CSCRF is SEBI’s common cybersecurity rulebook for regulated entities in India’s securities market, covering governance, protection, monitoring, incident response, recovery, audits and reporting.
The short answer
CSCRF stands for Cybersecurity and Cyber Resilience Framework. Issued by SEBI in August 2024, it replaces multiple earlier cybersecurity circulars with one standards-based framework for SEBI-regulated entities. Requirements vary by the entity’s category, but the framework expects every entity to govern cyber risk, identify assets, protect systems, detect attacks, respond quickly and recover services.
CSCRF is not only an IT checklist. It connects board oversight, vendor risk, application and API security, SOC monitoring, incident reporting, cyber audits, VAPT and recovery testing. The evidence must show that these controls operate, not merely that policies exist.
On this page
What CSCRF means
Cybersecurity
Prevent and detect
Protect systems, applications, networks, data and users against unauthorised access, disruption and attack.
Cyber resilience
Continue and recover
Maintain critical services during an incident and restore them safely within defined objectives.
Compliance evidence
Prove and report
Use standard reporting, audits, VAPT, incident records and closure evidence to show that controls work.
The framework is standards-based and aligns cyber resilience with CERT-In’s Cyber Crisis Management Plan. It also standardises how regulated entities report compliance and audit outcomes.
Who does CSCRF apply to?
CSCRF covers a wide set of SEBI-regulated entities, including stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, AIFs, portfolio managers, investment advisers, research analysts, merchant bankers, credit rating agencies, custodians, KRAs, RTAs, debenture trustees and other securities-market intermediaries named by SEBI.
| CSCRF category | How the framework treats it |
|---|---|
| Market Infrastructure Institutions | The most systemically important market institutions, subject to the broadest requirements and CCI assessment. |
| Qualified REs | Larger regulated entities crossing the relevant operational thresholds, also covered by CCI requirements. |
| Mid-size REs | Entities in the middle threshold band, with requirements scaled to their size and exposure. |
| Small-size REs | Smaller entities with a reduced but still substantive control baseline. |
| Self-certification REs | The smallest category, allowed a simplified compliance route but still required to complete applicable controls and VAPT. |
The category changes the depth, not the need for security
CSCRF follows a graded approach based on factors such as client count, trading volume and assets under management. Smaller entities receive proportionate requirements; they are not exempt from cybersecurity or resilience.
The CSCRF operating model
Governance assigns ownership and oversight. Identify maps assets, data and risks. Protect deploys controls. Detect monitors for anomalies. Respond contains and manages incidents. Recover restores services and feeds lessons back into the programme.
What the framework requires
| Control area | What implementation looks like |
|---|---|
| Governance and risk | Board and IT Committee oversight, named accountability, policies, a current cyber risk assessment, risk treatment and periodic review. |
| Asset and data management | Inventories of hardware, software, information assets and dependencies; data classification, retention and localisation controls. |
| Identity and access | Least privilege, segregation of duties, privileged-access governance, periodic access review and multi-factor authentication. |
| Application and API security | Secure development, separated production and non-production environments, change controls, testing, and API security. |
| Vulnerability management | Scanning, patching, configuration review and VAPT covering infrastructure, web applications, APIs, mobile apps, cloud and segmentation. |
| Cloud, SaaS and suppliers | Due diligence, contractual responsibilities, hosted-service controls, supply-chain risk management and continuous cloud posture monitoring. |
| Software supply chain | Maintain a software bill of materials, manage dependencies and address third-party component risk. |
| Data protection | Encryption, backups, access controls and data loss prevention appropriate to the data classification. |
| Security monitoring | Continuous event monitoring through an own, group, market or managed SOC, supported by endpoint and network telemetry such as EDR. |
| Incident and recovery | Documented response, containment, communications, evidence preservation, recovery plans, exercises and post-incident improvement. |
Every regulated entity needs monitoring
CSCRF requires appropriate security monitoring through a Security Operations Centre. The entity may use its own SOC, a group SOC, a market SOC or another managed SOC, depending on its category and operating model.
Where the framework goes beyond a basic security policy
Coverage
Critical systems first
Cyber audits must cover 100% of critical systems and document the sampling approach for non-critical systems.
Testing
Not only web apps
VAPT scope includes infrastructure, APIs, mobile apps, Wi-Fi, databases, cloud implementation and segmentation.
Evidence
Keep the proof
Audit evidence, observations, remediation decisions and closure records may be scrutinised during regulatory inspection.
Incident reporting and cyber audit timelines
| Event | Core CSCRF timeline |
|---|---|
| CERT-In Directions incident | 6 hours Notify SEBI and CERT-In after noticing, detecting or being informed of the incident. |
| SEBI incident portal detail | 24 hours Submit the necessary incident details through the prescribed portal. |
| Other cybersecurity incidents | 24 hours Report to SEBI, CERT-In and NCIIPC where applicable. |
| Final cyber audit report | 1 month Submit after cyber-audit completion and IT Committee approval. |
| Audit finding closure | 3 months Close observations after report submission, following a graded criticality approach. |
| Follow-on audit | 5 months Complete after the original cyber audit. |
Do not wait for the reporting clock to start
Six-hour reporting is impossible without a defined severity model, monitored alert sources, current contact details, an escalation matrix and pre-approved reporting steps. Build and rehearse that workflow before an incident.
Cyber Capability Index
MIIs and Qualified REs use the Cyber Capability Index (CCI) to assess cybersecurity preparedness and resilience periodically. The index uses weighted parameters to turn maturity into a measurable score, so progress can be tracked rather than described only in narrative form.
Practical CSCRF readiness checklist
- Confirm the entity category. Record why the RE is an MII, Qualified, Mid-size, Small-size or Self-certification entity and map the applicable standards.
- Build a compliance matrix. Assign an owner, implementation, evidence source and review frequency to every applicable standard and mandatory guideline.
- Inventory assets and data. Include cloud accounts, endpoints, applications, APIs, databases, network devices, vendors, SaaS systems and critical dependencies.
- Complete cyber risk assessment. Link priority risks to controls, budgets, owners, due dates and accepted residual risk.
- Deploy prevention and detection. Cover identity, endpoints, networks, applications, APIs, cloud posture, email, data and logs.
- Establish SOC coverage. Define monitoring scope, alert severity, triage ownership, escalation and evidence retention.
- Run complete VAPT. Use the applicable CERT-In-empanelled audit route and cover the entire required scope, not only the public website.
- Test response and recovery. Exercise a realistic incident, measure detection and recovery, and record what changed afterwards.
- Prepare reporting. Keep SEBI, CERT-In, NCIIPC, exchange and depository routes current, with a workflow capable of meeting six-hour and 24-hour deadlines.
- Track audit closure. Route findings through the IT Committee, preserve remediation proof and close observations before the next audit.
How Osto supports CSCRF readiness
Osto brings the technical controls behind CSCRF into one operating view across cloud, applications, APIs, code, endpoints, identities, data and networks. Web application protection, API protection, CSPM, SAST, SBOM, DLP, endpoint detection and vulnerability testing generate evidence while they run.
That evidence can be mapped to the applicable CSCRF standards, assigned to owners and tracked through remediation. Instead of reconstructing the audit trail from separate dashboards and vendor reports, the RE can connect the requirement, the live control, the finding and the closure record.
Free CSCRF readiness assessment
Turn CSCRF controls into live evidence
Map the applicable requirements, deploy the security controls and keep audit-ready evidence across one platform.
Get a free security assessmentBook a platform walkthroughSecurity controls · Audit evidence · One platform, everything
Frequently asked questions
What does CSCRF stand for?
CSCRF stands for Cybersecurity and Cyber Resilience Framework. It is SEBI’s consolidated cybersecurity framework for regulated entities in India’s securities market.
Who must comply with CSCRF?
SEBI-regulated entities covered by the framework, including market infrastructure institutions and securities-market intermediaries. The exact requirements depend on the RE’s category and applicable thresholds.
What are the six CSCRF functions?
Governance, Identify, Protect, Detect, Respond and Recover. Together they organise the cybersecurity controls across the full lifecycle.
What are the five cyber resilience goals?
Anticipate, Withstand, Contain, Recover and Evolve. They describe how an entity should prepare for an attack, limit its effect, restore services and improve afterwards.
Does every regulated entity need a SOC?
Every RE needs appropriate security monitoring through a SOC mechanism. Depending on its category and model, it may use its own SOC, a group SOC, a market SOC or a third-party managed SOC.
Does CSCRF require VAPT?
Yes, for applicable entities. The prescribed scope extends beyond a website to infrastructure, applications, APIs, mobile applications, Wi-Fi, network segmentation, operating systems, databases, cloud implementation and configuration.
How quickly must a cyber incident be reported?
Specified incidents falling under CERT-In directions must be notified to SEBI and CERT-In within six hours. Necessary portal details follow within 24 hours, while other cybersecurity incidents generally have a 24-hour reporting requirement. The exact route depends on the entity and incident.
What is the Cyber Capability Index?
CCI is SEBI’s index for rating the cybersecurity preparedness and resilience of MIIs and Qualified REs using weighted maturity parameters.
Is ISO 27001 enough for CSCRF compliance?
No. ISO 27001 provides a strong security-management foundation, but CSCRF adds SEBI-specific categorisation, mandatory controls, reporting formats, incident timelines, audit rules, SOC expectations and CCI requirements.

