Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Financial Services

VAPT for Banks, NBFCs and Fintechs in India

VAPT for banks and NBFCs is testing with a regulator reading over your shoulder. SecureRoot runs manual, exploit-driven penetration testing of the systems RBI and SEBI expect you to test: internet and mobile banking, customer portals, partner and payment APIs, the network edge and the cloud accounts behind them. Every finding carries proof and a fix, critical issues reach you within three hours, and the retest that shows each fix held is part of the engagement, so the evidence is ready before your formal audit rather than after it.

Regulators

What Your Regulator Expects

The instrument that applies to you sets how often you test, what counts as in scope and who must sign the formal report. Read the source, not a summary: each row links the regulator's own text.

  • Who it covers
    Commercial banks, small finance banks and NBFCs, each under its own 2026 Directions, which repealed the earlier IT governance and cyber instructions for that entity type. Payments banks, credit information companies and all-India financial institutions should confirm which instrument now applies to them.
    What it expects
    For critical systems and customer-facing systems in the DMZ: vulnerability assessment at least every six months and penetration testing at least every 12 months, plus testing across the system lifecycle, by independent information security experts or auditors. For NBFCs this sits in the chapter for middle, upper and top layer entities.
  • Who it covers
    SEBI regulated entities, graded into market infrastructure institutions, qualified, mid-size, small-size and self-certification categories: stockbrokers, depository participants, portfolio managers, AMCs, KRAs and RTAs among them.
    What it expects
    At least one VAPT a year starting in the first quarter, or one in each half-year for entities NCIIPC has identified as protected systems or CII and, per SEBI's June 2025 FAQs, for Qualified Stock Brokers; VAPT after every major release for all but small-size and self-certification entities; report within one month, findings closed within three months, revalidation within five months. Read with SEBI's later CSCRF clarifications.
  • Who it covers
    Service providers, intermediaries, data centres and body corporates in India, which includes every regulated financial entity.
    What it expects
    Not a testing cycle: cyber incidents must be reported to CERT-In within six hours of noticing them, which is why detection and logging are tested alongside the applications.

Where your regulator requires the formal VAPT report to come from a CERT-In empanelled auditor, that requirement stands. SecureRoot is not a CERT-In empanelled auditing organisation; the section below explains where our work sits beside the auditor who signs.

Services

What We Test and Review

When Testing Feeds a Wider Programme

Card data, customer data and third-party risk bring their own obligations. The same team runs those programmes, so a test is scoped to satisfy every control it is evidence for.

How It Runs

How a Regulated Engagement Runs

The scope, the timeline and the price are written down before anyone starts, and the scope is drawn from your critical systems inventory rather than from a guess.

  1. 01

    Scoping Against Your Inventory

    You hear back within one business day. On the scoping call we map your critical and internet-facing systems against the instrument that applies to you, and agree what is in and out.

  2. 02

    A Written Scope and a Fixed Price

    Targets, test windows, rules of engagement, deliverables and the price, in writing. Testing windows respect change freezes and settlement cycles.

  3. 03

    Manual Testing, Critical Findings at Once

    Testing by hand and with intent, backed by tooling rather than replaced by it. Critical findings reach you within three hours of discovery, not at the end of the engagement.

  4. 04

    Remediation, Retest and Evidence

    The tester who found the flaw explains it to your developers. Once fixes land we retest inside the engagement and issue a verified retest report for your board, your auditor and your regulator file.

Our Role

Where We Sit Beside Your Empanelled Auditor

SecureRoot is not a CERT-In empanelled auditing organisation, and we will not blur that line. If your regulator or a tender requires the formal VAPT report to be signed by an empanelled auditor, that auditor signs it.

What we do is the work that decides how that audit goes. We test the same systems earlier and by hand, prove which findings are real, help your developers fix them, and retest until they are closed. When the formal cycle begins, the auditor confirms controls that already hold instead of opening a remediation list that runs past your deadline.

The same testing serves the rest of the year: after a major release, before a new partner integration goes live, and as evidence for ISO 27001, PCI DSS and DPDP Act programmes. SecureRoot Risk Advisory LLP holds ISO/IEC 27001:2022 certification (certificate IN60432E), and engagements are led by named testers holding credentials including CISM and eWPTX.

Who It Is For

Who We Test For

Financial-services teams whose systems face a regulator, a partner bank or both.

  • Banks and Small Finance Banks

    Internet and mobile banking, customer onboarding, and the internet-facing estate an RBI inspection reads the test reports for.

  • NBFCs

    Lending platforms, loan management systems and collection apps, scoped to the layer-based expectations in the RBI direction.

  • Payment Aggregators and Gateways

    Checkout flows, merchant dashboards and payment APIs, where card data brings PCI DSS into the same scope.

  • Stockbrokers, AMCs and Depository Participants

    Trading apps, client portals and back-office integrations, tested ahead of the CSCRF cycle for your category.

  • Fintechs Serving a Regulated Partner

    Companies whose bank or NBFC partner passes its testing and due-diligence expectations down the contract.

  • Insurers and Insurtechs

    Policy, claims and distribution platforms, and the partner APIs that connect them to aggregators.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Is SecureRoot a CERT-In empanelled auditor?

No. SecureRoot Risk Advisory LLP is not a CERT-In empanelled information security auditing organisation. Where a regulator, a tender or a partner requires the formal VAPT report to be signed by an empanelled auditor, that auditor must sign it, and we say so on the scoping call. Our role is the testing, remediation support and retest that come before and alongside that audit: we find and prove the real issues early, help your developers close them, and confirm each fix held, so the formal audit verifies controls that already work. The same testing also serves as evidence for ISO 27001, PCI DSS and DPDP Act programmes and for partner due diligence.

How often must a bank or NBFC run VAPT?

On 31 July 2026 the RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks and NBFCs, repealing the earlier IT governance and cyber instructions for each. The testing cadence carried over: critical information systems and customer-facing systems in the DMZ need a vulnerability assessment at least once every six months and a penetration test at least once every 12 months, with a risk-based cycle for non-critical systems and testing across the system lifecycle, including on production after implementation. Testing must be done by independent information security experts or auditors. For NBFCs these provisions sit in the chapter covering middle, upper and top layer entities, so confirm your layer first.

What does SEBI CSCRF require for VAPT?

Under section 4.3 of SEBI's Cybersecurity and Cyber Resilience Framework of 20 August 2024, most regulated entities must complete at least one VAPT a year, starting in the first quarter of the financial year, while entities identified by NCIIPC as protected systems or critical information infrastructure complete one in each half-year. The report is due within one month of completing the VAPT, findings must be closed within three months of the report, and revalidation within five months of the VAPT. VAPT is also mandated after every major release for all but small-size and self-certification entities, and CSCRF audits go to CERT-In empanelled auditors. Check later SEBI clarifications for your category.

Can one engagement serve both RBI and SEBI obligations?

Often, yes. Groups with a lending arm and a broking arm, or fintechs serving both a bank and a broker, run many of the same applications, APIs and infrastructure under both regulators. One engagement can test those shared systems once and produce findings mapped to each instrument, with the regulator-specific parts, such as report format, frequency and who must sign, handled separately. On the scoping call we list which systems fall under which regulator and where the formal audit needs an empanelled auditor, so nothing is tested twice and nothing required is missed.

Do fintechs working with a partner bank need their own VAPT?

Usually, in practice. A bank or NBFC that outsources a customer-facing function remains accountable to its regulator for it, so partner agreements typically require the fintech to test the systems involved, share reports and fix findings within agreed timelines. Even where a contract is silent, due diligence before go-live and at renewal tends to ask for recent penetration test evidence. Testing your own platform before the partner asks keeps an onboarding or renewal from stalling, and the retest report shows the issues were closed, not merely found.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.