Skip to main content
NSE / SEBI CSCRF Compliance

NSE Trading Member
VAPT Submission Checklist

Three things have to be true at once for a submission under NSE/INSP/70471 to stand: the assessment covered the mandated scope, the report is in the Annexure 2 format, and the auditor meets the Annexure 3 norms. Two of the three is not enough.

NSE/INSP/70471
The circular
30 Jun
VAPT report due
30 Nov
Action Taken Report due

NSE Trading Member VAPT Submission Checklist

Enter your work email for the printable worksheet: the scope-coverage table, the Annexure 2 report gate, the Annexure 3 auditor gate, and a dated plan working back from the deadline.

By downloading, you agree to receive relevant communications. We respect your privacy.

The three gates

Where a submission actually fails

The circular sets its requirements in three separate places, and a report can be technically excellent while failing on any one of them.

Scope

Every mandated testing area, or a recorded reason

An area excluded with a reason recorded is a defensible position. An area silently missing is a gap an inspection will find before you do.

Annexure 2

The report in the prescribed format

Severity per finding, remediation guidance for each one, remediation status, Action Taken Report details, and the auditor’s attestation. A finding marked fixed needs retest evidence behind it.

Annexure 3

An auditor who meets the eligibility norms

Including CERT-In empanelment covering the assessment date. Empanelment runs for a fixed term, so confirm it before the engagement is commissioned: eligibility describes who performed the assessment, and revising the report afterwards cannot change that.

Scope

The mandated testing areas

The worksheet gives each one a row for the assets in scope and a column for whether it was covered, so an exclusion becomes a recorded decision instead of a blank. Check the list against your own copy of the circular; the worksheet leaves blank rows for anything your estate adds.

01

Infrastructure vulnerability assessment

Servers, firewalls, routers, switches, endpoints and network devices, for known vulnerabilities and misconfigurations.

02

Application vulnerability assessment

Trading platforms and the other applications the member operates.

03

External penetration testing

Simulated attack against internet-facing systems, not a scan of them.

04

WiFi security assessment

Wireless networks at office, branch and data-centre locations: unauthorised access, rogue access points, encryption weaknesses.

05

API security testing

Trading APIs, market-data feeds, client-facing APIs and internal integrations, tested for authentication, authorisation and data exposure.

06

Mobile application testing

Mobile trading applications, with each distinct app tested on its own.

07

Cloud security review

Cloud infrastructure, storage, access controls and configuration for cloud-hosted trading and business systems.

08

Configuration audit

Operating system, database, application server and network device configuration against hardening benchmarks.

09

Network segmentation testing

Validation that trading systems, back-office networks and internet-facing services are properly isolated.

Dates

Two cycles, and which one applies to you

Who Cycle Dates
Every trading member Yearly VAPT report by 30 June; Action Taken Report by 30 November.
Qualified Stock Brokers, NCIIPC-designated Protected Systems, and Critical Information Infrastructure entities Half-yearly, in addition A twice-yearly cadence with tighter dates. Confirm the applicable dates against the circular and any subsequent NSE communication for your category.

The circular sets the deadline; the schedule around it is yours. Commissioning an engagement eight to ten weeks before it leaves time to remediate and retest findings before the report is finalised, instead of being submitted open.

Need the assessment itself, not just the checklist?

Security Brigade has been CERT-In empanelled since 2008 and delivers VAPT reports in the Annexure 2 format, with remediation tracked to closure before the report is finalised.

Talk to a compliance lead