Regulation

SEBI CSCRF: what the framework requires, category by category

SEBI’s CSCRF — circular 2024/113 of 20 August 2024, five amendments, compliance due 31 August 2025. Which category you are in, and what recurs every year.

In short
SEBI’s Cybersecurity and Cyber Resilience Framework binds every regulated entity in the Indian securities market, at a standard set by which of five categories it falls into. The category is re-fixed each April on the previous financial year’s data. The principal deadline was 31 August 2025 after two extensions, so the live obligation is the recurring audit and reporting cycle.

CSCRF replaced a patchwork of separate cyber circulars — one for stock brokers, one for portfolio managers, one for KYC registration agencies — with a single framework covering the whole securities market. That consolidation is the point of it, and it is also why the obligations differ so much between two entities that are both “CSCRF compliant”.

The framework is six circulars, not one

Almost every reference to CSCRF cites the August 2024 circular alone. Two of the things a compliance officer actually needs — the revised categorisation thresholds, and the deadline that landed on 31 August 2025 after being moved twice — are in the five circulars that followed it.

CircularDateWhat it did
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/11320 August 2024Issued the framework.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/18431 December 2024Answered the first round of queries from regulated entities.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/4528 March 2025Extended compliance timelines by three months, to 30 June 2025, for all REs except MIIs, KRAs and QRTAs.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/6030 April 2025Revised the categorisation criteria and thresholds, including for Depository Participants.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/9630 June 2025Extended compliance timelines by a further two months, to 31 August 2025, for all REs except MIIs, KRAs and QRTAs.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/11928 August 2025Technical readings of the standards, issued as the principal deadline passed.
The CSCRF circular chain. Numbers and dates read from the circulars on sebi.gov.in.

The two extensions are worth reading precisely, because both carved out the same three classes. The March 2025 circular moved the deadline three months to 30 June 2025 for all regulated entities except Market Infrastructure Institutions, KYC Registration Agencies and Qualified Registrars to an Issue and Share Transfer Agents. The June 2025 circular moved it a further two months to 31 August 2025, with the same three carve-outs. Those three were never given the extension and were expected at the original timeline.

Which category you are in, and why it changes

CSCRF grades regulated entities into five bands, and the standard applied to you follows the band rather than the licence. From the top: Market Infrastructure Institutions — the stock exchanges, clearing corporations and depositories — then Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.

The thresholds are quantitative, and they turn on a different parameter for almost every entity type — registered clients and trading volume for a stock broker, assets under management for a mutual fund, assets under custody for a custodian, folios serviced for an RTA. Some entity types take a fixed category instead: every active Merchant Banker is a Small-size RE, and KYC Registration Agencies are Qualified REs. Where a firm holds more than one registration, the highest category applies.

Stock brokers are the one entity type categorised on two parameters — total registered clients and annual clientele trading volume — and the April 2025 clarification is explicit that the two are applied independently, with the higher result winning. A broker large on one axis and small on the other takes the heavier category. That clarification also replaced the original test outright: categorisation no longer runs on active UCC client base, and the distinction CSCRF v1.0 drew between client-based and proprietary brokers no longer exists.

The full matrix, for every entity type and against the thresholds as they currently stand, is in the CSCRF category finder.

Qualified Stock Brokers are a separate designation, made under a 2023 circular rather than under CSCRF, and it overrides the category for testing purposes: a QSB runs VAPT and cyber audit half-yearly whichever CSCRF category it otherwise falls into.

The five cyber resilience goals

CSCRF is organised around five goals — Anticipate, Withstand, Contain, Recover and Evolve — layered over the familiar Identify, Protect, Detect, Respond and Recover functions. The resilience framing is the substantive change: the framework assumes the control set will sometimes fail and asks what the entity does then, rather than treating prevention as the whole of the obligation.

Cyber Capability Index

The CCI is the framework's maturity measurement, and who computes it differs by standing. Market Infrastructure Institutions must have their cyber resilience assessed against the CCI by a third party, half-yearly. Qualified REs self-assess. Scores are taken to two decimal places. The distinction matters: for an MII the index is an external opinion, for a Qualified RE it is a self-report, and the two carry different evidential weight in a supervisory conversation.

Security Operations Centre

Every regulated entity needs SOC coverage, obtained in one of several ways — its own SOC, a group SOC, or onboarding to a Market SOC (M-SOC) run for smaller entities. A globally present firm whose Indian securities business puts it in the Small-size or Self-certification band may use its group SOC rather than onboard to the M-SOC, but it must still submit SOC efficacy reports periodically. The obligation is the efficacy evidence, not the building.

VAPT, SBOM and the auditor requirement

  • VAPT on a periodic basis, with the cadence set by category — and half-yearly for Qualified Stock Brokers regardless. Vulnerabilities identified during VAPT must be closed within three months of the report being submitted, and that timeline holds whether the defect is in the entity's own code or in a third-party dependency it does not control.
  • CERT-In empanelled auditors. DAST or SAST testing of commercial off-the-shelf and in-house developed software must be carried out by a CERT-In empanelled information security auditing organisation. Forensic audits are treated differently — third-party auditors selected after due diligence, with Indian government forensic labs available, and CERT-In empanelment not mandated.
  • SBOM. A software bill of materials for the systems in scope, which is what makes the three-month third-party vulnerability timeline enforceable at all.
  • ISO/IEC 27001 certification covering, at minimum, the primary data centre, the DR and near-DR sites, the SOC and any colocation facility — and extending to third parties where those functions are outsourced to them.

The CISO provisions

For MIIs and Qualified REs the CISO's level, grade and standing must be at least equivalent to the CTO or CIO, and reporting to an Executive Director or to the MD or CEO is treated as compliant. A group-level CISO may serve multiple entities within the same group. A remote CISO is permitted only if dedicated to a single organisation. A part-time CISO is not permitted at all.

The incident-reporting clocks

CSCRF sets its reporting obligations in Annexure-O, and the framing usually given — “six hours to SEBI” — describes about a third of it. A reportable incident produces three filings, not one, and for a stock broker or depository participant it produces four.

WhatBy whenTo whom
Initial notification6 hoursSEBI at mkt_incidents@sebi.gov.in, and CERT-In
Necessary details of the incident24 hoursSEBI Incident Reporting Portal
Stock brokers and depository participants — additionally6 hoursStock Exchanges and Depositories
Any other cybersecurity incident24 hoursSEBI, CERT-In and NCIIPC as applicable
Reportable-incident filings under CSCRF Annexure-O. All clocks run from noticing or detecting the incident, or from being brought to notice of it.

Note what starts the clock. The framework says noticing or detecting such incidents, or being brought to notice about them — the same three limbs as CERT-In. A vendor's call, a researcher's email or a regulator's enquiry starts it exactly as an internal alert does, and an investigation in progress does not pause it.

Annexure-O also sets the threshold for what belongs in the six-hour bucket rather than the twenty-four: incidents of a severe nature on public information infrastructure — denial of service, intrusion, the spread of a contaminant including ransomware — together with data breaches and data leaks, and large-scale or frequently recurring intrusions. Two of those categories are triggered well below the threshold most firms picture when they say “a breach”.

The framework attaches a consequence to silence. Where a regulated entity does not report an incident it was aware of, in the manner the applicable framework lays down, appropriate regulatory action may be taken.

What the live obligation is now

The adoption deadline has passed and SEBI has issued no further blanket extension — nor, as at August 2026, any further CSCRF circular at all: the chain above is complete. What remains is recurring: the cyber audit cycle with its standardised reporting formats, the half-yearly CCI assessment for MIIs, periodic SOC efficacy submission, the VAPT cadence, and DC-DR drills. Every one of those produces an artefact on a schedule, which is the point — the framework was written so that compliance is demonstrated by a series rather than asserted at a moment.

SEBI has continued to issue guidance around the framework without amending it. Its advisory of 5 May 2026 on emerging advanced artificial intelligence tools for vulnerability detection is the current example — not a change to the standards, but an indication of where supervisory attention is going, and worth reading alongside what agentic AI does to an attack surface.

Where a regulator prescribes the shape of the evidence, an internal narrative stops being a substitute for it. That is the practical difference between CSCRF and the circulars it replaced.

Read from the SEBI circulars linked above and from SEBI's FAQs on CSCRF dated 11 June 2025. Every instrument cited here was verified against the issuing regulator's own notification on . This page is general information, not legal advice — confirm applicability, your category and current status with your own counsel and compliance function.

Where BitScore fits, and where it does not

CSCRF's Anticipate goal is the one an external, continuous measurement speaks to directly: knowing what is exposed before it is exploited, on a schedule shorter than the audit cycle. Two obligations in particular are hard to discharge from the inside alone.

  • Asset inventory and classification. An outside-in view of the estate finds internet-facing assets the register does not describe. SEBI has already fined a depository ₹1 crore over exactly this failure — the CDSL order is the worked example, and it is worth reading before assuming your own inventory is complete.
  • Third-party and outsourcing obligations. Continuous monitoring of a service provider's external posture is evidence about that provider, produced independently of it, updated between review cycles.

What a rating does not do is satisfy CSCRF. It is not a SOC, not a VAPT, not an SBOM, not an ISO 27001 certification, and it does not produce a Cyber Capability Index score. It cannot be submitted in place of a prescribed reporting format, and no auditor will accept it as one. It evidences external hygiene and supports third-party due diligence. Treating a good score as regulatory cover would be a serious misreading of both the framework and the rating.

Questions this page answers

Which CSCRF category are we in?
One of five — Market Infrastructure Institution, Qualified, Mid-size, Small-size or Self-certification — set by quantitative thresholds rather than by licence type. The thresholds were revised by the clarifications of 30 April 2025, so a categorisation carried out before that date should be redone against the current figures.
Does our CSCRF category stay the same year to year?
No. Categories are re-fixed at the start of each financial year on the previous year’s data, and the entity stays in that category for the whole year. A firm that crossed a threshold last year moves up this April. The category is a property of the year, not a permanent attribute of the firm.
What was the final CSCRF compliance deadline?
31 August 2025, reached through two extensions from the original timeline. Both carved out the same three classes — Market Infrastructure Institutions, KYC Registration Agencies and Qualified Registrars to an Issue and Share Transfer Agents. Those three were never granted either extension and were expected at the original date.
How long do we have to report a cyber incident under CSCRF?
Six hours to notify SEBI at mkt_incidents@sebi.gov.in and CERT-In, then twenty-four hours to file the details on the SEBI Incident Reporting Portal. Stock brokers and depository participants must also tell the exchanges or depositories within the same six hours. Any other cybersecurity incident goes to SEBI, CERT-In and NCIIPC within twenty-four hours. The clock runs from noticing or detecting the incident, or from being brought to notice of it — an investigation in progress does not pause it.
Does reporting to CERT-In satisfy the SEBI obligation?
No. They are two filings and neither discharges the other. CSCRF requires notification to SEBI and CERT-In in the same breath, and the twenty-four-hour portal submission is a third step rather than a substitute for either. Where a regulated entity does not report an incident it was aware of, the framework states that appropriate regulatory action may be taken.
We are a listed regulated entity — what else applies?
The listing regulations, from a different direction. Regulation 30(6) requires a material event to reach the stock exchanges within twelve hours where it emanates from within the listed entity, which a ransomware event or data breach does — the twenty-four hours usually quoted is the limb for events arising outside the entity. Regulation 27(2)(ba) separately requires details of cyber security incidents, breaches or loss of data in the quarterly corporate governance report, with no materiality test. Materiality under Regulation 30 is determined by Key Managerial Personnel authorised by the board.
Is CSCRF a single circular?
Six, as at August 2026. The circular of 20 August 2024 issued the framework; four more answered queries, revised the categorisation thresholds and moved the deadline twice; the circular of 28 August 2025 added technical readings of the standards. Citing only the first misses both the current thresholds and the deadline that actually applied.
Does every regulated entity need its own SOC?
Every regulated entity needs SOC coverage, but not necessarily its own. It can come from an in-house SOC, a group SOC, or onboarding to the Market SOC run for smaller entities. A firm relying on a group SOC still submits SOC efficacy reports periodically — the obligation is the efficacy evidence rather than who operates the facility.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ