| VAPT | Table 18 carries two rows. The first is REs which have been identified as “Protected systems” and/ or CII by NCIIPC. The second is the rest of the REs. Both rows are written against that NCIIPC designation, and the designation is what moves a firm between them. | For the first row, at least twice: one VAPT activity completed — including report submission, closure and revalidation — in each half of the financial year, April to September and October to March. For the second row, at least once, with the activity commencing in the first quarter of the financial year. |
| Table 18, section 4.3.2, pages 48–49 of SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, Version 1.0. Read 2026-09-14. Section 4.3.2 also provides that REs shall plan their VAPT activity at the beginning of the financial year, and that no audit cycle shall be left unaudited due to a change in category — in such cases the unaudited period is included in the current audit cycle. |
| Cyber audit | Table 21 carries three entity rows against two periodicity cells. MIIs and Qualified REs occupy the first row. Mid-size REs and Small-size REs who are providing IBT or Algo trading facility occupy the second. The first periodicity cell is merged across both of those rows. The rest of the REs occupy the third. | At least twice in a year for the two rows under the merged cell. At least once in a year for the third row. |
| Table 21, section 4.4.1, page 51. Read 2026-09-14. The merged cell is the part that is easy to misread: it spans rows 1 and 2 rather than row 1 alone. Section 4.4 adds that cyber audit shall cover 100% of critical systems and 25% of non-critical systems, chosen on a sample basis. |
| Red teaming | MIIs and Qualified REs. Standard DE.DP.S4 prints the applicability as MIIs and Qualified REs (Mandatory). | Half-yearly. Guideline 1 provides that REs shall conduct red teaming exercises as part of their cybersecurity framework on a half-yearly basis, through use of red and blue teams. |
| Table 15 item 12, section 4.1, page 47, and standard DE.DP.S4 at page 121. Read 2026-09-14. Table 15 closes with a note that during cyber audit, auditors shall also validate adherence to the periodicities it sets. |
| Threat hunting | MIIs and Qualified REs. Standard DE.DP.S5 prints the applicability as MIIs and Qualified REs (Mandatory). | Quarterly. Guideline 2 sets threat hunting, drawing on threat intelligence, IOCs and IOAs, on a quarterly basis. Of the four activities on this page, quarterly is the cadence attached to this one. |
| Table 15 item 13, section 4.1, page 47, and standard DE.DP.S5 at page 122. Read 2026-09-14. Guideline 1 puts the activity as proactively searching for hidden and undetected cyber threats in the RE’s network. |