Which Indian Regulators Require Security Testing
A map rather than a manual: which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
If you are regulated in India, the question "how often should we test" is answered for you, and the answer depends on which regulator binds you and what kind of entity you are.
This is a map, not a manual. Each entry names the regulator, who it applies to, and the one thing worth knowing before you read further. The detailed readings — entity classifications, tier thresholds, paragraph-level obligations — are on Security Brigade's compliance pages, linked from each section, because they run to considerably more than a page each.
Reserve Bank of India
Who: banks, non-banking financial companies, urban co-operative banks, small finance and payments banks, credit information companies, payment aggregators, and — through them — many of their technology suppliers.
Worth knowing: the 2026 cyber security Directions separate the two halves of VAPT rather than treating them as one activity. Vulnerability assessment and penetration testing carry different intervals — six months and twelve months respectively — which means "we run an annual VAPT" does not straightforwardly satisfy both. The Directions also govern who may perform the work.
Detail: the RBI Directions, 2026 and RBI cyber security by entity type.
Securities and Exchange Board of India
Who: SEBI-regulated entities — stock brokers and depository participants, asset management companies, custodians, KRAs and QRTAs, AIFs and VCFs, among others.
Worth knowing: the Cyber Security and Cyber Resilience Framework classifies regulated entities into tiers, and the tier decides how much applies to you. The classification parameters differ by entity type — for brokers it is one pair of measures, for asset managers another — so the first question is not "what does CSCRF require" but "which tier am I in".
Detail: SEBI CSCRF.
Insurance Regulatory and Development Authority of India
Who: insurers and insurance intermediaries.
Worth knowing: IRDAI has issued information and cyber security guidelines applicable to the sector, and periodic audit sits within them. Read the current instrument for your entity type rather than a summary of it, including this one.
Detail: IRDAI cyber security.
CERT-In
Who: in effect everyone, and separately the auditors themselves.
Worth knowing: CERT-In operates in two distinct ways here. Its 2022 Directions impose incident reporting and log retention obligations broadly. Separately, it maintains the register of empanelled information security auditing organisations — and for a large class of requirements across the other regulators, the audit is only accepted if it comes from a firm on that register. That is a qualification of the auditor, not of you, and it is checkable before you commission anything.
Detail: CERT-In requirements, and how to check an auditor is really empanelled.
UIDAI
Who: authentication user agencies and KYC user agencies — anyone integrating with Aadhaar authentication.
Detail: UIDAI AUA/KUA audits.
NPCI
Who: participants in the payment systems it operates, including UPI.
Detail: NPCI and UPI audits.
Not a regulator, but binding anyway
PCI DSS is a card scheme standard rather than a regulation, and it binds you contractually if you handle cardholder data. Version 4.0 requires internal and external penetration testing at least once every twelve months and after any significant infrastructure or application change (requirements 11.4.2 and 11.4.3), with segmentation controls on a schedule of their own. Detail: PCI DSS.
Two things this map does not settle
Overlap. Many organisations are subject to more than one of these at once, and the requirements are not additive in a simple way — one exercise can satisfy several obligations if it is scoped and evidenced for all of them, and cannot if it is not. That is worth establishing before commissioning rather than afterwards.
The minimum is a minimum. Every interval above is a floor for a defined scope. It says nothing about the application you shipped last month, which is the argument for testing on change as well as on the calendar — see how often you should run a VAPT.
If no regulator names you at all, the requirement usually still arrives — from a different direction. That is the other half of this subject.
Continue reading
All articles →VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors — and each wants something slightly different.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.
The VAPT Certificate: What It Evidences
There is no standardised VAPT certificate and no authority that issues one. What the document actually is, what it proves, what it does not, and who accepts it.