SEBI CSCRF Compliance: What Regulated Entities Must Know
Most regulated entities discovered SEBI's CSCRF the same way: an email from their designated Stock Exchange or Depository, forwarding a circular, with a compliance date already in the past. The panic that followed was less about the controls and more about a single word buried in the framework — auditability. SEBI did not just ask you to be secure. It asked you to prove it, on a schedule, in a format its examiners can read.
The Cyber Security and Cyber Resilience Framework — CSCRF — consolidated a decade of scattered SEBI cyber circulars into one document in August 2024. If you are a stockbroker, depository participant, mutual fund, KRA, RTA, portfolio manager or any of the twenty-two-odd regulated entity categories, this is now the ceiling and the floor of what SEBI expects. The trouble is that it borrowed heavily from NIST, wrapped it in SEBI's own maturity model, and then bolted on reporting timelines that catch most teams flat-footed.
Who actually falls under CSCRF, and to what depth
The first mistake teams make is assuming CSCRF applies uniformly. It does not. SEBI graded its regulated entities — REs, in the framework's language — into five categories, and the depth of obligation scales with that grade. A large stockbroker and a small research analyst do not carry the same load, and pretending otherwise wastes budget or, worse, leaves you exposed.
| RE category | Typical entities | Broad obligation |
|---|---|---|
| Market Infrastructure Institutions (MIIs) | Stock exchanges, depositories, clearing corporations | Full framework, SOC/C-SOC, VAPT, cyber audit, board oversight |
| Qualified REs | Large stockbrokers, DPs, AMCs above thresholds | Near-full framework, mandatory SOC access, periodic audit |
| Mid-size REs | Mid-tier brokers, RTAs, KRAs | Core controls, VAPT, scaled reporting |
| Small-size REs | Smaller brokers, PMs above minimum | Baseline controls, simplified compliance |
| Self-certification REs | Smallest brokers, research analysts, IAs | Self-certified baseline hygiene |
Your category is not something you choose. SEBI defines the thresholds — typically on number of clients, trading volume, or assets under management — and your exchange or depository will tell you where you sit. What you can control is how honestly you read the obligation that follows. A Qualified RE that self-assesses as Mid-size to dodge a SOC requirement is buying a finding, not saving money.
The framework SEBI actually built
CSCRF is organised around the NIST Cybersecurity Framework's functions, which SEBI calls Cyber Resilience Goals. If you have ever run a NIST assessment, the spine will feel familiar. What is different is that SEBI made each goal measurable through a Cyber Capability Index — CCI — and, for the larger REs, mandated a minimum maturity score you must hit and evidence.
| CSCRF goal (NIST function) | What it demands in practice | Common gap |
|---|---|---|
| Anticipate (Govern/Identify) | Asset inventory, risk assessment, third-party risk, board-approved policy | Stale asset registers, no vendor risk tiering |
| Withstand (Protect) | Access control, encryption, hardening, data localisation | Shared admin accounts, unencrypted backups |
| Contain (Detect) | SOC or C-SOC, log retention, monitoring of critical systems | No 24x7 monitoring, logs under 180 days |
| Recover (Respond/Recover) | Incident response plan, RTO/RPO, tested DR, backup restoration | IR plan never rehearsed, DR untested |
| Evolve (Improve) | Lessons learned, metrics, continuous improvement | Post-incident reviews not documented |
The CCI is where CSCRF stops being a checklist and becomes an audit instrument. SEBI publishes a scoring methodology across roughly two dozen parameters. MIIs must achieve and maintain a defined maturity band; Qualified REs a lower but still substantial one. Your auditor does not tick boxes — they score you, and that number goes to SEBI. Get it wrong by inflating your self-score and the gap between your claim and the auditor's finding becomes the story.
The SOC question that trips everyone
CSCRF requires larger REs to have Security Operations Centre coverage — either their own SOC, a shared C-SOC provided by an MII or an approved market SOC, or a managed SOC from an empanelled provider. The word most teams miss is continuous. A SOC that only reviews alerts during business hours does not meet Contain. SEBI's examiners ask for the shift roster, the mean time to detect, and the alerts closed over the last quarter. If your SOC is a dashboard nobody watches after 6pm, that surfaces immediately.
What the reporting clock really looks like
CSCRF's teeth are in its timelines. Two of them matter most, and confusing them is a classic error. Incident reporting to SEBI and to CERT-In are separate obligations with separate clocks. CERT-In's Directions of April 2022 require reporting of listed cyber incidents within six hours of detection. SEBI, through CSCRF, layers its own reporting to your exchange or depository on top.
The compliance date most commentary still gets wrong
Separate from the incident clocks is the date CSCRF itself became binding, and most write-ups still quote a superseded one. SEBI issued the framework by circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 on 20 August 2024, then moved the compliance date twice. Circular 2025/45 of 28 March 2025 pushed it out three months to 30 June 2025. Circular 2025/96 of 30 June 2025 pushed it a further two months to 31 August 2025. Both extensions applied to every regulated entity except Market Infrastructure Institutions, KYC Registration Agencies and Qualified RTAs, which stayed on the original timeline throughout.
That final date has passed. CSCRF is fully in force, which changes the question an examiner opens with: not whether you are ready, but what your evidence shows for the period since. Two extensions in a row taught a lot of firms to wait for a third. There was not one.
The most recent amendment is circular 2025/119 of 28 August 2025, and nothing has superseded it. It matters most if you answer to more than one regulator. It introduces a Principle of Exclusivity and a Principle of Equivalence, so a custodian, depository participant or merchant banker that is also a bank under RBI supervision can demonstrate compliance once instead of running two parallel control sets and two evidence trails. It also re-categorises Portfolio Managers and Merchant Bankers, so if your category was settled before September 2025 it is worth re-checking against Part C rather than assuming it still holds.
One line in the framework decides who may sign the work. Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by a CERT-In empanelled information security auditing organisation, and the same expectation is repeated for the VAPT and cyber audit that the Market SOC provides to small and mid-size entities. An internal team or a non-empanelled consultancy can help you prepare and can dry-run the evidence, but it cannot produce the audit SEBI expects to receive.
| Obligation | Trigger | Timeline |
|---|---|---|
| CERT-In incident report | Any of the 20 listed incident types (ransomware, data breach, etc.) | Within 6 hours of noticing |
| SEBI/exchange incident report | Cyber incident affecting the RE | Within stipulated hours per circular, plus root-cause report |
| Root Cause Analysis (RCA) | Post-incident, for significant events | Typically within a defined window after the incident |
| VAPT report submission | Annual (half-yearly for MIIs) | After remediation, with closure evidence |
| Cyber audit report | Annual | Submitted to exchange/depository/SEBI |
The six-hour CERT-In window is the one that ruins weekends. Detection, not confirmation, starts the clock. Teams waste hours deciding whether an anomaly is real before reporting; by the time they do, they have already breached. The right posture is to report on reasonable suspicion and refine later — CERT-In accepts follow-up updates. A late first report is a finding. An over-cautious early report is not.
What actually happens in the audit room
Picture the second morning of a CSCRF cyber audit at a mid-size broking house. The CISO has produced a clean policy pack — access control, IR, BCP-DR — all board-approved, all recently dated. The auditor nods, then asks one question: show me the last time you restored a backup and how long it took. Silence. The backups run nightly, monitored, green ticks everywhere. Nobody has ever restored one. The DR drill on paper says RTO of four hours; the team has never measured it.
So the auditor asks for a live restoration of a non-production dataset. Ninety minutes in, it is still running, because the backups are full-image and the storage is throttled. The RTO claim collapses in real time. This is the CSCRF finding that recurs more than any other — not missing controls, but untested ones. SEBI's framework specifically calls for tested recovery, and testable is the operative word. A control you have never exercised is a hypothesis, not a safeguard.
The other question that lands hard is on log retention. CSCRF and CERT-In together expect logs — including for critical systems — to be retained and available, with CERT-In mandating a rolling 180-day retention within Indian jurisdiction. Auditors ask to see logs from a date five months ago. If your SIEM only holds 90 days hot and archives nothing, the finding writes itself.
Five gaps that sink CSCRF audits
Across CSCRF assessments the same five gaps account for most non-compliances. Fix these before your auditor arrives and you have handled the bulk of your exposure.
- Untested DR and backups — clean policies, but no evidence of an actual restoration or a measured RTO/RPO against the claimed figures.
- SOC that is not truly continuous — monitoring during business hours only, no 24x7 roster, no MTTD metric to show.
- Log retention short of 180 days or stored outside India, breaching CERT-In alignment baked into CSCRF.
- Third-party and vendor risk ignored — critical outsourced systems (including your RTA, cloud, and SOC vendor) not risk-tiered or contractually bound to CSCRF-equivalent controls.
- Inflated self-assessed CCI — a maturity score the entity claims but the auditor cannot substantiate with artefacts.
Data localisation and the parts people overlook
CSCRF carries data localisation expectations consistent with SEBI's broader stance: regulatory and transaction data, and the systems processing it, should reside in India. If your CRM, your email security, or your log analytics runs on infrastructure hosted abroad, that is a live question. It intersects with the DPDP Act, 2023, which governs personal data of your clients. CSCRF is a cyber framework; DPDP is a privacy law. They overlap on breach notification and on data handling, and a mature RE treats them as one programme rather than two silos.
The other overlooked piece is API security. Brokers and depository participants expose trading and account APIs, and CSCRF's Protect and Detect goals apply directly to them. Rate limiting, authentication, and monitoring of these interfaces is not optional; a compromised API on a broking platform is exactly the incident CERT-In wants reported within six hours.
What a CSCRF programme costs, honestly
Budgets vary enormously by RE category, but treating CSCRF as a one-off audit spend is the fastest way to overrun. It is an operating cost. Below is a realistic annual range for a mid-size to Qualified RE that does not already have a mature security function.
| Component | Indicative annual cost (INR) | Notes |
|---|---|---|
| CSCRF gap assessment + cyber audit | 6 - 18 lakh | Higher for Qualified REs and MIIs |
| VAPT (application + infrastructure) | 4 - 15 lakh | Half-yearly for MIIs raises this |
| Managed SOC / C-SOC access | 12 - 60 lakh | Largest single line; scales with log volume |
| SIEM + 180-day log retention | 5 - 20 lakh | Storage and licensing |
| DR/BCP setup and testing | 5 - 25 lakh | Depends on RTO/RPO ambition |
| CISO / governance capacity | Varies | Often a shared or fractional role for smaller REs |
The instinct to compress this — skip the managed SOC, self-certify a higher CCI, defer the DR test — is understandable and almost always regretted. The cost of a SEBI observation is not the remediation; it is the enhanced monitoring, the repeat audit, and the reputational drag with your exchange. Spend the money once, correctly.
The fix-it checklist before your next audit
If you do nothing else this quarter, work through this list. It maps directly to the findings SEBI examiners raise most often, and every item produces an artefact you can hand over.
- Confirm your RE category in writing from your exchange or depository, and scope your obligations to it — do not over- or under-build.
- Run one real backup restoration and time it; document the actual RTO/RPO against your claimed figures and close the gap.
- Verify your SIEM retains at least 180 days of logs, within India, and pull a five-month-old log as a live test.
- Get your SOC roster and MTTD/MTTR metrics for the last quarter in a single document — if 24x7 coverage is required for your category, prove it.
- Risk-tier every critical vendor (RTA, cloud, SOC, connectivity) and confirm CSCRF-equivalent obligations sit in the contract.
- Rehearse your incident response plan with a tabletop exercise that includes the six-hour CERT-In report as a timed step.
- Reconcile your self-assessed CCI with the underlying evidence before the auditor does it for you.
- Align your CSCRF breach-notification workflow with DPDP Act obligations so one incident does not trigger two uncoordinated processes.
The point SEBI is really making
CSCRF is not asking whether you have controls. Every RE has a firewall and an antivirus and a policy PDF. It is asking whether those controls work under pressure, whether you can prove it on a timeline, and whether your recovery is real rather than aspirational. The framework's genius is that it made evidence the currency. The entities that struggle are not the insecure ones — they are the ones who never tested what they built.
Go back to that first panicked email forwarding the circular. The entities that handled CSCRF well treated it not as a deadline but as the moment to finally restore a backup, watch a SOC alert at midnight, and time their incident response. If your programme needs a hard, hands-on read before SEBI gives you one, our CERT-In empanelled auditors at CyberSigma do exactly this work — sitting in the room, scoring the CCI, and testing the controls that matter.
FAQs
When did SEBI CSCRF come into effect and does it replace older circulars?
SEBI notified CSCRF in August 2024, consolidating and superseding its earlier standalone cybersecurity and cyber resilience circulars for regulated entities. Implementation dates were staggered by RE category, with several extensions issued. It is now the single reference framework for cyber obligations across covered entities.
How do I know which CSCRF category my entity falls into?
SEBI defines category thresholds based on parameters such as number of clients, trading turnover, or assets under management, and your Stock Exchange, Depository or the relevant SEBI-recognised body communicates your classification. You cannot self-select a lower category; the obligation depth follows the assigned grade.
What is the Cyber Capability Index and do I have to hit a specific score?
The CCI is CSCRF's maturity scoring methodology across roughly two dozen parameters. MIIs and Qualified REs must achieve and maintain a defined minimum maturity band, evidenced through an auditor-verified score submitted to SEBI. Smaller REs face a lighter or self-certified assessment.
Do I report a cyber incident to SEBI or to CERT-In?
Both, on separate clocks. CERT-In's Directions require reporting listed incident types within six hours of noticing. SEBI, through CSCRF, additionally requires reporting to your exchange or depository per the applicable circular, followed by a root-cause analysis. Treat them as parallel obligations, not alternatives.
Is a managed SOC mandatory under CSCRF?
For larger RE categories, continuous security monitoring is mandatory — met through your own SOC, access to an MII-provided C-SOC or market SOC, or a managed SOC from an empanelled provider. Business-hours-only monitoring does not satisfy the Contain goal. Smaller REs have scaled expectations.
How does CSCRF relate to the DPDP Act?
CSCRF governs cybersecurity and resilience; the DPDP Act, 2023 governs personal data protection. They overlap on breach handling, data localisation and notification. A mature regulated entity runs them as one coordinated programme so that a single incident does not trigger two disjointed response and reporting workflows.
Liked the post? Share on:




Leave A Comment