SEBI · Circular

Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45

In short
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 is the first extension to the CSCRF compliance timeline, issued on 28 March 2025. It moved the deadline three months to 30 June 2025 for all regulated entities except Market Infrastructure Institutions, KYC Registration Agencies and Qualified Registrars to an Issue and Share Transfer Agents, whose timelines were not extended.

The record

ReferenceSEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeCircular
Date of issue28 March 2025
StatusIn force
BindsExtended compliance timelines by three months, to 30 June 2025, for all REs except MIIs, KRAs and QRTAs.
Dates it sets
  • 30 June 2025Extended compliance deadline for every RE except MIIs, KRAs and QRTAs.
First extension, March 2025 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Extends the CSCRF compliance timeline by three months, to 30 June 2025.
  • Excludes MIIs, KRAs and QRTAs from the extension — their timelines were never moved.
  • Superseded in practice by the second extension of 30 June 2025, which moved the same deadline again to 31 August 2025.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113SEBI regulated entities, graded into five categories with obligations scaled to the category.
  • Second extension, June 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96Moved the CSCRF deadline to 31 August 2025, again excluding MIIs, KRAs and QRTAs.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The SEBI CSCRF compliance guide