Skip to main content

InsightPublished

Depository and Exchange Cyber Reporting Requirements: Why VAPT Closure Evidence Now Matters More

Cyber reporting is moving beyond submitting VAPT reports. Market participants now need disciplined closure evidence, revalidation records, owner tracking, and correct report submission under CSCRF-linked expectations.

  • cscrf
  • vapt
  • cyber audit
  • cybersecurity compliance
  • cdsl
  • nse
Depository and Exchange Cyber Reporting Requirements: Why VAPT Closure Evidence Now Matters More | CompliSense
Depository and Exchange Cyber Reporting Requirements: Why VAPT Closure Evidence Now Matters More

There is a difference between completing a VAPT exercise and being ready for cyber reporting.

Many market participants are now learning that difference.

A VAPT report may identify vulnerabilities. A cyber audit may record observations. An auditor may submit a technical view. But the regulatory question is moving further: what did the entity do after the weakness was found?

That is where closure evidence matters.

Under the CSCRF environment, exchanges and depositories are no longer treating cyber compliance as a broad policy exercise. The expectation is becoming more operational: identify weaknesses, close them within the required timeline, preserve proof, submit the correct report in the correct format, and be ready to explain the status if asked.

VAPT Lifecycle

For stock brokers, depository participants, and other market intermediaries, this is a major shift in discipline.

The old comfort line was: “VAPT has been conducted.”

That is not enough anymore.

The better question is: “Can we show that every VAPT finding was reviewed, assigned, remediated, revalidated, reported, and archived?”

The first point firms should understand is that a VAPT finding is not an IT observation alone. It is a compliance item with a lifecycle. Once a vulnerability is identified, it should enter a tracked closure process. The finding should have severity, affected system, owner, target date, action taken, closure evidence, auditor validation status, and management visibility where required.

If the finding stays only inside a PDF report, the control is weak.

The second point is that closure evidence must be specific. A note saying “patched” or “resolved” is not strong enough. Evidence may include patch records, configuration screenshots, access-control changes, vendor confirmation, ticket closure logs, retest results, auditor revalidation, deployment notes, or compensating control approval where immediate closure is not possible.

The evidence should prove the action, not merely describe it.

This is where teams often face friction. IT may believe the issue is fixed. The auditor may need proof. Compliance may need a closure report. Management may want assurance that high-risk findings are not still open. The vendor may have to provide technical evidence. If these expectations are not defined early, everyone starts chasing documents close to the submission deadline.

The third point is ownership.

Every VAPT finding should have one responsible owner. Not “IT team.” Not “vendor.” Not “to be checked.” One person or role should be responsible for closure. Supporting teams can help, but accountability should not be vague.

Some findings may belong to infrastructure. Some may belong to application teams. Some may require vendor patches. Some may require policy change, user access review, configuration hardening, or network segmentation. If all findings are kept in one common bucket, the serious items can get lost among routine fixes.

A good closure tracker should separate findings by severity and ownership.

The fourth point is revalidation.

Closure is not always complete when the entity says the issue is fixed. For material findings, especially high or critical vulnerabilities, auditor confirmation or revalidation may be necessary. This is what makes the closure file defensible.

Without revalidation, the entity may only have internal comfort. With revalidation, it has a stronger record that the weakness was tested again or appropriately reviewed after remediation.

That matters because cyber findings are technical, but regulatory assurance is evidentiary.

The fifth point is report quality.

Cyber reporting is not only about sending something before the due date. It is about sending the right thing. SEBI’s clarificatory approach around CSCRF has made format discipline important, including submission of VAPT and cyber audit summaries in the prescribed CSCRF format and avoiding unnecessary disclosure of explicit vulnerabilities unless specifically asked.

This is practical, not theoretical.

A report that reveals sensitive vulnerability details unnecessarily can create security risk. A report that omits required summary information can create compliance risk. A report sent in the wrong format, to the wrong channel, or without the required declarations can create avoidable follow-up.

Firms should treat cyber reporting like a controlled submission, not an email attachment exercise.

The sixth point is timing.

VAPT closure cannot be done properly in the last week. Vulnerabilities may need development work, patch testing, change approval, downtime planning, vendor coordination, or retesting. Some fixes may affect production systems. Some may require business approval. Some may expose old architecture decisions.

If the closure tracker begins only when the submission deadline is near, the firm has already lost control.

The right approach is to create the closure plan immediately after the VAPT report is received. The highest-severity findings should be reviewed first. Owners should be assigned quickly. Vendor-dependent findings should be escalated early. Revalidation windows should be booked in advance. Evidence should be collected as the fix happens, not reconstructed later.

The seventh point is management visibility.

Cyber closure should not remain buried between IT and the auditor. Senior management should know how many findings are open, how many are critical or high severity, which systems are affected, whether any closure is delayed, whether a vendor is blocking remediation, and whether the regulatory submission is on track.

This does not mean management needs every technical detail. It means management needs exception visibility.

A simple monthly cyber-closure view can show: total findings, critical/high findings, overdue findings, pending vendor items, revalidated closures, submission due dates, and residual risk items requiring approval.

This is enough to move cyber compliance from technical follow-up to governance oversight.

The eighth point is archival discipline.

Once reports are submitted, the file should not disappear into an inbox. The entity should preserve the VAPT report, summary report, closure tracker, evidence pack, revalidation record, auditor declaration, management approval, and submission proof.

This becomes important during future audits, inspections, cyber incidents, and internal reviews. A regulator, exchange, depository, auditor, or management committee may later ask what was found, what was closed, what remained open, and what proof supports the closure.

The answer should not depend on someone searching old email threads.

The practical mistake firms should avoid is treating VAPT as a one-time annual or half-yearly exercise. Under the newer reporting environment, VAPT is part of a continuous cyber-control cycle.

Findings must be converted into action.
Action must be converted into evidence.
Evidence must be converted into a closure report.
The closure report must be submitted correctly.
The full record must remain searchable.

That is the operating standard.

For depository participants and exchange-regulated intermediaries, this is especially important because cyber controls sit close to client records, transaction systems, trading access, demat operations, reporting utilities, and market infrastructure connectivity. A weak cyber closure process is not just an IT gap. It is a regulated-business risk.

The key internal question should be simple:

If asked tomorrow, can we show the status and evidence for every VAPT finding?

If the answer is no, the firm is not ready for the reporting expectation.

The direction of travel is clear. Exchanges and depositories are not only asking whether audits and VAPT were conducted. They are increasingly concerned with whether findings were closed, evidenced, and reported correctly.

That is why VAPT closure evidence now matters more.

Related compliance hubs

Continue from this explainer into topic hubs that connect analysis with regulator updates and workflow context.

Related regulator archives

Continue into source-linked archives for regulators connected to this topic area.

Related legal updates

Source-linked updates that place this article in the current regulatory workflow.

Content accountability

Prepared by CompliSense Editorial Desk (Regulatory Content Team) and reviewed by CompliSense Regulatory Review Desk (Compliance Review Team).

This attribution reflects the preparation and review roles used for CompliSense regulatory publishing.

Continue evaluation