VAPT, cyber audit, red teaming and threat hunting are four separate obligations
Four obligations, three periodicity tables, two standards. The error made against CSCRF most often is not about the depth of any one of them — it is that all four end up as a single annual booking. Every reference below names the table or standard it came from, and the sourcing block at the foot records what was checked and when.
Yash K · · Regulation · about 9 min
The conflation
One exercise, asked to stand for four
A compliance plan is built around bookings, and a booking has one name. Four obligations with four periodicities become one line on it.
The master circular writes the four in three different places, and that is most of why they collapse into one. VAPT carries a periodicity table of its own, Table 18 at page 48. Cyber audit carries one of its own, Table 21 at page 51. Red teaming and threat hunting are written as standards — DE.DP.S4 and DE.DP.S5 — and their periodicities are printed alongside the other standards in Table 15, at pages 46 to 47. Four obligations, three periodicity tables, two standards, and three different applicability tests between them. What follows names each one, says where its periodicity is written and which REs its rows apply to, then sets out the periodicities in the wording each table itself uses. Every reference is to the master circular, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, unless a row says otherwise.
The citation spine
Where each of the four is written, and which REs its rows apply to
The column a planner skips is the first one. Two of the four carry a periodicity table of their own; two are standards whose periodicities are printed with the rest.
| Obligation | Where its periodicity is written | Which REs its rows apply to |
|---|---|---|
| VAPT | Table 18, at page 48 of the master circular. VAPT carries its own periodicity table rather than sitting in the general list. | Table 18 carries two rows, and both are written against whether NCIIPC has identified the RE as a “Protected system” and/ or CII. |
| The row a firm reads here turns on a designation made by NCIIPC — a different test from the one Table 21 applies to the cyber audit, and a different one again from the line the two standards carry. | ||
| Cyber audit | Table 21, at page 51. The cyber audit is a separate deliverable from VAPT, with a separate periodicity table. | Table 21 carries three entity rows: MIIs and Qualified REs; Mid-size and Small-size REs providing an IBT or Algo trading facility; and the rest of the REs. |
| Two deliverables, two tables, read separately. A plan that books one exercise and files it against both rows has answered only whichever row it was actually scoped against. | ||
| Red teaming | Standard DE.DP.S4. Its periodicity is printed with the other standards in Table 15, at pages 46 to 47, rather than in a table of its own. | MIIs and Qualified REs. |
| Threat hunting | Standard DE.DP.S5. Its periodicity is also printed in Table 15, at pages 46 to 47. | MIIs and Qualified REs — the same line Table 15 gives red teaming, and the only applicability test of the four that two obligations share. |
VAPT
- Where its periodicity is written
- Table 18, at page 48 of the master circular. VAPT carries its own periodicity table rather than sitting in the general list.
- Which REs its rows apply to
- Table 18 carries two rows, and both are written against whether NCIIPC has identified the RE as a “Protected system” and/ or CII.
The row a firm reads here turns on a designation made by NCIIPC — a different test from the one Table 21 applies to the cyber audit, and a different one again from the line the two standards carry.
Cyber audit
- Where its periodicity is written
- Table 21, at page 51. The cyber audit is a separate deliverable from VAPT, with a separate periodicity table.
- Which REs its rows apply to
- Table 21 carries three entity rows: MIIs and Qualified REs; Mid-size and Small-size REs providing an IBT or Algo trading facility; and the rest of the REs.
Two deliverables, two tables, read separately. A plan that books one exercise and files it against both rows has answered only whichever row it was actually scoped against.
Red teaming
- Where its periodicity is written
- Standard DE.DP.S4. Its periodicity is printed with the other standards in Table 15, at pages 46 to 47, rather than in a table of its own.
- Which REs its rows apply to
- MIIs and Qualified REs.
Threat hunting
- Where its periodicity is written
- Standard DE.DP.S5. Its periodicity is also printed in Table 15, at pages 46 to 47.
- Which REs its rows apply to
- MIIs and Qualified REs — the same line Table 15 gives red teaming, and the only applicability test of the four that two obligations share.
Applicability
Which row you are reading is a different question for each
One of the four turns on a designation by NCIIPC. One turns on entity category and on an activity the firm carries out. Two share a single applicability line.
VAPT
- What the rows are written against
- Whether NCIIPC has identified the RE as a “Protected system” and/ or CII. That designation is what moves a firm between the two rows.
- The first row
- At least twice a year — one VAPT activity completed, including report submission, closure and revalidation, in each half of the financial year.
- The second row
- The rest of the REs, at least once a year, with the VAPT commencing in the first quarter of the financial year.
Cyber audit
- What the rows are written against
- Entity category, and for one row whether the firm is providing an IBT or Algo trading facility.
- At least twice a year
- MIIs and Qualified REs.
- At least once a year
- Mid-size and Small-size REs providing an IBT or Algo trading facility, and the rest of the REs.
Red teaming and threat hunting
- The applicability line
- Both standards carry the same one: MIIs and Qualified REs. It is the one applicability test of the four that two obligations share.
- Red teaming
- Half-yearly. Table 15 prints the periodicity for standard DE.DP.S4.
- Threat hunting
- Quarterly. Table 15 prints the periodicity for standard DE.DP.S5.
Indexed by clock
Four periodicities, and which obligations sit on each
The same facts, read the other way round. Each periodicity is given in the wording its own table uses rather than normalised into a common one.
| State | What it means | What follows |
|---|---|---|
| Quarterly | Threat hunting. Table 15 prints the periodicity for standard DE.DP.S5, against MIIs and Qualified REs. | One obligation carries this periodicity. |
| Half-yearly | Red teaming. Table 15 prints the periodicity for standard DE.DP.S4, against the same applicability line, MIIs and Qualified REs. | One obligation carries this periodicity. |
| At least twice a year | VAPT, on the first row of Table 18 — the row written against the NCIIPC designation — where one activity has to be completed, including report submission, closure and revalidation, in each half of the financial year. Cyber audit, on the first row of Table 21: MIIs and Qualified REs. | Two obligations carry this periodicity, each on its own row. |
| At least once a year Terminal | VAPT, on the second row of Table 18 — the rest of the REs — with the activity commencing in the first quarter of the financial year. Cyber audit, on the two remaining rows of Table 21: Mid-size and Small-size REs providing an IBT or Algo trading facility, and the rest of the REs. | Two obligations carry this periodicity, each on its own row. |
- One obligation carries this periodicity
- Two obligations carry this periodicity, each on its own row
- TerminalNo state follows this one
How it goes wrong
Four shapes the collapse takes
Each of these is recognisable from a compliance calendar rather than from a circular, which is why the circular is quoted beside each one.
A single exercise carrying four names
One line in the year, labelled VAPT, expected to stand for the other three as well. Four periodicities are printed across Table 15, Table 18 and Table 21, and the one exercise answers to whichever of those rows it was actually scoped against.
“Quarterly VAPT”
This one travels, so it is worth putting the two references side by side. Quarterly is the periodicity Table 15 prints for standard DE.DP.S5, threat hunting. VAPT’s periodicity is printed in Table 18, as at least twice a year or at least once a year across its two rows.
Three tests, read as though they were one
A Qualified RE reads a single line for red teaming and threat hunting — MIIs and Qualified REs — and can carry that line across to the other two. Table 18 runs its own test: its rows turn on whether NCIIPC has identified the RE as a “Protected system” and/ or CII. Table 21 runs a third, on entity category and, for one row, on whether the firm provides an IBT or Algo trading facility.
Two submissions, summarised separately
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025 moved the VAPT and cyber audit report submissions to summaries in the format CSCRF prescribes, rather than the full reports the master circular had taken. Two deliverables, two summaries.
The document itself
Why the four sit in three different places
The layout of the circular is part of the answer, and it is checkable in a way that opinion about the layout is not.
Table 15, at pages 46 to 47, is where the periodicities attached to the CSCRF standards are listed together, and red teaming and threat hunting sit there as DE.DP.S4 and DE.DP.S5, alongside the drills, the reviews and the assessments that keep the same company. VAPT and cyber audit each carry a periodicity table of their own instead — Table 18 at page 48 and Table 21 at page 51 — each written against an applicability test of its own. A reader who has found one of the four is therefore standing some distance from where the other three are written, and a calendar assembled from whichever one was found first inherits that distance. The practical reading is the plain one: find the row your firm sits on in each of the three tables, and let each of the four keep its own clock.
Sourcing
What was checked, and when
Every reference above, and where it came from As of 2026-09-14
- The master circular is SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. Tables 15, 18 and 21 and standards DE.DP.S4 and DE.DP.S5 are the parts of it this article rests on, and every reference above was checked against them on 14 September 2026.
- One reference is from outside the master circular: SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025, which is where the summary form of the VAPT and cyber audit report submissions comes from.
- Periodicity is quoted in the wording each table uses rather than normalised. Table 15 prints half-yearly and quarterly. Table 18 prints at least twice a year and at least once a year, against the halves of the financial year. Table 21 prints at least twice a year and at least once a year.
Deliberately excluded
- No determination of a CSCRF entity category is made here. Each row reproduces the applicability its own table prints.
- The submission, closure and revalidation clocks that run after an activity finishes are not covered here. They are set out in full on the SEBI CSCRF page on this site, alongside the form each report submission takes.