As cyber threats continue to increase in frequency and sophistication, Indian financial regulators have placed strong emphasis on structured and auditable vulnerability management programs. Both the Reserve Bank of India and the Securities and Exchange Board of India mandate regular vulnerability assessment, penetration testing, timely remediation, and strong governance oversight for regulated entities.
This blog provides an overview of RBI and SEBI vulnerability management requirements, a clear comparison between the two, and how organizations can operationalize compliance effectively.
RBI Vulnerability Management Requirements
RBI defines its cybersecurity and vulnerability management expectations under the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices issued in 2023. These directions apply to banks, select NBFCs, CICs, and other RBI regulated entities.
Vulnerability Assessment and Penetration Testing
RBI mandates periodic vulnerability assessment and penetration testing for critical systems. For critical information systems and systems deployed in demilitarized zones, vulnerability assessments must be conducted at least once every six months, while penetration testing must be conducted at least once every twelve months.
Testing is also required before systems go live, after implementation, and following major changes or upgrades. RBI expects these activities to be conducted by trained and independent security professionals to ensure objectivity.
For non critical systems, RBI allows a risk based approach where testing frequency and depth are determined based on business impact and exposure.
Remediation and Closure
RBI requires all identified vulnerabilities and associated risks to be remediated in a time bound manner. Regulated entities must ensure that known vulnerabilities do not recur, particularly those already documented in public vulnerability databases.
Evidence of remediation and closure must be maintained for audits and supervisory reviews.
Broader Vulnerability Management Controls
RBI expects organizations to implement a comprehensive vulnerability management framework that includes continuous risk assessments, security monitoring, structured patch management, SOC based monitoring, board approved cybersecurity governance, and incident response and cyber crisis management mechanisms.
SEBI Vulnerability Management Requirements
SEBI addresses vulnerability management through its Cybersecurity and Cyber Resilience Framework, applicable to regulated entities such as stock brokers, asset management companies, market infrastructure institutions, KRAs, AIFs, and other intermediaries.
Vulnerability Assessment and Penetration Testing
SEBI mandates vulnerability assessment and penetration testing of all critical systems at least once every financial year. If a system is designated as a protected system by the National Critical Information Infrastructure Protection Centre, testing must be conducted twice a year.
SEBI also mandates that testing be performed only by CERT In empanelled organizations.
Pre Commissioning Testing and Reporting
Vulnerability assessment and penetration testing must be conducted before commissioning any new critical system or adding major components to existing systems.
Final reports must be approved by the relevant technology or security committees and submitted to SEBI or the relevant market infrastructure entity within one month of completion. All identified vulnerabilities must be remediated immediately, with closure evidence submitted within three months.
Scope and Integration
SEBI defines a broad testing scope covering infrastructure, applications, APIs, cloud environments, operating systems, and databases. Vulnerability management must be integrated with patch management, third party risk management, asset inventory, governance oversight, and incident reporting.
RBI vs SEBI Vulnerability Management Requirements Comparison
| Aspect | RBI | SEBI |
| Applicable framework | Master Direction on IT Governance Risk Controls and Assurance Practices | Cybersecurity and Cyber Resilience Framework |
| Regulated entities | Banks NBFCs CICs and RBI regulated entities | Brokers AMCs MIIs KRAs AIFs and other SEBI regulated entities |
| VA frequency for critical systems | At least once every six months | At least once every financial year |
| PT frequency for critical systems | At least once every twelve months | Once per year or twice if protected system |
| Risk based testing | Allowed for non critical systems | Limited primarily to critical systems |
| Empanelled testing | Independent and qualified empaneled organizations | Mandatory CERT In empaneled organizations |
| Pre go live testing | Mandatory | Mandatory |
| Reporting timelines | Reviewed through audits and inspections | One month for report three months for closure |
| Governance oversight | Board and senior management | Technology and security committees |
How CyRAACS Can Help
Meeting RBI and SEBI vulnerability management requirements requires more than periodic testing. Organizations must demonstrate governance, structured remediation, evidence of closure, and audit readiness. CyRAACS helps organizations achieve this through a compliance focused and risk driven approach.
CyRAACS delivers vulnerability assessment and penetration testing programs aligned with RBI and SEBI regulatory expectations. Engagements are designed based on system criticality, regulatory timelines, and risk exposure, covering infrastructure, applications, APIs, and cloud environments.
For SEBI regulated entities, CyRAACS supports engagements through CERT In empanelled testing organizations, ensuring regulatory compliance while maintaining consistency in reporting and remediation validation.
CyRAACS also assists organizations in validating fixes, tracking time bound remediation, and preparing closure evidence required for regulatory submissions and audits. In addition, CyRAACS supports the establishment of vulnerability management frameworks, integration with SOC and incident response processes, and preparation for RBI inspections, SEBI submissions, and internal or external audits.
Closing Thoughts
RBI and SEBI have clearly established vulnerability management as a continuous, governance driven discipline rather than a one time compliance exercise. Organizations that adopt a structured, risk based, and audit ready approach are better positioned to meet regulatory expectations and strengthen cyber resilience.
Unsure if your vulnerability management program meets RBI and SEBI requirements?
Get an expert-led assessment of your security controls and compliance readiness.
👉 Request a Regulatory VAPT Assessment




