RBI Cybersecurity Framework: VAPT for Indian Banks and NBFCs
July 30, 2026
The Reserve Bank of India (RBI) has issued a series of cybersecurity directives over the last decade that establish VAPT as a mandatory practice for banks, non-banking financial companies (NBFCs), payment aggregators (PAs), and payment gateways (PGs). The regulatory expectations have expanded from initial framework requirements to detailed prescriptions for scope, cadence, and reporting. This document describes the current state of RBI VAPT expectations and how regulated entities structure programmes to satisfy them.
The Regulatory Landscape
The RBI Master Direction on Cyber Security Framework in Banks (June 2016 with subsequent updates) established VAPT as one of the technical controls required of banks. Subsequent Master Directions and circulars have extended equivalent requirements to NBFCs (with graduated expectations based on NBFC layer classification), to payment aggregators and payment gateways under the 2020 PA/PG guidelines, to account aggregators under the AA framework, and to specific product categories like UPI and mobile banking.
The graduated NBFC framework (Base Layer, Middle Layer, Upper Layer, Top Layer) establishes progressively stricter cybersecurity expectations as NBFC systemic importance increases. Base Layer NBFCs have foundational requirements; Upper Layer NBFCs have expectations comparable to smaller banks. VAPT cadence and depth align to the layer classification, and NBFCs transitioning between layers should expect updated VAPT expectations to accompany the transition.
The 2022 CERT-In Directions on cybersecurity added a supplementary regulatory layer that affects any entity operating in India, not just financial regulated entities. Six-hour incident notification requirements, log retention obligations, and specified assessment expectations under the directions interact with existing RBI requirements. Entities subject to both RBI and CERT-In obligations should structure their VAPT programmes to produce evidence satisfying both regulatory frameworks efficiently.
Scope of RBI VAPT
The RBI VAPT scope for banks includes internet-facing infrastructure, internal networks, all customer-facing applications, core banking systems, payment infrastructure, and any cloud environments processing regulated financial data. Explicitly enumerated components include internet banking portals, mobile banking applications, UPI integration components, ATM switches, card management systems, and third-party integrations with the bank's core systems.
Payment aggregator VAPT scope covers all systems in the transaction processing path — merchant onboarding systems, tokenisation infrastructure, payment gateway integration, settlement systems, and back-office applications with access to card data. The scope explicitly extends to APIs exposed to merchant integrations, which is often where PA VAPT engagements find high-severity issues because these APIs handle high-volume, high-value transactions with less scrutiny than internal systems.
Mobile banking application VAPT under RBI requirements aligns to OWASP Mobile Application Security Verification Standard (MASVS) plus RBI-specific concerns around transaction authorisation, root/jailbreak detection, and certificate pinning. Mobile banking VAPT should cover both the mobile applications themselves and the backend APIs the applications call; findings in either component are within scope. Assessments that report only mobile client findings without backend API testing produce follow-up questions from RBI inspectors.
Cyber Security Audit Report (SAR) Requirements
Regulated entities must file a Cyber Security Audit Report (SAR) periodically with RBI. The SAR consolidates VAPT findings, remediation status, and compliance posture into a report suitable for regulatory review. The format is prescribed and includes specific sections for VAPT findings by severity, remediation timelines, exception justifications, and management attestation.
SAR preparation is one of the more operationally intensive activities in the RBI compliance calendar. Entities that maintain continuous VAPT evidence throughout the reporting period assemble SARs substantially faster than entities that conduct annual VAPT and then compile the SAR from the annual report. The distinction matters both for operational efficiency and for the quality of the SAR — continuous evidence produces more comprehensive remediation history than annual snapshots.
SARs are reviewed by RBI inspection teams during on-site inspections and remote assessments. The consistency between the SAR and the underlying VAPT evidence is scrutinised; entities whose SAR narrative does not match the detail of the underlying VAPT reports receive follow-up questions. A defensive programme ensures SAR content is derived directly from the VAPT evidence base rather than being drafted independently and later reconciled.
CERT-In Empanelled Auditors and VAPT
CERT-In maintains a panel of empanelled information security auditors qualified to conduct VAPT and other security assessments. Certain RBI requirements specifically require use of CERT-In empanelled auditors — particularly for post-incident assessments and for entities in regulated categories with prescribed auditor requirements. Regulated entities should confirm which of their VAPT engagements require empanelled auditor involvement based on their specific regulatory category.
AI-powered VAPT platforms and CERT-In empanelled auditor engagements are typically complementary rather than substitutive. Continuous VAPT platforms produce the ongoing evidence and rapid feedback cycle that continuous security requires; empanelled auditor engagements provide the periodic independent third-party assessment that specific regulatory requirements demand. Combining both — continuous platform-based VAPT with periodic empanelled auditor assessment — provides comprehensive coverage that satisfies both operational and regulatory requirements.
The output of continuous VAPT can substantially reduce empanelled auditor engagement time and cost. Auditors reviewing an environment with mature continuous VAPT evidence spend proportionally more time on independent validation and less time on baseline discovery, resulting in faster and less expensive engagements. This dynamic has become one of the more compelling operational benefits of continuous VAPT programmes for RBI-regulated entities.
Data Localisation and Sovereign Requirements
RBI's Storage of Payment System Data circular (2018) and subsequent clarifications require payment system data to be stored in India. The requirement extends to systems that process the data, not just systems that store it, and has implications for where VAPT can be conducted and where VAPT evidence is stored. Regulated entities should ensure their VAPT programme complies with data localisation by conducting assessments from India-based infrastructure and storing evidence in India-hosted systems.
International VAPT vendors typically address data localisation through India-based operational deployments. Regulated entities evaluating VAPT vendors should verify India-based data handling capabilities as part of vendor due diligence. The absence of India-based deployment is not necessarily disqualifying — some assessment activities can be conducted with data remaining in India even when the vendor is based elsewhere — but the specific data flow should be reviewed against the applicable localisation requirements.
The Digital Personal Data Protection Act, 2023 introduces additional data protection requirements that interact with RBI cybersecurity obligations. DPDP-compliant handling of personal data during VAPT — including redaction of any personal data observed during testing, controlled retention of test data, and Data Fiduciary responsibilities of VAPT vendors — has become a required consideration for RBI-regulated entities structuring their VAPT programmes.
Change-Driven VAPT and Modern Delivery
RBI expectations increasingly recognise the reality that regulated environments change continuously. Prescribed annual VAPT is retained as a baseline, but change-driven VAPT is expected for significant changes to systems, networks, or application code. The definition of "significant change" has expanded to include changes to segmentation controls, changes to third-party integrations, and material changes to authentication or authorization mechanisms.
For entities operating on continuous deployment cycles, satisfying change-driven VAPT expectations through periodic engagements becomes operationally infeasible. Continuous VAPT integrated with the deployment pipeline is the practical response — each significant change automatically triggers assessment of the affected surface, producing the required evidence at the moment of change. This satisfies the regulatory requirement while eliminating operational friction with development velocity.
RBI inspection teams have begun asking specifically about how regulated entities satisfy change-driven VAPT expectations given modern deployment cadences. Entities that describe a continuous VAPT programme with automated triggering based on deployment events give a substantially stronger response than entities that describe annual VAPT plus ad-hoc reassessment. The regulatory expectation has caught up with the operational reality faster than many regulated entities anticipated, and 2026 inspection cycles are the first where this expectation is uniformly applied.