Skip to main content
SBI ePay · Payment Gateway Onboarding

SBI VSCC
Readiness Checklist

A rejected VSCC is not a correction. It is a fresh start, and your onboarding date moves with it. SBI publishes three reasons a certificate is rejected — and only one of them is about the security of your site.

3
Published rejection causes
8
Assessment areas
5–10
Business days, typically

SBI VSCC Readiness Checklist

Enter your work email for the printable worksheet — a self-assessment across the eight areas, a finding-closure register, the auditor empanelment check, and a timeline working back from your onboarding date.

By downloading, you agree to receive relevant communications. We respect your privacy.

Why this is organised this way

The three ways a VSCC gets rejected

Most preparation material restates the assessment scope. That is the wrong spine — the scope is what your auditor covers, and it is not where merchants come unstuck.

01

The certificate was incomplete

Form C is SBI’s prescribed format and the auditor completes it — but every field they cannot answer from what you gave them becomes a gap in the document SBI receives. An entity name that differs between the certificate and the onboarding application is a completeness failure with no technical cause at all.

02

Findings were not adequately closed

The only one of the three that is about your site. "Closed" means fixed and demonstrated, not fixed and asserted — a finding closed without a retest is a claim, and a fix applied to staging rather than the assessed environment is the classic false closure.

03

The auditor was not properly CERT-In empanelled

A complete certificate with every finding closed does not stand if the signing firm was not properly empanelled — and empanelment is a term, not a permanent status, so a lapse between assessment and signature is worth checking for.

Scope

The eight areas the assessment reaches

Self-assess these before the auditor arrives. A finding you already know about is a finding you can have closed before the clock starts — and the clock is typically five to ten business days from scoping to certificate issuance.

01

SSL certificate and encryption controls

Valid SSL/TLS, encryption in transit and at rest, and certificate chain validation.

02

Web application security testing

The website and payment-facing application, for OWASP Top 10 and business-logic vulnerabilities.

03

Network vulnerability assessment

Vulnerabilities across infrastructure, servers and internet-exposed services.

04

Network penetration testing

Whether those vulnerabilities are actually exploitable, and what the impact is.

05

Firewall configuration and review

Rules, access control lists, and the segmentation protecting payment infrastructure.

06

Data storage and localisation

That payment and customer data is stored in line with SBI and RBI data-localisation requirements.

07

Audit trail and logging controls

Logging, audit-trail integrity, retention policy and monitoring capability.

08

Data sharing and privacy controls

Data-sharing practices, privacy controls, consent, and third-party data handling.

The VSCC is not PCI DSS, and holding one does not substitute for the other. PCI DSS may be referenced within the VSCC checklist where cardholder data is involved — so have that evidence to hand, but do not assume it discharges anything.

What the certificate actually is

  • A procurement gate. SBI will not process a merchant onboarding application for SBI ePay or the SBI payment gateway without one.
  • Form C. SBI’s prescribed certificate format, which the auditor fills, signs and certifies. This checklist deliberately does not enumerate its fields — that is SBI’s format and belongs to your auditor’s current copy.
  • Signed only by a CERT-In empanelled auditor. No other firm is authorised to perform the assessment or sign the certificate.

Need the certificate, not just the checklist?

Security Brigade has been CERT-In empanelled since 2008 and is authorised to perform the assessment and issue the signed Form C certificate.

Talk to a compliance lead