Penetration Testing India: What Regulators Require
Penetration testing in India has moved from best practice to expectation. Between CERT-In's directions, sectoral regulators, and the Digital Personal Data Protection (DPDP) Act 2023, most organizations serving Indian customers or handling Indian personal data now need documented security testing they can defend to a regulator, an auditor, or an enterprise client.
Who requires testing in India
- CERT-In. The Indian Computer Emergency Response Team's 2022 directions require service providers, intermediaries, data centres, and government entities to report specified cyber incidents within six hours of detection. CERT-In also empanels security auditing organizations, which matters for government and public-sector work: if you serve those clients, your testing provider should be empanelled.
- RBI. The Reserve Bank of India's cybersecurity framework expects banks and large NBFCs to commission penetration tests on a defined frequency. VAPT is a standing expectation for regulated financial entities.
- SEBI. The Cyber Security and Cyber Resilience Framework puts vulnerability assessment and penetration testing on a defined schedule for market infrastructure institutions and regulated entities. Findings feed straight into the framework's compliance reporting.
- IRDAI. Insurers operate under cybersecurity guidelines that include regular testing of internet-facing systems.
What the DPDP Act changes
The DPDP Act 2023 requires data fiduciaries to take reasonable security safeguards to prevent personal data breaches (Section 8(5)). The Act is in force and its rules are still being finalized, which means organizations are being measured against the law's expectations before the rulebook is complete.
For VAPT scoping, the effect is direct: any system that processes personal data of Indian residents is now in scope for a security review, whether or not a sector regulator already mandates it. Data fiduciaries should be able to show a documented testing cycle, findings registered with risk treatment decisions, and remediation verified by retest.
The payments angle
India's digital payments ecosystem puts fintechs and payment processors under a tighter lens. Card payments carry PCI DSS obligations, and payment aggregators and issuers sit under RBI expectations that include periodic security testing. If you handle card data, a PCI ASV scan and a manual penetration test are different exercises with different outputs; make sure the engagement you buy is the one your requirement calls for.
What a VAPT for the Indian market involves
The technical work is the same as anywhere: web, API, mobile, and network testing with manual validation on top of scanning. Our web app pentest walkthrough and API checklist describe the methodology in detail.
The difference is the evidence trail. Indian regulators and enterprise buyers look for a report that names the scope, the tester's independence, the methodology, and the remediation status of every finding. They also expect the loop to close: findings go into a risk register, treatment decisions are recorded, and the retest confirms fixes.
Data residency also matters. Confirm where test evidence, reports, and any extracted test data are stored, and cover it in the NDA before the engagement starts.
Choosing a provider for India engagements
- CERT-In empanelment if you serve government, PSU, or defense-linked clients.
- Sector experience with the RBI, SEBI, or IRDAI frameworks relevant to your business.
- Reporting format that a regulator or auditor can act on, with reproduction steps and CVSS 3.1 scoring.
- A retest policy so the engagement does not end with open findings.
- Delivery model that fits: most web, API, and network testing is delivered remotely within a documented testing window, which keeps costs down without changing the depth.
Takeaways
- Map your sector regulator's expectation first; the RBI, SEBI, and IRDAI all have defined testing expectations.
- The DPDP Act makes security safeguards a legal obligation, not an option, and scope now includes personal-data processing systems.
- If you are breached, CERT-In reporting timelines start ticking within six hours of detection; know the process before you need it.
- Document the full cycle: scope, method, findings, treatment, retest.
- If you handle card data, confirm whether you need a PCI ASV scan or a manual pentest; they are different.
NIMR's web, API, and network VAPT services are aligned with ISO 27001, NIST, and GDPR controls and serve clients across India and the Middle East. Request an assessment, or compare budgets with our penetration testing cost guidance.