SEBI CSCRF Compliance: Guide for Regulated Entities

SEBI CSCRF Compliance guide for regulated entities

SEBI CSCRF Compliance is now an operating requirement for regulated entities, covering governance, critical systems, continuous monitoring, VAPT, incident response, recovery and evidence. The practical challenge is not reading one circular. It is keeping the right controls live and proving that they work.

TL;DR

SEBI CSCRF Compliance requires a regulated entity to confirm its category, maintain current asset and risk inventories, operate appropriate security controls and SOC monitoring, conduct prescribed VAPT and cyber audits, report incidents on time, test recovery and retain audit-ready evidence.

Start with applicability. SEBI uses a graded model, so the exact control depth and assurance cadence depend on the entity type and category.

What SEBI CSCRF Compliance actually means

The Cybersecurity and Cyber Resilience Framework gives SEBI-regulated entities a common cybersecurity structure. It links governance, asset management, identity and access, application and API security, cloud and supplier risk, vulnerability management, monitoring, incident response and recovery.

The framework is designed around five resilience outcomes. A regulated entity should be able to anticipate risk, withstand disruption, contain an incident, recover critical services and improve after the event.

Cyber resilience goals
The five outcomes CSCRF expects an RE to build for
01
Anticipate
02
Withstand
03
Contain
04
Recover
05
Evolve

This is why SEBI CSCRF Compliance cannot be demonstrated with policies alone. An access-control policy needs operating evidence such as MFA configuration, access reviews and privileged-access records. A vulnerability policy needs asset coverage, testing results, remediation and verified closure.

CSCRF operating model
Six functions organise the security programme
Governance
Identify
Protect
Detect
Respond
Recover

On mobile, the same diagram stacks into two columns for readability.

Who is covered by SEBI CSCRF?

The framework applies across a wide range of securities-market participants. This includes market infrastructure institutions and intermediaries such as stock brokers, mutual funds, portfolio managers, investment advisers, custodians and Depository Participants. The exact obligations depend on how the entity is classified.

Market Infrastructure Institutions Qualified REs Mid-size REs Small-size REs Self-certification REs

Classification affects control depth, audit frequency and the assurance route. Before building a checklist, confirm the current category against SEBI’s latest circulars and any entity-specific instructions. The Osto glossary on SEBI Regulated Entities explains the distinction between entity type and CSCRF category.

9 critical steps for SEBI CSCRF Compliance

01

Confirm applicability and category

Record the legal entity, SEBI registration, RE type, CSCRF category, reporting route and applicable assurance cadence. This becomes the basis for the rest of the programme.

02

Map critical assets and dependencies

Maintain an inventory covering applications, APIs, cloud workloads, endpoints, networks, databases, third-party services and critical business dependencies.

03

Assign governance and ownership

Define accountable owners for cybersecurity risk, IT Committee review, policy approval, exceptions, audit findings, incidents and regulatory reporting.

04

Protect identities, systems and data

Translate the framework into operating controls such as MFA, least privilege, secure configuration, endpoint protection, encryption, application security, API protection and software-supply-chain controls.

05

Operate continuous security monitoring

Use the SOC model applicable to the entity and ensure critical telemetry is connected. The SOC and Market SOC glossary explains the recognised operating models and the accountability that remains with the RE.

06

Run vulnerability management continuously

Keep scanning, patching and configuration review active throughout the year so critical findings do not accumulate between formal assurance cycles.

07

Complete VAPT and revalidation

Test the full in-scope attack surface, track findings by severity, close them within the applicable timeline and retain evidence of retesting. See the Osto glossary on SEBI VAPT requirements for scope and process detail.

08

Prepare incident reporting before an incident

Define who decides whether an event is reportable, who approves notification, which authorities must be contacted and what evidence must be preserved.

09

Keep evidence audit-ready

Retain approvals, inventories, access reviews, SOC records, VAPT reports, cyber-audit findings, remediation evidence, incident records and recovery-test results as the work happens.

VAPT and cyber-audit timelines under SEBI CSCRF Compliance

VAPT is one of the most visible assurance requirements, but a compliant cycle includes more than a scanner report. Scope, auditor route, management review, remediation and revalidation all matter.

VAPT timeline
Three milestones to keep visible after testing finishes
1 monthSubmit the approved VAPT report after completion.
3 monthsClose observations from report submission using the graded approach.
5 monthsComplete revalidation from the original VAPT completion date.

A cyber audit is separate from VAPT. VAPT tests weaknesses and exploitability. The cyber audit tests compliance with the applicable control framework. Frequency depends on the RE category and, for some entities, the services they provide.

Practical SEBI CSCRF Compliance checklist

AreaWhat to verifyEvidence
ApplicabilityCorrect RE category and reporting routeApplicability note and classification rationale
AssetsComplete inventory and critical-system mappingAsset register, owners, architecture
AccessMFA, least privilege and periodic reviewsConfigurations, approvals, review logs
MonitoringCritical telemetry reaches the selected SOC modelCoverage, alerts, cases, escalation records
VAPTScope, frequency, remediation and revalidationReports, tickets, retest evidence
Cyber auditApplicable controls tested at the right cadenceAudit report and closure register
IncidentsEscalation and reporting workflow is usableIR plan, exercises, notifications
RecoveryCritical services can be restored and testedBCP/DR results and action items

Five mistakes that weaken SEBI CSCRF Compliance

  1. Starting with a generic checklist. The entity category should determine the requirement set, not the other way around.
  2. Buying tools without proving coverage. A SIEM, EDR or scanner is useful only when it covers the in-scope systems, is monitored and produces usable evidence.
  3. Testing an incomplete attack surface. A clean report is misleading if APIs, cloud assets or critical integrations were missing from scope.
  4. Closing findings without retesting. Remediation is stronger when closure is independently revalidated and retained as evidence.
  5. Preparing evidence only before an audit. Reconstructing months of approvals and logs creates avoidable gaps and slows remediation.
The operating layer

Turn CSCRF from a checklist into a working security programme

For lean security and compliance teams, the hard part is usually fragmentation. One tool protects applications, another monitors endpoints, another scans cloud posture, a separate vendor runs VAPT, and evidence is rebuilt in spreadsheets before every audit.

Osto brings security and compliance into one operating layer across cloud, code, endpoints, networks, applications and evidence. That gives teams a clearer path from requirement to live control, finding, owner and verified closure.

SEBI CSCRF readiness

Make SEBI CSCRF Compliance easier to operate.

See how Osto can connect security controls, VAPT, remediation and audit-ready evidence across one platform.

Book a Demo →

Frequently asked questions

What is SEBI CSCRF Compliance?

SEBI CSCRF Compliance is the process of implementing and evidencing the cybersecurity and cyber-resilience requirements that apply to a SEBI-regulated entity under the CSCRF and subsequent clarifications.

What are the five CSCRF categories?

The broad categories are Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The applicable requirements vary by category.

Does every regulated entity need a SOC?

CSCRF requires appropriate security monitoring. Depending on category and operating model, an RE may use its own SOC, a group SOC, the Market SOC or another managed SOC route, subject to current SEBI instructions.

How often is VAPT required?

The frequency depends on applicability and criticality. Most covered REs have an annual cycle, while protected systems or Critical Information Infrastructure can have higher-frequency requirements. Always verify the current SEBI instructions for the entity.

Is VAPT the same as a cyber audit?

No. VAPT tests vulnerabilities and exploitability across technical assets. A cyber audit assesses whether the regulated entity meets the applicable CSCRF control requirements.

How quickly must certain cyber incidents be reported?

For incidents falling under CERT-In cybersecurity directions, CSCRF includes a six-hour notification requirement to SEBI and CERT-In after detection or notice. Teams should also use SEBI’s current Cyber Incident Reporting Portal process.

Is ISO 27001 enough for SEBI CSCRF Compliance?

No. ISO 27001 can support the management-system layer, but it does not replace direct mapping, implementation and evidence against the CSCRF requirements that apply to the RE.

Primary regulatory references: SEBI CSCRF circular, August 20, 2024, SEBI clarification, April 30, 2025 and SEBI technical clarification, August 28, 2025. Applicability should be confirmed for the entity and current date. This guide is not legal advice.