The National Stock Exchange (NSE) on April 20, 2026, notified regarding the revision in Terms of Reference (TOR) and Formats for submission of system audit report & submission of Vulnerability Assessment and Penetration Testing (VAPT) report for Vendors providing Co-Location as a Service (CaaS) facility.
The following has been stated:
• The circular requires CaaS vendors to submit half-yearly System Audit Reports and VAPT (Vulnerability Assessment and Penetration Testing) Reports to the Exchange as per prescribed timelines. For the April–September period, System Audit reports shall be submitted by 30 November (with final/ATR by 28 February), while for October–March, submission is due by 31 May. Similarly, VAPT reports are to be submitted by 31 August (final by 31 December) for April–September, and by 30 June (final by 30 September) for October–March.
• The circular also introduces standardised formats and revised Terms of Reference (TOR), along with specified auditor selection norms and defined scope/format for VAPT reports (Annexures 1–4).
• Additionally, all reports shall be approved by senior authorities such as the Managing Director, CTO, CISO, or relevant Technology/Cyber Security Committee before submission.
The detailed circular is attached below.
[Notification no. - NSE/MSD/73805]