We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · Capital markets

SEBI CSCRF compliance consultant

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) consolidates cyber-security obligations for SEBI-regulated entities — stock brokers, depository participants, AMCs, RIAs and market infrastructure institutions — with graded requirements, cyber audits, VAPT, SOC/monitoring expectations and defined reporting timelines. CyberSigma is a CERT-In empanelled auditor that maps your entity type to its applicable CSCRF requirements, runs the cyber audit and VAPT, and delivers an auditable report and remediation plan you can file and defend.

Get a free CSCRF readiness snapshot →Book a 20-minute call
Who needs it

Who CSCRF applies to

SEBI-regulated entities on a graded basis — from Market Infrastructure Institutions and qualified REs down to smaller entities with proportionate requirements. Your classification determines the depth of controls, audit and reporting.

Scope

What CSCRF covers

Governance & controls
Cyber-security policy, identify/protect/detect/respond/recover functions and standards alignment.
Audit & testing
Periodic cyber audit and VAPT by empanelled auditors, with closure evidence.
Monitoring & reporting
SOC/monitoring expectations and incident reporting within defined timelines.
Timeline & cost

Timeline and cost factors

Timeline
Typically 4–8 weeks depending on entity classification, systems and whether VAPT is bundled.
Cost factors
Entity grade, number of applications and third parties, and remediation support scope.
Deliverables

What you receive

CSCRF-mapped audit report
Findings mapped to your applicable CSCRF requirements, filing-ready.
VAPT + closure
Application and infrastructure testing with retest evidence.
Common failures

Where entities fall short

  • Misclassifying entity grade and under-scoping
  • Monitoring/SOC expectations not evidenced
  • VAPT findings without documented closure
  • Missed reporting timelines for incidents
Proof

See how we’ve done it before

Relevant case study
How a capital-markets entity evidenced CSCRF cyber-audit and VAPT closure. Read case studies →
Redacted sample deliverable
Inspect a redacted tracker/report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Issuance and final compliance timelineEffective 31 August 2025

    SEBI issued the Cybersecurity and Cyber Resilience Framework vide circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024 (Version 1.0, 205 pages). The compliance timeline was extended twice: circular 2025/45 of 28 March 2025 moved it by three months to 30 June 2025, and circular 2025/96 of 30 June 2025 moved it by a further two months to 31 August 2025. Both extensions applied to all regulated entities except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs) and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), which stayed on the original timeline. That final date has passed, so CSCRF is fully in force.

    Upgraded to a primary source: this entry previously rested on the June 2025 FAQ plus independent legal analyses. The extension chain has now been read directly from the SEBI circulars themselves. The most recent CSCRF amendment is circular 2025/119 of 28 August 2025; no later CSCRF circular has issued as at 2026-08-04.

  • Regulated entities are sorted into five compliance categoriesEffective 20 August 2024

    CSCRF applies proportionately by category: (i) Market Infrastructure Institutions (MIIs), (ii) Qualified REs, (iii) Mid-size REs, (iv) Small-size REs and (v) Self-certification REs. Entity-wise thresholds that determine which category an RE falls into are set out in the framework's “Thresholds for REs’ categorization” section.

    Portfolio Managers and Merchant Bankers were re-categorised by circular 2025/119 of 28 August 2025 (Part C).

  • Audits must be conducted by a CERT-In empanelled organisationEffective 20 August 2024

    The framework states: “Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization.” The same requirement is restated for the VAPT and cyber audit that the Market SOC is to provide to small- and mid-size REs at affordable cost.

    Quoted verbatim from footnote 16, page 48 of 205.

  • VAPT frequency depends on NCIIPC designationEffective 20 August 2024

    REs identified as “Protected systems” and/or Critical Information Infrastructure by NCIIPC must complete at least two VAPT activities each year — one in each half of the financial year (April to September, October to March), each including report submission, closure and revalidation. All other REs must complete at least one, with the activity commencing in the first quarter of the financial year.

    Table 18, page 48. REs must plan VAPT at the start of the financial year, and no audit cycle may be left unaudited because of a change in category.

  • VAPT reporting, closure and revalidation deadlinesEffective 20 August 2024

    The VAPT report must be submitted within one month of completing the VAPT activity, after approval from the RE's IT Committee. Findings must be closed within three months of report submission, following a graded approach based on the criticality of the observations. Revalidation of the VAPT must be completed within five months of its completion.

    Table 19, page 49. Vulnerabilities still open after three months require IT Committee approval and must be closed before the next VAPT exercise begins.

  • A Security Operations Centre is mandatory, with a Market SOC route for smaller entitiesEffective 20 August 2024

    CSCRF mandates a SOC for all REs except client-based stock brokers with fewer than 100 clients. An RE may use its own or group SOC, any third-party managed SOC, or the Market SOC. Small-size and Self-certification category REs are required to onboard the Market SOC, which NSE and BSE must set up and which NSDL and/or CDSL may set up optionally.

    Box Item 11, page 69. For small- and mid-size REs the Market SOC is also to provide VAPT and cyber audit services.

  • The Cyber Capability Index applies only to the top two categoriesEffective 20 August 2024

    The Cyber Capability Index (CCI) applies only to MIIs and Qualified REs. MIIs must have their cyber resilience assessed against the CCI by a third party on a half-yearly basis; Qualified REs self-assess their cyber resilience using the CCI on a yearly basis.

    Page 14 of 205; the index itself is set out at Annexure-K, page 163.

  • Latest amendment: technical clarifications of 28 August 2025Effective 28 August 2025

    Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025 issues technical clarifications in four parts: Part A, principles for REs under multiple regulators' purview, introducing a Principle of Exclusivity and a Principle of Equivalence so an RE regulated by both SEBI and (for example) RBI can demonstrate compliance without duplicating work; Part B, technical clarifications; Part C, re-categorisation of Portfolio Managers and Merchant Bankers; and Part D, Cyber Security Audit Policy Guidelines from CERT-In.

    This is the most recent CSCRF circular as at 2026-08-04.

Related in this cluster

SEBI CSCRF — FAQs

Does CSCRF apply to our entity?

CSCRF applies to SEBI-regulated entities on a graded basis. Your entity type and size determine the applicable requirements — we confirm your classification during scoping.

Do you perform the required VAPT?

Yes. As a CERT-In empanelled auditor we perform the cyber audit and VAPT CSCRF expects, and document closure via retest.

Talk to a CSCRF specialist

We confirm your CSCRF classification, run the audit and VAPT, and give you a filing-ready report. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your SEBI CSCRF compliance requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.