SEBI CSCRF compliance for stock brokers turns on two things: your tier and whether you are a Qualified Stock Broker. This guide explains which rules apply to your firm, what the core obligations are, and how to meet them without a large security team.
TL;DR
SEBI CSCRF compliance for stock brokers is set by a two-parameter rule, your client count or trading volume, whichever puts you in the higher CSCRF tier. Brokers below both a client and a volume threshold are exempt. The core duties are governance, a Security Operations Centre, VAPT, six-hour incident reporting to SEBI, and a CERT-In empanelled audit. The critical twist: a Qualified Stock Broker must run VAPT and cyber audit half-yearly, not annually, whichever category it otherwise falls into.
On this page
What SEBI CSCRF compliance for stock brokers means
SEBI CSCRF compliance for stock brokers means meeting the Cybersecurity and Cyber Resilience Framework that the Securities and Exchange Board of India applies across the securities market, as it lands specifically on broking firms. CSCRF replaced the older broker-specific cyber circulars with one standardised framework, and it treats a broker’s trading platform, client-facing applications, and back-office systems as critical systems to be governed, monitored, tested, and audited. For a broker, this is now a board-level, evidence-based obligation, not an IT afterthought.
How your tier is decided
The first step is working out which standard applies to you, because it is proportionate to your size and there is a genuine exemption at the bottom.
SEBI uses a two-parameter rule for brokers: your category is set by your number of clients or your trading volume, whichever places you in the higher tier. A broker below both thresholds, broadly under a client-count line and a trading-volume line, is exempt, but tripping either one brings you in. Above the exemption, your CSCRF category, from the lighter tiers up to Qualified regulated entity, sets how deep your obligations run. Because the category is re-fixed each April on the prior year’s data, a growing broker can move up a tier the next year, so plan ahead.
The core obligations
Whatever your tier, a common set of controls defines the broker obligations. These formalise strong practice into mandatory, evidenced obligations.
In practice that means governance through a technology and cyber committee, a Security Operations Centre for continuous monitoring, whether built in-house or consumed as a managed service, a vulnerability assessment and penetration testing programme across your trading and back-office systems, cyber incident reporting to SEBI within six hours, a cyber audit by a CERT-In empanelled organisation, and documented incident-response plans tested through drills, with records retained for around five years. A structured VAPT programme is usually the fastest way to evidence the testing pillar.
The Qualified Stock Broker rule
Here is the single most important nuance for brokers, and the one most often missed.
A Qualified Stock Broker is a separate designation, created under a 2023 circular rather than under CSCRF, given to the largest and most systemically important brokers. It overrides your CSCRF category for testing purposes: a Qualified Stock Broker must run VAPT and cyber audit on a half-yearly basis, regardless of which CSCRF category it would otherwise fall into. Most other brokers test annually on their category cadence. If your firm is a Qualified Stock Broker, building your compliance calendar around an annual cycle is a mistake that an inspection will catch.
If you are also regulated by the RBI
Many broking groups also hold an NBFC licence, and there is relief here. SEBI’s Principle of Exclusivity and Equivalence lets a genuinely equivalent programme under another regulator satisfy the corresponding CSCRF requirement. In practice, the RBI’s six-monthly vulnerability assessment can meet or exceed the CSCRF VAPT minimum, provided the scope covers the SEBI-regulated systems and the work is done by a CERT-In empanelled auditor. That lets a dual-regulated broker run one coherent testing programme rather than two, an efficient way to approach compliance for brokers that are also NBFCs. The key is that a scan alone will not do, and our guide on VAPT versus vulnerability scanning explains why.
The lean-team path to SEBI CSCRF compliance for stock brokers
Meeting all of this, governance, a SOC, VAPT on the right cadence, six-hour-ready incident reporting, and audit-ready evidence, is a heavy lift for a broking firm without a large security team. Assembling it from separate tools and consultants is slow and hard to keep current. The efficient path is a single platform that runs the security work and organises the evidence together.
Meet SEBI CSCRF compliance for stock brokers without a big team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups and lean financial teams. Run VAPT, stand up monitoring, and keep audit-ready evidence on the right cadence, on one platform. No security team required.
Book a Demo →Frequently asked questions
Does CSCRF apply to all stock brokers?
Not all. Brokers below both a client-count and a trading-volume threshold are exempt. Trip either threshold and the framework applies, at the tier set by whichever parameter is higher.
How is a broker’s CSCRF tier decided?
By a two-parameter rule, your number of clients or your trading volume, whichever puts you in the higher tier. The category is re-fixed each April on the previous year’s data, so a growing broker can move up a tier the next year.
What is a Qualified Stock Broker under CSCRF?
A separate designation for the largest, most systemically important brokers, created under a 2023 circular. It overrides the CSCRF category for testing: a Qualified Stock Broker runs VAPT and cyber audit half-yearly, not annually.
What is the incident reporting timeline for brokers?
Brokers must report cyber incidents to the SEBI incident reporting portal within six hours of detection. The clock runs from detection, so continuous monitoring through a SOC is essential.
Who can conduct a broker’s CSCRF audit?
Only a CERT-In empanelled information-security auditing organisation. The audit covers governance, control testing, VAPT reconciliation, SOC effectiveness, vendor risk, and SBOM, annually for most brokers and half-yearly for Qualified Stock Brokers.
My broking firm is also an NBFC. Do I run two programmes?
Often not. SEBI’s Exclusivity and Equivalence principle lets an equivalent RBI programme satisfy the corresponding CSCRF requirement, so one well-scoped testing programme by a CERT-In empanelled auditor can serve both, provided it covers the SEBI-regulated systems.

