Annual Pentest vs Monthly BAS: What RBI Actually Requires

Pawan Sharma Published 06 Oct 2026  ·  By Pawan Sharma  ·  Compliance  ·  9 min read

RBI's new cyber Directions of 31 July 2026 set the testing floor for banks at a vulnerability assessment every six months and a penetration test every twelve. Many teams read that as the target. It's a minimum — and it leaves most of the year in which nobody checks whether your defences still work. Here's what the clauses actually say, what changed in 2026, and where breach-and-attack simulation (BAS) fits alongside the pentest you're already paying for.

Vulnerability assessment

6 months

Critical and customer-facing DMZ systems

Penetration test

12 months

Same scope, independent experts

Incident reporting

6 hours

On RBI's DAKSH platform, plus CERT-In

Findings to committees

Quarterly

Closure status to ITSC and ISC

What the Directions say about testing

RBI issued seven Directions on the same day, one for each type of regulated entity. The clause numbers below are from the one for commercial banks; the small finance bank, payments bank, AIFI and credit information company versions follow the same pattern.

“For critical information systems and / or those in the DMZ having customer interface, VA shall be conducted at least once in every six months and PT at least once in 12 months.”Commercial Banks Directions 2026, para 151
RequirementParaWhat it means in practice
Scope149All critical and internet-facing systems.
Test after changes150Testing before go-live, after go-live and after changes — not just on the calendar.
Test in production152Post-implementation testing runs on production; testing elsewhere needs the Information Security Committee's approval.
Fix in time153“Time-bound” remediation. RBI sets no number of days, so your own policy has to.
Who tests155“Appropriately trained and independent” experts or auditors. CERT-In empanelment isn't mandated; para 159 only covers how to work with empanelled auditors if you use them.
Auditor accountability158A later breach through a weakness the tester missed counts as the auditor's deficiency.
Report closure161Status of findings to the IT Strategy Committee and Information Security Committee at least quarterly.
Red teaming162Optional (“may”): simulate an attacker to check whether defences and controls actually work.
NBFCs and urban co-operative banks differ. NBFCs in the Middle Layer and above have the same six-month VA and twelve-month PT rule (NBFC Directions, para 121). UCBs must do VA every six months and PT “at least once in a year”, by “professionally qualified teams” (paras 116 and 119). Neither text has a red-teaming clause.

What's actually new in 2026 (and what isn't)

The testing frequency isn't new. RBI's 2023 Master Direction on IT governance already required VA every six months and PT every twelve for the same systems. If a vendor tells you the six-month rule arrived this year, check the rest of their advice too.

What is new is everything around the tests:

  • A 24x7 security operations centre for banks, with round-the-clock monitoring (paras 143, 221 and 223), in-house or managed.
  • A six-hour reporting clock on RBI's DAKSH platform, plus notifying CERT-In (para 182).
  • Testers on the hook for what they miss (para 158).
  • An explicit invitation to test whether defences work — the optional red-teaming clause (para 162).

Read together, the direction of travel is clear: RBI cares less about whether you ran a scan and more about whether you'd actually catch and contain an attack. For the background on the rest of the Directions, see our full guide to the 2026 Directions.

The gap between pentests

An annual pentest is a snapshot. It tells you what a skilled tester could do during a week or two in, say, March. By June your environment has changed: new applications, firewall rule changes, an EDR policy someone relaxed to fix a false positive, a SOC rule that stopped firing after a log source moved. Para 150 asks you to test after changes, but very few teams commission a pentest every time a rule changes.

The six-monthly VA doesn't close that gap either. A vulnerability scan finds missing patches and misconfigurations. It doesn't tell you whether your EDR blocks credential dumping, whether your SOC raises an alert when someone moves laterally, or whether data could leave through DNS. Those are exactly the questions a 24x7 SOC mandate implies you can answer.

Pentest, VA and BAS: different jobs

Vulnerability assessmentPenetration testBreach-and-attack simulation
Question it answersWhat's unpatched or misconfigured?Can a skilled attacker get in and how far?Do our controls and SOC detect and stop known attacker techniques?
HowAutomated scanningHuman testers, creative and targetedAutomated, repeatable attacker behaviour mapped to MITRE ATT&CK
How oftenRBI minimum: 6 monthsRBI minimum: 12 monthsAs often as you like — monthly, and after major changes
Satisfies para 151?Yes, for VAYes, for PTNo — it complements, it doesn't replace
Best evidence forPatch hygieneExploitable pathsControl effectiveness and SOC detection (paras 143, 150, 162)

Be clear about the last-but-one row. BAS does not replace the pentest or the VA RBI requires. Its value is in the months between them, and in evidence the pentest report doesn't give you: proof that a given technique was blocked or detected on a given date, run again after every significant change.

A testing programme that uses all three

A practical annual calendar for a bank or upper-layer NBFC

  1. Month 1: independent pentest of critical and customer-facing systems (para 151). Fix findings on a dated plan (para 153).
  2. Months 1 and 7: vulnerability assessments, same scope.
  3. Every month: a BAS run against the attacker behaviour that matters to Indian BFSI — phishing payloads, credential theft, lateral movement, ransomware precursors, data exfiltration. Feed every miss to the SOC as a detection-engineering ticket.
  4. After every major change (new app, firewall or EDR policy change, SOC rule change): a targeted BAS re-run, so para 150 is met with evidence rather than a promise.
  5. Every quarter: one page to the ITSC and ISC (para 161) — VA/PT findings closed, and the BAS trend: techniques blocked, detected, missed.
  6. Once a year, optionally: a red-team exercise (para 162) for entities ready for it.

Three things to get right

  • Run BAS safely in production. Para 152 expects production testing; use benign payloads, agree a window with the SOC, and start on a few representative hosts.
  • Keep the pentester independent. Para 155 wants independent experts, and para 158 makes them accountable. Don't let the team that runs your security also mark its own pentest.
  • Measure detection, not just prevention. A technique your EDR blocks silently, with no SOC alert, is still a gap in a 24x7 monitoring model.
Breach-and-attack simulation

See what your controls actually catch

Ogma's self-service BAS platform runs MITRE ATT&CK-mapped adversary profiles inside your network from a lightweight agent and gives you a report of what was blocked, what was detected and what got through. New accounts start with free credits. Need the pentest and VA too? We do those as well.

Try BAS free VAPT services or call +91 80 0979 0979

Related: RBI 2026 Cybersecurity Directions guide · Why Indian banks need BAS · Breach-and-attack simulation · VAPT in India

Sources: RBI (Commercial Banks / Small Finance Banks / Payments Banks / UCB / AIFI / NBFC / CIC – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, dated 31 July 2026, as updated 1 October 2026; RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 7 November 2023. Paragraph numbers refer to the Commercial Banks Directions unless stated. This post is guidance, not legal advice.

Stay ahead of cyber threats

One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.


Cato Firewall as a Service
Cato ZTNA — Zero Trust Network Access
Cato SASE Solution