Annual Pentest vs Monthly BAS: What RBI Actually Requires
RBI's new cyber Directions of 31 July 2026 set the testing floor for banks at a vulnerability assessment every six months and a penetration test every twelve. Many teams read that as the target. It's a minimum — and it leaves most of the year in which nobody checks whether your defences still work. Here's what the clauses actually say, what changed in 2026, and where breach-and-attack simulation (BAS) fits alongside the pentest you're already paying for.
Vulnerability assessment
6 months
Critical and customer-facing DMZ systems
Penetration test
12 months
Same scope, independent experts
Incident reporting
6 hours
On RBI's DAKSH platform, plus CERT-In
Findings to committees
Quarterly
Closure status to ITSC and ISC
What the Directions say about testing
RBI issued seven Directions on the same day, one for each type of regulated entity. The clause numbers below are from the one for commercial banks; the small finance bank, payments bank, AIFI and credit information company versions follow the same pattern.
| Requirement | Para | What it means in practice |
|---|---|---|
| Scope | 149 | All critical and internet-facing systems. |
| Test after changes | 150 | Testing before go-live, after go-live and after changes — not just on the calendar. |
| Test in production | 152 | Post-implementation testing runs on production; testing elsewhere needs the Information Security Committee's approval. |
| Fix in time | 153 | “Time-bound” remediation. RBI sets no number of days, so your own policy has to. |
| Who tests | 155 | “Appropriately trained and independent” experts or auditors. CERT-In empanelment isn't mandated; para 159 only covers how to work with empanelled auditors if you use them. |
| Auditor accountability | 158 | A later breach through a weakness the tester missed counts as the auditor's deficiency. |
| Report closure | 161 | Status of findings to the IT Strategy Committee and Information Security Committee at least quarterly. |
| Red teaming | 162 | Optional (“may”): simulate an attacker to check whether defences and controls actually work. |
What's actually new in 2026 (and what isn't)
The testing frequency isn't new. RBI's 2023 Master Direction on IT governance already required VA every six months and PT every twelve for the same systems. If a vendor tells you the six-month rule arrived this year, check the rest of their advice too.
What is new is everything around the tests:
- A 24x7 security operations centre for banks, with round-the-clock monitoring (paras 143, 221 and 223), in-house or managed.
- A six-hour reporting clock on RBI's DAKSH platform, plus notifying CERT-In (para 182).
- Testers on the hook for what they miss (para 158).
- An explicit invitation to test whether defences work — the optional red-teaming clause (para 162).
Read together, the direction of travel is clear: RBI cares less about whether you ran a scan and more about whether you'd actually catch and contain an attack. For the background on the rest of the Directions, see our full guide to the 2026 Directions.
The gap between pentests
An annual pentest is a snapshot. It tells you what a skilled tester could do during a week or two in, say, March. By June your environment has changed: new applications, firewall rule changes, an EDR policy someone relaxed to fix a false positive, a SOC rule that stopped firing after a log source moved. Para 150 asks you to test after changes, but very few teams commission a pentest every time a rule changes.
The six-monthly VA doesn't close that gap either. A vulnerability scan finds missing patches and misconfigurations. It doesn't tell you whether your EDR blocks credential dumping, whether your SOC raises an alert when someone moves laterally, or whether data could leave through DNS. Those are exactly the questions a 24x7 SOC mandate implies you can answer.
Pentest, VA and BAS: different jobs
| Vulnerability assessment | Penetration test | Breach-and-attack simulation | |
|---|---|---|---|
| Question it answers | What's unpatched or misconfigured? | Can a skilled attacker get in and how far? | Do our controls and SOC detect and stop known attacker techniques? |
| How | Automated scanning | Human testers, creative and targeted | Automated, repeatable attacker behaviour mapped to MITRE ATT&CK |
| How often | RBI minimum: 6 months | RBI minimum: 12 months | As often as you like — monthly, and after major changes |
| Satisfies para 151? | Yes, for VA | Yes, for PT | No — it complements, it doesn't replace |
| Best evidence for | Patch hygiene | Exploitable paths | Control effectiveness and SOC detection (paras 143, 150, 162) |
Be clear about the last-but-one row. BAS does not replace the pentest or the VA RBI requires. Its value is in the months between them, and in evidence the pentest report doesn't give you: proof that a given technique was blocked or detected on a given date, run again after every significant change.
A testing programme that uses all three
A practical annual calendar for a bank or upper-layer NBFC
- Month 1: independent pentest of critical and customer-facing systems (para 151). Fix findings on a dated plan (para 153).
- Months 1 and 7: vulnerability assessments, same scope.
- Every month: a BAS run against the attacker behaviour that matters to Indian BFSI — phishing payloads, credential theft, lateral movement, ransomware precursors, data exfiltration. Feed every miss to the SOC as a detection-engineering ticket.
- After every major change (new app, firewall or EDR policy change, SOC rule change): a targeted BAS re-run, so para 150 is met with evidence rather than a promise.
- Every quarter: one page to the ITSC and ISC (para 161) — VA/PT findings closed, and the BAS trend: techniques blocked, detected, missed.
- Once a year, optionally: a red-team exercise (para 162) for entities ready for it.
Three things to get right
- Run BAS safely in production. Para 152 expects production testing; use benign payloads, agree a window with the SOC, and start on a few representative hosts.
- Keep the pentester independent. Para 155 wants independent experts, and para 158 makes them accountable. Don't let the team that runs your security also mark its own pentest.
- Measure detection, not just prevention. A technique your EDR blocks silently, with no SOC alert, is still a gap in a 24x7 monitoring model.
See what your controls actually catch
Ogma's self-service BAS platform runs MITRE ATT&CK-mapped adversary profiles inside your network from a lightweight agent and gives you a report of what was blocked, what was detected and what got through. New accounts start with free credits. Need the pentest and VA too? We do those as well.
Try BAS free VAPT services or call +91 80 0979 0979Related: RBI 2026 Cybersecurity Directions guide · Why Indian banks need BAS · Breach-and-attack simulation · VAPT in India
Sources: RBI (Commercial Banks / Small Finance Banks / Payments Banks / UCB / AIFI / NBFC / CIC – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, dated 31 July 2026, as updated 1 October 2026; RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 7 November 2023. Paragraph numbers refer to the Commercial Banks Directions unless stated. This post is guidance, not legal advice.
Stay ahead of cyber threats
One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.