VAPT for banks and NBFCs
Banks, cooperative banks and NBFCs must evidence independent vulnerability assessment and penetration testing under RBI’s cyber-security and IT-governance directions — typically by a CERT-In empanelled auditor. CyberSigma performs application, API, mobile, network and cloud VAPT for BFSI, aligned to RBI expectations and CERT-In methodology, and delivers regulator-ready reports with proof-of-concept findings, CVSS ratings, remediation guidance and a free retest to evidence closure.
Who this is for
What we test
- Internet and mobile banking applications, customer portals and admin consoles
- APIs and integrations (account aggregator, UPI, card, lending)
- External and internal network infrastructure, and cloud configuration
- Business-logic, authentication/authorisation and session-management testing
Applicable RBI expectations
RBI cyber-security frameworks for banks and cooperative banks, and the Master Direction on IT Governance, Risk, Controls and Assurance Practices for NBFCs, generally expect periodic VAPT by an empanelled auditor and evidenced closure of findings.
Timeline and cost factors
What you receive
What we most often find in BFSI
- Broken access control and IDOR in customer portals and APIs
- Weak authentication, OTP and session handling
- Exposed admin interfaces and cloud misconfiguration
- Outdated components with known CVEs on internet-facing systems
See how we’ve done it before
Is your application one bug away from a breach?
Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.
VAPT for banks & NBFCs — FAQs
Does RBI require a CERT-In empanelled auditor for VAPT?
RBI cyber-security and IT-governance directions generally expect periodic VAPT and, in practice, testing by a CERT-In empanelled auditor with evidenced closure. CyberSigma is CERT-In empanelled.
How often should a bank or NBFC run VAPT?
At minimum annually and after significant change to internet-facing systems, with quarterly ASV scans where card data is in scope. Your specific RBI framework sets the cadence.
Do you provide closure/retest evidence?
Yes. A free retest confirms fixes and we re-issue the report so you can evidence closure to your Board and RBI inspection.
Talk to a CERT-In empanelled BFSI tester
Get a fixed VAPT scope and quote, with senior testers and regulator-ready reporting. Reply within four business hours.
Book a 20-minute VAPT call →Ready to discuss your VAPT for banks and NBFCs requirement?
CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.
