Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
Industry Insights

RBI Cyber Security Framework: A VAPT Readiness Guide for BFSI

April 14, 2026·CyVigilant Security Team
Industry InsightsCyVigilant

India's banking and financial services sector faces one of the most demanding cyber security regulatory environments in the world. The Reserve Bank of India has progressively tightened requirements through a series of directives — from the original Cyber Security Framework for Banks (2016) to the Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023) and ongoing circulars on cyber risk. For organisations regulated by RBI, SEBI, or IRDAI, VAPT is not a discretionary best practice — it is a mandated, periodic activity with specific expectations around scope, methodology, and reporting.

What the RBI Master Direction requires

The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (issued January 2023, effective April 2024 for large and mid-size banks) establishes a comprehensive framework for IS audits and security testing. Key requirements include: annual VAPT of internet-facing applications and critical internal systems; VAPT by qualified and experienced assessors (in practice, CERT-In empanelled firms); comprehensive IS audit by independent auditors with appropriate certifications; a Board-approved cyber crisis management plan; and specific vulnerability management SLAs — critical vulnerabilities to be remediated within defined timeframes, not exceeding 30 days in most interpretations.

For Banks and NBFCs, the scope of mandated testing extends beyond web applications. Network VAPT (external and internal), mobile banking application VAPT, API security testing for open banking interfaces, cloud infrastructure security assessment (where applicable), and ATM and payment network infrastructure testing are all within the regulatory expectation.

SEBI CSCRF: requirements for market infrastructure

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF), updated in 2023, applies to Market Infrastructure Institutions (MIIs) including stock exchanges, depositories, and clearing corporations, as well as Qualified Registered Entities (QREs) such as stock brokers, depository participants, and mutual funds above defined AUM thresholds. The CSCRF requires quarterly vulnerability assessments and annual penetration tests, conducted by CERT-In empanelled auditors for MIIs and at a minimum by qualified third-party assessors for QREs. VAPT findings must be reviewed by the CISO and reported to the Board.

Preparing your BFSI environment for VAPT

Effective VAPT readiness for BFSI organisations requires preparation across four dimensions.

Scope definition: work with your CISO and audit committee to define the VAPT scope accurately. Include all internet-facing applications, APIs, and infrastructure. Internal systems that process customer financial data should be in scope. Mobile applications (iOS and Android) should be assessed using the OWASP Mobile Application Security Verification Standard (MASVS). Third-party integrations and payment gateways may require coordination with partners.

Environment preparation: ensure test environments are representative of production where possible. Collect network diagrams, application architecture documents, and API documentation before testing begins. Designate technical points of contact for each application and infrastructure domain. Arrange appropriate access credentials and test accounts.

Remediation capacity: the most common VAPT programme failure is poor remediation velocity. Define remediation SLAs before the audit: critical findings (CVSS 9.0+) within 7 days, high findings within 30 days, medium findings within 90 days. Assign ownership. Ensure a re-test is included in the engagement scope — many RBI-compliant VAPT engagements require a re-test within 30 days to confirm critical and high findings have been remediated before the final report is issued.

Reporting requirements: the VAPT report must meet specific content standards for regulatory acceptance. It should include an executive summary, a complete findings register with CVSS scores, evidence of exploitation, remediation recommendations, and a re-test summary. Reports from CERT-In empanelled firms carry the necessary credibility for regulatory submission.

Common findings in BFSI VAPT engagements

Based on patterns across BFSI security assessments, the most frequently identified vulnerabilities include: insecure direct object references in customer-facing APIs, insufficient authorisation controls on mobile banking endpoints, inadequate session management and token expiry, outdated TLS configurations and weak cipher suites, misconfigured cloud storage buckets or object permissions in hybrid cloud deployments, and hardcoded credentials or API keys in mobile application binaries. Prioritise these areas in your pre-audit hardening.

CyVigilant specialises in VAPT for BFSI organisations, delivering CERT-In empanelled reports that satisfy RBI and SEBI requirements. Talk to an expert to discuss your regulatory VAPT calendar.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert