The Bombay Stock Exchange (NSE) on May 15, 2026, notified regarding the Periodic submission of System, Cyber, and VAPT Audit by Application Service Provider (ASP).
The following has been stated:
• It has directed registered Application Service Providers (ASPs) to conduct periodic System Audit, Cyber Security Audit, and Vulnerability Assessment & Penetration Testing (VAPT) of their non-exchange trading front-end platforms to strengthen cybersecurity and operational resilience.
• The audits will cover the period from April 1 to March 31 each year, and the audit reports must be submitted by June 30, while Action Taken Reports (ATR), wherever applicable, must be submitted by September 30.
• The Exchange has also issued detailed guidelines covering auditor selection criteria, reporting formats, declarations, assessment scope, and terms of reference for system and cyber audits through various annexures.
• Additionally, ASP vendors are required to submit the audit reports only after approval from their Managing Director, Director, CTO, or CISO.
[Notification no. - 20260515-23]