+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

SEBI's CSCRF: what it asks of your systems

Security By Mits Engineering Team 2 min read
SEBI's CSCRF: what it asks of your systems

SEBI's Cybersecurity and Cyber Resilience Framework arrived as circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 on 20 August 2024, and has been amended twice since — on 30 April 2025 and 28 August 2025. It applies to twenty-two categories of regulated entity, spanning stock exchanges, clearing corporations, depositories, brokers, asset managers, custodians and alternative investment fund managers. If you build or operate software for any of them, the framework is now part of your delivery obligations whether or not it is named in the contract.

The single most important thing to establish before any scoping conversation is which of five tiers the entity sits in, because the obligations differ enormously. Market Infrastructure Institutions — the exchanges, depositories and clearing corporations — sit at the top. Qualified regulated entities include large brokers, defined since the April 2025 amendment by client count above ten lakh or trading volume above ten lakh crore, along with KYC registration agencies and major custodians. Below them sit mid-size, small-size and self-certification entities.

For MIIs and qualified entities the cadence is demanding: vulnerability assessment and penetration testing twice a year by a CERT-In empanelled auditor, cyber audit twice a year, red teaming and cyber drills half-yearly, threat hunting quarterly, and hardware security modules required. Mid-size entities face annual VAPT and cyber audit, an annual cyber drill and a mandatory IT committee. Small-size and self-certification entities have annual testing with a self-certification model. Quoting a mid-size scope to a qualified entity, or the reverse, is the commonest and most expensive mistake in this space.

Two amendments are worth knowing because they changed advice that circulated widely. The August 2025 amendment downgraded ISO 27001 from mandatory to recommended for the tiers where it had been required, narrowed the definition of critical systems, and noted that the data localisation requirement has been in abeyance since December 2024. Anyone working from guidance written in late 2024 is likely to be over-specifying, which sounds harmless until a client is quoted for work SEBI no longer requires.

Incident reporting runs to a six-hour deadline to SEBI's incident reporting portal, alongside the separate notification to CERT-In under the April 2022 Directions. Two portals, one clock, and both must be satisfied. As with CERT-In generally, six hours is not a process you can invent during an incident — it needs a named person, a pre-agreed threshold for what counts, and the account credentials known to more than one individual.

The newest layer is SEBI's AI vulnerability detection advisory of May 2026, which asks regulated entities to use AI-based vulnerability assessment tooling where possible and to maintain a software bill of materials for all critical applications. The SBOM requirement is the one with real engineering consequences: producing an accurate, current inventory of every component in a system is straightforward if built into the pipeline and painful if reconstructed on demand. Building it now is considerably cheaper than being asked for it later.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security