In 2024, a mid-size stockbroker in Mumbai received a routine email from its exchange with a new SEBI circular attached. The compliance head forwarded it to the CISO, who noticed that the firm had followed separate cyber circulars for years and now faced one framework with new audits, a security operations requirement and a reporting clock measured in hours.
The team needed to know which parts applied to them and what evidence an auditor would expect. Many SEBI regulated entities asked the same questions, because SEBI replaced a decade of entity-specific cyber circulars with a single graded framework called CSCRF.
This guide explains what CSCRF is, who must comply, which controls apply and how to prepare.
What Is SEBI CSCRF?
SEBI CSCRF is the Cybersecurity and Cyber Resilience Framework that SEBI issued on August 20, 2024 for every SEBI Regulated Entity. The framework consolidates and replaces six earlier cyber circulars that SEBI had issued for individual entity types between 2015 and 2023. It requires each entity to run a cybersecurity and cyber resilience program that matches its size, complexity and criticality. The official SEBI circular remains the primary reference for the framework.
Why Did SEBI Introduce The Cybersecurity And Cyber Resilience Framework?
SEBI introduced CSCRF to give the securities market one consistent cyber standard in place of several overlapping circulars. Each earlier circular covered a different group, such as brokers, mutual funds or KYC registration agencies, which left gaps and duplicated effort. The new framework aligns with industry standards, supports efficient audits and applies a graded approach, so smaller firms carry lighter obligations than exchanges and depositories. Market participants also share systems and vendors, so a weakness at one entity can affect investors across the ecosystem.

Who Must Comply With SEBI CSCRF?
Every SEBI Regulated Entity must comply, and the depth of compliance depends on its category. SEBI assigns the category using thresholds such as registered clients, trading volume, assets under management and folios serviced. CSCRF defines five categories:
- Market Infrastructure Institutions: stock exchanges, clearing corporations and depositories.
- Qualified REs: for example, stockbrokers with more than 10 lakh clients or mutual funds with AUM of Rs. 1 lakh crore and above.
- Mid-size REs: for example, stockbrokers with 1 lakh to 10 lakh clients.
- Small-size REs: for example, stockbrokers with 10,000 to 1 lakh clients.
- Self-certification REs: for example, stockbrokers with 1,000 to 10,000 clients.
SEBI sets the category at the start of each financial year using data from the previous year, and an entity with multiple registrations follows the highest category. Stockbrokers with fewer than 1,000 clients and under Rs. 1,000 crores in annual trading volume are exempt. SEBI revised some thresholds for Portfolio Managers and Merchant Bankers in its August 2025 technical clarifications, so confirm current figures before you finalize your category.
What Does The Scope Of SEBI CSCRF Cover?
The scope covers governance, technology controls, monitoring, response and recovery across the full IT environment of a regulated entity. SEBI builds the framework around five cyber resilience goals, which are Anticipate, Withstand, Contain, Recover and Evolve. It maps those goals to six cybersecurity functions, which are Governance, Identify, Protect, Detect, Respond and Recover. The structure draws on industry standards such as NIST CSF, so teams that already use NIST or ISO 27001 can map existing controls with less rework. Entities that run regulated workloads on cloud must also follow SEBI’s Framework for Adoption of Cloud Services.
What Controls Does SEBI CSCRF Require?
CSCRF requires a mix of governance, testing and operational controls, and the exact set depends on the entity category. The main requirements include:
- An IT Committee that includes at least one external independent cybersecurity expert.
- ISO 27001 certification for the categories that carry this obligation.
- Vulnerability assessment and penetration testing once or twice each financial year, with the report submitted within one month.
- A cyber audit once or twice each year, aligned to the CERT-In Cyber Security Audit Policy Guidelines and submitted within one month.
- Threat-based risk assessment, red teaming and threat hunting for the applicable categories.
- Cyber Capability Index assessments, security training and scenario-based drills.
- Continuous security monitoring, including onboarding to the Market SOC for many entities, with exemptions for some entities that serve fewer than 100 clients.
When Do CSCRF Deadlines And Incident Reporting Timelines Apply?
The implementation deadline has passed for most entities. SEBI first set January 1, 2025 and April 1, 2025 as start dates, then extended the timeline to August 31, 2025 for most entities through circulars issued in March and June 2025. Market Infrastructure Institutions, KYC registration agencies and qualified RTAs were excluded from those extensions. The live obligation now is the recurring audit and reporting cycle.
Incident reporting runs on two clocks. An entity must send an initial notification to SEBI within 6 hours of detection, and CERT-In also expects a report within 6 hours under its April 2022 directions. The entity must then file incident details on the SEBI Incident Reporting Portal within 24 hours.

Where Do Regulated Entities Struggle Most With CSCRF?
Resource limits, talent gaps and documentation load create the most pressure. Smaller entities often lack the budget for a SOC or a red team exercise. Larger entities usually own plenty of tooling but struggle to produce evidence on demand for several audits at once. Third-party dependencies add another gap, because brokers rely on trading platforms, KYC vendors and cloud providers whose controls the entity must still oversee. Teams that start with one control inventory and one evidence repository close these gaps faster than teams that treat each audit as a separate project.
How Can Regulated Entities Prepare For SEBI CSCRF Compliance?
Preparation starts with five steps:
- Confirm your category using data from the previous financial year.
- Run a gap assessment against the CSCRF controls for that category.
- Build an asset inventory and a threat-based risk assessment.
- Document an incident response workflow that meets the 6-hour and 24-hour clocks, then test it with a scenario drill.
- Schedule VAPT and cyber audits, and store evidence in one place so reports reach the exchange or SEBI on time.
Strong CSCRF programs treat the framework as an operating routine rather than a one-time project, because audits, drills and reporting repeat every year. Regulated entities that map their category, test their incident workflow and centralize evidence early enter each audit cycle with fewer surprises, and they respond faster when a real incident starts the 6-hour clock.
| Talk to Ampcus Cyber’s compliance experts to map your CSCRF category, close control gaps and stay audit ready. |
People Also Ask
Is SEBI CSCRF mandatory for all SEBI registered entities?
Yes, with defined exemptions. Entities such as FPIs, REITs and InvITs, and the smallest stock brokers, fall outside the compliance submission requirement.
Which CSCRF category does my firm fall into?
Common groupings include cyber and software risk, access and data risk, operational and concentration risk, and compliance risk.
What is the difference between SCRM and TPRM?
SEBI assigns the category from registered clients, trading volume, AUM or folios, measured on the previous financial year. An entity with several registrations follows the highest category.
Is ISO 27001 mandatory under CSCRF?
It is required for the categories that carry the obligation, so check the control list for your category.
How often is VAPT required under CSCRF?
Once or twice each financial year, depending on category, with the report submitted within one month of completion.
How long do we have to report a cyber incident to SEBI?
Six hours for the initial notification and 24 hours for incident details on the SEBI Incident Reporting Portal.
Do I report a cyber incident to SEBI or CERT-In?
Both. They are separate obligations with separate filings, each starting from detection.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










