SEBI · Framework

Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113

In short
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 is the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, issued on 20 August 2024. It grades regulated entities as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs, and the compliance deadline reached 31 August 2025 through two separate extensions that both carved out MIIs, KRAs and QRTAs. Five later circulars have amended it, and the categorisation thresholds are in one of those rather than in this one.

The record

ReferenceSEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeFramework
Date of issue20 August 2024
StatusIn force
BindsSEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.
Dates it sets
  • 31 August 2025Compliance deadline as twice extended, for every RE except MIIs, KRAs and QRTAs.
SEBI CSCRF as the register holds it, read from the issuing regulator's own notification.

What it says

  • Grades SEBI regulated entities into five categories — Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs — with obligations scaled to the category.
  • Sets the compliance deadline that, after two extensions, landed on 31 August 2025 for every RE except MIIs, KRAs and QRTAs, which were never extended.
  • Carries the Cyber Capability Index in Annexure-K, the maturity score a categorised RE computes against twenty-three weighted parameters.
  • Has been amended five times since issue: two rounds of clarifications, two extensions and one set of technical clarifications.
  • Is not the source of the current categorisation thresholds — those were revised by the clarifications circular of 30 April 2025.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The SEBI CSCRF compliance guide