Skip to main content
Regulation · SEBI CSCRF

VAPT, cyber audit, red teaming and threat hunting are four separate obligations

Four obligations, three periodicity tables, two standards. The error made against CSCRF most often is not about the depth of any one of them — it is that all four end up as a single annual booking. Every reference below names the table or standard it came from, and the sourcing block at the foot records what was checked and when.

Yash K · · Regulation · about 9 min

The conflation

One exercise, asked to stand for four

A compliance plan is built around bookings, and a booking has one name. Four obligations with four periodicities become one line on it.

The master circular writes the four in three different places, and that is most of why they collapse into one. VAPT carries a periodicity table of its own, Table 18 at page 48. Cyber audit carries one of its own, Table 21 at page 51. Red teaming and threat hunting are written as standards — DE.DP.S4 and DE.DP.S5 — and their periodicities are printed alongside the other standards in Table 15, at pages 46 to 47. Four obligations, three periodicity tables, two standards, and three different applicability tests between them. What follows names each one, says where its periodicity is written and which REs its rows apply to, then sets out the periodicities in the wording each table itself uses. Every reference is to the master circular, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, unless a row says otherwise.

The citation spine

Where each of the four is written, and which REs its rows apply to

The column a planner skips is the first one. Two of the four carry a periodicity table of their own; two are standards whose periodicities are printed with the rest.

ObligationWhere its periodicity is writtenWhich REs its rows apply to
VAPT Table 18, at page 48 of the master circular. VAPT carries its own periodicity table rather than sitting in the general list. Table 18 carries two rows, and both are written against whether NCIIPC has identified the RE as a “Protected system” and/ or CII.
The row a firm reads here turns on a designation made by NCIIPC — a different test from the one Table 21 applies to the cyber audit, and a different one again from the line the two standards carry.
Cyber audit Table 21, at page 51. The cyber audit is a separate deliverable from VAPT, with a separate periodicity table. Table 21 carries three entity rows: MIIs and Qualified REs; Mid-size and Small-size REs providing an IBT or Algo trading facility; and the rest of the REs.
Two deliverables, two tables, read separately. A plan that books one exercise and files it against both rows has answered only whichever row it was actually scoped against.
Red teaming Standard DE.DP.S4. Its periodicity is printed with the other standards in Table 15, at pages 46 to 47, rather than in a table of its own. MIIs and Qualified REs.
Threat hunting Standard DE.DP.S5. Its periodicity is also printed in Table 15, at pages 46 to 47. MIIs and Qualified REs — the same line Table 15 gives red teaming, and the only applicability test of the four that two obligations share.

VAPT

Where its periodicity is written
Table 18, at page 48 of the master circular. VAPT carries its own periodicity table rather than sitting in the general list.
Which REs its rows apply to
Table 18 carries two rows, and both are written against whether NCIIPC has identified the RE as a “Protected system” and/ or CII.

The row a firm reads here turns on a designation made by NCIIPC — a different test from the one Table 21 applies to the cyber audit, and a different one again from the line the two standards carry.

Cyber audit

Where its periodicity is written
Table 21, at page 51. The cyber audit is a separate deliverable from VAPT, with a separate periodicity table.
Which REs its rows apply to
Table 21 carries three entity rows: MIIs and Qualified REs; Mid-size and Small-size REs providing an IBT or Algo trading facility; and the rest of the REs.

Two deliverables, two tables, read separately. A plan that books one exercise and files it against both rows has answered only whichever row it was actually scoped against.

Red teaming

Where its periodicity is written
Standard DE.DP.S4. Its periodicity is printed with the other standards in Table 15, at pages 46 to 47, rather than in a table of its own.
Which REs its rows apply to
MIIs and Qualified REs.

Threat hunting

Where its periodicity is written
Standard DE.DP.S5. Its periodicity is also printed in Table 15, at pages 46 to 47.
Which REs its rows apply to
MIIs and Qualified REs — the same line Table 15 gives red teaming, and the only applicability test of the four that two obligations share.

Applicability

Which row you are reading is a different question for each

One of the four turns on a designation by NCIIPC. One turns on entity category and on an activity the firm carries out. Two share a single applicability line.

01 Table 18 · two rows

VAPT

What the rows are written against
Whether NCIIPC has identified the RE as a “Protected system” and/ or CII. That designation is what moves a firm between the two rows.
The first row
At least twice a year — one VAPT activity completed, including report submission, closure and revalidation, in each half of the financial year.
The second row
The rest of the REs, at least once a year, with the VAPT commencing in the first quarter of the financial year.
02 Table 21 · three rows

Cyber audit

What the rows are written against
Entity category, and for one row whether the firm is providing an IBT or Algo trading facility.
At least twice a year
MIIs and Qualified REs.
At least once a year
Mid-size and Small-size REs providing an IBT or Algo trading facility, and the rest of the REs.
03 DE.DP.S4 and DE.DP.S5

Red teaming and threat hunting

The applicability line
Both standards carry the same one: MIIs and Qualified REs. It is the one applicability test of the four that two obligations share.
Red teaming
Half-yearly. Table 15 prints the periodicity for standard DE.DP.S4.
Threat hunting
Quarterly. Table 15 prints the periodicity for standard DE.DP.S5.

Indexed by clock

Four periodicities, and which obligations sit on each

The same facts, read the other way round. Each periodicity is given in the wording its own table uses rather than normalised into a common one.

Four periodicities, and which obligations sit on each
StateWhat it meansWhat follows
Quarterly Threat hunting. Table 15 prints the periodicity for standard DE.DP.S5, against MIIs and Qualified REs. One obligation carries this periodicity.
Half-yearly Red teaming. Table 15 prints the periodicity for standard DE.DP.S4, against the same applicability line, MIIs and Qualified REs. One obligation carries this periodicity.
At least twice a year VAPT, on the first row of Table 18 — the row written against the NCIIPC designation — where one activity has to be completed, including report submission, closure and revalidation, in each half of the financial year. Cyber audit, on the first row of Table 21: MIIs and Qualified REs. Two obligations carry this periodicity, each on its own row.
At least once a year Terminal VAPT, on the second row of Table 18 — the rest of the REs — with the activity commencing in the first quarter of the financial year. Cyber audit, on the two remaining rows of Table 21: Mid-size and Small-size REs providing an IBT or Algo trading facility, and the rest of the REs. Two obligations carry this periodicity, each on its own row.
Key
  • One obligation carries this periodicity
  • Two obligations carry this periodicity, each on its own row
  • TerminalNo state follows this one

How it goes wrong

Four shapes the collapse takes

Each of these is recognisable from a compliance calendar rather than from a circular, which is why the circular is quoted beside each one.

One booking

A single exercise carrying four names

One line in the year, labelled VAPT, expected to stand for the other three as well. Four periodicities are printed across Table 15, Table 18 and Table 21, and the one exercise answers to whichever of those rows it was actually scoped against.

One phrase

“Quarterly VAPT”

This one travels, so it is worth putting the two references side by side. Quarterly is the periodicity Table 15 prints for standard DE.DP.S5, threat hunting. VAPT’s periodicity is printed in Table 18, as at least twice a year or at least once a year across its two rows.

One applicability test

Three tests, read as though they were one

A Qualified RE reads a single line for red teaming and threat hunting — MIIs and Qualified REs — and can carry that line across to the other two. Table 18 runs its own test: its rows turn on whether NCIIPC has identified the RE as a “Protected system” and/ or CII. Table 21 runs a third, on entity category and, for one row, on whether the firm provides an IBT or Algo trading facility.

One report

Two submissions, summarised separately

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025 moved the VAPT and cyber audit report submissions to summaries in the format CSCRF prescribes, rather than the full reports the master circular had taken. Two deliverables, two summaries.

The document itself

Why the four sit in three different places

The layout of the circular is part of the answer, and it is checkable in a way that opinion about the layout is not.

Table 15, at pages 46 to 47, is where the periodicities attached to the CSCRF standards are listed together, and red teaming and threat hunting sit there as DE.DP.S4 and DE.DP.S5, alongside the drills, the reviews and the assessments that keep the same company. VAPT and cyber audit each carry a periodicity table of their own instead — Table 18 at page 48 and Table 21 at page 51 — each written against an applicability test of its own. A reader who has found one of the four is therefore standing some distance from where the other three are written, and a calendar assembled from whichever one was found first inherits that distance. The practical reading is the plain one: find the row your firm sits on in each of the three tables, and let each of the four keep its own clock.

Sourcing

What was checked, and when

Every reference above, and where it came from As of 2026-09-14
  • The master circular is SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. Tables 15, 18 and 21 and standards DE.DP.S4 and DE.DP.S5 are the parts of it this article rests on, and every reference above was checked against them on 14 September 2026.
  • One reference is from outside the master circular: SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025, which is where the summary form of the VAPT and cyber audit report submissions comes from.
  • Periodicity is quoted in the wording each table uses rather than normalised. Table 15 prints half-yearly and quarterly. Table 18 prints at least twice a year and at least once a year, against the halves of the financial year. Table 21 prints at least twice a year and at least once a year.

Deliberately excluded

  • No determination of a CSCRF entity category is made here. Each row reproduces the applicability its own table prints.
  • The submission, closure and revalidation clocks that run after an activity finishes are not covered here. They are set out in full on the SEBI CSCRF page on this site, alongside the form each report submission takes.

Every CSCRF cadence, cited to the table it is written in

The SEBI CSCRF page sets each of the four against its own table, adds the submission, closure and revalidation clocks that follow an activity, and records the date every row was last checked.