We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · Capital markets

SEBI CSCRF compliance consultant

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) consolidates cyber-security obligations for SEBI-regulated entities — stock brokers, depository participants, AMCs, RIAs and market infrastructure institutions — with graded requirements, cyber audits, VAPT, SOC/monitoring expectations and defined reporting timelines. CyberSigma is a CERT-In empanelled auditor that maps your entity type to its applicable CSCRF requirements, runs the cyber audit and VAPT, and delivers an auditable report and remediation plan you can file and defend.

Get a free CSCRF readiness snapshot →Book a 20-minute call
Who needs it

Who CSCRF applies to

SEBI-regulated entities on a graded basis — from Market Infrastructure Institutions and qualified REs down to smaller entities with proportionate requirements. Your classification determines the depth of controls, audit and reporting.

Scope

What CSCRF covers

Governance & controls
Cyber-security policy, identify/protect/detect/respond/recover functions and standards alignment.
Audit & testing
Periodic cyber audit and VAPT by empanelled auditors, with closure evidence.
Monitoring & reporting
SOC/monitoring expectations and incident reporting within defined timelines.
Timeline & cost

Timeline and cost factors

Timeline
Typically 4–8 weeks depending on entity classification, systems and whether VAPT is bundled.
Cost factors
Entity grade, number of applications and third parties, and remediation support scope.
Deliverables

What you receive

CSCRF-mapped audit report
Findings mapped to your applicable CSCRF requirements, filing-ready.
VAPT + closure
Application and infrastructure testing with retest evidence.
Common failures

Where entities fall short

  • Misclassifying entity grade and under-scoping
  • Monitoring/SOC expectations not evidenced
  • VAPT findings without documented closure
  • Missed reporting timelines for incidents
Proof

See how we’ve done it before

Relevant case study
How a capital-markets entity evidenced CSCRF cyber-audit and VAPT closure. Read case studies →
Redacted sample deliverable
Inspect a redacted tracker/report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

SEBI CSCRF — FAQs

Does CSCRF apply to our entity?

CSCRF applies to SEBI-regulated entities on a graded basis. Your entity type and size determine the applicable requirements — we confirm your classification during scoping.

Do you perform the required VAPT?

Yes. As a CERT-In empanelled auditor we perform the cyber audit and VAPT CSCRF expects, and document closure via retest.

Talk to a CSCRF specialist

We confirm your CSCRF classification, run the audit and VAPT, and give you a filing-ready report. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your SEBI CSCRF compliance requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.