SEBI · Cyber resilience

SEBI CSCRF
the Cybersecurity and Cyber Resilience Framework, explained.

Who the framework covers, which of the five categories you fall into, the deadlines as extended four times, and the recurring work that remains: the SOC, the six-hour report, the cyber audit and VAPT cycles, and ISO 27001 for the largest entities.

Circular of 20 Aug 2024Five RE categoriesSix-hour reportingCERT-In empanelled audit

Last updated Published by TryTrustableNot legal advice

01

What is SEBI CSCRF?

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is one set of cybersecurity standards for every entity SEBI regulates, issued by circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 on 20 August 2024. It replaced the separate cyber circulars SEBI had issued since 2015 and grades obligations by the size and risk of the regulated entity.

The circular and its 205-page framework are organised around five cyber resilience goals, anticipate, withstand, contain, recover and evolve, and the familiar functions under them: govern, identify, protect, detect, respond and recover. Each standard carries an applicability column, so the same document asks much more of a stock exchange than of a small portfolio manager. SEBI first issued a cyber framework for market infrastructure institutions in 2015 and then extended versions of it to brokers and depository participants, mutual funds, KYC registration agencies, qualified RTAs and portfolio managers. CSCRF brings all of them, and many entities that had no cyber circular at all, under one text.

02

Which entities does CSCRF apply to?

CSCRF applies to every category of SEBI regulated entity the circular addresses, from stock exchanges, clearing corporations and depositories to brokers, mutual funds, portfolio managers, AIFs, RTAs, credit rating agencies, custodians and merchant bankers. Each entity is placed in one of five categories, which decides how much of the framework applies.

The five categories are market infrastructure institutions (MIIs), qualified REs, mid-size REs, small-size REs and self-certification REs. The category is set at the start of each financial year on the previous year's data and holds for the year. The thresholds differ by entity type and were revised by the clarifications circular of 30 April 2025. For stock brokers, the higher of two independent tests applies:

Stock broker categoryTotal registered clientsClientele trading volume in a year
Qualified REMore than 10 lakhMore than ₹10,00,000 crore
Mid-size REMore than 1 lakh, up to 10 lakhMore than ₹1,00,000 crore, up to ₹10,00,000 crore
Small-size REMore than 10,000, up to 1 lakhMore than ₹10,000 crore, up to ₹1,00,000 crore
Self-certification REMore than 1,000, up to 10,000More than ₹1,000 crore, up to ₹10,000 crore
ExemptFewer than 1,000And under ₹1,000 crore

From the SEBI circular of 30 April 2025, which revised the August 2024 thresholds. Other entity types have their own tests; AIFs and VCFs are now categorised at manager level.

The same circular made several other changes worth knowing. KYC registration agencies moved from MII to qualified RE. Investment advisers and research analysts not registered with SEBI in any other capacity are exempt. Portfolio managers above ₹3,000 crore AUM are mid-size and the rest self-certification. Depository participants that are not brokers are qualified REs. Bankers to an issue and self-certified syndicate banks submit a certificate of compliance based on RBI's cybersecurity rules rather than running CSCRF separately.

03

What are the CSCRF compliance deadlines?

CSCRF took effect from 1 January 2025 for the six categories that already had SEBI cyber circulars and 1 April 2025 for everyone else. After four follow-up circulars, most regulated entities had until 31 August 2025. MIIs, KYC registration agencies and qualified RTAs were held to the earlier dates.

CircularWhat it changed
20 Aug 2024
CIR/2024/113
Framework issued. Compliance by 1 January 2025 where a cyber circular already existed, and 1 April 2025 for entities covered for the first time.
31 Dec 2024
CIR/2024/184
Regulatory forbearance to 31 March 2025 for entities that could show meaningful progress. KRAs and depository participants moved to 1 April 2025. The data localisation standard (PR.DS.S2) put in abeyance until further notice.
28 Mar 2025
CIR/2025/45
Three-month extension to 30 June 2025 for all REs except MIIs, KRAs and qualified RTAs.
30 Apr 2025
CIR/2025/60
Categories and thresholds revised; exemptions for small brokers, stand-alone IAs and RAs; KRAs recategorised.
30 Jun 2025
CIR/2025/96
Two-month extension to 31 August 2025 for all REs except MIIs, KRAs and qualified RTAs.
28 Aug 2025
CIR/2025/119
Technical clarifications to the standards.

As of 28 September 2026 we have not found a later general extension on sebi.gov.in. Check the Circulars listing before relying on this.

Note the data localisation point. The framework as issued included a data localisation standard, PR.DS.S2. It has been in abeyance since the December 2024 circular pending further consultation. That is a SEBI decision about CSCRF only; it does not affect RBI's payment data rule or anything in the DPDP Act.

04

Does CSCRF require a security operations centre?

Yes. Every regulated entity must monitor security events continuously through a SOC, which can be its own, a group SOC, a third-party SOC or the Market SOC that BSE and NSE were mandated to build. Small-size and self-certification entities are expected to onboard onto the Market SOC.

A SOC existing is not enough. MIIs and qualified REs must measure the functional efficacy of their SOC every six months; other entities using a third-party or Market SOC obtain an efficacy report from the provider once a year. The framework gives a quantified method and a list of parameters for the measurement. The April 2025 circular exempted depository participants with fewer than 100 clients, and self-certification portfolio managers with fewer than 100 clients, from the SOC or Market SOC requirement.

MIIs and qualified REs also carry red-teaming every six months and threat hunting every quarter, and must calculate a Cyber Capability Index: MIIs through a third-party assessment every six months, qualified REs by self-assessment once a year, with evidence submitted within fifteen days.

05

How fast must a cyber incident be reported to SEBI?

Within six hours. Any incident that falls under the CERT-In directions must be notified to SEBI and CERT-In within six hours of noticing it, by email to SEBI's incident address, with details on the SEBI Incident Reporting Portal within 24 hours. Brokers and depository participants also inform the exchanges or depositories within six hours.

Incidents outside the CERT-In categories are reported to SEBI, CERT-In and, where applicable, NCIIPC within 24 hours. Every entity must also have an incident response plan with SOPs, a Cyber Crisis Management Plan, and root cause analysis after an incident. If the incident involves personal data, the DPDP duties to tell the Data Protection Board and each affected person apply as well, with the Board's detailed report within 72 hours. CERT-In and DPDP breach reporting compared lays the two regimes side by side.

06

How often are CSCRF cyber audits and VAPT required?

Cyber audits are due at least twice a year for MIIs, qualified REs, and mid-size and small-size REs offering internet-based or algorithmic trading, and at least once a year for everyone else. VAPT is due twice a year for protected systems and critical information infrastructure, and once a year otherwise. Unless stated, all audits use CERT-In empanelled auditors.

ActivityFrequencyDeadlines after the activity
Cyber auditTwice a year: MIIs, qualified REs, and mid- or small-size REs with IBT or algo trading. Once a year: the rest.Report within one month, after IT Committee approval. Findings closed within three months of the report.
VAPTTwice a year for systems NCIIPC identifies as protected systems or CII, one in each half of the financial year. Once a year for the rest, starting in the first quarter.Report within one month. Findings closed within three months. Revalidation within five months.
ISO 27001Certification mandatory for MIIs and qualified REs, within a year of CSCRF's issue.Evidence submitted with the cyber audit report.
Policy reviewsCyber resilience policy and cyber risk management policy, yearly, all REs.Auditors validate the periodicities during the cyber audit.
Access reviewsUser access and privileged activity: quarterly for MIIs and qualified REs, half-yearly for others.None
Recovery drillsScenario-based drills: half-yearly for MIIs and qualified REs, yearly for others.None

Summarised from sections 4.1 to 4.4 of CSCRF. Brokers and DPs submit to the exchanges or depositories; MIIs and most others submit to SEBI.

Open observations after a follow-on audit go to the entity's IT Committee and must be closed on timelines its board approves. The framework also expects a risk register the IT Committee reviews. For critical systems it sets a two-hour recovery time objective, following IOSCO, and a fifteen-minute recovery point objective; check the applicability column for your category.

07

How does CSCRF relate to ISO 27001 and the DPDP Act?

CSCRF is SEBI's sector security framework. ISO 27001 is the international management system standard CSCRF makes mandatory for its largest entities. The DPDP Act governs personal data. Most controls overlap across all three, but none of them discharges the others.

A broker that already runs an ISO 27001 ISMS has most of the protect and detect controls in place; the work CSCRF adds is SEBI-specific: the categories, the reporting formats, the Market SOC, the Cyber Capability Index and the fixed calendar. The DPDP Act adds a separate set of duties toward clients as individuals: notice, consent, rights and erasure, with substantive duties from 13 May 2027. The ISO 27001 solution covers the management system, and the fintech sector page covers the DPDP side for brokers and wealth platforms.

08

Where TryTrustable fits, and where it does not

TryTrustable does not ship a CSCRF control set, does not provide a SOC, and is not a CERT-In empanelled auditor. It supports ISO 27001, which CSCRF makes mandatory for MIIs and qualified REs, and its cross-framework mapping includes custom framework authoring, so CSCRF standards can be entered and mapped onto controls you already run. The evidence ledger records passes and failures with timestamps, which is what a twice-yearly audit asks for between the two dates.

Questions

The things people ask us

What is SEBI CSCRF?

The Cybersecurity and Cyber Resilience Framework is SEBI's single set of cybersecurity standards for the entities it regulates, issued by circular on 20 August 2024. It replaced the separate cyber circulars for exchanges, brokers, mutual funds and others with one framework, graded into five categories of regulated entity by size and risk.

What is the deadline for CSCRF compliance?

It depends on the entity. The original dates were 1 January 2025 for the six categories that already had cyber circulars and 1 April 2025 for the rest. Most regulated entities then received extensions to 30 June and finally 31 August 2025. Market infrastructure institutions, KYC registration agencies and qualified RTAs were excluded from those extensions.

How quickly must a SEBI regulated entity report a cyber incident?

Incidents covered by the CERT-In directions go to SEBI and CERT-In within six hours of noticing them, with details on the SEBI incident reporting portal within 24 hours. Stock brokers and depository participants also report to the exchanges or depositories within six hours. Other cybersecurity incidents are reported within 24 hours.

Do all SEBI regulated entities need their own SOC?

No. Each needs security monitoring through a SOC, but it can be its own, a group SOC, a third-party SOC or the Market SOC that BSE and NSE were directed to set up. Small-size and self-certification entities are expected to use the Market SOC, with exemptions for some very small depository participants and portfolio managers.

How often is a CSCRF cyber audit required?

At least twice a year for market infrastructure institutions and qualified entities, and for mid-size and small-size entities offering internet-based or algorithmic trading. At least once a year for the rest. Audits are done by a CERT-In empanelled auditing organisation, reports are due within a month, and findings must close within three months.

Is ISO 27001 mandatory under CSCRF?

For market infrastructure institutions and qualified regulated entities, yes. The framework requires them to obtain ISO 27001 certification, and to submit evidence of it with the cyber audit report. Other categories are not required to certify, though the controls CSCRF expects overlap heavily with the standard's Annex A.

One control, many regimes

Run the ISMS once and map CSCRF onto it.

See how one control result reaches ISO 27001, SOC 2 and a regulator framework you author yourself, with the evidence behind each pass and each failure.