SOC and Market SOC: Meaning and SEBI Requirements

SEBI SOC and Market SOC model for continuous monitoring of regulated entities

A Security Operations Centre watches an organisation’s systems continuously; a Market SOC provides that monitoring as shared securities-market infrastructure for participating SEBI Regulated Entities.

  • Glossary
  • SEBI compliance
  • Threat detection

The short answer

A Security Operations Centre (SOC) combines people, processes and technology to monitor security events, investigate suspicious activity and coordinate response. Under SEBI’s CSCRF, an RE may use its own or group SOC, the Market SOC, or another managed SOC. The Market SOC is shared infrastructure established mandatorily by NSE and BSE and optionally by NSDL or CDSL to give participating REs access to robust, cost-effective monitoring. Using it does not transfer the RE’s compliance accountability.

A SOC is not simply a room or a dashboard. Its value comes from continuous telemetry, detection logic, trained analysts, defined escalation, incident playbooks and evidence showing that alerts were investigated on time.

What does a Security Operations Centre do?

Observe

Continuous visibility

Collect security events from endpoints, networks, cloud, applications, identity systems and suppliers.

Decide

Detection and investigation

Correlate signals, filter noise and determine whether an anomaly is a real incident.

Act

Contain and escalate

Run playbooks, preserve evidence, notify owners and coordinate containment and reporting.

The SOC turns raw telemetry into decisions. A SIEM may collect and correlate logs, while EDR, WAF, cloud and identity controls provide signals and response actions. The SOC is the operating function that brings those tools, analysts and procedures together.

Core functionPractical outcome
Continuous monitoringWatch endpoints and networks around the clock for abnormal or suspicious behaviour.
Log managementCollect, retain and review logs needed for detection, investigation and regulatory evidence.
Detection and triagePrioritise alerts by severity, context and potential impact rather than treating every event equally.
InvestigationReconstruct what happened, which assets or accounts were affected and whether the threat persists.
Incident responseContain the event, coordinate remediation and trigger the RE’s escalation and reporting process.
Threat intelligenceUse known attacker indicators and behaviour to improve detection rules and threat hunting.

What is a Market SOC under SEBI?

The Market SOC is a shared SOC route created under CSCRF for the securities-market ecosystem. NSE and BSE must set up the service; NSDL and CDSL may also do so. Its purpose is to bridge the technology and capability gap for smaller REs and make robust monitoring available at a proportionate cost.

MARKET SOCshared monitoring and response capabilityDetectRespondSmall-size REsparticipating entitiesSelf-certification REsparticipating entitiesOther participating REsas applicableMarket providersNSE · BSE · NSDL/CDSLShared operations support the RE; accountability remains with the RE.
Swipe to see the full diagram. The Market SOC centralises capability while each RE retains ownership of its systems, decisions and compliance.

Market SOC is a delivery model, not a regulator

It supplies monitoring and related services within the CSCRF structure. The participating RE must still maintain governance, give the SOC appropriate visibility, respond to alerts, make regulatory decisions and prove compliance.

The SOC models CSCRF permits

ModelWho operates itBest fit and trade-off
RE’s own SOCThe regulated entity’s internal team and technology.Maximum control and context, with the highest staffing and operating burden.
Group SOCA shared function within the RE’s corporate group.Centralises expertise across group entities, provided responsibilities, access and segregation are clear.
Market SOCMarket-level service established by NSE/BSE and optionally NSDL/CDSL.Bridges the capability and cost gap for participating REs, especially smaller entities.
Third-party managed SOCAn external managed-security provider.Provides specialist monitoring without a large internal team; oversight, contracts and integration remain essential.

Box Item 11 of CSCRF states that SOC is mandated for REs, with a stated exception for client-based stock brokers having fewer than 100 clients. It also states that Small-size and Self-certification REs are to be onboarded to the Market SOC model. The exact applicability should be confirmed against the entity’s category and current SEBI instructions.

What must SOC monitoring cover?

CSCRF expects the SOC to be up and running 24×7×365 and to monitor, prevent, predict, detect, investigate and respond to cyber threats. Coverage is wider than servers and firewall logs.

Telemetry areaExamples of events the SOC should see
Network and security devicesConnections, blocked traffic, unusual destinations, policy changes and segmentation violations.
EndpointsMalware, suspicious processes, privilege escalation, device isolation and policy violations through EDR.
Identity and personnel activityFailed logins, impossible travel, new admins, MFA anomalies and unauthorised access.
Applications and APIsAttack attempts, authentication abuse, sensitive actions and unusual request patterns from WAF and API security.
Cloud and dataRisky configuration changes, public exposure, excessive permissions and sensitive-data movement.
Third partiesProvider activity, remote access, service anomalies and events affecting outsourced systems or dependencies.
Physical and unauthorised assetsUnauthorised personnel, devices, connections, software or mobile code affecting the environment.

Coverage must match the asset inventory

A SOC cannot detect an incident on an asset that never sends telemetry. Reconcile onboarding against current endpoints, systems, applications, APIs, cloud accounts, network devices and service providers—and track blind spots to closure.

How a SOC turns an event into a response

COLLECTlogs andtelemetryCORRELATEjoin relatedsignalsTRIAGEseverity andpriorityINVESTIGATEscope, causeand impactRESPONDcontain andescalateIMPROVEtune rules andplaybooksEvery stage should leave a timestamped record, owner and outcome.
Swipe to see the full workflow. Detection is effective only when an alert moves through a tested decision and response process.

Roles and responsibilities for detection must be defined, and detection processes should be tested through playbooks and use cases. Threat hunting and compromise assessment complement automated alerts by looking for attacker behaviour that existing rules did not flag.

What the Market SOC does not transfer

Market SOC can provideThe participating RE still owns
Monitoring infrastructure, analysts, alerting and shared detection capability.Accurate asset onboarding, access, data classification and business context.
Alert triage, investigation support and recommended actions.Decision rights, containment approval, operational remediation and continuity.
Records and dashboards supporting CSCRF monitoring evidence.Governance review, risk acceptance, regulator communication and compliance submissions.
Cost-effective VAPT and cyber-audit access for applicable small and mid-size REs.Correct scope, remediation, closure evidence and use of the prescribed auditor route.

Outsourced operations, retained accountability

CSCRF states expressly that responsibility and accountability for compliance remain with the RE. Contracts and service levels should therefore define telemetry coverage, escalation, evidence access, incident cooperation and exit arrangements clearly.

How SOC efficacy is evidenced

SEBI expects the Market SOC provider to evolve with new controls and guidelines, ensure participating REs adhere to minimum IT and security protocols, undergo annual audit and report functional efficacy. Annexure N measures SOC efficacy across five broad domains.

Efficacy domainWhat it asks
Coverage of assetsAre relevant assets actually monitored by the required SOC technologies?
SOC operationsAre events collected, alerts investigated, cases managed and service levels met?
Personnel competencyDo deployed analysts have sufficient skills, staffing and operating knowledge?
SOC governanceAre ownership, oversight, policies, escalation and assurance clearly defined?
Enrichment and enhancementDoes the SOC improve through intelligence, automation, tuning, hunting and lessons learned?

Useful operational evidence includes telemetry onboarding records, detection-rule inventories, alert timestamps, analyst notes, case severity, escalation records, response actions, false-positive tuning, playbook tests, threat-hunting results and incident reports.

Market SOC onboarding checklist

  1. Confirm applicability. Record the RE category, SOC route and any stated exception or mandatory Market SOC requirement.
  2. Define accountability. Name the RE owner, technical contacts, incident decision-makers and regulatory reporting owner.
  3. Inventory the environment. Include endpoints, networks, cloud, applications, APIs, identities, data stores and third-party connections.
  4. Map telemetry. Identify the exact log or signal source for every in-scope asset and how collection failure is detected.
  5. Agree severity and service levels. Define priority, triage, escalation and response expectations before alerts begin.
  6. Connect playbooks. Align Market SOC actions with the RE’s incident response, crisis management, continuity and reporting procedures.
  7. Test the route. Run scenarios that prove alert delivery, contact availability, investigation access, containment and decision-making.
  8. Review evidence. Make dashboards, cases, reports and retention accessible for IT Committee review, audit and inspection.
  9. Manage change. Add telemetry for every new system and remove or update retired assets without leaving monitoring gaps.
  10. Measure performance. Track coverage, detection time, response time, open cases, recurring alerts and improvement actions.

How Osto supports SOC and Market SOC readiness

Osto generates and correlates security telemetry across endpoints, identities, cloud, applications, APIs, code, networks and data. Because these controls sit in one platform, analysts receive joined context rather than isolated alerts from separate dashboards.

For an RE using a Market SOC or another managed SOC, Osto can provide the preventive and detective control layer that supplies useful telemetry and evidence. Findings from WAF, API protection, endpoint security, CSPM, VAPT and SIEM can be tracked to an owner, response and verified closure.

Continuous security monitoring

Give the SOC signals it can act on

Connect endpoint, cloud, application, API and identity activity with the evidence needed to investigate and respond.

Get a free security assessment

Connected telemetry · Faster investigation · One platform, everything

Frequently asked questions

What does SOC stand for?

SOC stands for Security Operations Centre. It combines analysts, procedures and security technology to monitor, investigate and respond to cyber threats.

What is a Market SOC under SEBI?

It is shared market-level SOC infrastructure established under CSCRF to provide participating regulated entities with robust and cost-effective security monitoring.

Who sets up the Market SOC?

CSCRF requires NSE and BSE to set it up and allows NSDL and CDSL to do so optionally.

Can an RE use its own SOC instead?

CSCRF recognises an RE’s own or group SOC, the Market SOC and another third-party managed SOC as delivery models, subject to the entity’s category and applicable Market SOC onboarding requirement.

Which REs must onboard to the Market SOC?

Box Item 11 states that Small-size and Self-certification category REs are mandated to onboard to the Market SOC. Applicability should be checked against the RE’s current classification and subsequent SEBI instructions.

Does the Market SOC take over the RE’s compliance responsibility?

No. CSCRF expressly keeps responsibility and accountability for compliance with the participating RE.

Does a SOC need to operate continuously?

CSCRF describes the SOC as a 24×7×365 function for monitoring, preventing, predicting, detecting, investigating and responding to cyber threats.

What is the difference between a SOC and a SIEM?

A SIEM is technology for collecting and correlating security events. A SOC is the broader operating function containing people, processes, playbooks and multiple technologies, often including a SIEM.

What should a SOC monitor?

Coverage includes networks, endpoints, physical environment, personnel activity, malicious code, third-party activity and unauthorised personnel, devices, connections and software, along with relevant cloud, application, API and identity signals.

How is Market SOC effectiveness assessed?

CSCRF measures functional efficacy across asset coverage, SOC operations, personnel competency, governance, and enrichment and enhancement. Market SOC providers also undergo audit and periodic reporting.