RBI's cybersecurity requirements for regulated financial entities have evolved significantly since the original 2016 circular. The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, issued in April 2024, consolidated and tightened those requirements into a single binding document. Understanding what it actually requires — as opposed to what organisations typically do to satisfy an audit — is the difference between genuine security and an expensive compliance theatre exercise.
What the 2016 circular established
RBI's 2016 cybersecurity circular established the baseline: banks must implement a board-approved cybersecurity policy, conduct VAPT at least annually for critical systems, and report significant cyber incidents within a defined window. It was a starting point, not an endpoint. The circular identified the requirement but left significant discretion in implementation, which meant that in practice, many regulated entities ran minimal annual assessments against a narrow subset of systems and called the obligation met.
What the Master Direction changed
The April 2024 Master Direction is more prescriptive. It specifies that VAPT must cover all internet-facing systems, not just those defined as critical by the entity itself. It requires that remediation be verified — not just reported — through re-testing. It sets requirements for the qualification of testing entities. And it embeds the testing requirement within a broader IT governance framework that includes board-level reporting of cybersecurity posture, not just incident reporting.
The test-fix-retest problem
The most practically significant change in the Master Direction is the re-testing requirement. Traditional VAPT engagements deliver a report and close. The remediation work happens separately, on a different timeline, often by a different team. Whether the remediation was effective is rarely verified by the original testers — it is self-certified by the development or operations team and reported to the auditor as complete.
The Master Direction requires verification. That means the testing entity must confirm that identified vulnerabilities have been remediated before the engagement can be considered closed for compliance purposes. For a traditional engagement with a six-week delivery timeline, adding re-testing at the end extends the cycle to four or five months. At the scale of a bank with forty-plus internet-facing applications, running that cycle across all of them is operationally and financially unsustainable at human scale.
What the economics of compliance actually look like
A mid-sized bank running traditional VAPT across its internet-facing application estate can expect to spend ₹5 to 50 lakh per engagement, depending on scope and the vendor's day rates. At quarterly frequency across all systems in scope, this becomes a programme of ₹50 lakh or more annually — before the cost of remediation, re-testing, and the internal security team time required to manage the process.
The compliance cost is not the only concern. The lag time is. A traditional engagement takes two to six weeks from kick-off to report delivery. Remediation takes eight to twelve weeks. Re-testing, if it happens at all, adds another two to four weeks. By the time the cycle completes, the environment has changed, new code has been deployed, and the report is already stale. The organisation has spent significant money on an assessment that accurately described the environment four months ago.
The structural answer
The Master Direction's requirements — comprehensive scope, verified remediation, board-level reporting, on-premise handling of vulnerability data — describe a programme that is structurally difficult to run at human scale with traditional VAPT vendors. The frequency, coverage, and verification requirements are achievable, but only if the testing process is substantially faster than the traditional six-week engagement model.
Automated and agentic testing platforms address the economics. A platform that completes a full assessment in hours rather than weeks, generates machine-readable findings that map directly to the Master Direction's reporting requirements, and can be deployed entirely on-premise satisfies the compliance requirement at a fraction of the cost and timeline of traditional engagement-based approaches. The re-testing requirement, which is the most operationally expensive part of the Master Direction's mandate, becomes trivial when the test itself can be re-run in hours.
Close your security gaps — continuously.
Arxiis runs entirely on-premise, satisfying RBI's data localisation requirements while delivering VAPT-equivalent assessments in hours. Every finding maps directly to RBI CSF, CERT-In, and nine more frameworks. Re-testing after remediation takes hours, not months.