CDSL VAPT Closure Reports and the CSCRF Push: Why Cyber Evidence Is Now a Board-Level Issue
CDSL’s March 2026 VAPT closure requirement puts the focus on more than finding vulnerabilities. DPs must now demonstrate remediation, revalidation and governance-backed evidence under SEBI’s CSCRF.
- cdsl
- sebi
- cscrf
- vapt
- cybersecurity
- depository participants

CDSL’s March 2026 VAPT closure requirement puts the focus on more than finding vulnerabilities. DPs must now demonstrate remediation, revalidation and governance-backed evidence under SEBI’s CSCRF.
1. The Deadline Is About Closure, Not Another Cyber Audit
CDSL’s 5 March 2026 Communiqué CDSL/OPS/DP/POLCY/2026/152 requires applicable Depository Participants to submit compliance regarding closure of findings identified during VAPT for the half-yearly period April 2025 to September 2025 by 31 March 2026. Importantly, this particular requirement applies to DPs falling within the Qualified Stock Broker (QSB) and Protected Regulated Entity categories. The submission is not another VAPT report; it is the Action Taken Report showing what happened after vulnerabilities were identified.
That distinction is important. Cybersecurity compliance can easily become audit-centric: conduct the VAPT, receive a report, circulate findings and mark the audit exercise as completed. CSCRF pushes the process further. A vulnerability that has been identified but remains unresolved is still a live risk, irrespective of how detailed the original audit report was. CDSL’s March communiqué therefore brings the focus back to remediation and the evidence showing that remediation actually occurred.
2. The March Deadline Was Already Built Into the CSCRF Cycle
The 31 March deadline did not appear unexpectedly. CDSL’s December 2025 communiqué had already set out the sequence for the April–September 2025 half-yearly cycle. The VAPT was required to be conducted through a CERT-In empanelled auditor, with the VAPT report submitted to the Depository after approval from the respective IT Committee by 31 December 2025. The subsequent ATR/Revalidation Report, showing closure status and again approved by the respective IT Committee, was due by 31 March 2026.
The March communiqué is therefore best understood as the closure stage of an existing compliance lifecycle:
VAPT → findings → remediation → revalidation → IT Committee review → closure reporting
For a DP, the question at this stage is no longer whether a vulnerability was discovered. It is whether someone owned it, whether corrective action was completed, whether the fix was independently revalidated and whether the supporting evidence can withstand scrutiny.
3. “Closed” Must Mean More Than a Status Change
The weakest form of VAPT tracking is a spreadsheet in which a finding moves from “Open” to “Closed” because an internal team says the issue has been resolved. That may be useful for project management, but it is not necessarily strong compliance evidence.
A robust closure file should allow an independent reviewer to understand what vulnerability existed, what action was taken, when it was completed and how closure was verified. Depending on the finding, that evidence might include configuration records, patch details, screenshots, change tickets, revised access controls, application-release evidence, logs or re-test results from the auditor.
SEBI’s CSCRF clarifications reinforce the emphasis on timely remediation. Other VAPT observations are generally subject to the prescribed closure timeline, while patch-related high-severity vulnerabilities may also interact with tighter patch-management requirements. SEBI has further clarified that third-party dependencies do not remove the regulated entity’s responsibility for meeting VAPT closure timelines; firms are encouraged to reflect these obligations in vendor SLAs and consider compensating controls where appropriate.
This is where evidence quality becomes critical. A DP should not discover on 30 March that several vulnerabilities are technically “fixed” but cannot be convincingly demonstrated as closed.
4. Closure Tracking Needs an Owner, Age and Evidence
A VAPT finding should behave like a controlled compliance exception, not like an email forwarded to the Technology team. For every material finding, the organisation should know the responsible owner, severity, remediation action, target date, current status, dependency on any vendor, revalidation status and supporting evidence. High-risk items should be visible well before the regulatory closure deadline, particularly where remediation requires application releases, infrastructure changes or cooperation from third-party providers.
A useful closure tracker therefore needs more than Open / Closed. It should be capable of answering:
- Why is the finding still open?
- Who owns remediation?
- Has the technical fix actually been implemented?
- Has the auditor or relevant control function revalidated it?
- What evidence supports closure?
- Has the item received the required governance approval?
These are relatively simple questions, but they expose the difference between performing VAPT as an annual or half-yearly exercise and operating it as a continuing cybersecurity risk-management process.
5. Why This Becomes a Senior-Governance Issue
The CDSL requirement is particularly significant because the relevant VAPT report and ATR/Revalidation Report are required to carry approval from the respective IT Committee. The communiqué does not say that the Board itself must approve the March ATR, and that distinction should be maintained. However, the involvement of the IT Committee means vulnerability closure is no longer something that can comfortably remain buried within an information-security team.
For senior management and Board-level cyber-risk oversight, the implications are straightforward. If material vulnerabilities remain open, management should understand why. If closure depends on a vendor, there should be an escalation path. If a vulnerability has been accepted rather than remediated, the basis and authority for that decision should be visible. And if a report presented for governance approval says a vulnerability is closed, the institution should have credible evidence supporting that representation.
This is why cyber evidence increasingly becomes a governance issue. Senior committees do not need to review every screenshot or patch log, but they do need confidence that the underlying closure process is reliable.
6. The Real Risk Is the Gap Between Technology and Compliance
VAPT findings often sit across several functions. Information Security identifies or receives the finding. Technology implements the fix. A vendor may supply the patch. The auditor performs revalidation. Compliance tracks the regulatory date. The IT Committee approves the report.
Problems arise when these functions operate independently. Technology may consider an issue fixed while the auditor has not revalidated it. Compliance may see a green tracker while supporting evidence remains incomplete. A vendor may promise remediation after the CSCRF deadline. None of these problems becomes visible if the organisation only focuses on producing the final ATR shortly before submission.
The stronger model is one common closure workflow in which the technical fix, evidence, independent validation, regulatory deadline and governance approval remain connected from the moment the finding is raised.
7. What Applicable DPs Should Be Doing Before 31 March
The immediate priority for QSBs and Protected REs falling within CDSL’s March requirement is to reconcile the original VAPT findings against the closure position and ensure that the Action Taken Report accurately reflects the current status. DPs should pay particular attention to findings marked closed without sufficient evidence, items dependent on third parties, vulnerabilities awaiting re-test and discrepancies between internal trackers and the auditor’s closure position.
The objective should not be to produce a clean report at the deadline. It should be to ensure the report is an accurate representation of the organisation’s actual cyber-risk position.
8. Key Takeaway
CDSL’s March 2026 communiqué illustrates what CSCRF is increasingly demanding from regulated entities: not merely cybersecurity activity, but cybersecurity evidence. Conducting a VAPT proves that the organisation looked for vulnerabilities. The closure report has to demonstrate what happened after they were found. That requires clear ownership, timely remediation, credible evidence, independent revalidation and governance visibility.
For DPs, the stronger question is therefore not:
“Have we submitted the VAPT ATR?”
It is:
“If someone challenges a finding we have marked as closed, can we prove why we called it closed?”
That is where cyber compliance becomes operational governance.
Related compliance hubs
Continue from this explainer into topic hubs that connect analysis with regulator updates and workflow context.
Related regulator archives
Continue into source-linked archives for regulators connected to this topic area.
Related articles
Continue with related analysis selected by the editorial team or sharing the same topics.
Related legal updates
Source-linked updates that place this article in the current regulatory workflow.
Content accountability
Prepared by CompliSense Editorial Desk (Regulatory Content Team) and reviewed by CompliSense Regulatory Review Desk (Compliance Review Team).
This attribution reflects the preparation and review roles used for CompliSense regulatory publishing.