Fintech Cybersecurity
CERT-In empanelled cybersecurity services for Fintech organisations. 6,700+ assessments delivered since 2006.
Challenges
Security challenges in Fintech
RBI PA-PG Master Direction compliance with annual CERT-In system audits
API security at scale — BOLA, BFLA, mass assignment across payment, lending, and KYC APIs
Real-time transaction security and replay-attack protection
Data localization — payment data must reside exclusively in India per RBI mandate
Third-party integrations with banks, NPCI, BBPS, and credit bureaus — each a new attack surface
Trusted by
The test
You are regulated by what you do, not by what you call yourself
Nothing attaches to the word "fintech". Obligations attach to the licence or registration behind each activity, and most fintechs are running more than one.
| If you do this | What attaches | The audit it brings |
|---|---|---|
| Aggregate payments or operate a gateway | The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and unaffected by it. | An annual system and cybersecurity audit by a CERT-In empanelled auditor. The instrument names the empanelment requirement rather than leaving it to the entity. |
| Store payment system data | The payment-data localisation requirement, also administered separately. | A system audit report by a CERT-In empanelled auditor, board-approved and submitted to RBI. |
| Lend on your own book | The NBFC Directions of 31 July 2026, where which chapter reaches you is decided by your Scale Based Regulation layer (¶3) — not by your product, your funding or your headcount. | VA six-monthly and PT twelve-monthly at ¶121, reaching the Middle Layer and above. Below that the instrument asks for markedly less. |
| Lend as a service to a regulated lender | Nothing directly — and that is the exposure. The obligation sits with the regulated lender, who discharges it by pushing it into your contract. | Whatever the lender's own instrument requires of its outsourced arrangements, arriving as a contractual demand rather than a regulatory one. |
| This is the most common position for a fintech to be in and the one least visible on a compliance register, because no regulator wrote your name anywhere. | ||
| Distribute securities or advise | SEBI CSCRF, which classifies you into a tier before it applies anything, and where a second registration can change the answer entirely. | Set by tier. A non-individual adviser registered in another SEBI category inherits that category's tier, which is frequently heavier than the adviser treatment. |
Aggregate payments or operate a gateway
- What attaches
- The PA-PG Master Direction, administered separately from the 31 July 2026 consolidation and unaffected by it.
- The audit it brings
- An annual system and cybersecurity audit by a CERT-In empanelled auditor. The instrument names the empanelment requirement rather than leaving it to the entity.
Store payment system data
- What attaches
- The payment-data localisation requirement, also administered separately.
- The audit it brings
- A system audit report by a CERT-In empanelled auditor, board-approved and submitted to RBI.
Lend on your own book
- The audit it brings
- VA six-monthly and PT twelve-monthly at ¶121, reaching the Middle Layer and above. Below that the instrument asks for markedly less.
Lend as a service to a regulated lender
- What attaches
- Nothing directly — and that is the exposure. The obligation sits with the regulated lender, who discharges it by pushing it into your contract.
- The audit it brings
- Whatever the lender's own instrument requires of its outsourced arrangements, arriving as a contractual demand rather than a regulatory one.
This is the most common position for a fintech to be in and the one least visible on a compliance register, because no regulator wrote your name anywhere.
Distribute securities or advise
- The audit it brings
- Set by tier. A non-individual adviser registered in another SEBI category inherits that category's tier, which is frequently heavier than the adviser treatment.
The consequence
Each licence brings its own auditor requirement
The instruments do not agree with each other about who may test you, which is a procurement problem before it is a security one.
-
Establish
List the activities, not the products
One product frequently spans several regulated activities — a lending app that also aggregates payments and distributes an insurance add-on is three regimes wearing one brand.
-
Map
Attach the instrument to each activity
Payment aggregation and payment-data storage both name a CERT-In empanelled auditor. The NBFC Directions set a cadence by layer. SEBI sets one by tier. They are not interchangeable.
-
Scope
Take the union, not the average
A single programme is achievable and cheaper — but it has to be scoped to the strictest requirement across the set, then reported so each regime receives what it asks for.
-
Evidence
Keep the auditor evidence with the report
Where an instrument specifies empanelment, the empanelment is part of the deliverable. A technically excellent report from a firm that does not meet the named criterion does not discharge the obligation.
The estate
What testing has to reach in a fintech
The technology estate of a fintech is unusual in two ways, and both change the scope. First, most of it is somebody else's: a card issuer, a sponsor bank, a KYC provider, a bureau, an account aggregator, a cloud-native everything. The interfaces belong to you even when the systems on the far side do not, and the question worth answering is what your side does when the far side sends something unexpected. Second, the release cadence is weekly rather than annual, which makes a point-in-time assessment a statement about a version that no longer exists. Lifecycle testing — pre-implementation, post-implementation and after changes — is written into the RBI instruments at ¶121 and ¶150 for exactly this reason, and it is the clause that most obviously does not fit an annual engagement.
Where this goes wrong
Three ways fintechs discover an obligation late
The threshold crossed quietly
The NBFC layer test is asset-size based and moves with the book. Nothing announces the crossing, and the chapter that starts applying is substantially larger than the one that stopped.
The partner's obligation, in your contract
A lending service provider or co-branded partner carries the regulated entity's duties by contract. Those clauses are negotiated by a commercial team and land on a security team that was not in the room.
The auditor who does not qualify
Two of the instruments a fintech is most likely to be under name a CERT-In empanelled auditor. Discovering that at submission means repeating the audit, not amending the report.
Services
Recommended Services for Fintech
RBI, NPCI, and PCI DSS-aligned security for fintech platforms
Web Application Penetration Testing
Security testing for digital lending platforms, wealth management apps, neobanking dashboards, and payment gateways.
Learn More →API Security Testing
OWASP API Top 10 coverage for open banking APIs, AA/PIS/BA frameworks, partner integrations, and webhook endpoints.
Learn More →Secure Code Review
Code-level analysis for lending algorithms, risk engines, KYC/AML workflows, and payment processing pipelines.
Learn More →Mobile Application Security Testing
iOS and Android security for fintech consumer apps, agent apps, and SDKs with reverse engineering and dynamic instrumentation.
Learn More →Cloud Security Assessment
Multi-cloud posture review for fintech infrastructure — AWS, Azure, GCP with RBI data localisation and DPDP Act coverage.
Learn More →Frequently Asked Questions
We are not RBI-regulated. Does any of this apply to us?
Frequently, through a contract rather than a rulebook. A regulated lender, bank or aggregator discharges its own obligations partly by imposing them on the providers it depends on, so the requirements arrive as clauses — testing rights, report sharing, source-code assurance, incident notification windows. The practical effect is the same and the timetable is usually worse, because a contractual deadline is set by a counterparty rather than by a supervisor.
Which of our licences decides who is allowed to test us?
The strictest one. Payment aggregation and payment-system-data storage both name a CERT-In empanelled auditor, and SEBI CSCRF does too. If any activity you run sits under one of those, that requirement governs the engagement — there is no benefit to scoping a separate cheaper assessment for the activities that do not name it.
Secure Your Fintech Organisation
One scoping call to align on scope, methodology, and timing.
Request a Scoping Call →