// INDIAN REGULATORY COMPLIANCE

BSE / NSE Cybersecurity Audit

Cybersecurity audit for listed companies and intermediaries meeting BSE and NSE exchange mandates.

BSE & NSECirculars
AnnualCertification
CERT-InEmpanelled
TradingInfrastructure

BSE / NSE Exchange Cybersecurity Audit

The Bombay Stock Exchange (BSE) and National Stock Exchange (NSE) have issued circulars mandating annual cybersecurity audits for listed companies, trading members, and depository participants. These exchange-level mandates operate alongside SEBI CSCRF requirements and require entities to submit a cybersecurity compliance certification to the exchange annually — signed by the entity's Board and supported by an independent audit from a CERT-In empanelled organisation.

Intelliroot conducts BSE/NSE exchange-mandated cybersecurity audits covering all prescribed control domains — from network security of trading infrastructure and algo trading security controls to endpoint protection across trading terminals and co-location security arrangements. Our audit report satisfies the requirements of both BSE and NSE circulars simultaneously, reducing audit fatigue for organisations listed on both exchanges.

BSE Circular 2021 NSE Circular SEBI CSCRF CERT-In Empanelled

Why Exchange Cybersecurity Compliance Matters

Exchange Listing Obligation

Failure to submit the annual cybersecurity compliance certification to BSE/NSE is a breach of listing obligations. Exchanges can impose penalties, issue public notices, and escalate non-compliant entities to SEBI — creating both regulatory and reputational risk.

Trading Infrastructure Is Mission-Critical

A cyberattack that disrupts trading systems, order management, or market data feeds can result in trading halts, financial losses, and regulatory investigations. Exchange audit circulars specifically target the controls protecting this critical infrastructure.

Algo Trading Requires Specialist Controls

Algorithmic trading introduces unique security risks — unauthorised algo deployment, parameter manipulation, and runaway algorithms. Exchange circulars require specific controls around algo testing, deployment, and monitoring that generic IS audits do not cover.

Co-Location Security Obligations

Trading members using co-location services at BSE or NSE are subject to specific security requirements for co-location environments. Non-compliance with co-location security obligations can result in suspension of co-location services.

What the Exchange Audit Covers

Trading Infrastructure Security

  • Order management system and matching engine connectivity
  • Market data feed integrity and access controls
  • Network segmentation for trading infrastructure
  • Co-location environment security review

Algo Trading Controls

  • Algo testing and deployment authorisation process
  • Algo parameter change control and monitoring
  • Kill switch and circuit breaker effectiveness
  • Unauthorised algo detection capabilities

Endpoint & Access Security

  • Endpoint protection for trading terminals
  • Privileged access to trading systems
  • Trader workstation security configuration
  • Remote access security for trading staff

Governance & Compliance Reporting

  • Exchange circular compliance gap assessment
  • Incident reporting obligations to exchanges
  • Annual compliance certification preparation
  • Board-level attestation documentation

Our BSE / NSE Audit Approach

01

Circular Mapping & Scoping

Map the applicable BSE and NSE circular requirements to the entity's specific profile (listed company, trading member, depository participant). Define the audit scope — including trading systems, algo frameworks, terminals, and co-location arrangements.

02

Document & Policy Review

Review IS policies, trading system security procedures, algo governance documentation, BCP/DR plans, and exchange correspondence. Identify documentation gaps that would fail exchange inspection.

03

Technical Security Assessment

Conduct targeted VAPT of trading infrastructure, configuration review of order management and market data systems, endpoint security assessment of trading terminals, and security review of algo deployment pipelines.

04

Compliance Verification & Gap Analysis

Map all findings to specific BSE/NSE circular requirements. Classify gaps by severity and compliance impact. Identify any findings that must be remediated before the annual compliance certification can be submitted.

05

Compliance Certification & Report Issuance

Issue the exchange-mandated cybersecurity audit report signed by the CERT-In empanelled auditor. Prepare the annual compliance certification for Board attestation and exchange submission. Deliver remediation roadmap for outstanding gaps.

BSE Circular NSE Circular Listed Companies Trading Members Algo Trading Co-Location Security Trading Infrastructure SEBI CSCRF CERT-In Empanelled

Frequently Asked Questions

Both BSE and NSE circulars cover listed entities (companies listed on the exchange), trading members (registered brokers with exchange membership), and depository participants. The specific control requirements may vary by entity category and size. Our scoping process identifies the precise requirements applicable to your entity type.
No. Intelliroot conducts a single consolidated audit that satisfies the requirements of both BSE and NSE circulars simultaneously. We prepare separate compliance certifications for each exchange where required, but the underlying audit and technical assessment covers both sets of requirements in one engagement — significantly reducing cost and audit fatigue.
There is significant overlap. Both SEBI CSCRF and exchange circulars require cybersecurity controls for capital market participants. We offer a bundled CSCRF + Exchange Audit engagement that eliminates duplication between the two programmes, reusing evidence and assessments where the requirements overlap while ensuring both sets of compliance obligations are fully met.
Deadlines vary by exchange and entity type and are specified in the applicable circular. BSE and NSE typically require annual submissions within a defined period after the financial year end. We track these deadlines for our clients and initiate the audit engagement well in advance to avoid last-minute certification pressure.

Deliverables

Exchange Cybersecurity Audit Report

Full cybersecurity audit report signed by CERT-In empanelled auditor, structured to satisfy both BSE and NSE circular requirements simultaneously.

Annual Compliance Certification

Exchange-mandated annual compliance certification prepared for Board attestation and submission to BSE and NSE — formatted to each exchange's required template.

Control Gap Register

Risk-rated gap register mapping findings to specific BSE/NSE circular requirements, with evidence references and remediation recommendations.

Trading Infrastructure Security Report

Technical findings from the VAPT and configuration review of trading systems, order management, co-location, and algo trading infrastructure.

Remediation Roadmap

Prioritised remediation plan for outstanding compliance gaps, with effort estimates and implementation guidance aligned to the next exchange compliance submission deadline.

GET STARTED
Accepting New Engagements · 24h Response

Request a Security Assessment

Tell us about your environment and security objectives. We'll design a bespoke assessment and deliver a detailed proposal within 48 hours.

Scoping Call with a Certified Consultant 45-minute deep-dive with a senior practitioner — no sales pitch.
Proposal Delivered in 48 Hours Fully scoped engagement plan with pricing and timeline.
Free Attack Surface Analysis Preliminary external exposure report at no cost.
Fully Confidential. NDA Available. No obligation. Your data is never shared.
200+ Engagements
40+ Services
98% Satisfaction
CERT-In Empanelled ISO 27001 OSCP · CEH · CISSP
1
You
2
Service
3
Details

About You

We'll use this to route you to the right expert.

What Do You Need?

Select all that apply — you can pick multiple.

Select at least one area to continue.

Final Details

Optional context to help us scope your engagement.

By submitting, you agree to our Privacy Policy. We'll never share your data.