We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · BFSI

VAPT for banks and NBFCs

Banks, cooperative banks and NBFCs must evidence independent vulnerability assessment and penetration testing under RBI’s cyber-security and IT-governance directions — typically by a CERT-In empanelled auditor. CyberSigma performs application, API, mobile, network and cloud VAPT for BFSI, aligned to RBI expectations and CERT-In methodology, and delivers regulator-ready reports with proof-of-concept findings, CVSS ratings, remediation guidance and a free retest to evidence closure.

Get a free BFSI VAPT scope →Book a 20-minute call
Who needs it

Who this is for

Banks & cooperative banks
Internet/mobile banking, payment and core-adjacent systems under RBI cyber-security frameworks.
NBFCs
Customer-facing apps, APIs and infrastructure under RBI IT-governance expectations.
BFSI vendors
Fintech and technology partners who must evidence testing to their bank customers.
Scope

What we test

  • Internet and mobile banking applications, customer portals and admin consoles
  • APIs and integrations (account aggregator, UPI, card, lending)
  • External and internal network infrastructure, and cloud configuration
  • Business-logic, authentication/authorisation and session-management testing
Regulation

Applicable RBI expectations

RBI cyber-security frameworks for banks and cooperative banks, and the Master Direction on IT Governance, Risk, Controls and Assurance Practices for NBFCs, generally expect periodic VAPT by an empanelled auditor and evidenced closure of findings.

Timeline & cost

Timeline and cost factors

Timeline
Scoping 2–4 days; testing 1–3 weeks by scope; report and free retest 3–5 days.
Cost factors
Number of applications, APIs and hosts; grey-box vs black-box; source-code review; and reporting depth for RBI.
Deliverables

What you receive

Executive & technical reports
Risk-rated summary plus every finding with evidence, CVSS and remediation.
Closure evidence
Free retest and re-issue your RBI inspection can rely on.
Common failures

What we most often find in BFSI

  • Broken access control and IDOR in customer portals and APIs
  • Weak authentication, OTP and session handling
  • Exposed admin interfaces and cloud misconfiguration
  • Outdated components with known CVEs on internet-facing systems
Proof

See how we’ve done it before

Relevant case study
How BFSI VAPT surfaced and closed critical exposures ahead of an RBI inspection. Read case studies →
Redacted sample deliverable
Inspect a redacted VAPT report first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Payment system data storage in IndiaEffective 6 October 2018

    RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

    Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.

  • IT Governance Master DirectionEffective 1 April 2024

    Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

    Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.

  • IT Outsourcing Master DirectionEffective 1 October 2023

    Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

    Direction number cited for retrieval via RBI notification search.

  • Digital Payment Security Controls Master DirectionEffective 18 February 2021

    Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

    Direction cited by title and date for retrieval via RBI notification search.

  • Cyber Security Framework in BanksEffective 2 June 2016

    RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Related in this cluster

VAPT for banks & NBFCs — FAQs

Does RBI require a CERT-In empanelled auditor for VAPT?

RBI cyber-security and IT-governance directions generally expect periodic VAPT and, in practice, testing by a CERT-In empanelled auditor with evidenced closure. CyberSigma is CERT-In empanelled.

How often should a bank or NBFC run VAPT?

At minimum annually and after significant change to internet-facing systems, with quarterly ASV scans where card data is in scope. Your specific RBI framework sets the cadence.

Do you provide closure/retest evidence?

Yes. A free retest confirms fixes and we re-issue the report so you can evidence closure to your Board and RBI inspection.

Talk to a CERT-In empanelled BFSI tester

Get a fixed VAPT scope and quote, with senior testers and regulator-ready reporting. Reply within four business hours.

Book a 20-minute VAPT call →

Ready to discuss your VAPT for banks and NBFCs requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.