Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
The record
| Reference | SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 |
|---|---|
| Issued by | Securities and Exchange Board of India (SEBI) |
| Instrument type | Framework |
| Date of issue | 20 August 2024 |
| Status | In force |
| Binds | SEBI Regulated Entities across the securities market, graded as Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. |
| Dates it sets |
|
What it says
- Grades SEBI regulated entities into five categories — Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs — with obligations scaled to the category.
- Sets the compliance deadline that, after two extensions, landed on 31 August 2025 for every RE except MIIs, KRAs and QRTAs, which were never extended.
- Carries the Cyber Capability Index in Annexure-K, the maturity score a categorised RE computes against twenty-three weighted parameters.
- Has been amended five times since issue: two rounds of clarifications, two extensions and one set of technical clarifications.
- Is not the source of the current categorisation thresholds — those were revised by the clarifications circular of 30 April 2025.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- CSCRF clarifications, December 2024 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 — Answers to the first round of queries on CSCRF.
- First extension, March 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 — Moved the CSCRF deadline to 30 June 2025, excluding MIIs, KRAs and QRTAs.
- CSCRF clarifications, April 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 — Revised the CSCRF categorisation criteria and thresholds, including for Depository Participants.
- Second extension, June 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96 — Moved the CSCRF deadline to 31 August 2025, again excluding MIIs, KRAs and QRTAs.
- Technical clarifications, August 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 — Technical readings of the CSCRF standards, issued three days before the deadline fell.
- SEBI incident portal — FIRE format HO/(449)2026-ITD-5_DIV1/I/19448/2026 — Moved SEBI incident filing to the FIRE format and staged it, without moving either clock.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .