Skip to main content
CERT-In Empanelled Since 2008 — One of India's earliest empanelled cybersecurity auditors with 18+ years of continuous empanelment

SBI VSCC Audit: Get Your Vendor Site Compliance Certificate for SBI Payment Gateway Integration

Security Brigade is a CERT-In empanelled auditor authorised to issue the SBI Vendor Site Compliance Certificate (VSCC). We assess your application, network, and payment integration controls and deliver the signed Form C certificate required for SBI ePay and payment gateway merchant onboarding.

VSCC
Vendor Audit
SBI-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Where this sits

A certificate that unblocks an onboarding, not a framework you adopt

VSCC is a gate in someone else’s process. Understanding that shapes the whole engagement: the deliverable is a signed document with a deadline attached to a commercial launch.

01 Commercial

The trigger

What is happening
You are being onboarded as a merchant or integration partner for SBI ePay or the payment gateway, and the compliance certificate is one of the conditions to go live.
Why timing dominates
The date that matters is a launch date, not an audit calendar. Everything below is arranged around getting to a signed certificate without a second cycle.
02 One to two weeks

The assessment

What happens
Application, network and payment-integration controls assessed against the certification requirements: the checkout and callback paths, session and authentication handling, how card and payment data is handled in transit and at rest, and the infrastructure beneath.
03 The part that decides the date

Closure

What happens
Findings go back with the specific fix, and we retest. A certificate cannot be signed over an open material finding, so remediation speed, not assessment speed, sets the timeline.
How we shorten it
Findings are written so an engineer can act without a clarifying call, and retests are run as fixes land, not batched to the end.
04 Deliverable

The certificate

What you receive
The signed Vendor Site Compliance Certificate, Form C, together with the assessment report behind it. Security Brigade is CERT-In empanelled and authorised to issue the VSCC, so the assessment and the certificate come from the same engagement, with no second party needed.

Why this is quick when it is quick

The delay is almost never the assessment

Engagements of this shape fail their date in one of three ways, and none of them is the testing. The first is scope discovered late: the integration turns out to include a second environment, a partner-hosted component or a callback path nobody mentioned at scoping, and the assessment has to widen after it has started. The second is a finding that needs an architectural change and not a fix. Payment data written to an application log, a callback endpoint that authenticates the payload but not the caller, a shared credential across environments: for these the remediation is a week of engineering, not a configuration change. The third, and the most common, is a retest cycle that waits: fixes are made, nobody says so, and the retest is scheduled for the end, which turns a one-day verification into a fortnight of calendar. We plan against all three. Scoping asks specifically about environments, partner components and callbacks, not about systems. Findings are triaged on the day they are found so anything architectural surfaces first, while there is still time. And retests run continuously as fixes land, so the certificate follows the last fix instead of waiting for a scheduled pass. A short engagement is not a shallower one; it is one where nothing waited.

What is assessed

Four areas, and what makes each one pass

Four areas, and what makes each one pass
StateWhat it meansWhat follows
The payment integration The checkout, callback, refund and reconciliation paths, including how the integration authenticates both directions and what it trusts from the other side. The area that most often produces a material finding, because callbacks are commonly built to verify the payload and not the caller.
The application Authentication, session handling, authorisation on every path that touches an order or a payment, and input handling across the transaction flow. Passes cleanly where the application was tested before, and produces the long tail of findings where it was not.
Payment data handling What is stored, what is logged, what reaches analytics and what crosses to a third party, in transit and at rest, across every environment. Logging is the recurring finding. Card and payment data written to application logs is easy to fix and hard to see without looking.
Network and infrastructure Exposed services, management interfaces, segregation between environments and credential handling around the payment estate. Usually the cleanest area, and the one where a shared credential across environments is the thing that holds up a signature.
Key
  • Where material findings come from
  • Depends on prior testing
  • Usually clean

After the certificate

What the same assessment has already paid for

Reuse

Evidence your other obligations can use

The application and infrastructure testing behind the certificate is the same evidence an ISO 27001 ISMS or a SOC 2 readiness programme needs for its technical controls. Produced once, it answers more than one question.

Next time

A baseline for the next integration

Most organisations that need one payment-gateway certification need another within a year. The second is materially cheaper when the first left a tracked, retested evidence base instead of a PDF.

Worth having anyway

A view of where payment data actually goes

The data-handling assessment produces a map of what is stored, logged and shared across environments, which is the question every payment-related obligation eventually asks in some form.

Optional

Continuous visibility between assessments

A certificate proves a posture on a date. ShadowMap watches the internet-facing boundary continuously, so drift between assessments is visible, not discovered at the next one.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's VSCC methodology is built around one goal: delivering a valid, SBI-accepted certificate as quickly as possible without cutting corners on assessment depth. Every engagement follows a structured workflow managed through our Lemon platform, giving you real-time visibility into progress, findings, and remediation status.

Discovery
01

Scoping and Checklist Mapping

We review your SBI integration scope, identify all in-scope applications, infrastructure, and payment flows, and map them against the full SBI VSCC checklist. This ensures complete coverage from day one with no surprises mid-assessment.

02

Technical Assessment

Our CERT-In empanelled auditors perform the core technical assessment: web application security testing, network vulnerability assessment, network penetration testing, SSL and encryption validation, firewall review, and data handling controls. B-52, our AI-powered audit engine, ensures consistent coverage across all checklist requirements.

Testing
03

Findings Review and Remediation Support

All findings are documented with clear severity ratings, proof-of-concept evidence, and technology-specific remediation guidance. Findings are published to the Lemon client portal in real time. Our team provides hands-on remediation support to help your developers close gaps quickly.

Delivery
04

Revalidation and Closure

Once your team marks findings as fixed in Lemon, our auditors retest each finding to confirm the fix is effective. Only confirmed fixes are marked as closed. This verified remediation evidence is critical for certificate issuance.

05

Certificate Issuance (Form C)

After all findings are closed and validated, we issue the signed and sealed VSCC certificate (Form C) along with the complete technical assessment report. The certificate package is formatted for direct submission to SBI as part of your merchant onboarding documentation.

"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Head of Platform Engineering, Fintech Unicorn
Head of Platform Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

VSCC, answered

What it is, how long it takes, and what decides the date. Talk to our team if you have a launch to hit.

Contact us
Can Security Brigade issue the VSCC?+
Yes. Security Brigade is a CERT-In empanelled auditor authorised to issue the SBI Vendor Site Compliance Certificate, so the assessment and the signed Form C come from the same engagement, with no second party needed. We have held CERT-In empanelment continuously since 2008.
How long does it take?+
One to two weeks of assessment for a typical single integration, and the total depends almost entirely on remediation, not on testing. Where findings are configuration-level and fixed quickly, the certificate follows within days of the last retest. Where a finding needs an architectural change (payment data in application logs, a callback that does not authenticate its caller), the engineering work sets the date.
What is assessed?+
The payment integration itself, including checkout, callback, refund and reconciliation paths; the application around it, covering authentication, session handling and authorisation on every path touching an order or payment; how payment data is handled in transit and at rest across every environment, including what reaches logs and analytics; and the network and infrastructure beneath. The integration and the data handling produce most material findings.
What do we actually receive?+
The signed Vendor Site Compliance Certificate, Form C, and the assessment report behind it, with every finding carrying reproduction steps, severity, the specific fix and its retest evidence. The report is written so it is useful after the certificate is filed, not a document that exists only to be submitted.
We have a launch date. Can you work to it?+
Usually, and the way to protect a date is to scope honestly at the start. Tell us about every environment, partner-hosted component and callback path up front. Late scope discovery is the most common reason one of these slips. We triage findings on the day they are found so anything architectural surfaces while there is still time, and retest continuously as fixes land, not batching a pass at the end.

Ready to Get Your SBI VSCC Certificate?

Talk to a CERT-In empanelled auditor today. We will scope your assessment, provide a fixed-fee quote, and get you on the fastest path to your VSCC certificate.

Typically responds within 1 business day · No commitment required

Request a Scoping Call