On this page · 12 sections
- Which category you are in decides almost everything
- Five goals, six functions
- What the 28 August 2025 circular quietly changed
- The build list
- The audit calendar is the real deadline
- The Cyber Capability Index, in numbers
- Post-quantum: a real requirement without a date
- A sequencing plan for a team starting now
- What this costs, honestly
- FAQ
- How eCorpIT can help
- References
Summary. SEBI issued the Cybersecurity and Cyber Resilience Framework on 20 August 2024 as circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, a 205-page document that superseded eight earlier circular groups and 22 advisories. It sorts every regulated entity into five categories, from Market Infrastructure Institutions down to self-certification REs, using thresholds such as ₹1,000 crore in AIF corpus or 5,00,000 active broker clients. The deadline moved twice in 2025, landing at 31 August 2025 for most REs, and there has been no blanket extension since. What remains is a permanent engineering programme: a security operations centre, a Cyber Capability Index scored across 23 weighted parameters, a software bill of materials for every core system, cyber audits by CERT-In empanelled organisations covering 100 percent of critical systems and a 25 percent sample of the rest, a two-hour recovery time objective and a 15-minute recovery point objective. The detail most compliance write-ups still get wrong: the technical clarifications circular of 28 August 2025 downgraded three headline mandates, including ISO 27001 certification for Qualified REs, from required to recommended.
This guide separates what CSCRF actually obliges you to build from what the secondary commentary says it does, works through the category thresholds, sets out the audit calendar, and gives a sequencing plan for a team starting the work now.
Which category you are in decides almost everything
CSCRF is not one standard applied uniformly. Obligations scale by category, and your category is fixed at the start of the financial year using the previous year's data, with the highest applicable classification winning where more than one test applies.
| Entity type | Self-certification | Small-size | Mid-size | Qualified |
|---|---|---|---|---|
| Stock brokers (active clients, UCC) | 10,000 or fewer with no internet or algo trading | Over 10,000 to 50,000, or 10,000 or fewer with internet or algo trading | Over 50,000 to 5,00,000 | Over 5,00,000; QSBs are Qualified |
| AIFs and VCFs (corpus) | Below ₹100 crore | ₹100 crore to ₹500 crore | ₹500 crore to ₹1,000 crore | ₹1,000 crore and above |
| Mutual funds and AMCs (AUM) | Not applicable | Below ₹10,000 crore | ₹10,000 crore to ₹1 lakh crore | ₹1 lakh crore and above |
| Custodians (assets under custody) | Not applicable | Below ₹1 lakh crore | ₹1 lakh crore to ₹10 lakh crore | ₹10 lakh crore and above |
| Portfolio managers (re-categorised 28 August 2025) | ₹3,000 crore or less | Over ₹3,000 crore to below ₹10,000 crore | ₹10,000 crore and above | Not applicable |
Market Infrastructure Institutions sit above all of this: stock exchanges, depositories, clearing corporations, KYC registration agencies and qualified registrars and transfer agents. Two category decisions from the August 2025 circular are worth knowing because they moved real populations of firms. All active merchant bankers were placed in the small-size category, and inactive merchant bankers were exempted. Portfolio managers were re-cut so that the Qualified tier no longer applies to them at all.
Registrars and transfer agents with fewer than 10,000 folios are excluded; between 10,000 and 1 crore folios they are small-size, and between 1 crore and 2 crore they are mid-size. Proprietary brokers are graded on collateral placed with clearing corporations, with ₹10 crore or less putting a firm in self-certification and more than ₹1,000 crore in mid-size.
Get this wrong and you build the wrong programme. A firm that reads itself as small-size when it is mid-size will discover the gap at its first audit, which is the most expensive moment to discover it.
Five goals, six functions
CSCRF is structured around five cyber resilience goals adopted from CERT-In's Cyber Crisis Management Plan: Anticipate, Withstand, Contain, Recover, Evolve. Those map onto six functions that organise the standards and guidelines: Governance, Identify, Protect, Detect, Respond and Recover, with an additional Evolve strand.
That structure matters practically because the control identifiers you will be audited against carry the function prefix. PR.MA.S3, the standard requiring high-severity patches within one week, sits under Protect. GV.SC.S5, the SBOM standard, sits under Governance and supply chain. PR.AA.S8 and S9 cover access and audit retention policy. When an auditor asks for evidence, they ask by identifier, so your control register should be keyed the same way from day one rather than mapped afterwards.
What the 28 August 2025 circular quietly changed
This is where most published guidance is now stale, and it is the difference between an expensive programme and a proportionate one.
| Requirement | As widely reported after August 2024 | Position after 28 August 2025 |
|---|---|---|
| ISO 27001 certification for Qualified REs | Mandatory within one year | "Qualified REs are encouraged and recommended (not mandatory) to obtain ISO 27001" |
| Zero trust architecture | Mandated architecture | Reframed as suggested strategies |
| Mobile application security guidelines | Mandatory | Recommendatory |
| Portfolio manager categories | Included a Qualified tier | Qualified tier no longer applies; thresholds re-cut at ₹3,000 crore and ₹10,000 crore |
| Merchant bankers | Categorised by size | All active merchant bankers are small-size; inactive merchant bankers exempt |
| Data localisation of regulatory data | Mandatory storage in India | Held in abeyance by the 31 December 2024 clarifications |
The ISO 27001 change is the one with budget consequences. A certification programme for a Qualified RE covering the primary data centre, disaster recovery site, near-DR site, SOC and colocation footprint, including outsourced providers, is a multi-quarter project with external certification fees attached. It is still a defensible investment, and our SOC 2 and ISO 27001 audit readiness guide sets out what that work involves, but under CSCRF as clarified it is a choice rather than an instruction.
The localisation position needs care in the other direction. Abeyance is not repeal. If you are designing storage architecture in 2026 on the assumption that regulatory data can sit anywhere permanently, you are building a migration you will pay for later; the same reasoning we apply to data residency architecture under the DPDP Act applies here.
The build list
Strip the framework down to what an engineering team has to deliver and it is a short, expensive list.
| Requirement | What it actually means | Who it binds |
|---|---|---|
| Security operations centre | Own SOC, group SOC, Market SOC, or third-party managed SOC. NSE and BSE are mandated to build a Market-SOC; NSDL and CDSL may. Small-size and self-certification REs are mandated to onboard to a SOC | All REs |
| SOC efficacy measurement | Half-yearly for MIIs and Qualified REs, yearly for everyone else | All REs |
| Cyber Capability Index | 23 weighted parameters, evidence supplied within 15 days, automated dashboard expected | MIIs (third-party assessed, half-yearly) and Qualified REs (self-assessed, yearly) |
| Software bill of materials | For all software supporting core and critical operations, in-house or third-party, listing components, dependencies and data relationships, updated with every upgrade or change | All REs |
| VAPT | By CERT-In empanelled information security auditing organisations only. Twice a financial year for NCIIPC-designated protected systems and critical information infrastructure, once otherwise; QSBs half-yearly; mandatory after every major release | All REs |
| Cyber audit | 100 percent of critical systems plus a 25 percent sample of non-critical systems | All REs |
| Patch response | High-severity patches within one week under PR.MA.S3 | All REs |
| Disaster recovery | Disaster declared within 30 minutes, RTO of 2 hours, RPO of 15 minutes | All REs |
| Data classification | Two classes, Regulatory Data and IT and Cybersecurity Data, with Regulatory Data held in India in legible and usable form (localisation currently in abeyance) | All REs |
| Governance | Quarterly IT committee including at least one external cybersecurity expert; MD or CEO declaration accompanying every VAPT and audit report | All REs |
Four items on that list are usually under-scoped when teams budget.
The SBOM is continuous, not a document. CSCRF requires it kept updated with every upgrade or change, which makes it a build-pipeline artefact rather than a spreadsheet a vendor produces once. Legacy systems that cannot produce one need documented approval from the board, partners or proprietor. If you are already generating attestations in CI, you are most of the way there; if not, our software supply chain security work starts at exactly this point.
The auditor pool is restricted. Every audit route in the framework runs through CERT-In empanelled information security auditing organisations, including dynamic and static application security testing for both commercial off-the-shelf and in-house software. That constrains scheduling far more than teams expect, because the empanelled pool is finite and everyone in the market is booking the same windows against the same financial-year calendar.
The DR numbers are IOSCO-grade. A 2-hour recovery time objective with a 15-minute recovery point objective and a 30-minute window to declare a disaster is not something you retrofit with backups. It is an architecture decision about replication, failover automation and tested runbooks.
Accountability is personal and explicit. SEBI's position is that REs are "solely accountable" for third-party services and remain "responsible and accountable for any violations". An MD or CEO declaration accompanies every VAPT and audit report. Outsourcing the work does not outsource the answer.
The audit calendar is the real deadline
CSCRF timelines are financial-year based, which means the calendar, not a single cut-off date, governs your year.
| Obligation | Frequency | Timeline |
|---|---|---|
| Cyber audit, MIIs and Qualified REs | Twice per financial year | Report within 1 month of completion |
| Cyber audit, mid-size and small REs offering internet or algo trading | Twice per financial year | Report within 1 month |
| Cyber audit, all other REs | Once per financial year | Report within 1 month |
| VAPT, protected systems and CII | Twice per financial year | Closure within 3 months, revalidation within 5 months |
| VAPT, all other REs | Once per financial year | Closure within 3 months, revalidation within 5 months |
| Red teaming, MIIs and Qualified REs | Half-yearly | Per framework |
| Threat hunting, MIIs and Qualified REs | Quarterly | Per framework |
SEBI's own FAQs settle a question that generated a lot of noise: REs conducting a cyber audit once a year for the period April 2025 to March 2026 should start that audit after March 2026. Read together with the one-month report window, the three-month closure window and the five-month revalidation window, an audit that begins in April leaves findings open into the following September. There is no slack in that chain for a firm that treats the audit as a year-end event.
One clarification on dates circulating in vendor material: a "30 June 2026 deadline" appears in several commercial guides but not in any SEBI circular text we could locate. Work from your own financial-year calendar and the published windows, not from a date you cannot trace to a circular.
The Cyber Capability Index, in numbers
For MIIs and Qualified REs, the CCI turns cyber posture into a score. It runs across 23 weighted parameters, supports partial scoring to two decimal places, and expects evidence to be produced within 15 days.
| Band | Score | What it signals |
|---|---|---|
| Exceptional | 100 to 91 | Mature, measured programme |
| Optimal | 90 to 81 | Working programme with minor gaps |
| Manageable | 80 to 71 | Gaps identified and being worked |
| Developing | 70 to 61 | Programme exists, controls incomplete |
| Bare minimum | 60 to 51 | Material weakness |
| Fail | 50 and below | Below the framework's floor |
MIIs are assessed by a third party half-yearly; Qualified REs self-assess yearly. Both are expected to maintain an automated dashboard rather than assembling the score by hand each cycle. That expectation is the whole design intent: a number you can only compute once every six months with a two-week evidence scramble is a compliance artefact, while a number your systems emit continuously is a management tool. Building the dashboard first and the score second is the cheaper order.
Post-quantum: a real requirement without a date
CSCRF asks REs to run periodic post-quantum risk assessments, maintain a cryptographic asset inventory covering keys, certificates, algorithms and purpose, and prioritise post-quantum migration by risk and criticality. It names the "harvest now, decrypt later" threat explicitly.
What it does not do is set a deadline or name algorithms. Treat the inventory as the deliverable that is actually due: knowing every place your organisation uses cryptography, and for what, is both the prerequisite for any future migration and a control you will be asked to evidence long before a migration date exists.
A sequencing plan for a team starting now
- Fix your category in writing, using prior-financial-year data, and record which threshold test decided it. Re-check it against the 28 August 2025 re-categorisations if you are a portfolio manager or merchant banker.
- Build the control register keyed to CSCRF identifiers, not to your existing internal taxonomy. Mapping later costs more than keying correctly now.
- Book the CERT-In empanelled auditor early. The pool is finite and the demand curve follows the financial year. This is the single most common cause of a missed window.
- Stand up the SOC route. Decide between own, group, Market SOC and managed SOC on the basis of your category's efficacy-measurement frequency, not on price alone.
- Make the SBOM a pipeline artefact. Generate it on every build, store it with the release, and wire the update on change that the standard requires.
- Test the DR numbers before you assert them. Declare-in-30-minutes, RTO 2 hours, RPO 15 minutes is a tested claim or it is a paragraph.
- Instrument the CCI as a dashboard if you are an MII or Qualified RE, with evidence collection automated to the 15-day window.
- Write the cryptographic asset inventory. It is the post-quantum deliverable that exists today.
Firms running several Indian regulatory programmes at once should sequence them together rather than in series. The evidence pipelines overlap heavily with the RBI digital lending engineering checklist, the DPDP Act engineering playbook and the accessibility work in our SEBI digital accessibility audit remediation guide. One evidence platform serving four programmes is a materially cheaper build than four programmes each collecting their own.
What this costs, honestly
SEBI does not publish a compliance cost estimate and neither will we invent one. What we can say about the shape of the spend, from the framework's own requirements:
The recurring line items are the CERT-In empanelled audit engagements, at a frequency set by your category; the SOC, whether built or subscribed; and the engineering time to keep the SBOM, the control register and the CCI evidence current. The one-off lines are the DR architecture work needed to hit a 2-hour RTO, the control register build, and, if you elect to pursue it, ISO 27001 certification covering primary, DR, near-DR, SOC and colocation scope.
The variable that moves the total most is automation. Evidence assembled by hand for a half-yearly cycle costs the same amount of senior time every cycle, forever. Evidence emitted by systems costs once. Framed against a five-year horizon, the automation decision usually dominates every other line in the budget.
Notably, CSCRF states no penalty, fine or sanction for non-compliance. It relies instead on accountability: leadership ownership of cyber risk, the MD or CEO declaration, the rule that no audit cycle may be left unaudited, and compliance dashboards that must be available for SEBI onsite inspection. That is a weaker stick than a fine schedule and a stronger one than it looks, because it puts a named individual's signature on every submission.
FAQ
How eCorpIT can help
eCorpIT is a Gurugram-based technology consulting organisation, founded in 2021, and our senior engineering teams build the systems that make frameworks like CSCRF evidenceable rather than aspirational: control registers keyed to the framework's own identifiers, SBOM generation wired into the build pipeline, disaster-recovery architecture tested against a two-hour RTO, and automated evidence dashboards that feed the Cyber Capability Index without a fortnight of manual collection. We are CMMI Level 5, MSME certified and ISO 27001:2022 certified, and we design applications aligned with CSCRF, DPDP Act and CERT-In requirements as an engineering discipline rather than a document exercise. We work with AWS, Microsoft and Google as partners across the delivery stack. If you are a SEBI-regulated entity sizing this programme, start at /contact-us/ and we will scope it against your category.
References
- SEBI, Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024.
- SEBI, CSCRF framework document, version 1.0, 205 pages, August 2024.
- SEBI, Technical Clarifications to CSCRF for SEBI Regulated Entities, 28 August 2025.
- SEBI, Clarifications to CSCRF for SEBI Regulated Entities, April 2025.
- SEBI, Extension towards Adoption and Implementation of CSCRF, 30 June 2025.
- SEBI, Frequently Asked Questions on CSCRF, June 2025.
- SEBI, Consultation Paper on Consolidated Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities, July 2023.
- CAalley, SEBI circular text: technical clarifications to CSCRF, 28 August 2025.
- Association of Portfolio Managers in India, Cybersecurity and Cyber Resilience Framework (CSCRF) presentation, retrieved 6 August 2026.
- vCISOdesk, SEBI CSCRF implementation guide for regulated entities, retrieved 6 August 2026.
- CyberNX, SEBI CSCRF explained, retrieved 6 August 2026.
- Eventus Security, SEBI CSCRF compliance guide, retrieved 6 August 2026.
_Last updated: 6 August 2026._