SBI VSCC
Readiness Checklist
A rejected VSCC is not a correction. It is a fresh start, and your onboarding date moves with it. SBI publishes three reasons a certificate is rejected — and only one of them is about the security of your site.
SBI VSCC Readiness Checklist
Enter your work email for the printable worksheet — a self-assessment across the eight areas, a finding-closure register, the auditor empanelment check, and a timeline working back from your onboarding date.
Check your inbox
We've emailed you a link to download SBI VSCC Readiness Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
Something went wrong. Please try again.
Why this is organised this way
The three ways a VSCC gets rejected
Most preparation material restates the assessment scope. That is the wrong spine — the scope is what your auditor covers, and it is not where merchants come unstuck.
01
The certificate was incomplete
Form C is SBI’s prescribed format and the auditor completes it — but every field they cannot answer from what you gave them becomes a gap in the document SBI receives. An entity name that differs between the certificate and the onboarding application is a completeness failure with no technical cause at all.
02
Findings were not adequately closed
The only one of the three that is about your site. "Closed" means fixed and demonstrated, not fixed and asserted — a finding closed without a retest is a claim, and a fix applied to staging rather than the assessed environment is the classic false closure.
03
The auditor was not properly CERT-In empanelled
A complete certificate with every finding closed does not stand if the signing firm was not properly empanelled — and empanelment is a term, not a permanent status, so a lapse between assessment and signature is worth checking for.
Scope
The eight areas the assessment reaches
Self-assess these before the auditor arrives. A finding you already know about is a finding you can have closed before the clock starts — and the clock is typically five to ten business days from scoping to certificate issuance.
01
SSL certificate and encryption controls
Valid SSL/TLS, encryption in transit and at rest, and certificate chain validation.
02
Web application security testing
The website and payment-facing application, for OWASP Top 10 and business-logic vulnerabilities.
03
Network vulnerability assessment
Vulnerabilities across infrastructure, servers and internet-exposed services.
04
Network penetration testing
Whether those vulnerabilities are actually exploitable, and what the impact is.
05
Firewall configuration and review
Rules, access control lists, and the segmentation protecting payment infrastructure.
06
Data storage and localisation
That payment and customer data is stored in line with SBI and RBI data-localisation requirements.
07
Audit trail and logging controls
Logging, audit-trail integrity, retention policy and monitoring capability.
08
Data sharing and privacy controls
Data-sharing practices, privacy controls, consent, and third-party data handling.
The VSCC is not PCI DSS, and holding one does not substitute for the other. PCI DSS may be referenced within the VSCC checklist where cardholder data is involved — so have that evidence to hand, but do not assume it discharges anything.
What the certificate actually is
- A procurement gate. SBI will not process a merchant onboarding application for SBI ePay or the SBI payment gateway without one.
- Form C. SBI’s prescribed certificate format, which the auditor fills, signs and certifies. This checklist deliberately does not enumerate its fields — that is SBI’s format and belongs to your auditor’s current copy.
- Signed only by a CERT-In empanelled auditor. No other firm is authorised to perform the assessment or sign the certificate.
Related
Where this fits
SBI VSCC Audit
The assessment, the Form C certificate, and how the engagement runs.
CERT-In Security Audit
What empanelment means, and why the signing firm’s status decides whether a certificate stands.
Web Application Testing
The area that produces most VSCC findings, and what a thorough test covers.
Need the certificate, not just the checklist?
Security Brigade has been CERT-In empanelled since 2008 and is authorised to perform the assessment and issue the signed Form C certificate.
Talk to a compliance lead