Reminder - Submission of VAPT Report for the FY 2025-26
- Issued
- Effective
- Compliance deadline
- Published
What changed
Multi Commodity Exchange of India Limited (MCX), vide Circular No. MCX/TECH/433/2026 dated 27 July 2026, has announced an important update regarding the reminder for submission of the VAPT Report for FY 2025–26.
Key Details of the Update –
• The circular reminds members to submit the VAPT Report for FY 2025–26 in accordance with the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) and subsequent clarification circulars.
• Applicability: Self-certification REs, Small-size REs, Mid-size REs, Qualified REs (not categorized as QSBs), and separately, QSBs and REs identified as ‘Protected Systems’ and/or Critical Information Infrastructure (CII) by NCIIPC.
• For Self-certification REs, Small-size REs, Mid-size REs and Qualified REs (non-QSBs), VAPT is to be conducted once annually for FY 2025–26 through a CERT-In empanelled auditor. The VAPT activity is to be initiated after the financial year (April 2025–March 2026).
• The VAPT Report must be submitted after approval from the respective IT Committee. Where applicable, the ATR/Revalidation Report is also required to be submitted after approval from the respective IT Committee through the same CERT-In empanelled auditor.
• For QSBs and REs identified as ‘Protected Systems’ and/or CII by NCIIPC, there is no change in the prescribed half-yearly VAPT timelines.
• Members registered with NSE and any other Exchange (including MCX) and using algorithm software across exchanges are required to submit VAPT details only to NSE under the technology-based common submission mechanism. NSE will share the submission with the respective exchanges. Members not registered with NSE must continue submitting to MCX through the existing process.
• Effective Date: The circular is effective from 27 July 2026 and serves as a reminder of the existing submission timelines for FY 2025–26.
• Key Changes: No new compliance requirements are introduced. The circular reiterates the existing VAPT submission timelines and the common submission mechanism through NSE for eligible members.
• Penalty/Consequence: Not Mentioned.
Actions if Any –
• Conduct the VAPT through a CERT-In empanelled auditor within the prescribed timeline.
• Obtain approval of the VAPT Report from the respective IT Committee before submission.
• Submit the VAPT Report and, where applicable, the ATR/Revalidation Report in the prescribed format through the Exchange Portal or to NSE, as applicable under the common submission mechanism.
Compliance Deadline –
• Self-certification REs, Small-size REs, Mid-size REs and Qualified REs (non-QSBs): Conduct VAPT by 30 June 2026, submit the approved VAPT Report by 31 July 2026, and submit the ATR/Revalidation Report (if applicable) by 30 November 2026.
• QSBs and Protected REs: Conduct VAPT and submit the approved report by 30 June 2026, and submit the ATR/Revalidation Report (if applicable) by 30 September 2026.
Need deeper implementation context?
Read the legal update above, then use CompliSense for deeper applicability review, workflow interpretation, ownership tracking, and evidence-ready compliance execution.