NSE Trading Member
VAPT Submission Checklist
Three things have to be true at once for a submission under NSE/INSP/70471 to stand: the assessment covered the mandated scope, the report is in the Annexure 2 format, and the auditor meets the Annexure 3 norms. A submission that satisfies two of the three is not a submission.
NSE Trading Member VAPT Submission Checklist
Enter your work email for the printable worksheet — the scope-coverage table, the Annexure 2 report gate, the Annexure 3 auditor gate, and a dated plan working back from the deadline.
Check your inbox
We've emailed you a link to download NSE Trading Member VAPT Submission Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
Something went wrong. Please try again.
The three gates
Where a submission actually fails
The circular sets its requirements in three separate places, and a report can be technically excellent while failing on any one of them.
Scope
Every mandated testing area, or a recorded reason
The mandated scope is not a network scan. An area consciously excluded with a reason recorded is a defensible position; an area silently missing is a gap an inspection will find before you do.
Annexure 2
The report in the prescribed format
Severity per finding, remediation guidance rather than description alone, remediation status, Action Taken Report details, and the auditor’s attestation. A finding marked fixed without retest evidence is a claim, not a closure.
Annexure 3
An auditor who meets the eligibility norms
Including CERT-In empanelment covering the assessment date — empanelment is a term, not a permanent status. Confirm it before the engagement is commissioned: eligibility describes who performed the assessment, so it is not something a revision to the report can supply.
Scope
The mandated testing areas
The worksheet gives each one a row for the assets in scope and a column for whether it was covered — so an exclusion is a recorded decision rather than a blank. Reconcile the list against your own copy of the circular; the worksheet leaves blank rows for anything your estate adds.
01
Infrastructure vulnerability assessment
Servers, firewalls, routers, switches, endpoints and network devices, for known vulnerabilities and misconfigurations.
02
Application vulnerability assessment
Trading platforms and the other applications the member operates.
03
External penetration testing
Simulated attack against internet-facing systems, rather than a scan of them.
04
WiFi security assessment
Wireless networks at office, branch and data-centre locations — unauthorised access, rogue access points, encryption weaknesses.
05
API security testing
Trading APIs, market-data feeds, client-facing APIs and internal integrations — authentication, authorisation and data exposure.
06
Mobile application testing
Mobile trading applications, each distinct app rather than one build taken as representative.
07
Cloud security review
Cloud infrastructure, storage, access controls and configuration for cloud-hosted trading and business systems.
08
Configuration audit
Operating system, database, application server and network device configuration against hardening benchmarks.
09
Network segmentation testing
Validation that trading systems, back-office networks and internet-facing services are properly isolated.
Dates
Two cycles, and which one applies to you
| Who | Cycle | Dates |
|---|---|---|
| Every trading member | Yearly | VAPT report by 30 June; Action Taken Report by 30 November. |
| Qualified Stock Brokers, NCIIPC-designated Protected Systems, and Critical Information Infrastructure entities | Half-yearly, in addition | A twice-yearly cadence with tighter dates. Confirm the applicable dates against the circular and any subsequent NSE communication for your category. |
Commissioning an engagement eight to ten weeks before the deadline is a recommendation rather than a requirement of the circular. It exists so findings can be remediated and retested before the report is finalised, instead of being submitted open.
Related
Where this fits
Need the assessment itself, not just the checklist?
Security Brigade has been CERT-In empanelled since 2008 and delivers VAPT reports in the Annexure 2 format, with remediation tracked to closure before the report is finalised.
Talk to a compliance lead