Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

RBI and SEBI Requirements for Vulnerability Management in India

As cyber threats continue to increase in frequency and sophistication, Indian financial regulators have placed strong emphasis on structured and auditable vulnerability management programs. Both the Reserve Bank of India and the Securities and Exchange Board of India mandate regular vulnerability assessment, penetration testing, timely remediation, and strong governance oversight for regulated entities.

This blog provides an overview of RBI and SEBI vulnerability management requirements, a clear comparison between the two, and how organizations can operationalize compliance effectively.

RBI Vulnerability Management Requirements

RBI defines its cybersecurity and vulnerability management expectations under the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices issued in 2023. These directions apply to banks, select NBFCs, CICs, and other RBI regulated entities.

Vulnerability Assessment and Penetration Testing

RBI mandates periodic vulnerability assessment and penetration testing for critical systems. For critical information systems and systems deployed in demilitarized zones, vulnerability assessments must be conducted at least once every six months, while penetration testing must be conducted at least once every twelve months.

Testing is also required before systems go live, after implementation, and following major changes or upgrades. RBI expects these activities to be conducted by trained and independent security professionals to ensure objectivity.

For non critical systems, RBI allows a risk based approach where testing frequency and depth are determined based on business impact and exposure.

Remediation and Closure

RBI requires all identified vulnerabilities and associated risks to be remediated in a time bound manner. Regulated entities must ensure that known vulnerabilities do not recur, particularly those already documented in public vulnerability databases.

Evidence of remediation and closure must be maintained for audits and supervisory reviews.

Broader Vulnerability Management Controls

RBI expects organizations to implement a comprehensive vulnerability management framework that includes continuous risk assessments, security monitoring, structured patch management, SOC based monitoring, board approved cybersecurity governance, and incident response and cyber crisis management mechanisms.

SEBI Vulnerability Management Requirements

SEBI addresses vulnerability management through its Cybersecurity and Cyber Resilience Framework, applicable to regulated entities such as stock brokers, asset management companies, market infrastructure institutions, KRAs, AIFs, and other intermediaries.

Vulnerability Assessment and Penetration Testing

SEBI mandates vulnerability assessment and penetration testing of all critical systems at least once every financial year. If a system is designated as a protected system by the National Critical Information Infrastructure Protection Centre, testing must be conducted twice a year.

SEBI also mandates that testing be performed only by CERT In empanelled organizations.

Pre Commissioning Testing and Reporting

Vulnerability assessment and penetration testing must be conducted before commissioning any new critical system or adding major components to existing systems.

Final reports must be approved by the relevant technology or security committees and submitted to SEBI or the relevant market infrastructure entity within one month of completion. All identified vulnerabilities must be remediated immediately, with closure evidence submitted within three months.

Scope and Integration

SEBI defines a broad testing scope covering infrastructure, applications, APIs, cloud environments, operating systems, and databases. Vulnerability management must be integrated with patch management, third party risk management, asset inventory, governance oversight, and incident reporting.

RBI vs SEBI Vulnerability Management Requirements Comparison

AspectRBISEBI
Applicable frameworkMaster Direction on IT Governance Risk Controls and Assurance PracticesCybersecurity and Cyber Resilience Framework
Regulated entitiesBanks NBFCs CICs and RBI regulated entitiesBrokers AMCs MIIs KRAs AIFs and other SEBI regulated entities
VA frequency for critical systemsAt least once every six monthsAt least once every financial year
PT frequency for critical systemsAt least once every twelve monthsOnce per year or twice if protected system
Risk based testingAllowed for non critical systemsLimited primarily to critical systems
Empanelled testingIndependent and qualified empaneled organizationsMandatory CERT In empaneled organizations
Pre go live testingMandatoryMandatory
Reporting timelinesReviewed through audits and inspectionsOne month for report three months for closure
Governance oversightBoard and senior managementTechnology and security committees

How CyRAACS Can Help

Meeting RBI and SEBI vulnerability management requirements requires more than periodic testing. Organizations must demonstrate governance, structured remediation, evidence of closure, and audit readiness. CyRAACS helps organizations achieve this through a compliance focused and risk driven approach.

CyRAACS delivers vulnerability assessment and penetration testing programs aligned with RBI and SEBI regulatory expectations. Engagements are designed based on system criticality, regulatory timelines, and risk exposure, covering infrastructure, applications, APIs, and cloud environments.

For SEBI regulated entities, CyRAACS supports engagements through CERT In empanelled testing organizations, ensuring regulatory compliance while maintaining consistency in reporting and remediation validation.

CyRAACS also assists organizations in validating fixes, tracking time bound remediation, and preparing closure evidence required for regulatory submissions and audits. In addition, CyRAACS supports the establishment of vulnerability management frameworks, integration with SOC and incident response processes, and preparation for RBI inspections, SEBI submissions, and internal or external audits.

Closing Thoughts

RBI and SEBI have clearly established vulnerability management as a continuous, governance driven discipline rather than a one time compliance exercise. Organizations that adopt a structured, risk based, and audit ready approach are better positioned to meet regulatory expectations and strengthen cyber resilience.

Unsure if your vulnerability management program meets RBI and SEBI requirements?
Get an expert-led assessment of your security controls and compliance readiness.

👉 Request a Regulatory VAPT Assessment

Let us help you

By clicking on this button, you can connect with us. Let’s make your brand secure.

you may also like