, see how our approach fits your BFSI security programme or talk to our team about scoping.
Explore all ← Back to Insights