Compliance

SEBI CSCRF Audit and VAPT Requirements

CSCRF does not take your word for it. It builds in independent assurance through cyber audits, VAPT and, for larger entities, a Cyber Capability Index. Here's what each involves and how often.

Nilesh Wagh · Co-Founder, Pelta Technologies11 min readUpdated Part of SEBI CSCRF

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) does not rely on self-assertion. It builds in independent assurance, so that your compliance is tested rather than assumed. That assurance comes in three forms: Vulnerability Assessment and Penetration Testing (VAPT), a periodic cyber audit, and, for larger and more critical entities, a Cyber Capability Index (CCI) that measures cyber resilience maturity. This guide explains what each involves, how often it applies, who is allowed to perform it, and how to walk into these assessments ready rather than exposed. For the full control picture these assessments test against, see the SEBI CSCRF compliance checklist.

This article is general guidance, not legal advice. The scope, frequency and required qualifications for CSCRF audits and VAPT depend on your entity category and the current SEBI circular. Confirm the specifics that apply to you.

VAPT under SEBI CSCRF

VAPT is the technical test of whether your defences hold. Under CSCRF it is not a one-off: it recurs at a cadence set by your category, and its value is only realised when findings are actually closed.

  • Scope across internet-facing and critical internal systems, applications, networks and infrastructure.
  • A frequency set for your category, with higher categories testing more often and more deeply.
  • Testing by suitably qualified, independent testers (CERT-In empanelled providers are commonly used).
  • Findings tracked to closure with retesting, not just reported and shelved.
  • Evidence of the whole cycle: scope, findings, remediation and closure, ready for inspection.

The CSCRF cyber audit

Where VAPT tests the technology, the cyber audit assesses the whole program: governance, controls, processes and evidence. It is an independent, periodic examination against the CSCRF requirements applicable to your category.

  • Conducted by independent, suitably qualified auditors, separate from the teams running the audited systems.
  • Scoped to the CSCRF functions and controls that apply to your category.
  • Reported to your board or audit committee, and to SEBI where required.
  • Findings tracked to remediation and closure, with the trail retained as evidence.

The Cyber Capability Index (CCI)

For market infrastructure institutions and Qualified REs, CSCRF introduces the Cyber Capability Index, a structured way to measure and report cyber resilience maturity on a periodic basis. Rather than a pass or fail, the CCI scores your capability across defined parameters, so both you and the regulator can track whether resilience is improving over time. Confirm whether the CCI applies to your category and how often it must be assessed.

CSCRF assurance mechanisms compared
MechanismWhat it testsTypical performer
VAPTTechnical vulnerabilities in systems, apps and infrastructureIndependent, qualified testers (often CERT-In empanelled)
Cyber auditThe whole program: governance, controls, processes, evidenceIndependent, suitably qualified auditors
Cyber Capability IndexCyber resilience maturity, scored over timeAssessed per SEBI's defined method (higher categories)
Assurance intensity scales with your category
Heavier assurance

Market Infrastructure Institutions

Full VAPT, audit and CCI, most frequent

5

Qualified REs

VAPT, cyber audit and CCI

4

Mid-size REs

VAPT and periodic audit

3

Small-size REs

Proportionate testing and audit

2

Self-certification REs

Baseline, lighter cadence

1
Wider, deeper bars = more of the framework applies. Levels are indicative, confirm the thresholds for your entity type.

Who can perform CSCRF audits and VAPT

Independence and competence are the two tests. VAPT is typically performed by qualified security testers, with CERT-In empanelled providers a common and defensible choice. The cyber audit must be conducted by suitably qualified auditors who are independent of the teams and systems being audited, so an internal team that runs the controls cannot audit its own work. Confirm the specific qualification and empanelment expectations for your category before you appoint anyone.

Common audit and VAPT gaps

  • VAPT findings reported but never closed, or closed without retesting.
  • An audit scoped to the wrong category, missing obligations that actually apply.
  • Using an internal team that lacks independence from the systems it audits.
  • No evidence trail linking findings to the remediation that resolved them.
  • Treating CCI as a one-off rather than a maturity measure tracked over time.

Putting it together

CSCRF assurance is about proving your program holds up under independent scrutiny. Run VAPT on your category's cadence and close what it finds, undergo a genuine independent cyber audit, track your Cyber Capability Index where it applies, and keep evidence of the whole cycle. Confirm the exact frequencies and qualifications for your category in the current circular, and check where you sit using the applicability guide.

Frequently asked questions

How often is VAPT required under SEBI CSCRF?+

VAPT recurs at a frequency set by your entity category, with larger and more critical entities testing more often and more deeply. Findings must be tracked to closure with retesting. Confirm the specific cadence for your category against the current SEBI circular.

Who can conduct a SEBI CSCRF cyber audit?+

The cyber audit must be performed by suitably qualified auditors who are independent of the teams and systems being audited. An internal function that operates the controls cannot audit its own work. VAPT is typically carried out by qualified testers, with CERT-In empanelled providers a common choice.

What is the Cyber Capability Index (CCI) under SEBI CSCRF?+

The CCI is a structured measure of cyber resilience maturity that CSCRF introduces for market infrastructure institutions and Qualified REs. It scores capability across defined parameters on a periodic basis, so resilience can be tracked over time rather than judged pass or fail. Confirm whether it applies to your category.

What is the difference between a CSCRF cyber audit and VAPT?+

VAPT is a technical test of vulnerabilities in your systems, applications and infrastructure. The cyber audit is a broader independent examination of the whole program, including governance, controls, processes and evidence. Most entities need both, at a cadence set by their category.

About the author

N

Nilesh Wagh

Co-Founder, Pelta Technologies

Former CISO · 10+ years in information security & GRC

Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.

Connect on LinkedIn →

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.