NSE Trading Member VAPT: Comply with NSE/INSP/70471 and SEBI CSCRF Requirements
NSE requires all trading members to submit VAPT reports under the SEBI Cyber Security and Cyber Resilience Framework. Security Brigade, CERT-In empanelled since 2008, delivers submission-ready VAPT reports aligned to NSE/INSP/70471 requirements.
NSE circular NSE/INSP/70471 dated September 26, 2025 mandates all trading members to submit comprehensive VAPT reports for FY 2025-26. The circular enforces SEBI CSCRF compliance with strict yearly and half-yearly deadlines, detailed scope requirements across infrastructure, applications, APIs, cloud, WiFi, and mobile, and specific reporting formats under Annexure 2 and auditor norms under Annexure 3. Non-compliance puts your trading membership, reputation, and client trust at risk. Not sure which CSCRF tier your firm falls under? Run our self-service SEBI CSCRF compliance wizard to determine your classification, obligations, and prioritised gaps. Security Brigade has navigated complex compliance requirements across 370+ BFSI engagements, delivering technically rigorous, regulator-ready VAPT reports.
Trusted by India's leading enterprises
Two obligations, one estate
A trading member answers to the exchange and to the framework behind it
Scoping them together is what keeps this to one assessment.
The exchange submission
NSE requires trading members to submit VAPT reports. The report has to satisfy the exchange’s inspection process, which means it is read by someone checking completeness against a format.
The framework behind it
Stock brokers are SEBI regulated entities under the Cyber Security and Cyber Resilience Framework, and the control set that applies to you is decided by your category and tier, not by your exchange membership.
CERT-InThe auditor credential
Empanelment is the precondition Indian regulators apply to who may perform the assessment, and it attaches to the firm for a defined period, and the practical question is whether it was held on the days the work was done.
One assessment, two outputs
The testing that satisfies the exchange submission is largely the testing CSCRF expects. Run as one engagement it is one evidence base and two reports; run separately it is the same work paid for twice.
Which tier are you
Two parameters, applied independently, and the higher one wins
From the SEBI clarifications of 30 April 2025. A broker who classified once and never revisited it is the most common scoping error on this page’s subject.
| Category | Total registered clients | Clientele trading volume in a year (₹ crore) |
|---|---|---|
| Qualified RE | More than 10 lakh | More than 10,00,000 |
| Mid-size RE | More than 1 lakh and up to 10 lakh | More than 1,00,000 and up to 10,00,000 |
| Small-size RE | More than 10,000 and up to 1 lakh | More than 10,000 and up to 1,00,000 |
| Self-certification RE | More than 1,000 and up to 10,000 | More than 1,000 and up to 10,000 |
| Stock brokers with less than 1,000 crore of clientele trading volume in a year and less than 1,000 total registered clients are exempted from CSCRF by the same clarifications. If that is you, the honest answer is that you have an exchange submission and not a framework programme, and we would sooner say so at scoping than at invoice. | ||
Qualified RE
- Total registered clients
- More than 10 lakh
- Clientele trading volume in a year (₹ crore)
- More than 10,00,000
Mid-size RE
- Total registered clients
- More than 1 lakh and up to 10 lakh
- Clientele trading volume in a year (₹ crore)
- More than 1,00,000 and up to 10,00,000
Small-size RE
- Total registered clients
- More than 10,000 and up to 1 lakh
- Clientele trading volume in a year (₹ crore)
- More than 10,000 and up to 1,00,000
Self-certification RE
- Total registered clients
- More than 1,000 and up to 10,000
- Clientele trading volume in a year (₹ crore)
- More than 1,000 and up to 10,000
Stock brokers with less than 1,000 crore of clientele trading volume in a year and less than 1,000 total registered clients are exempted from CSCRF by the same clarifications. If that is you, the honest answer is that you have an exchange submission and not a framework programme, and we would sooner say so at scoping than at invoice.
What the testing has to reach
The trading estate is wider than the trading application
A VAPT scoped to the client-facing trading application will pass an inspection and miss the things that actually matter on a broking estate. The order path runs from a mobile and web front end through an order management system to exchange connectivity, and every hop is an integration with its own authentication, its own session handling and its own failure modes. Behind it sits the back office: risk management, margin, settlement, the client master, and the KYC and account-opening flows that hold more personal data than the trading system does. Alongside it sits an API surface that has grown quickly at most brokers: partner integrations, algo and execution APIs, data feeds, and increasingly a public developer programme, which is where authorisation flaws concentrate because entitlements were designed for humans and then reused for keys. And around all of it is the vendor estate: the OMS vendor, the KYC provider, the SMS and email gateways, the cloud accounts, and the market-data plumbing. Our assessments cover applications, APIs, network and infrastructure across that whole picture, and test the business logic: whether an order can be placed against another client’s limits, whether a session survives a role change, whether a report can be pulled for an account the user does not own. Those are the findings that do not appear in a scanner’s output and are the reason the exercise is worth doing at all.
Before you commission it
Four things that decide whether the report is accepted first time
| State | What it means | What follows |
|---|---|---|
| The auditor was empanelled at the time | CERT-In empanelment held on the days the testing was performed, not merely on the day the engagement was signed or the report issued. | This is a date question, and the first thing checked. Security Brigade has held empanelment continuously since 2008. |
| Findings are closed, with retest evidence | Each finding carries a retest result and a date. | A submission with open findings and no closure trail invites a follow-up. Closing before submission is cheaper than answering afterwards. |
| Scope matches the estate as it is now | The systems tested are the systems in production today, including the API surface and the partner integrations added since the last cycle. | Scope drift between cycles is the quiet failure. A report that covers last year’s estate is accurate and not useful. |
| The tier was re-established this year | Category and tier read against the current thresholds, on both parameters. | Client counts and trading volumes move, and the higher of the two parameters decides. A broker who grew across a threshold is preparing for the wrong control set. |
- Accepted first time
- Accurate but incomplete
- Wrong control set entirely
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade does not treat NSE VAPT as a checkbox exercise. Our methodology combines SEBI CSCRF compliance requirements with genuine cybersecurity depth, ensuring your report satisfies NSE submission criteria while identifying vulnerabilities that actually matter. Every engagement follows a repeatable, auditable process managed through our Lemon platform for full traceability. Our testing methodology aligns with the standards referenced in SEBI CSCRF Annexure 1: NIST SP 800-115, OWASP Testing Guide, OSSTMM, PCI-DSS standards, ISO 27001, and CERT-In guidelines.
Scoping and Asset Discovery
We inventory all in-scope systems: trading platforms, back-office applications, APIs, market data feeds, mobile apps, cloud infrastructure, WiFi networks, and network devices. Architecture and data-flow documentation is created.
Infrastructure Vulnerability Assessment
Automated and manual assessment of servers, network devices, firewalls, endpoints, and infrastructure components. Findings are classified by severity with exploitation context.
Application, API, and Mobile Testing
Deep application security testing of trading apps, client portals, internal tools, APIs, and mobile applications using B-52 AI-assisted testing framework. Business logic and transaction flow testing included.
External PT, WiFi, Cloud, and Config Audit
External penetration testing against internet-facing perimeter, WiFi security assessment, cloud configuration review, and configuration audit of OS, databases, and application servers.
Remediation Support and Closure Validation
Findings are tracked in Lemon with remediation guidance. We validate fixes and confirm closure before report finalisation. Practical guidance is provided to your IT and DevOps teams.
Report Finalisation and NSE Submission Support
Final VAPT report prepared in Annexure 2 format. Executive summary, technical findings, remediation status, and ATR details are included. L1/L2/L3 quality review before delivery. Note: the NSE submission portal is expected to be detailed in a forthcoming NSE circular — Security Brigade will update reporting formats as portal requirements are published.
"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
FAQ
Trading member VAPT, answered
Scope, tier and submission. Talk to our team about your estate.
Contact usDoes the auditor need to be CERT-In empanelled?
How do I know which CSCRF category applies to us?
Is the exchange submission the same as CSCRF compliance?
What should be in scope?
How long does it take?
Plan your NSE VAPT submission cycle
Security Brigade delivers submission-ready VAPT reports for NSE trading members. CERT-In empanelled since 2008. 370+ BFSI engagements. Lemon-backed delivery.
Typically responds within 1 business day · No commitment required