Skip to main content
SBI ePay · Payment Gateway Onboarding

SBI VSCC
Readiness Checklist

A rejected VSCC sends you back to the start of the process, and your onboarding date moves with it. SBI publishes three reasons a certificate is rejected. Only one of them is about the security of your site.

3
Published rejection causes
8
Assessment areas
5–10
Business days, typically

SBI VSCC Readiness Checklist

Enter your work email for the printable worksheet: a self-assessment across the eight areas, a finding-closure register, the auditor empanelment check, and a timeline working back from your onboarding date.

By downloading, you agree to receive relevant communications. We respect your privacy.

Rejection causes

The three ways a VSCC gets rejected

The assessment scope is what your auditor covers. These three are where merchants come unstuck.

01

The certificate was incomplete

Form C is SBI’s prescribed format and the auditor completes it, but every field they cannot answer from what you gave them becomes a gap in the document SBI receives. An entity name that differs between the certificate and the onboarding application is a completeness failure with no technical cause at all.

02

Findings were not adequately closed

The only one of the three that is about your site. "Closed" means fixed and demonstrated. A finding closed without a retest is a claim, and a fix applied to staging instead of the assessed environment is the classic false closure.

03

The auditor was not properly CERT-In empanelled

A complete certificate with every finding closed does not stand if the signing firm was not properly empanelled. Empanelment runs for a fixed term, so check that it covers both the assessment and the date of signature.

Scope

The eight areas the assessment reaches

Self-assess these before the auditor arrives. A finding you already know about is one you can have closed before the clock starts, and that clock is typically five to ten business days from scoping to certificate issuance.

01

SSL certificate and encryption controls

Valid SSL/TLS, encryption in transit and at rest, and certificate chain validation.

02

Web application security testing

The website and payment-facing application, for OWASP Top 10 2025 and business-logic vulnerabilities.

03

Network vulnerability assessment

Vulnerabilities across infrastructure, servers and internet-exposed services.

04

Network penetration testing

Whether those vulnerabilities are actually exploitable, and what the impact is.

05

Firewall configuration and review

Rules, access control lists, and the segmentation protecting payment infrastructure.

06

Data storage and localisation

That payment and customer data is stored in line with SBI and RBI data-localisation requirements.

07

Audit trail and logging controls

Logging, audit-trail integrity, retention policy and monitoring capability.

08

Data sharing and privacy controls

Data-sharing practices, privacy controls, consent, and third-party data handling.

The VSCC and PCI DSS do not substitute for each other. PCI DSS may be referenced within the VSCC checklist where cardholder data is involved, so have that evidence to hand.

What the certificate actually is

  • A procurement gate. SBI will not process a merchant onboarding application for SBI ePay or the SBI payment gateway without one.
  • Form C. SBI’s prescribed certificate format, which the auditor fills, signs and certifies. The fields are not reproduced here; work from your auditor’s current copy.
  • Signed only by a CERT-In empanelled auditor. A firm outside the empanelment cannot perform the assessment or sign the certificate.

Need the certificate, not just the checklist?

Security Brigade has been CERT-In empanelled since 2008 and is authorised to perform the assessment and issue the signed Form C certificate.

Talk to a compliance lead