The Central Depository Services (India) Limited (CDSL) on March 05, 2026, notified regarding the submission of the Compliance of Closure of Findings Identified during VAPT.
It has advised Depository Participants (DPs) to comply with the Cybersecurity and Cyber Resilience Framework (CSCRF) issued by the Securities and Exchange Board of India (SEBI). DPs shall submit the closure compliance of findings identified during Vulnerability Assessment and Penetration Testing (VAPT) for the half-year period April 2025 to September 2025, applicable to Qualified Security-Based entities (QSBs) and Protected Regulated Entities (REs).
The VAPT Action Taken Report shall be submitted to CDSL on or before March 31, 2026, via the designated email.
[Notification no. - CDSL/OPS/DP/POLCY/2026/152]