RBI & SEBI Cybersecurity Rules: What VAPT Indian Fintechs Actually Need
"We'll need a pentest at some point" is where most fintech security conversations start — and where they stall, because the actual requirement depends on which regulator has jurisdiction over your specific business, and that's rarely a single, simple answer. Here's the practical breakdown.
If RBI regulates you
RBI's cybersecurity expectations apply to banks, NBFCs, payment aggregators, and account aggregators — in short, anything that touches money movement or holds a relevant RBI licence. The relevant framework spans the Cybersecurity Framework for Banks, the IT Framework for NBFCs, the Master Direction on Digital Payment Security Controls, and IT Governance/Risk/Audit guidelines, updated periodically. Cutting through the document sprawl, the consistent practical requirement is: annual VAPT covering your applications, infrastructure, and APIs, conducted by a qualified independent auditor, with findings tracked to closure.
If you're applying for or hold a Payment Aggregator licence specifically, security testing sits alongside net-worth requirements (₹15 crore at application, ₹25 crore ongoing by year three) as part of what RBI expects to see — testing isn't optional due diligence here, it's licensing-adjacent.
If SEBI regulates you
SEBI-regulated market intermediaries — brokers, mutual fund platforms, investment advisors operating digitally — fall under the Cybersecurity and Cyber Resilience Framework (CSCRF), which similarly expects regular VAPT along with broader resilience controls: incident response capability, business continuity planning, and periodic audits by empanelled or otherwise qualified auditors depending on your specific category.
Where DPDP overlaps with both
Neither RBI nor SEBI's frameworks replace your DPDP Act obligations — they layer on top of them. A fintech handling KYC data, transaction history, and payment credentials is squarely in DPDP's scope for consent, breach notification, and data-principal rights, independent of whatever RBI or SEBI-specific testing cadence applies. Product teams often discover this the hard way at onboarding-flow review time: the consent screen that satisfies a growth team's UX bar and the one that satisfies DPDP's itemised-consent requirement aren't always the same screen.
A practical annual cadence
For most regulated fintechs, this settles into a rhythm rather than a one-off project:
- Annual full VAPT across web, API, and infrastructure — the baseline nearly every framework above expects.
- Re-testing after material releases — a new payment flow or API surface shouldn't wait for next year's annual cycle to get looked at.
- DPDP-specific review of consent flows and data handling, run alongside (not instead of) the security testing.
- Documented findings-to-closure tracking — auditors and regulators care as much about whether last year's findings got fixed as whether this year's test is clean.
Our continuous retainer re-tests after every material release, so your annual VAPT cadence doesn't leave a gap between deploys and the next scheduled audit.
See how continuous testing works →