DeepScience Tech delivers CERT-In empanelled VAPT services for organisations mandated by SEBI, RBI, MeitY, IRDAI, NABH, and PCI DSS. Detailed CVSS-scored reports and regulatory submission certificates included.
RBI IT Framework mandates annual VAPT for all banks and NBFCs. SEBI CSCRF requires VAPT for market intermediaries. IRDAI mandates annual security audits for insurers.
ABDM-connected hospitals must pass security audits before joining the Health Information Exchange. NABH accreditation requires documented security controls and periodic assessments.
Government websites and e-governance portals must be STQC/CERT-In audited before go-live. Critical infrastructure operators have mandatory VAPT requirements.
Any organisation processing, storing, or transmitting cardholder data must maintain PCI DSS compliance — requiring annual penetration testing and quarterly vulnerability scans.
SEBI-regulated fintech platforms, IRDAI-licensed insurtechs, and MeitY-recognised startups have progressive VAPT requirements based on data sensitivity and transaction volumes.
Power sector (CEA guidelines), telecom (DOT regulations), and oil & gas (PNGRB) — all have sector-specific cyber security audit requirements with CERT-In empanelled firms.
OWASP Top 10, API security, authentication, authorisation, session management, input validation, and business logic vulnerabilities. Most common for SEBI and RBI mandates.
External perimeter assessment, internal network segmentation, firewall rule review, open port analysis, VPN security, and wireless network security.
iOS and Android security — OWASP Mobile Top 10, data storage, API security, binary analysis, and runtime manipulation. Required for banking and fintech apps.
AWS, OCI, Azure, GCP security assessment against cloud security benchmarks — IAM review, storage exposure, and network security groups.
REST/GraphQL/SOAP API testing — authentication, authorisation (BOLA/BFLA), injection, rate limiting, and sensitive data exposure. Essential for UPI and open banking.
HIMS, EMR, LIMS, and medical device security aligned to ABDM security guidelines, HIPAA-adjacent controls, and NABH documentation requirements.
Tell us your regulatory requirement (RBI, SEBI, CERT-In, NABH, PCI DSS) and we'll scope the right engagement within 24 hours.