CERT-In gives you six hours to report an incident. Your penetration test happens once a year. Both of those facts are true at the same time.

That is the whole problem in two lines. Regulators have tightened the clock on everything that happens after a breach, and left the clock on everything that happens before one roughly where it was a decade ago. Teams optimise for the visible deadline and quietly carry the invisible one.

Then 2026 happened. On 31 July 2026 the Reserve Bank of India issued new Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions across seven categories of regulated entity at once: commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies. The older IT Framework instructions stand repealed.

The cadence numbers did not move. Vulnerability assessment stayed at half yearly. Penetration testing stayed at annual. What moved was everything around them: board accountability, a consolidated assurance framework, and a six hour DAKSH reporting clock. The floor is the same. The scrutiny is not.

The frameworks never actually said annual

Read the clauses side by side and something obvious appears. Not one framework says "test once a year and stop".

PCI DSS says penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change. It also says exploitable vulnerabilities must be corrected and the test repeated to verify the correction. Retesting is not a nice-to-have in PCI. It is requirement 11.4.4.

RBI's 2026 directions require testing on the production environment after implementation, and remediation in a time-bound manner. SEBI CSCRF puts a three-month closure clock on VAPT observations and a one-week timeline on high-severity patch-related fixes. DORA Article 26(2) requires threat-led penetration testing to be performed on live production systems, which quietly kills the staging environment excuse.

132/day
New CVEs published on average in 2025 (48,185 total, up 20.6%)
−7 days
Mean time to exploit, 2025 (Mandiant) — before public disclosure
43 days
Median time to fully remediate a known exploited vulnerability (Verizon 2026)
The calendar is the floor for a system that never changes. Nobody has one of those.

What happens in the gap

Say you test quarterly. You are in the top band already. Cobalt's data shows quarterly is the most common cadence at 30 percent, and 27 percent of organisations still test annually. So quarterly puts you ahead of most peers.

Now count what happens in those 91 days. 48,185 CVEs were published in 2025, up 20.6 percent, which is roughly 132 a day. VulnCheck recorded 884 known exploited vulnerabilities first seen exploited in 2025, and found that 28.96 percent were exploited on or before the day their CVE was published. Mandiant now estimates mean time to exploit at minus seven days. Exploitation is arriving before disclosure.

Meanwhile remediation is getting worse, not better. The 2026 Verizon DBIR found only 26 percent of CISA known exploited vulnerabilities were fully remediated, down from 38 percent, and the median time to full remediation stretched to 43 days from 32.

So the gap is widening from both ends. Vulnerabilities are being exploited faster and fixed slower. A test cadence measured in months is being asked to cover a threat cycle measured in days.

Your app does not wait for the test date

There is a second gap, and it is the one nobody puts in the compliance spreadsheet. The calendar gap assumes your application sits still between tests. It does not.

DORA's 2025 State of DevOps research found that AI-assisted development improves delivery throughput while showing a negative relationship with delivery stability. Teams are shipping faster and breaking things slightly more often. A team deploying daily ships roughly 65 changes across a 90-day quarter, and around 260 across a PCI annual cycle. Each of those is a chance to open something the last test proved closed.

PCI DSS 11.4.4 already says this. Exploitable vulnerabilities must be corrected and the test repeated to verify the correction. That retest clause is not optional. Most programmes treat it as one, because it costs a separate engagement every time. Continuous validation makes it a default.

Continuous is the better evidence, not just the safer choice

ISO 27001:2022 and SOC 2 do not mandate a frequency at all. ISO Annex A 8.8 requires vulnerability information to be obtained promptly and acted on. SOC 2 criterion CC4.1 expects ongoing and separate evaluations, and names penetration testing directly. NIS2's implementing regulation goes further and asks entities to define and justify a testing frequency rather than handing them a number.

A dated PDF is the weakest possible way to demonstrate the word "ongoing". An auditor asking to show testing after your last major release, or the retest that proves the fix worked, or the state on an arbitrary date in the year — those questions have very different answers depending on whether you test continuously or annually.

Aim above the floor

Quarterly VAPT is a reasonable minimum in 2026. It is not a target. The frameworks that look strictest, like DORA with its three-year TLPT cycle, are strict precisely because that test is deep, adversarial and expensive. A three-year cadence only makes sense if something continuous sits underneath it.

Arxiis is built for that layer. An autonomous AI red team runs across 26 modules and 6 attack vectors, maps findings to MITRE ATT&CK, RBI and CERT-In, and re-earns a known-secure state every 24 hours. Your annual pentest still happens. It just stops being the only thing standing between two dates on a calendar.

Stop asking whether you are compliant. Ask whether you could prove it on any given Tuesday.

That is the question the 2026 rules are quietly moving towards. RBI made it a board conversation. SEBI put a clock on closure. DORA put testing on live production. The direction of travel is from an event to a state. The teams that get there first will find the audit gets easier, not harder.

Close your security gaps — continuously.

Arxiis is an autonomous AI penetration-testing platform that runs a coordinated crew of specialist agents through a full engagement in hours, not weeks — continuously, not annually. Every finding is CVSS-scored, MITRE ATT&CK-tagged, and auto-mapped to RBI CSF, CERT-In and nine more frameworks. It runs entirely on your own infrastructure. Nothing leaves the perimeter.