Skip to main content
NSE / SEBI CSCRF Compliance

NSE Trading Member
VAPT Submission Checklist

Three things have to be true at once for a submission under NSE/INSP/70471 to stand: the assessment covered the mandated scope, the report is in the Annexure 2 format, and the auditor meets the Annexure 3 norms. A submission that satisfies two of the three is not a submission.

NSE/INSP/70471
The circular
30 Jun
VAPT report due
30 Nov
Action Taken Report due

NSE Trading Member VAPT Submission Checklist

Enter your work email for the printable worksheet — the scope-coverage table, the Annexure 2 report gate, the Annexure 3 auditor gate, and a dated plan working back from the deadline.

By downloading, you agree to receive relevant communications. We respect your privacy.

The three gates

Where a submission actually fails

The circular sets its requirements in three separate places, and a report can be technically excellent while failing on any one of them.

Scope

Every mandated testing area, or a recorded reason

The mandated scope is not a network scan. An area consciously excluded with a reason recorded is a defensible position; an area silently missing is a gap an inspection will find before you do.

Annexure 2

The report in the prescribed format

Severity per finding, remediation guidance rather than description alone, remediation status, Action Taken Report details, and the auditor’s attestation. A finding marked fixed without retest evidence is a claim, not a closure.

Annexure 3

An auditor who meets the eligibility norms

Including CERT-In empanelment covering the assessment date — empanelment is a term, not a permanent status. Confirm it before the engagement is commissioned: eligibility describes who performed the assessment, so it is not something a revision to the report can supply.

Scope

The mandated testing areas

The worksheet gives each one a row for the assets in scope and a column for whether it was covered — so an exclusion is a recorded decision rather than a blank. Reconcile the list against your own copy of the circular; the worksheet leaves blank rows for anything your estate adds.

01

Infrastructure vulnerability assessment

Servers, firewalls, routers, switches, endpoints and network devices, for known vulnerabilities and misconfigurations.

02

Application vulnerability assessment

Trading platforms and the other applications the member operates.

03

External penetration testing

Simulated attack against internet-facing systems, rather than a scan of them.

04

WiFi security assessment

Wireless networks at office, branch and data-centre locations — unauthorised access, rogue access points, encryption weaknesses.

05

API security testing

Trading APIs, market-data feeds, client-facing APIs and internal integrations — authentication, authorisation and data exposure.

06

Mobile application testing

Mobile trading applications, each distinct app rather than one build taken as representative.

07

Cloud security review

Cloud infrastructure, storage, access controls and configuration for cloud-hosted trading and business systems.

08

Configuration audit

Operating system, database, application server and network device configuration against hardening benchmarks.

09

Network segmentation testing

Validation that trading systems, back-office networks and internet-facing services are properly isolated.

Dates

Two cycles, and which one applies to you

Who Cycle Dates
Every trading member Yearly VAPT report by 30 June; Action Taken Report by 30 November.
Qualified Stock Brokers, NCIIPC-designated Protected Systems, and Critical Information Infrastructure entities Half-yearly, in addition A twice-yearly cadence with tighter dates. Confirm the applicable dates against the circular and any subsequent NSE communication for your category.

Commissioning an engagement eight to ten weeks before the deadline is a recommendation rather than a requirement of the circular. It exists so findings can be remediated and retested before the report is finalised, instead of being submitted open.

Need the assessment itself, not just the checklist?

Security Brigade has been CERT-In empanelled since 2008 and delivers VAPT reports in the Annexure 2 format, with remediation tracked to closure before the report is finalised.

Talk to a compliance lead