Financial Regulation

SEBI CSCRF Explained: A Compliance Guide for Brokers, Fund Managers, Advisors & Intermediaries

LowerPlane Team10 min read

TL;DR

  • • SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued August 2024, consolidates all prior cybersecurity circulars into a single framework for SEBI-regulated entities
  • • Applies to stock brokers, mutual funds & AMCs, investment advisers, research analysts, depository participants, merchant bankers, and other market intermediaries
  • • Obligations are graded by RE category: MIIs, Qualified REs, Mid-size REs, Small-size REs, and Self-certification REs
  • • Key requirements: SOC coverage (own, group, or Market SOC), periodic VAPT, Cyber Capability Index (CCI) reporting, cyber audits by empanelled auditors, and CERT-In incident reporting within 6 hours
  • • Non-compliance risks SEBI enforcement action, inspection findings, and in serious cases suspension of registration

If you run a stock broking firm, an asset management company, an advisory practice, or any other SEBI-registered intermediary, cybersecurity is no longer an IT department concern — it's a regulatory obligation with board-level accountability. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) sets out exactly what every regulated entity must implement, test, audit, and report. This guide breaks down what CSCRF requires and how to get compliant without hiring an army of consultants.

What Is the SEBI CSCRF?

The Cybersecurity and Cyber Resilience Framework (CSCRF) was issued by SEBI in August 2024. It replaces and consolidates the patchwork of earlier cybersecurity circulars that applied separately to stock brokers, mutual funds, depositories, and other intermediaries — creating one unified, graded framework for the entire securities market ecosystem.

CSCRF is structured around five cyber resiliency goals — Anticipate, Withstand, Contain, Recover, and Evolve — mapped across six functional areas: Governance, Identify, Protect, Detect, Respond, and Recover. If you're familiar with NIST CSF, the structure will feel recognizable, but CSCRF adds India-specific mandates like Market SOC access, the Cyber Capability Index, and CERT-In reporting timelines.

The framework's most important design decision is proportionality: obligations scale with the size and systemic importance of your firm. A large AMC and a two-person research analyst firm are not held to the same standard — but both have obligations.

Who Does CSCRF Apply To?

CSCRF applies to all SEBI-regulated entities (REs). If your firm holds a SEBI registration, you are in scope. Here's what that means for the main segments:

Stock Brokers & Broking Firms

Brokers handle client funds, securities, and trading credentials — making them prime targets for account takeover and unauthorized trading attacks. Depending on client count and trading volumes, brokers fall into Qualified, Mid-size, or Small-size RE categories. Larger brokers must operate or subscribe to a SOC, run periodic VAPT on trading systems, and report their Cyber Capability Index. Brokers using algo trading or open APIs face additional scrutiny on system integrity and access controls.

Fund Managers & Asset Management Companies

Mutual funds, AMCs, PMS providers, and AIF managers typically land in the Qualified RE category due to assets under management. That brings the heavier obligations: ISO 27001 alignment expectations, a full SOC (own or group-level), annual cyber audits by SEBI-empanelled auditors, comprehensive VAPT coverage, and board-approved cybersecurity policies with a designated CISO. Investor data, NAV systems, and RTA integrations are all in audit scope.

Investment Advisers & Agents

Registered Investment Advisers (RIAs) and research analysts are usually Small-size or Self-certification REs. The compliance load is lighter — self-certification against the CSCRF baseline, basic hygiene controls (MFA, patching, endpoint protection, data encryption), and incident reporting — but it is not optional. Advisers holding client financial data and KYC records must demonstrate that data is classified, encrypted, and access-controlled.

Intermediaries & Other Market Participants

Depository participants, merchant bankers, registrars & transfer agents, custodians, and credit rating agencies all fall under CSCRF with category-based obligations. Intermediaries connected to exchange or depository infrastructure face particular attention on network segmentation, third-party risk, and secure connectivity — a compromise at an intermediary is a potential pathway into market infrastructure.

RE Categorization: Which Bucket Are You In?

CSCRF divides regulated entities into five categories, with obligations scaling accordingly:

CategoryWhoKey Obligations
MIIsStock exchanges, depositories, clearing corporationsFull framework, dedicated SOC, ISO 27001 certification, most frequent audits and VAPT
Qualified REsLarge brokers, AMCs/mutual funds, large intermediariesSOC (own/group), ISO 27001 alignment, annual cyber audit, comprehensive VAPT, CCI reporting
Mid-size REsMid-tier brokers and intermediariesSOC coverage (Market SOC permitted), periodic VAPT, cyber audit, graded control set
Small-size REsSmaller brokers, advisers, analystsBaseline controls, Market SOC option, lighter audit cadence
Self-certification REsSmallest advisers, agents, analystsSelf-certification against CSCRF baseline, core hygiene controls, incident reporting

Don't Guess Your Category

Categorization thresholds are based on parameters like number of clients, trading volumes, and assets under management — and your category can change as your business grows. Confirm your category with your exchange, depository, or association, and reassess annually. Being in the wrong bucket means either wasted spend or a compliance gap.

Key CSCRF Requirements

1. Governance: Board-Approved Policy and a CISO

Every RE needs a board-approved cybersecurity and cyber resilience policy, reviewed periodically, with a designated CISO or officer responsible for cybersecurity. Accountability sits with the board — cybersecurity failures are now governance failures.

2. Security Operations Centre (SOC)

Qualified REs and MIIs must have 24x7 SOC coverage — their own SOC or a group SOC. Smaller REs can subscribe to the Market SOC set up by exchanges (NSE/BSE), which dramatically lowers the barrier for mid-size and small firms. Either way, security events from your systems must be monitored and triaged continuously.

3. VAPT (Vulnerability Assessment & Penetration Testing)

Periodic VAPT of critical systems is mandatory, with cadence based on RE category. Findings must be remediated within defined timelines and closure verified. Trading platforms, client-facing portals, and systems connected to exchange infrastructure are always in scope.

4. Cyber Capability Index (CCI)

CSCRF introduces a quantitative maturity score — the Cyber Capability Index — that Qualified REs and MIIs must calculate and report periodically. The CCI aggregates weighted parameters across the framework's domains, turning your security posture into a number your board and SEBI can track over time.

5. Cyber Audits by Empanelled Auditors

Periodic cyber audits must be conducted by auditors empanelled with CERT-In or as specified by SEBI. Audit reports, along with management comments and remediation plans, are submitted to the relevant authority. Evidence management is the biggest practical pain point here — auditors will ask for policies, logs, VAPT reports, training records, and access reviews.

6. Incident Reporting Within 6 Hours

Cybersecurity incidents must be reported to CERT-In within 6 hours of detection, with parallel reporting obligations to SEBI and your exchange/depository. That timeline is only achievable with a rehearsed incident response plan, clear ownership, and pre-drafted reporting templates.

7. Data Protection, SBOM, and Third-Party Risk

CSCRF mandates data classification and encryption, log retention, a Software Bill of Materials (SBOM) for critical systems, and structured vendor risk management. If your RTA, cloud provider, or software vendor is compromised, SEBI still holds you accountable — outsourcing the function does not outsource the obligation.

CSCRF Compliance Checklist

Determine your RE category (MII / Qualified / Mid-size / Small-size / Self-certification) and confirm it with your exchange or association
Get a board-approved cybersecurity and cyber resilience policy in place, and designate a CISO or responsible officer
Map your critical systems: trading platforms, client portals, back-office, RTA/exchange connectivity, and cloud infrastructure
Establish SOC coverage — own SOC, group SOC, or subscribe to the Market SOC (NSE/BSE) if eligible
Schedule VAPT for critical systems at the cadence required for your category, and track remediation to closure
Implement baseline controls: MFA everywhere, privileged access management, patching, endpoint protection, and network segmentation
Classify and encrypt sensitive data (client KYC, holdings, credentials) at rest and in transit
Set up centralized log collection with the required retention period
Maintain an SBOM for critical applications and assess vendor/third-party cyber risk
Build and rehearse an incident response plan capable of CERT-In reporting within 6 hours
Calculate your Cyber Capability Index (if Qualified RE/MII) and establish periodic reporting
Engage a CERT-In empanelled auditor for your cyber audit, and centralize evidence before the audit starts
Run cybersecurity awareness training for all employees, including phishing simulations
If you are an MII or Qualified RE, plan your ISO 27001 alignment or certification path

The Real Challenge: Evidence, Not Controls

Most brokers, AMCs, and intermediaries already run many of the required controls — firewalls, MFA, backups, antivirus. What they lack is the compliance machinery around them: documented policies mapped to CSCRF clauses, evidence collected on a schedule, VAPT findings tracked to closure, CCI calculated defensibly, and an audit trail an empanelled auditor can verify without weeks of back-and-forth.

Doing this in spreadsheets means a compliance officer chasing screenshots every quarter. Doing it with a compliance automation platform means evidence flows in automatically from your cloud, identity, and endpoint tools, controls are continuously tested, and audit packages are generated on demand.

How LowerPlane Helps SEBI-Regulated Entities

  • CSCRF control library mapped to your RE category — no over- or under-scoping
  • Automated evidence collection from AWS, Azure, GCP, Okta, Google Workspace, and 375+ tools
  • Policy templates for board-approved cybersecurity policies, incident response, and vendor risk
  • VAPT finding tracking, CCI dashboard, and audit-ready evidence packages for empanelled auditors
  • Shared controls with ISO 27001 — one implementation satisfies both, critical for Qualified REs
Explore CSCRF Compliance with LowerPlane

Get CSCRF-Ready Without the Consultant Bills

LowerPlane automates evidence collection, control testing, and audit preparation for SEBI-regulated entities — brokers, AMCs, advisers, and intermediaries.

Book a Demo