Skip to main content
Since 2008 — CERT-In empanelled auditor with deep capital markets experience

NSE Trading Member VAPT: Comply with NSE/INSP/70471 and SEBI CSCRF Requirements

NSE requires all trading members to submit VAPT reports under the SEBI Cyber Security and Cyber Resilience Framework. Security Brigade, CERT-In empanelled since 2008, delivers submission-ready VAPT reports aligned to NSE/INSP/70471 requirements.

NSE/INSP/70471
Sep 2025 Circular
Jun 30 / Nov 30
VAPT + ATR Deadlines
Since 2008
CERT-In Empanelled
Full Scope
VAPT Scope Coverage

NSE circular NSE/INSP/70471 dated September 26, 2025 mandates all trading members to submit comprehensive VAPT reports for FY 2025-26. The circular enforces SEBI CSCRF compliance with strict yearly and half-yearly deadlines, detailed scope requirements across infrastructure, applications, APIs, cloud, WiFi, and mobile, and specific reporting formats under Annexure 2 and auditor norms under Annexure 3. Non-compliance puts your trading membership, reputation, and client trust at risk. Not sure which CSCRF tier your firm falls under? Run our self-service SEBI CSCRF compliance wizard to determine your classification, obligations, and prioritised gaps. Security Brigade has navigated complex compliance requirements across 370+ BFSI engagements, delivering technically rigorous, regulator-ready VAPT reports.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Two obligations, one estate

A trading member answers to the exchange and to the framework behind it

Scoping them together is what keeps this to one assessment.

NSE/INSP/70471

The exchange submission

NSE requires trading members to submit VAPT reports. The report has to satisfy the exchange’s inspection process, which means it is read by someone checking completeness against a format.

SEBI CSCRF

The framework behind it

Stock brokers are SEBI regulated entities under the Cyber Security and Cyber Resilience Framework, and the control set that applies to you is decided by your category and tier, not by your exchange membership.

CERT-In

The auditor credential

Empanelment is the precondition Indian regulators apply to who may perform the assessment, and it attaches to the firm for a defined period, and the practical question is whether it was held on the days the work was done.

How we scope it

One assessment, two outputs

The testing that satisfies the exchange submission is largely the testing CSCRF expects. Run as one engagement it is one evidence base and two reports; run separately it is the same work paid for twice.

Which tier are you

Two parameters, applied independently, and the higher one wins

From the SEBI clarifications of 30 April 2025. A broker who classified once and never revisited it is the most common scoping error on this page’s subject.

CategoryTotal registered clientsClientele trading volume in a year (₹ crore)
Qualified RE More than 10 lakh More than 10,00,000
Mid-size RE More than 1 lakh and up to 10 lakh More than 1,00,000 and up to 10,00,000
Small-size RE More than 10,000 and up to 1 lakh More than 10,000 and up to 1,00,000
Self-certification RE More than 1,000 and up to 10,000 More than 1,000 and up to 10,000
Stock brokers with less than 1,000 crore of clientele trading volume in a year and less than 1,000 total registered clients are exempted from CSCRF by the same clarifications. If that is you, the honest answer is that you have an exchange submission and not a framework programme, and we would sooner say so at scoping than at invoice.

Qualified RE

Total registered clients
More than 10 lakh
Clientele trading volume in a year (₹ crore)
More than 10,00,000

Mid-size RE

Total registered clients
More than 1 lakh and up to 10 lakh
Clientele trading volume in a year (₹ crore)
More than 1,00,000 and up to 10,00,000

Small-size RE

Total registered clients
More than 10,000 and up to 1 lakh
Clientele trading volume in a year (₹ crore)
More than 10,000 and up to 1,00,000

Self-certification RE

Total registered clients
More than 1,000 and up to 10,000
Clientele trading volume in a year (₹ crore)
More than 1,000 and up to 10,000

Stock brokers with less than 1,000 crore of clientele trading volume in a year and less than 1,000 total registered clients are exempted from CSCRF by the same clarifications. If that is you, the honest answer is that you have an exchange submission and not a framework programme, and we would sooner say so at scoping than at invoice.

What the testing has to reach

The trading estate is wider than the trading application

A VAPT scoped to the client-facing trading application will pass an inspection and miss the things that actually matter on a broking estate. The order path runs from a mobile and web front end through an order management system to exchange connectivity, and every hop is an integration with its own authentication, its own session handling and its own failure modes. Behind it sits the back office: risk management, margin, settlement, the client master, and the KYC and account-opening flows that hold more personal data than the trading system does. Alongside it sits an API surface that has grown quickly at most brokers: partner integrations, algo and execution APIs, data feeds, and increasingly a public developer programme, which is where authorisation flaws concentrate because entitlements were designed for humans and then reused for keys. And around all of it is the vendor estate: the OMS vendor, the KYC provider, the SMS and email gateways, the cloud accounts, and the market-data plumbing. Our assessments cover applications, APIs, network and infrastructure across that whole picture, and test the business logic: whether an order can be placed against another client’s limits, whether a session survives a role change, whether a report can be pulled for an account the user does not own. Those are the findings that do not appear in a scanner’s output and are the reason the exercise is worth doing at all.

Before you commission it

Four things that decide whether the report is accepted first time

Four things that decide whether the report is accepted first time
StateWhat it meansWhat follows
The auditor was empanelled at the time CERT-In empanelment held on the days the testing was performed, not merely on the day the engagement was signed or the report issued. This is a date question, and the first thing checked. Security Brigade has held empanelment continuously since 2008.
Findings are closed, with retest evidence Each finding carries a retest result and a date. A submission with open findings and no closure trail invites a follow-up. Closing before submission is cheaper than answering afterwards.
Scope matches the estate as it is now The systems tested are the systems in production today, including the API surface and the partner integrations added since the last cycle. Scope drift between cycles is the quiet failure. A report that covers last year’s estate is accurate and not useful.
The tier was re-established this year Category and tier read against the current thresholds, on both parameters. Client counts and trading volumes move, and the higher of the two parameters decides. A broker who grew across a threshold is preparing for the wrong control set.
Key
  • Accepted first time
  • Accurate but incomplete
  • Wrong control set entirely

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade does not treat NSE VAPT as a checkbox exercise. Our methodology combines SEBI CSCRF compliance requirements with genuine cybersecurity depth, ensuring your report satisfies NSE submission criteria while identifying vulnerabilities that actually matter. Every engagement follows a repeatable, auditable process managed through our Lemon platform for full traceability. Our testing methodology aligns with the standards referenced in SEBI CSCRF Annexure 1: NIST SP 800-115, OWASP Testing Guide, OSSTMM, PCI-DSS standards, ISO 27001, and CERT-In guidelines.

Discovery
01

Scoping and Asset Discovery

We inventory all in-scope systems: trading platforms, back-office applications, APIs, market data feeds, mobile apps, cloud infrastructure, WiFi networks, and network devices. Architecture and data-flow documentation is created.

02

Infrastructure Vulnerability Assessment

Automated and manual assessment of servers, network devices, firewalls, endpoints, and infrastructure components. Findings are classified by severity with exploitation context.

Testing
03

Application, API, and Mobile Testing

Deep application security testing of trading apps, client portals, internal tools, APIs, and mobile applications using B-52 AI-assisted testing framework. Business logic and transaction flow testing included.

04

External PT, WiFi, Cloud, and Config Audit

External penetration testing against internet-facing perimeter, WiFi security assessment, cloud configuration review, and configuration audit of OS, databases, and application servers.

Delivery
05

Remediation Support and Closure Validation

Findings are tracked in Lemon with remediation guidance. We validate fixes and confirm closure before report finalisation. Practical guidance is provided to your IT and DevOps teams.

06

Report Finalisation and NSE Submission Support

Final VAPT report prepared in Annexure 2 format. Executive summary, technical findings, remediation status, and ATR details are included. L1/L2/L3 quality review before delivery. Note: the NSE submission portal is expected to be detailed in a forthcoming NSE circular — Security Brigade will update reporting formats as portal requirements are published.

"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
CISO, Top-3 Indian Bank
Chief Information Security Officer

Read more client stories →

FAQ

Trading member VAPT, answered

Scope, tier and submission. Talk to our team about your estate.

Contact us
Does the auditor need to be CERT-In empanelled?+
Yes. CERT-In empanelment is the precondition Indian regulators apply to who may perform this kind of assessment, and it attaches to the auditing firm for a defined period and not to an individual report. Security Brigade has been empanelled continuously since 2008. What is actually checked is a date: whether the firm held empanelment across the days the testing was performed.
How do I know which CSCRF category applies to us?+
Two parameters, applied independently, with the higher categorisation winning where they disagree: total registered clients, and clientele trading volume in a year. A broker above 10 lakh clients or above ₹10,00,000 crore of annual clientele trading volume is a Qualified RE; the bands below run through Mid-size, Small-size and Self-certification. Brokers with less than ₹1,000 crore of clientele trading volume in a year and less than 1,000 total registered clients are exempted from CSCRF by the clarifications of 30 April 2025. Re-establishing this each year matters, because growth across a threshold changes the control set.
Is the exchange submission the same as CSCRF compliance?+
They are different obligations answered by largely the same testing. The exchange submission is a VAPT report satisfying NSE’s inspection process; CSCRF is the framework governing you as a SEBI regulated entity, with a control set decided by your category and tier. We scope them as one engagement so the testing is performed once and written up for both audiences, because the alternative is paying twice for the same assurance.
What should be in scope?+
The order path end to end: mobile and web front ends, the order management system and exchange connectivity, plus the back office that surrounds it: risk and margin, settlement, client master, and the KYC and account-opening flows, which typically hold more personal data than the trading system. The API surface deserves particular attention: partner integrations, algo and execution APIs and developer programmes are where authorisation flaws concentrate, because entitlements designed for people get reused for keys.
How long does it take?+
Four to six weeks from scoping to a submission-ready report for a typical trading member, driven by the size of the API and partner estate and by how quickly findings can be retested. Where the CSCRF programme is scoped alongside, the additional time is small because the testing is shared and only the reporting differs.

Plan your NSE VAPT submission cycle

Security Brigade delivers submission-ready VAPT reports for NSE trading members. CERT-In empanelled since 2008. 370+ BFSI engagements. Lemon-backed delivery.

Typically responds within 1 business day · No commitment required

Request a Scoping Call