The National Stock Exchange (NSE) on March 05, 2026, issued the Formats for submission of System Audit report and Vulnerability Assessment and Penetration Testing (VAPT) report for Vendors providing Colocation as a Service (CaaS) facility.
The following has been stated:
• It has mandated vendors providing Colocation as a Service (CaaS) to submit System Audit Reports and Vulnerability Assessment and Penetration Testing (VAPT) Reports in standardized formats.
• The reports shall be submitted half-yearly for the audit periods April–September and October–March within specified timelines. The circular also prescribes detailed formats for preliminary audit reports, action taken reports, and VAPT summary reports, along with auditor selection norms. System auditors must have relevant certifications such as CISA, DISA, CISM, or CISSP, while VAPT auditors shall be CERT-In empanelled. The reports shall be approved by the vendor’s MD/CTO/CISO or technology committee before submission.
• The circular further introduces penalties for delayed or non-submission of reports and for failure to close identified vulnerabilities, including daily monetary charges and restrictions on onboarding new members.
[Notification no. - NSE/MSD/73152]