SEBI CSCRF Explained: A Compliance Guide for Brokers, Fund Managers, Advisors & Intermediaries
TL;DR
- • SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued August 2024, consolidates all prior cybersecurity circulars into a single framework for SEBI-regulated entities
- • Applies to stock brokers, mutual funds & AMCs, investment advisers, research analysts, depository participants, merchant bankers, and other market intermediaries
- • Obligations are graded by RE category: MIIs, Qualified REs, Mid-size REs, Small-size REs, and Self-certification REs
- • Key requirements: SOC coverage (own, group, or Market SOC), periodic VAPT, Cyber Capability Index (CCI) reporting, cyber audits by empanelled auditors, and CERT-In incident reporting within 6 hours
- • Non-compliance risks SEBI enforcement action, inspection findings, and in serious cases suspension of registration
If you run a stock broking firm, an asset management company, an advisory practice, or any other SEBI-registered intermediary, cybersecurity is no longer an IT department concern — it's a regulatory obligation with board-level accountability. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) sets out exactly what every regulated entity must implement, test, audit, and report. This guide breaks down what CSCRF requires and how to get compliant without hiring an army of consultants.
What Is the SEBI CSCRF?
The Cybersecurity and Cyber Resilience Framework (CSCRF) was issued by SEBI in August 2024. It replaces and consolidates the patchwork of earlier cybersecurity circulars that applied separately to stock brokers, mutual funds, depositories, and other intermediaries — creating one unified, graded framework for the entire securities market ecosystem.
CSCRF is structured around five cyber resiliency goals — Anticipate, Withstand, Contain, Recover, and Evolve — mapped across six functional areas: Governance, Identify, Protect, Detect, Respond, and Recover. If you're familiar with NIST CSF, the structure will feel recognizable, but CSCRF adds India-specific mandates like Market SOC access, the Cyber Capability Index, and CERT-In reporting timelines.
The framework's most important design decision is proportionality: obligations scale with the size and systemic importance of your firm. A large AMC and a two-person research analyst firm are not held to the same standard — but both have obligations.
Who Does CSCRF Apply To?
CSCRF applies to all SEBI-regulated entities (REs). If your firm holds a SEBI registration, you are in scope. Here's what that means for the main segments:
Stock Brokers & Broking Firms
Brokers handle client funds, securities, and trading credentials — making them prime targets for account takeover and unauthorized trading attacks. Depending on client count and trading volumes, brokers fall into Qualified, Mid-size, or Small-size RE categories. Larger brokers must operate or subscribe to a SOC, run periodic VAPT on trading systems, and report their Cyber Capability Index. Brokers using algo trading or open APIs face additional scrutiny on system integrity and access controls.
Fund Managers & Asset Management Companies
Mutual funds, AMCs, PMS providers, and AIF managers typically land in the Qualified RE category due to assets under management. That brings the heavier obligations: ISO 27001 alignment expectations, a full SOC (own or group-level), annual cyber audits by SEBI-empanelled auditors, comprehensive VAPT coverage, and board-approved cybersecurity policies with a designated CISO. Investor data, NAV systems, and RTA integrations are all in audit scope.
Investment Advisers & Agents
Registered Investment Advisers (RIAs) and research analysts are usually Small-size or Self-certification REs. The compliance load is lighter — self-certification against the CSCRF baseline, basic hygiene controls (MFA, patching, endpoint protection, data encryption), and incident reporting — but it is not optional. Advisers holding client financial data and KYC records must demonstrate that data is classified, encrypted, and access-controlled.
Intermediaries & Other Market Participants
Depository participants, merchant bankers, registrars & transfer agents, custodians, and credit rating agencies all fall under CSCRF with category-based obligations. Intermediaries connected to exchange or depository infrastructure face particular attention on network segmentation, third-party risk, and secure connectivity — a compromise at an intermediary is a potential pathway into market infrastructure.
RE Categorization: Which Bucket Are You In?
CSCRF divides regulated entities into five categories, with obligations scaling accordingly:
| Category | Who | Key Obligations |
|---|---|---|
| MIIs | Stock exchanges, depositories, clearing corporations | Full framework, dedicated SOC, ISO 27001 certification, most frequent audits and VAPT |
| Qualified REs | Large brokers, AMCs/mutual funds, large intermediaries | SOC (own/group), ISO 27001 alignment, annual cyber audit, comprehensive VAPT, CCI reporting |
| Mid-size REs | Mid-tier brokers and intermediaries | SOC coverage (Market SOC permitted), periodic VAPT, cyber audit, graded control set |
| Small-size REs | Smaller brokers, advisers, analysts | Baseline controls, Market SOC option, lighter audit cadence |
| Self-certification REs | Smallest advisers, agents, analysts | Self-certification against CSCRF baseline, core hygiene controls, incident reporting |
Don't Guess Your Category
Categorization thresholds are based on parameters like number of clients, trading volumes, and assets under management — and your category can change as your business grows. Confirm your category with your exchange, depository, or association, and reassess annually. Being in the wrong bucket means either wasted spend or a compliance gap.
Key CSCRF Requirements
1. Governance: Board-Approved Policy and a CISO
Every RE needs a board-approved cybersecurity and cyber resilience policy, reviewed periodically, with a designated CISO or officer responsible for cybersecurity. Accountability sits with the board — cybersecurity failures are now governance failures.
2. Security Operations Centre (SOC)
Qualified REs and MIIs must have 24x7 SOC coverage — their own SOC or a group SOC. Smaller REs can subscribe to the Market SOC set up by exchanges (NSE/BSE), which dramatically lowers the barrier for mid-size and small firms. Either way, security events from your systems must be monitored and triaged continuously.
3. VAPT (Vulnerability Assessment & Penetration Testing)
Periodic VAPT of critical systems is mandatory, with cadence based on RE category. Findings must be remediated within defined timelines and closure verified. Trading platforms, client-facing portals, and systems connected to exchange infrastructure are always in scope.
4. Cyber Capability Index (CCI)
CSCRF introduces a quantitative maturity score — the Cyber Capability Index — that Qualified REs and MIIs must calculate and report periodically. The CCI aggregates weighted parameters across the framework's domains, turning your security posture into a number your board and SEBI can track over time.
5. Cyber Audits by Empanelled Auditors
Periodic cyber audits must be conducted by auditors empanelled with CERT-In or as specified by SEBI. Audit reports, along with management comments and remediation plans, are submitted to the relevant authority. Evidence management is the biggest practical pain point here — auditors will ask for policies, logs, VAPT reports, training records, and access reviews.
6. Incident Reporting Within 6 Hours
Cybersecurity incidents must be reported to CERT-In within 6 hours of detection, with parallel reporting obligations to SEBI and your exchange/depository. That timeline is only achievable with a rehearsed incident response plan, clear ownership, and pre-drafted reporting templates.
7. Data Protection, SBOM, and Third-Party Risk
CSCRF mandates data classification and encryption, log retention, a Software Bill of Materials (SBOM) for critical systems, and structured vendor risk management. If your RTA, cloud provider, or software vendor is compromised, SEBI still holds you accountable — outsourcing the function does not outsource the obligation.
CSCRF Compliance Checklist
The Real Challenge: Evidence, Not Controls
Most brokers, AMCs, and intermediaries already run many of the required controls — firewalls, MFA, backups, antivirus. What they lack is the compliance machinery around them: documented policies mapped to CSCRF clauses, evidence collected on a schedule, VAPT findings tracked to closure, CCI calculated defensibly, and an audit trail an empanelled auditor can verify without weeks of back-and-forth.
Doing this in spreadsheets means a compliance officer chasing screenshots every quarter. Doing it with a compliance automation platform means evidence flows in automatically from your cloud, identity, and endpoint tools, controls are continuously tested, and audit packages are generated on demand.
How LowerPlane Helps SEBI-Regulated Entities
- →CSCRF control library mapped to your RE category — no over- or under-scoping
- →Automated evidence collection from AWS, Azure, GCP, Okta, Google Workspace, and 375+ tools
- →Policy templates for board-approved cybersecurity policies, incident response, and vendor risk
- →VAPT finding tracking, CCI dashboard, and audit-ready evidence packages for empanelled auditors
- →Shared controls with ISO 27001 — one implementation satisfies both, critical for Qualified REs
Get CSCRF-Ready Without the Consultant Bills
LowerPlane automates evidence collection, control testing, and audit preparation for SEBI-regulated entities — brokers, AMCs, advisers, and intermediaries.
Book a Demo