BSE notice 20260515-23 · 15 May 2026
Official title
Periodic submission of System, Cyber, and VAPT Audit by Application Service Provider (ASP)
Official record
Open source pageSummary
Check the official recordRegistered Application Service Providers of the Exchange must conduct annual system audits, cyber security audits, and Vulnerability Assessment and Penetration Testing for their platforms. These audits cover the period from 1 April to 31 March. Providers must submit audit reports by 30 June each year. Providers must submit any applicable Action Taken Reports by 30 September. The Managing Director, Director, Chief Technology Officer, or Chief Information Security Officer must approve all reports before submission. Providers must follow specific guidelines and formats provided in the annexures for auditor selection, reporting, and terms of reference.
What you must do
Who is affected
[Image omitted. See the official document.]
| Notice No. | 20260515-23 |
|---|---|
| Notice Date | 15 May 2026 |
| Category | Trading |
| Segment | General |
| Department | Trading Operations |
| Subject | Periodic submission of System, Cyber, and VAPT Audit by Application Service Provider (ASP) |
| Attachments | Annexures |
[Image omitted. See the official document.]
Registered ASPs of the Exchange are required to conduct periodic system audit of the Non-Exchange Trading Frontend and security controls built in their ASP platform.
In order to strengthen the cybersecurity measures in securities market and to ensure adequate cyber resilience against cybersecurity incidents/attacks, registered ASP vendors are also required to conduct periodic Cyber Security Audit & Vulnerability Assessment and Penetration Testing (VAPT) assessment audit on yearly basis for cyber security related controls built in their ASP platform.
The schedule for periodic submission of audit report and action taken report for system, cyber and VAPT audit are given in the below table:
| Sr. No. | Report Type | Audit Period | Schedule for submission of Audit Report | Action Taken Report (If Applicable) |
|---|---|---|---|---|
| 1 | System Audit Report | 01st April to 31st March | On or before 30th June | On or before 30th September |
| 2 | Cyber Audit Report | 01st April to 31st March | On or before 30th June | On or before 30th September |
| 3 | VAPT Report | 01st April to 31st March | On or before 30th June | On or before 30th September |
In view of the above, ASP vendors are advised to take note of following guidelines for the conduct of System Audit, Cyber Audit and VAPT assessment.
| Sr. No. | Particulars | Reference Annexures |
|---|---|---|
| 1 | Guideline for selecting Auditors for System Audit, Cyber Audit & VAPT | Annexure - A |
| 2 | Format for System Audit & Cyber Audit report & ATR | Annexure - B & Annexure - C |
| 3 | Formats of Declaration from Auditor, Assessment Details (scope), VAPT Audit report/Summary, in accordance with SEBI CSCRF | Annexure - D & Annexure - E |
| 4 | For System audit, Terms of Reference (TOR) of system audit | Annexure - F |
| 5 | For conduct of Cyber audit, Terms of Reference (TOR) of Cyber Audit | Annexure - G |
Additionally, ASP Vendors are required to submit the System audit, Cyber audit & VAPT audit report after approval by Managing Director/Director/CTO or CISO.
[Image omitted. See the official document.]
Enclosures:
Annexure A – Auditor selection Norms
Annexure B – System audit report format
Annexure C – Cyber audit report format
Annexure D – Auditor’s declaration – VAPT Scope
Annexure E – Format for VAPT Summary report
Annexure F – Terms of Reference (TOR) applicable for System Audit
Annexure G – Terms of Reference (TOR) applicable for Cyber Audit
For further information and clarification, participants may contact the Exchange as follows:
| Email Id: | trading.app@bseindia.com mscopr@bseindia.com |
|---|---|
| Contact Details: | 022-22725116/5873/8926/5376 022-69158540/022-45720640/022-45720440 |
For and on behalf of BSE Ltd.
Richa Ghosh Deputy Vice President Member Oversight
Vinod Ibrampurkar Deputy Vice President Trading Operations