← Market intermediaries
SEBI CSCRF Compliance for Regulated Entities
CSCRF consolidated a decade of scattered SEBI cyber circulars into one framework, with obligations scaling by the RE category SEBI assigns. The Cyber Capability Index turns it from a checklist into a scored audit instrument.
What SEBI CSCRF requires of market intermediaries
- RE category confirmed in writing by your Stock Exchange or Depository — it determines every obligation below.
- Cyber Capability Index self-assessment you can reproduce, with the working, not just the score.
- SOC coverage via your own SOC, a market/shared C-SOC, or a managed provider — with evidence of alert triage.
- Incident reporting to SEBI and CERT-In on separate clocks; the six-hour CERT-In window starts at detection.
- VAPT with retest, and demonstrable recovery against stated RTO.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Category confirmation from the exchange or depository
- CCI working papers and board consideration of the result
- SOC alert samples worked end to end
- VAPT report and the retest confirming closure
- A dated restoration test with timings against RTO
Where market intermediaries usually come unstuck
- Self-certifying a higher CCI than the evidence supports.
- Conflating the SEBI and CERT-In reporting clocks.
- A recovery objective that has never been proven by an actual restoration.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
