BSE issued circular on Submission of VAPT Report for the FY 2025-26

May 15, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Bombay Stock Exchange (BSE) on May 14, 2026, issued circular on Submission of VAPT Report for the FY 2025-26.

The circular provides updated guidance on the implementation of SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) with respect to Vulnerability Assessment and Penetration Testing (VAPT) for FY 2025–26. It reiterates that all Regulated Entities (REs) and trading members must plan their VAPT activities at the beginning of each financial year and ensure that no audit cycle is skipped. In case of any change in categorization, any unaudited period must be included in the current audit cycle to maintain continuity and compliance.

For most REs (self-certified, small, mid-size, and qualified REs excluding QSBs), VAPT is to be conducted once annually for the period April 1, 2025 to March 31, 2026. The VAPT must be completed by June 30, 2026, followed by submission of the report after IT Committee approval by July 31, 2026. Where applicable, the Action Taken Report (ATR) or revalidation report must be submitted by November 30, 2026. For Qualified Systemically Important Brokers (QSBs) and REs categorized as protected systems or Critical Information Infrastructure (CII), VAPT continues on a half-yearly basis, with timelines extending up to September 30, 2026 for ATR submission.

The scope of VAPT remains comprehensive, covering all critical assets such as networks, servers, databases, applications, and systems accessible via internal and external networks. The testing methodology must align with Annexure–L of the CSCRF circular. Updated formats for audit reports, declarations, and assessment details have been prescribed. Importantly, REs are not required to submit detailed vulnerability reports unless specifically requested by SEBI or exchanges, though such records must be maintained internally.

Additionally, entities must retain detailed VAPT reports along with supporting proof of concepts for a minimum of three years and ensure auditor selection complies with SEBI norms. The circular also highlights SEBI’s advisory on the use of advanced AI tools for vulnerability detection and outlines penalties for non-compliance. The submission portal for VAPT reports will be made available from May 25, 2026, reinforcing the push towards timely and standardized cybersecurity compliance.

[Notice No. 20260514-27]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT