Skip to main content

Which Indian Regulators Require Security Testing

Which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.

By Abhinav A
August 18, 20263 min read

If you are regulated in India, the question "how often should we test" is answered for you, and the answer depends on which regulator binds you and what kind of entity you are.

This is a map. Each entry names the regulator, who it applies to, and the one thing to know before you read further. The detailed readings cover entity classifications, tier thresholds and paragraph-level obligations. They sit on Security Brigade's compliance pages, linked from each section, because they run to considerably more than a page each.

Reserve Bank of India

Who: banks, non-banking financial companies, urban co-operative banks, small finance and payments banks, credit information companies, payment aggregators and, through them, many of their technology suppliers.

What matters: the 2026 cyber security Directions separate the two halves of VAPT instead of treating them as one activity. Vulnerability assessment runs on a six-month interval and penetration testing on a twelve-month one, which means "we run an annual VAPT" does not straightforwardly satisfy both. The Directions also govern who may perform the work.

Detail: the RBI Directions, 2026 and RBI cyber security by entity type.

Securities and Exchange Board of India

Who: SEBI-regulated entities: stock brokers and depository participants, asset management companies, custodians, KRAs and QRTAs, AIFs and VCFs, among others.

What matters: the Cyber Security and Cyber Resilience Framework classifies regulated entities into tiers, and the tier decides how much applies to you. The classification parameters differ by entity type. For brokers it is one pair of measures, for asset managers another, so the first question is not "what does CSCRF require" but "which tier am I in".

Detail: SEBI CSCRF.

Insurance Regulatory and Development Authority of India

Who: insurers and insurance intermediaries.

What matters: IRDAI has issued information and cyber security guidelines applicable to the sector, and periodic audit sits within them. Read the current instrument for your entity type, not a summary of it.

Detail: IRDAI cyber security.

CERT-In

Who: in effect everyone, and separately the auditors themselves.

What matters: CERT-In operates in two distinct ways here. Its 2022 Directions impose incident reporting and log retention obligations broadly. Separately, it maintains the register of empanelled information security auditing organisations. For a large class of requirements across the other regulators, the audit is only accepted if it comes from a firm on that register. Empanelment qualifies the auditor, not you, and you can check it before you commission anything.

Detail: CERT-In requirements, and how to check an auditor is really empanelled.

UIDAI

Who: authentication user agencies and KYC user agencies: anyone integrating with Aadhaar authentication.

Detail: UIDAI AUA/KUA audits.

NPCI

Who: participants in the payment systems it operates, including UPI.

Detail: NPCI and UPI audits.

Not a regulator, but binding anyway

PCI DSS is a card scheme standard, not a regulation, and it binds you contractually if you handle cardholder data. Version 4.0 requires internal and external penetration testing at least once every twelve months and after any significant infrastructure or application change (requirements 11.4.2 and 11.4.3), with segmentation controls on a schedule of their own. Detail: PCI DSS.

Two things this map does not settle

Overlap. Many organisations are subject to more than one of these at once, and the requirements are not additive in a simple way. One exercise can satisfy several obligations if it is scoped and evidenced for all of them, and cannot if it is not. Work that out before you commission the testing, not afterwards.

The minimum is a minimum. Every interval above is a floor for a defined scope. It says nothing about the application you shipped last month, which is the argument for testing on change as well as on the calendar. See how often you should run a VAPT.

If no regulator names you at all, the requirement usually still arrives from a different direction. That is the other half of this subject.

About the author

Abhinav A

Lead — VAPT & Security Assessments

Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR and telecom.