CANBK NSE filing

Canara Bank Submits SEBI Cybersecurity Compliance Reports

The RealCase readLow impact Neutral

Canara Bank submitted SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) compliance reports. VAPT report identified 54 critical and 107 high vulnerabilities. Cyber audit confirmed compliance with SEBI guidelines. Bank plans to transition to Small Size RE category by transferring DP accounts to subsidiary.

Why it matters

The announcement pertains to regulatory compliance and cybersecurity audits, which are standard operational procedures for banks. While the identification of vulnerabilities is noted, there is no immediate indication of a significant impact on the bank's operations or financial performance.

The market read

The announcement is a routine compliance filing related to cybersecurity audits. While it details identified vulnerabilities, it also confirms the bank's ongoing efforts and plans to address them and comply with regulatory requirements, making the sentiment neutral.

Canara Bank has submitted Certificates of Compliance and Reports on the Securities Exchange Board of India - Cybersecurity and Cyber Resilience Framework (SEBI-CSCRF) as per SEBI Circular No. SEBI/HO/ITD-1/ITD CSC EXT/P/CIR/2024/113 dated August 20, 2024.

The Vulnerability Assessment and Penetration Testing (VAPT) report, conducted by M/s AKS IT Services Pvt. Ltd. for the period October 1, 2025, to November 17, 2025, identified critical vulnerabilities: 54 critical, 107 high, 5720 medium, and 594 low.

The Cyber Audit Report, conducted by M/s Control Case International Private Limited for the period September 8-12, 2025, found the bank compliant with various SEBI CSCRF guidelines across its DP Secure, CITOS, Kondor Plus, and ASBA applications. The report noted that the bank is exploring the implementation of an automated Cyber Capability Index (CCI) tool with a tentative timeline of March 31, 2026, and currently prepares the CCI report manually.

Canara Bank is classified as a Qualified Regulated Entity (Qualified RE) due to its Depository Participant (DP) registration. However, the bank plans to transfer its DP accounts to its subsidiary, CanBank Securities Limited (CBSL), which is in the process of obtaining a CDSL license. Upon successful transfer, Canara Bank will surrender its DP license and fall under the Small Size RE category.

All applicable reports, including the Cyber Audit Report, SOC Efficacy Report, and VAPT Report, are to be submitted to SEBI, NSE/BSE, and CDSL within December 2025, signed by the MD & CEO.

Filing to action

What to do with a filing like this

Canara Bank filed this with the NSE as a statutory disclosure, categorised under sebi compliance filings. It is a primary document, not a recommendation, and the desk marks it low impact, the band that almost never moves a portfolio on its own.

That call is the part a filing cannot make for you. On RealCase, SEBI-registered research analysts and investment advisers read announcements like this one and turn the ones that matter into actions inside their model portfolios: a change in weight, a hold, or nothing at all. You are not left working out which of the roughly 250 filings published each day needs a response. The portfolio you follow is updated when a filing actually warrants it, with the reason written down.

See the model portfolios
Primary source

A plain-language summary of a public exchange filing by Canara Bank. Read the original for the full detail.

View original filing