The National Stock Exchange (NSE) on April 30, 2026, notified regarding the Periodic submission of System, Cyber, and VAPT Audit by Application Service Provider (ASP).
The following has been stated:
• The circular mandates that empaneled ASP vendors of the exchange shall conduct annual System Audit, Cyber Security Audit, and VAPT (Vulnerability Assessment & Penetration Testing) for their platforms (especially Non-NEAT Frontend/NNF systems) to strengthen cybersecurity and resilience against cyber threats.
• All audits are to be conducted for the period April 1 to March 31, with the preliminary audit report due by June 30 and the Action Taken Report (ATR) by September 30. Vendors shall appoint auditors as per prescribed selection norms and follow detailed formats, declarations, and Terms of Reference (TOR) provided in annexures for each audit type.
• Additionally, audit reports shall be approved by senior management (MD/Director/CTO/CISO) before submission. The framework ensures standardized audit procedures, accountability, and stronger security controls across ASP platforms in the securities market.
[Notification no. - NSE/INSP/74021]