Licence and market access
Regulators can raise cyber failures in inspections and audits. Weak controls put your standing and business activity at risk.
SEBI and the RBI expect regulated Indian firms to show tested cyber controls, regular VAPT and board oversight. Summit prepares you with gap analysis, penetration testing evidence and a board-ready report that holds up.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting SEBI CSCRF and RBI wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Regulators can raise cyber failures in inspections and audits. Weak controls put your standing and business activity at risk.
Senior management and the board are expected to oversee cyber risk. Documented, tested controls are your best record of having done so.
A cyber incident at a financial firm becomes public quickly. Clients expect proof that controls were tested.
Testing and submission calendars are set by the regulators. Someone senior needs to own the dates and the evidence.
SEBI regulated entities that must follow the CSCRF for their category.
Market infrastructure faces the most demanding controls and testing expectations.
RBI expects board-level IT oversight, tested controls and managed third-party risk.
Regulated customers pass requirements to you through contracts and vendor reviews.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Your controls mapped against SEBI and RBI expectations for your category, with a prioritised plan.
Manual testing across critical assets, including applications, networks, servers and databases.
We check that governance, logging and response controls work in practice.
Dated test reports, remediation logs and control evidence organised for your audit.
Guidance while your team fixes findings, then a retest and action taken report.
A plain-English summary for the board and IT committee, with technical detail behind it.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Identify your entity category and the SEBI and RBI texts, dates and submission formats that apply to you.
Compare current controls and testing with the requirements, then close policy, governance and technical gaps with evidence captured continuously.
Manual penetration testing across critical assets, written up for both regulators and technical teams.
Fix findings, retest, and prepare the action taken report within your deadlines.
Assemble the evidence pack and brief the board so management responses are consistent.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Confirm your category and the current circular dates.
VAPT scope starts with an accurate inventory.
Decisions on unfixed findings need a named owner.
Reports should show findings, closure rates and incident readiness.
Third-party exposure lands on your side of the table.
On 20 August 2024 SEBI issued the Cybersecurity and Cyber Resilience Framework (CSCRF), a consolidated circular that supersedes earlier cyber circulars and guidelines for SEBI regulated entities such as stock exchanges, depositories, brokers, depository participants, asset managers and others. Requirements are graded by entity category and organised around cyber resiliency goals, with expectations on governance, risk assessment, VAPT, cyber audits, monitoring and recovery.
Implementation dates were extended more than once after the original start dates, and later circulars set VAPT and audit submission timelines for particular categories of entity. Check the latest SEBI circulars for the dates and formats that apply to your entity type.
For banks and NBFCs, the RBI sets expectations through its master directions and circulars, including its Master Direction on IT governance, risk, controls and assurance practices, its IT outsourcing directions and earlier cyber security framework circulars. They cover board oversight, IT and information security governance, vulnerability assessment and penetration testing, incident reporting and third-party risk. Which rules apply depends on your regulatory category and scale, so confirm against the current texts.
This is a plain-English summary, not legal advice. Confirm exact obligations in the current SEBI and RBI texts for your entity type.
Both regulators expect cyber risk to be owned at senior level. The CSCRF asks for an IT committee and a named responsible officer, and for external cybersecurity expertise on the committee. RBI directions set out board and senior management responsibilities for IT governance.
SEBI expects VAPT across critical assets such as networks, security devices, servers, databases and applications, to recognised standards, with frequency and submission dates set by entity category. RBI expects regular testing and tracking of findings.
SEBI requires periodic cyber audits for specified entities. The audit is conducted by an auditor on CERT-In's approved list who declares no conflict of interest. Your side of it is evidence, not just policy.
Regulated entities need to detect and respond quickly. The CSCRF refers to security operations capability, and CERT-In directions require reporting of specified cyber incidents within six hours.
Regulators hold the regulated entity accountable for vendors. RBI has specific directions for outsourcing IT services, and SEBI expects vendor risk to be managed.
SEBI sets out VAPT expectations for critical assets, and RBI expects regular testing of IT systems. A manual test with clear severity ratings, a remediation log and a retest gives your auditor and your board a record they can rely on.
Testing across networks, security devices, servers, databases and applications, aligned to recognised standards.
A remediation log that shows each finding, owner, fix date and retest result.
Testing evidence supports board and audit committee oversight of IT risk.
Testing shows which weaknesses attackers could chain together, which informs detection and response plans.
Implementation and submission dates have moved before. Track current circulars and plan with margin.
Regulators refer to all critical assets. A test that only covers a website leaves the rest unproven.
Cyber oversight is a board matter. Reports that only technical teams understand do not meet the intent.
Findings without owners, dates and retest results are hard to defend in an audit.
It is SEBI's Cybersecurity and Cyber Resilience Framework, issued on 20 August 2024. It consolidates earlier cyber circulars for SEBI regulated entities and grades requirements by entity category.
SEBI regulated entities such as stock exchanges, depositories, brokers, depository participants, asset managers and others, with requirements varying by category. Check the circular for your entity type.
VAPT is expected across critical assets, to recognised standards, at a frequency and with submission timelines set by entity category. Findings must be closed and reported through an action taken report.
Where SEBI requires a cyber audit, it must be carried out by an auditor on CERT-In's approved list, who declares no conflict of interest.
The RBI expects board oversight of IT, a defined IT and information security governance structure, regular testing, incident reporting and controls over IT outsourcing. The details are in its master directions, which depend on your category.
Yes. SEBI extended implementation dates more than once after the original start dates. Always check the latest circulars before planning.
Both expect vulnerability assessment and penetration testing as part of a regular cyber testing programme. The exact scope and frequency depend on your entity category.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.