We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SEBI · Capital Markets

SEBI CSCRF: Cybersecurity and Cyber Resilience Framework

CSCRF is SEBI's Cybersecurity and Cyber Resilience Framework, consolidating its earlier cyber circulars into one standard for regulated entities — from stock brokers and depository participants to AMCs and market infrastructure institutions.

Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm

Quick answer

CSCRF stands for Cybersecurity and Cyber Resilience Framework — SEBI's consolidated cybersecurity standard for its regulated entities, replacing a patchwork of earlier circulars with one framework covering governance, identification, protection, detection, response and recovery. Obligations scale with the category an entity falls into, and compliance is evidenced through audit and periodic reporting to the entity's designated reporting authority. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA).

Who CSCRF applies to

CSCRF covers SEBI regulated entities across the market, with obligations graded by category rather than applied identically to everyone:

  • Market infrastructure institutions — stock exchanges, clearing corporations and depositories, which carry the heaviest obligations.
  • Stock brokers and depository participants, who report through their exchange or depository rather than directly to SEBI.
  • Asset management companies, mutual funds and portfolio managers.
  • Registrars, share transfer agents, investment advisers, research analysts and other intermediaries, with lighter obligations at the smaller end.
  • The category you fall into determines the depth of the control set, the audit cadence and who you report to — which is the first thing to establish, because scoping to the wrong category wastes money in one direction and creates exposure in the other.

What the framework asks for

CSCRF is structured around the familiar cyber-resilience functions, but SEBI's expectations are specific and evidence-led:

  • Governance — a board-approved cybersecurity policy, defined responsibility, and reporting that reaches the top of the organisation rather than stopping at IT.
  • Identification — asset inventory, classification of critical systems, and a risk assessment that is current rather than annual-and-forgotten.
  • Protection — access control, network segmentation, secure configuration, data protection and supply-chain and vendor risk management.
  • Detection — monitoring and a security operations capability, with the depth expected scaling by entity category.
  • Response and recovery — a tested incident response plan, defined reporting lines, and recovery objectives that have actually been exercised.
  • Audit and evidence — periodic assessment against the framework, with findings tracked to closure within the timeframe SEBI expects after report submission.

Where entities actually struggle

From assessments across regulated entities the pattern is consistent, and it is rarely the technology:

  • Category confusion — scoping against the wrong entity category, and discovering it during the audit.
  • Evidence that describes rather than demonstrates: a policy exists, but nobody can show it operating over the review period.
  • Monitoring capability assumed to be adequate because a tool is licensed, without anyone testing whether an incident would actually be detected.
  • Findings closed on paper but not re-tested, which does not survive scrutiny when closure has to be evidenced.
  • Vendor and outsourced-service risk left out of scope, when a material part of the platform runs there.

How we run a CSCRF engagement

We start by fixing your entity category and reporting authority, because everything downstream depends on it. We then assess against the applicable control set with evidence rather than interviews alone, test the controls that matter technically, and produce a findings register mapped clause by clause with owners and a remediation sequence. We re-test after remediation so closure is evidenced, not asserted. If you also hold obligations under the CERT-In Directions or ISO 27001 — most SEBI entities do — we gather evidence once and map it across, rather than running three overlapping audits.

Why CyberSigma for CSCRF

We are CERT-In empanelled, which matters because SEBI entities carry CERT-In obligations in parallel and the two are best assessed together. We scope to your actual entity category rather than selling the heaviest control set to everyone, and we stay through remediation and re-test so what you report is closure rather than intent.

Related services

Frequently asked questions

What does CSCRF stand for?

CSCRF stands for Cybersecurity and Cyber Resilience Framework. It is SEBI's consolidated cybersecurity standard for regulated entities, bringing its previously separate cyber circulars into a single framework organised around governance, identification, protection, detection, response and recovery.

Which entities does CSCRF apply to?

SEBI regulated entities across the market — market infrastructure institutions such as exchanges, clearing corporations and depositories; stock brokers and depository participants; AMCs, mutual funds and portfolio managers; and intermediaries including RTAs, investment advisers and research analysts. Obligations are graded by category, so the first step is establishing which category you fall into.

Who do we report our CSCRF compliance to?

It depends on your category. Stock brokers and depository participants report through their stock exchange or depository rather than directly to SEBI; other categories report to their designated authority. Establishing the correct reporting line is part of scoping.

How does CSCRF relate to the System Audit Report we already submit?

They are related but not identical. A System Audit Report is a regulator-mandated system audit with its own scope and submission route, while CSCRF is the cybersecurity and resilience framework your controls are assessed against. For many entities the underlying evidence overlaps substantially, so we scope them together where that is appropriate.

Do CSCRF and the CERT-In Directions overlap?

Yes, and usefully. CERT-In's Directions apply to you regardless of SEBI — six-hour incident reporting, 180-day log retention within India and time synchronisation — and the evidence supports both. We assess them together rather than running two audits over the same estate.

How long do we have to close audit findings?

SEBI expects findings identified during the audit to be closed within a defined window after the report is submitted, and closure needs to be evidenced. We build the remediation sequence around that window and re-test, so the closure you report can be substantiated.

Sources & references

Free tool
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Free resource
Get the free SEBI CSCRF readiness checklist
Executive checklist built by our CERT-In empanelled, PCI QSA authorised consultants. Delivered instantly.
Download checklist →

Ready to discuss your SEBI CSCRF Compliance requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →