The National Securities Depository Limited (NSDL), on April 27, 2026, issued a circular notifying amendments to its Business Rules, specifically Rule 18.1.1, concerning the penalty structure for failure or delay in submission of Vulnerability Assessment and Penetration Testing (VAPT) reports.
The revised provisions, detailed in Annexure A, aim to strengthen compliance and ensure timely submission of cybersecurity assessment reports by participants.
All participants are advised to take note of the amended penalty framework and ensure adherence to the updated requirements.
[Circular No. NSDL/POLICY/2026/0063]