Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Financial Services

VAPT for Banks, NBFCs and Fintechs in India

VAPT for banks and NBFCs is testing with a regulator reading over your shoulder. SecureRoot runs manual, exploit-driven penetration testing of the systems RBI and SEBI expect you to test: internet and mobile banking, customer portals, partner and payment APIs, the network edge and the cloud accounts behind them. Every finding carries proof and a fix, critical issues reach you within three hours, and the retest that shows each fix held is part of the engagement, so the evidence is ready before your formal audit rather than after it.

Regulators

What Your Regulator Expects

The instrument that applies to you sets how often you test, what counts as in scope and who must sign the formal report. Read the source, not a summary: each row links the regulator's own text.

  • Who it covers
    Commercial banks, small finance banks and NBFCs, each under its own 2026 Directions, which repealed the earlier IT governance and cyber instructions for that entity type. Payments banks, credit information companies and all-India financial institutions should confirm which instrument now applies to them.
    What it expects
    For critical systems and customer-facing systems in the DMZ: vulnerability assessment at least every six months and penetration testing at least every 12 months, plus testing across the system lifecycle, by independent information security experts or auditors. For NBFCs this sits in the chapter for middle, upper and top layer entities.
  • Who it covers
    SEBI regulated entities, graded into market infrastructure institutions, qualified, mid-size, small-size and self-certification categories: stockbrokers, depository participants, portfolio managers, AMCs, KRAs and RTAs among them.
    What it expects
    At least one VAPT a year starting in the first quarter, or one in each half-year for entities NCIIPC has identified as protected systems or CII and, per SEBI's June 2025 FAQs, for Qualified Stock Brokers; VAPT after every major release for all but small-size and self-certification entities; report within one month, findings closed within three months, revalidation within five months. Read with SEBI's later CSCRF clarifications.
  • Who it covers
    Service providers, intermediaries, data centres and body corporates in India, which includes every regulated financial entity.
    What it expects
    Not a testing cycle: cyber incidents must be reported to CERT-In within six hours of noticing them, which is why detection and logging are tested alongside the applications.

Where your regulator requires the formal VAPT report to come from a CERT-In empanelled auditor, that requirement stands. SecureRoot is not a CERT-In empanelled auditing organisation; the section below explains where our work sits beside the auditor who signs.

Services

What We Test and Review

When Testing Feeds a Wider Programme

Card data, customer data and third-party risk bring their own obligations. The same team runs those programmes, so a test is scoped to satisfy every control it is evidence for.

How It Runs

How a Regulated Engagement Runs

The scope, the timeline and the price are written down before anyone starts, and the scope is drawn from your critical systems inventory rather than from a guess.

  1. 01

    Scoping Against Your Inventory

    You hear back within one business day. On the scoping call we map your critical and internet-facing systems against the instrument that applies to you, and agree what is in and out.

  2. 02

    A Written Scope and a Fixed Price

    Targets, test windows, rules of engagement, deliverables and the price, in writing. Testing windows respect change freezes and settlement cycles.

  3. 03

    Manual Testing, Critical Findings at Once

    Testing by hand and with intent, backed by tooling rather than replaced by it. Critical findings reach you within three hours of discovery, not at the end of the engagement.

  4. 04

    Remediation, Retest and Evidence

    The tester who found the flaw explains it to your developers. Once fixes land we retest inside the engagement and issue a verified retest report for your board, your auditor and your regulator file.

Our Role

Where We Sit Beside Your Empanelled Auditor

SecureRoot is not a CERT-In empanelled auditing organisation, and we will not blur that line. If your regulator or a tender requires the formal VAPT report to be signed by an empanelled auditor, that auditor signs it.

What we do is the work that decides how that audit goes. We test the same systems earlier and by hand, prove which findings are real, help your developers fix them, and retest until they are closed. When the formal cycle begins, the auditor confirms controls that already hold instead of opening a remediation list that runs past your deadline.

The same testing serves the rest of the year: after a major release, before a new partner integration goes live, and as evidence for ISO 27001, PCI DSS and DPDP Act programmes. SecureRoot Risk Advisory LLP holds ISO/IEC 27001:2022 certification (certificate IN60432E), and engagements are led by named testers holding credentials including CISM and eWPTX.

Who It Is For

Who We Test For

Financial-services teams whose systems face a regulator, a partner bank or both.

  • Banks and Small Finance Banks

    Internet and mobile banking, customer onboarding, and the internet-facing estate an RBI inspection reads the test reports for.

  • NBFCs

    Lending platforms, loan management systems and collection apps, scoped to the layer-based expectations in the RBI direction.

  • Payment Aggregators and Gateways

    Checkout flows, merchant dashboards and payment APIs, where card data brings PCI DSS into the same scope.

  • Stockbrokers, AMCs and Depository Participants

    Trading apps, client portals and back-office integrations, tested ahead of the CSCRF cycle for your category.

  • Fintechs Serving a Regulated Partner

    Companies whose bank or NBFC partner passes its testing and due-diligence expectations down the contract.

  • Insurers and Insurtechs

    Policy, claims and distribution platforms, and the partner APIs that connect them to aggregators.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What does an auditor or a regulator actually expect to see in the report?

Assume the report will be read by someone who was not in the room. An auditor or an inspection team looks for the scope that was agreed and when, the method and standard behind each surface tested, every finding with a proof of concept showing the issue was reproduced rather than inferred, a severity that is justified, a fix that names the component to change, and a retest recording what closed and what still stands. SecureRoot writes findings that way and the retest sits inside the engagement, so the closure evidence and the original report come from the same team. SEBI adds a layer of its own: under CSCRF the report goes in within one month of the VAPT, with findings closed within three months and revalidation within five. The submission route and the sign-off it needs are set by the framework and its later clarifications, which our SEBI CSCRF compliance guide tracks, so confirm the current wording for your category.

How do you test core banking or payment systems without touching production data?

We scope around the data, not just the hostname. Testing of core banking, lending and payment systems normally runs against a staging or pre-production environment that mirrors the live build, seeded with synthetic or masked records, so no live customer data is handled to prove a finding. Where production has to be touched, because the 2026 RBI Directions expect post-implementation testing on the production environment, the written scope names the accounts, the test windows and the actions that are out of bounds: no denial of service, no destructive payloads, no bulk extraction of records, and windows that avoid settlement cycles and change freezes. A proof of concept stops at the point the issue is demonstrated. We ask for test credentials at each role rather than live ones. What we will not do is widen the scope mid-test; anything noticed outside it is reported to you, not exploited.

How should a fintech sequence its testing before an audit window?

Work backwards from the date the report is due, not the date the auditor arrives. Under SEBI CSCRF the report goes in within one month of completing the VAPT, findings close within three months of the report and revalidation is due within five months of the VAPT, so a test that starts late compresses remediation rather than testing. Under the 2026 RBI Directions, critical and customer-facing DMZ systems need a vulnerability assessment at least every six months and a penetration test at least every twelve, and that clock runs from your last test, not from the audit. A workable sequence: settle the critical systems list first, book testing at least a quarter before the window, act on critical findings as they arrive rather than at the end, give developers a real remediation period, then retest. The scoping call runs 30 to 45 minutes and produces a written scope, a timeline and a fixed price before anyone starts.

A vendor supplies our core banking or payment platform. What happens when a finding is theirs to fix?

The finding still comes to you, because the obligation does. Much of a regulated estate is bought rather than built: a core banking product, a payment switch, a lending platform, a KYC or onboarding SDK. Where the flaw sits in that component, the report names it as the vendor's to fix and gives you a proof of concept written to survive being forwarded to someone who was never on our calls. Two practical points follow. We test only what you have authorised in writing, so where a system is hosted or operated by the vendor we need their written permission as well, and obtaining it is usually the long pole; raise it on the scoping call rather than the week before testing. And the retest stays with us: when the vendor ships a fix we verify it held on your instance and record the closure, instead of accepting a patch note as evidence.

Where does CERT-In's six-hour incident reporting rule fit into a test?

CERT-In's April 2022 Directions under section 70B(6) of the IT Act are not a testing cycle. They require cyber incidents to be reported to CERT-In within six hours of noticing them, and they bind service providers, intermediaries, data centres and body corporates, which takes in every regulated financial entity. The RBI Directions of 2026 add their own supervisory reporting duty, and which chapter it falls under depends on the entity, so our RBI Cybersecurity Directions 2026 guide is the place to check yours. The practical consequence for a penetration test is that noticing is the hard part, which is why detection and logging get looked at alongside the applications. The written scope fixes test windows, source addresses and rules of engagement before testing starts, so you can line our activity up against your own logs and alerts afterwards and see plainly which actions raised nothing. Reporting an actual incident stays your obligation; we do not file on your behalf.

Is SecureRoot a CERT-In empanelled auditor?

No. SecureRoot Risk Advisory LLP is not a CERT-In empanelled information security auditing organisation, and on a regulated-finance engagement that distinction decides who signs what. Where a regulator, a tender or a partner requires the formal VAPT report to carry an empanelled auditor's signature, that auditor must sign it, and we say so on the scoping call rather than after the work. Our role is the testing, remediation support and retest that come before and beside that audit: we find and prove the real issues early, help your developers close them, and confirm each fix held, so the formal audit verifies controls that already work rather than discovering them. The same testing serves as evidence for ISO 27001, PCI DSS and DPDP Act programmes and for partner due diligence, so one engagement usually answers several questions at once. If empanelment is the only thing you need, we will tell you that too.

How often must a bank or NBFC run VAPT?

On 31 July 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance and cyber instructions for each. The testing cadence carried over: critical information systems and customer-facing systems in the DMZ need a vulnerability assessment at least once every six months and a penetration test at least once every 12 months, with a risk-based cycle for non-critical systems and testing across the system lifecycle, including on production after implementation. Testing must be done by independent information security experts or auditors. For NBFCs these provisions sit in the chapter covering middle, upper and top layer entities, so confirm your layer before you plan a calendar around them. Our RBI Cybersecurity Directions 2026 guide sets the chapters out entity by entity.

What does SEBI CSCRF require for VAPT?

Under section 4.3 of SEBI's Cybersecurity and Cyber Resilience Framework of 20 August 2024, most regulated entities must complete at least one VAPT a year, starting in the first quarter of the financial year, while entities identified by NCIIPC as protected systems or critical information infrastructure complete one in each half-year. The report is due within one month of completing the VAPT, findings must be closed within three months of the report, and revalidation within five months of the VAPT. VAPT is also mandated after every major release for all but small-size and self-certification entities, and CSCRF audits go to CERT-In empanelled auditors rather than to us. Categories and deadlines have been clarified more than once since the framework was issued, so confirm your own category before you plan around any single date. Our SEBI CSCRF compliance guide tracks those clarifications.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.