Financial Services
VAPT for Banks, NBFCs and Fintechs in India
VAPT for banks and NBFCs is testing with a regulator reading over your shoulder. SecureRoot runs manual, exploit-driven penetration testing of the systems RBI and SEBI expect you to test: internet and mobile banking, customer portals, partner and payment APIs, the network edge and the cloud accounts behind them. Every finding carries proof and a fix, critical issues reach you within three hours, and the retest that shows each fix held is part of the engagement, so the evidence is ready before your formal audit rather than after it.
Regulators
What Your Regulator Expects
The instrument that applies to you sets how often you test, what counts as in scope and who must sign the formal report. Read the source, not a summary: each row links the regulator's own text.
- Who it covers
- Commercial banks, small finance banks and NBFCs, each under its own 2026 Directions, which repealed the earlier IT governance and cyber instructions for that entity type. Payments banks, credit information companies and all-India financial institutions should confirm which instrument now applies to them.
- What it expects
- For critical systems and customer-facing systems in the DMZ: vulnerability assessment at least every six months and penetration testing at least every 12 months, plus testing across the system lifecycle, by independent information security experts or auditors. For NBFCs this sits in the chapter for middle, upper and top layer entities.
- Who it covers
- SEBI regulated entities, graded into market infrastructure institutions, qualified, mid-size, small-size and self-certification categories: stockbrokers, depository participants, portfolio managers, AMCs, KRAs and RTAs among them.
- What it expects
- At least one VAPT a year starting in the first quarter, or one in each half-year for entities NCIIPC has identified as protected systems or CII and, per SEBI's June 2025 FAQs, for Qualified Stock Brokers; VAPT after every major release for all but small-size and self-certification entities; report within one month, findings closed within three months, revalidation within five months. Read with SEBI's later CSCRF clarifications.
- Who it covers
- Service providers, intermediaries, data centres and body corporates in India, which includes every regulated financial entity.
- What it expects
- Not a testing cycle: cyber incidents must be reported to CERT-In within six hours of noticing them, which is why detection and logging are tested alongside the applications.
Where your regulator requires the formal VAPT report to come from a CERT-In empanelled auditor, that requirement stands. SecureRoot is not a CERT-In empanelled auditing organisation; the section below explains where our work sits beside the auditor who signs.
Services
What We Test and Review
The Systems Regulators Ask About
Each surface has its own methodology, deliverables and retest. Most financial-services scopes combine the customer-facing applications with the APIs and infrastructure behind them.
- Web ApplicationManual testing of your web apps against the OWASP WSTG
- Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- Network InfrastructureExternal and internal network testing with lateral movement
- CloudConfiguration and IAM testing across AWS, Azure and GCP
- Thick Client ApplicationDesktop app testing across binary, traffic and backend
Beyond the Test Cycle
Regulators look past the report to the controls around it: hardened configuration, a tested response and someone who owns security at board level.
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- vCISOSenior security leadership on demand, without a full-time hire
When Testing Feeds a Wider Programme
Card data, customer data and third-party risk bring their own obligations. The same team runs those programmes, so a test is scoped to satisfy every control it is evidence for.
How It Runs
How a Regulated Engagement Runs
The scope, the timeline and the price are written down before anyone starts, and the scope is drawn from your critical systems inventory rather than from a guess.
01
Scoping Against Your Inventory
You hear back within one business day. On the scoping call we map your critical and internet-facing systems against the instrument that applies to you, and agree what is in and out.
02
A Written Scope and a Fixed Price
Targets, test windows, rules of engagement, deliverables and the price, in writing. Testing windows respect change freezes and settlement cycles.
03
Manual Testing, Critical Findings at Once
Testing by hand and with intent, backed by tooling rather than replaced by it. Critical findings reach you within three hours of discovery, not at the end of the engagement.
04
Remediation, Retest and Evidence
The tester who found the flaw explains it to your developers. Once fixes land we retest inside the engagement and issue a verified retest report for your board, your auditor and your regulator file.
Our Role
Where We Sit Beside Your Empanelled Auditor
SecureRoot is not a CERT-In empanelled auditing organisation, and we will not blur that line. If your regulator or a tender requires the formal VAPT report to be signed by an empanelled auditor, that auditor signs it.
What we do is the work that decides how that audit goes. We test the same systems earlier and by hand, prove which findings are real, help your developers fix them, and retest until they are closed. When the formal cycle begins, the auditor confirms controls that already hold instead of opening a remediation list that runs past your deadline.
The same testing serves the rest of the year: after a major release, before a new partner integration goes live, and as evidence for ISO 27001, PCI DSS and DPDP Act programmes. SecureRoot Risk Advisory LLP holds ISO/IEC 27001:2022 certification (certificate IN60432E), and engagements are led by named testers holding credentials including CISM and eWPTX.
Who It Is For
Who We Test For
Financial-services teams whose systems face a regulator, a partner bank or both.
Banks and Small Finance Banks
Internet and mobile banking, customer onboarding, and the internet-facing estate an RBI inspection reads the test reports for.
NBFCs
Lending platforms, loan management systems and collection apps, scoped to the layer-based expectations in the RBI direction.
Payment Aggregators and Gateways
Checkout flows, merchant dashboards and payment APIs, where card data brings PCI DSS into the same scope.
Stockbrokers, AMCs and Depository Participants
Trading apps, client portals and back-office integrations, tested ahead of the CSCRF cycle for your category.
Fintechs Serving a Regulated Partner
Companies whose bank or NBFC partner passes its testing and due-diligence expectations down the contract.
Insurers and Insurtechs
Policy, claims and distribution platforms, and the partner APIs that connect them to aggregators.
Is SecureRoot a CERT-In empanelled auditor?
No. SecureRoot Risk Advisory LLP is not a CERT-In empanelled information security auditing organisation. Where a regulator, a tender or a partner requires the formal VAPT report to be signed by an empanelled auditor, that auditor must sign it, and we say so on the scoping call. Our role is the testing, remediation support and retest that come before and alongside that audit: we find and prove the real issues early, help your developers close them, and confirm each fix held, so the formal audit verifies controls that already work. The same testing also serves as evidence for ISO 27001, PCI DSS and DPDP Act programmes and for partner due diligence.
How often must a bank or NBFC run VAPT?
On 31 July 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance and cyber instructions for each. The testing cadence carried over: critical information systems and customer-facing systems in the DMZ need a vulnerability assessment at least once every six months and a penetration test at least once every 12 months, with a risk-based cycle for non-critical systems and testing across the system lifecycle, including on production after implementation. Testing must be done by independent information security experts or auditors. For NBFCs these provisions sit in the chapter covering middle, upper and top layer entities, so confirm your layer first.
What does SEBI CSCRF require for VAPT?
Under section 4.3 of SEBI's Cybersecurity and Cyber Resilience Framework of 20 August 2024, most regulated entities must complete at least one VAPT a year, starting in the first quarter of the financial year, while entities identified by NCIIPC as protected systems or critical information infrastructure complete one in each half-year. The report is due within one month of completing the VAPT, findings must be closed within three months of the report, and revalidation within five months of the VAPT. VAPT is also mandated after every major release for all but small-size and self-certification entities, and CSCRF audits go to CERT-In empanelled auditors. Check later SEBI clarifications for your category.
Can one engagement serve both RBI and SEBI obligations?
Often, yes. Groups with a lending arm and a broking arm, or fintechs serving both a bank and a broker, run many of the same applications, APIs and infrastructure under both regulators. One engagement can test those shared systems once and produce findings mapped to each instrument, with the regulator-specific parts, such as report format, frequency and who must sign, handled separately. On the scoping call we list which systems fall under which regulator and where the formal audit needs an empanelled auditor, so nothing is tested twice and nothing required is missed.
Do fintechs working with a partner bank need their own VAPT?
Usually, in practice. A bank or NBFC that outsources a customer-facing function remains accountable to its regulator for it, so partner agreements typically require the fintech to test the systems involved, share reports and fix findings within agreed timelines. Even where a contract is silent, due diligence before go-live and at renewal tends to ask for recent penetration test evidence. Testing your own platform before the partner asks keeps an onboarding or renewal from stalling, and the retest report shows the issues were closed, not merely found.
Related Reading
Articles on VAPT for Banks, NBFCs and Fintechs
Ready When You Are
Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.