Cybersecurity Compliance
SEBI CSCRF Explained: A Complete Guide for Regulated Entities
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) consolidates and significantly raises the cyber-security bar for the Indian securities market. It is one of the most demanding regulatory regimes in India - a five-tier model spanning 22 categories of regulated entities, pulling together VAPT, cyber audit, red teaming, threat hunting, a Market-SOC, ISO 27001, a named CISO and the full NIST CSF 2.0 control catalogue. This guide explains what CSCRF is and how to comply.
What is CSCRF and who does it cover?
CSCRF applies to SEBI-regulated entities (REs) - stock exchanges, clearing corporations, depositories, stock brokers, mutual funds/AMCs, Registrars and Transfer Agents (RTAs), and more. It replaces a patchwork of earlier circulars with one graded framework.
Entities are classified into tiers (from Market Infrastructure Institutions down to smaller REs), and obligations scale with the tier. Determining your correct tier is the essential first step, because it defines everything that follows.
The five-tier model
CSCRF grades regulated entities so that the most systemically important institutions carry the heaviest obligations, while smaller entities face a proportionate baseline. Higher tiers must implement the full control catalogue, a Market-SOC, mandatory red teaming and more frequent testing; lower tiers meet a scaled subset.
What CSCRF mandates
- Governance: a board-approved policy, a named CISO, and an IT/cyber committee
- The NIST CSF 2.0 control catalogue (Govern, Identify, Protect, Detect, Respond, Recover)
- VAPT of applications and infrastructure, with tracked remediation
- Red teaming / adversary simulation for higher tiers
- A Market-SOC (M-SOC) capability for continuous monitoring and threat hunting
- ISO 27001-aligned information security management
- Incident reporting to SEBI within defined timelines
- Cyber audit and a documented evidence pack
Data localization status
CSCRF's data-localization provisions have been the subject of regulatory forbearance - the mandate was placed in abeyance from December 2024 to give entities time to adapt. Design for compliance, but track the current enforcement position, because the direction of travel is toward localization.
A practical path to CSCRF compliance
- Classify your entity into the correct CSCRF tier
- Run a gap analysis against the NIST CSF 2.0 control catalogue for your tier
- Stand up governance: CISO, committee, board-approved policy
- Implement or contract a Market-SOC for monitoring and threat hunting
- Schedule VAPT (and red teaming where required) with remediation tracking
- Complete the cyber audit and assemble the SEBI-ready evidence pack
Need help with this in practice?
A5 Cyber Nexus audits, remediates and certifies against these frameworks.
Frequently asked questions
What is the difference between CSCRF and the old SEBI cyber circulars?
CSCRF consolidates the earlier entity-specific circulars into one graded, tier-based framework built on NIST CSF 2.0, with broader scope (22 entity categories) and stronger requirements like a Market-SOC and red teaming for higher tiers.
Do all SEBI entities need a Market-SOC?
Higher-tier entities must have a Market-SOC (M-SOC) capability. Lower tiers meet a scaled subset - which is why correctly determining your tier first is essential.
Is red teaming mandatory under CSCRF?
For higher-tier regulated entities, objective-based red teaming / adversary simulation is required in addition to standard VAPT.
Make it accessible.
Make it attack-ready.
Prove both before launch.
Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.
