SBI VSCC
Readiness Checklist
A rejected VSCC sends you back to the start of the process, and your onboarding date moves with it. SBI publishes three reasons a certificate is rejected. Only one of them is about the security of your site.
SBI VSCC Readiness Checklist
Enter your work email for the printable worksheet: a self-assessment across the eight areas, a finding-closure register, the auditor empanelment check, and a timeline working back from your onboarding date.
Check your inbox
We've emailed you a link to download SBI VSCC Readiness Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you SBI VSCC Readiness Checklist.
Rejection causes
The three ways a VSCC gets rejected
The assessment scope is what your auditor covers. These three are where merchants come unstuck.
01
The certificate was incomplete
Form C is SBI’s prescribed format and the auditor completes it, but every field they cannot answer from what you gave them becomes a gap in the document SBI receives. An entity name that differs between the certificate and the onboarding application is a completeness failure with no technical cause at all.
02
Findings were not adequately closed
The only one of the three that is about your site. "Closed" means fixed and demonstrated. A finding closed without a retest is a claim, and a fix applied to staging instead of the assessed environment is the classic false closure.
03
The auditor was not properly CERT-In empanelled
A complete certificate with every finding closed does not stand if the signing firm was not properly empanelled. Empanelment runs for a fixed term, so check that it covers both the assessment and the date of signature.
Scope
The eight areas the assessment reaches
Self-assess these before the auditor arrives. A finding you already know about is one you can have closed before the clock starts, and that clock is typically five to ten business days from scoping to certificate issuance.
01
SSL certificate and encryption controls
Valid SSL/TLS, encryption in transit and at rest, and certificate chain validation.
02
Web application security testing
The website and payment-facing application, for OWASP Top 10 2025 and business-logic vulnerabilities.
03
Network vulnerability assessment
Vulnerabilities across infrastructure, servers and internet-exposed services.
04
Network penetration testing
Whether those vulnerabilities are actually exploitable, and what the impact is.
05
Firewall configuration and review
Rules, access control lists, and the segmentation protecting payment infrastructure.
06
Data storage and localisation
That payment and customer data is stored in line with SBI and RBI data-localisation requirements.
07
Audit trail and logging controls
Logging, audit-trail integrity, retention policy and monitoring capability.
08
Data sharing and privacy controls
Data-sharing practices, privacy controls, consent, and third-party data handling.
The VSCC and PCI DSS do not substitute for each other. PCI DSS may be referenced within the VSCC checklist where cardholder data is involved, so have that evidence to hand.
What the certificate actually is
- A procurement gate. SBI will not process a merchant onboarding application for SBI ePay or the SBI payment gateway without one.
- Form C. SBI’s prescribed certificate format, which the auditor fills, signs and certifies. The fields are not reproduced here; work from your auditor’s current copy.
- Signed only by a CERT-In empanelled auditor. A firm outside the empanelment cannot perform the assessment or sign the certificate.
Related
Where this fits
SBI VSCC Audit
The assessment, the Form C certificate, and how the engagement runs.
CERT-In Security Audit
What empanelment means, and why the signing firm’s status decides whether a certificate stands.
Web Application Testing
The area that produces most VSCC findings, and what a thorough test covers.
Need the certificate, not just the checklist?
Security Brigade has been CERT-In empanelled since 2008 and is authorised to perform the assessment and issue the signed Form C certificate.
Talk to a compliance lead