SEBI CSCRF Compliance for Stock Brokers: A Complete Guide

SEBI CSCRF compliance for stock brokers guide
SEBI CSCRF Compliance for Stock Brokers: 6 Critical Rules | Osto

SEBI CSCRF compliance for stock brokers turns on two things: your tier and whether you are a Qualified Stock Broker. This guide explains which rules apply to your firm, what the core obligations are, and how to meet them without a large security team.

Osto Security Team10 min readSEBI Compliance

TL;DR

SEBI CSCRF compliance for stock brokers is set by a two-parameter rule, your client count or trading volume, whichever puts you in the higher CSCRF tier. Brokers below both a client and a volume threshold are exempt. The core duties are governance, a Security Operations Centre, VAPT, six-hour incident reporting to SEBI, and a CERT-In empanelled audit. The critical twist: a Qualified Stock Broker must run VAPT and cyber audit half-yearly, not annually, whichever category it otherwise falls into.

What SEBI CSCRF compliance for stock brokers means

SEBI CSCRF compliance for stock brokers means meeting the Cybersecurity and Cyber Resilience Framework that the Securities and Exchange Board of India applies across the securities market, as it lands specifically on broking firms. CSCRF replaced the older broker-specific cyber circulars with one standardised framework, and it treats a broker’s trading platform, client-facing applications, and back-office systems as critical systems to be governed, monitored, tested, and audited. For a broker, this is now a board-level, evidence-based obligation, not an IT afterthought.

How your tier is decided

The first step is working out which standard applies to you, because it is proportionate to your size and there is a genuine exemption at the bottom.

Who is covered
Thresholds, tiers, and the QSB override
Compliance depends on your size and your designation. A two-parameter rule decides your CSCRF tier, a small-broker exemption sits below it, and the Qualified Stock Broker label overrides your category for testing.
How a broker’s obligations are decided Below both thresholds Under ~1,000 clients and under ~1,000 crore volume. Exempt from CSCRF Trip either one and you are in. In scope, by tier Two-parameter rule: clients or trading volume, whichever puts you in the higher tier. Category sets the standard. Qualified Stock Broker A separate designation that overrides the category for testing. Half-yearly VAPT and audit.

SEBI uses a two-parameter rule for brokers: your category is set by your number of clients or your trading volume, whichever places you in the higher tier. A broker below both thresholds, broadly under a client-count line and a trading-volume line, is exempt, but tripping either one brings you in. Above the exemption, your CSCRF category, from the lighter tiers up to Qualified regulated entity, sets how deep your obligations run. Because the category is re-fixed each April on the prior year’s data, a growing broker can move up a tier the next year, so plan ahead.

Either threshold is enough
The exemption needs you below both the client and the volume line. Cross just one, more clients or more turnover, and SEBI CSCRF compliance for stock brokers applies in full at your tier. A fast-growing broker should watch both numbers, not just headcount.

The core obligations

Whatever your tier, a common set of controls defines the broker obligations. These formalise strong practice into mandatory, evidenced obligations.

The obligations
What brokers actually have to do
Depth scales with tier, but a recognisable core runs through every broker in scope. These are the controls that make up broker compliance in day-to-day practice.
Core obligations for stock brokersGovernanceTechnology and cyber committeeSOC monitoringIn-house or managed, real-timeVAPTOn trading and back-officesystemsSix-hour reportingIncidents to the SEBI portalCERT-In auditEmpanelled auditor, tier-basedcadenceIR and recordsTested drills, records kept fiveyears

In practice that means governance through a technology and cyber committee, a Security Operations Centre for continuous monitoring, whether built in-house or consumed as a managed service, a vulnerability assessment and penetration testing programme across your trading and back-office systems, cyber incident reporting to SEBI within six hours, a cyber audit by a CERT-In empanelled organisation, and documented incident-response plans tested through drills, with records retained for around five years. A structured VAPT programme is usually the fastest way to evidence the testing pillar.

It is an evidence model now
CSCRF shifted from guidance to an evidence-based audit model. For a broker, every control, drill, and report has to produce an artefact on a schedule. Compliance is demonstrated by a series of dated deliverables, not asserted at a single moment.

The Qualified Stock Broker rule

Here is the single most important nuance for brokers, and the one most often missed.

Cadence
Regular broker versus Qualified Stock Broker
One rule catches brokers out more than any other: the Qualified Stock Broker designation changes how often you test, no matter which CSCRF category you sit in.
Testing cadence: regular broker vs QSB Most brokers Annual VAPT and cyber audit, on the cadence set by their CSCRF category. Qualified Stock Brokers Half-yearly VAPT and cyber audit, whichever CSCRF category they otherwise fall in.

A Qualified Stock Broker is a separate designation, created under a 2023 circular rather than under CSCRF, given to the largest and most systemically important brokers. It overrides your CSCRF category for testing purposes: a Qualified Stock Broker must run VAPT and cyber audit on a half-yearly basis, regardless of which CSCRF category it would otherwise fall into. Most other brokers test annually on their category cadence. If your firm is a Qualified Stock Broker, building your compliance calendar around an annual cycle is a mistake that an inspection will catch.

If you are also regulated by the RBI

Many broking groups also hold an NBFC licence, and there is relief here. SEBI’s Principle of Exclusivity and Equivalence lets a genuinely equivalent programme under another regulator satisfy the corresponding CSCRF requirement. In practice, the RBI’s six-monthly vulnerability assessment can meet or exceed the CSCRF VAPT minimum, provided the scope covers the SEBI-regulated systems and the work is done by a CERT-In empanelled auditor. That lets a dual-regulated broker run one coherent testing programme rather than two, an efficient way to approach compliance for brokers that are also NBFCs. The key is that a scan alone will not do, and our guide on VAPT versus vulnerability scanning explains why.

The lean-team path to SEBI CSCRF compliance for stock brokers

Meeting all of this, governance, a SOC, VAPT on the right cadence, six-hour-ready incident reporting, and audit-ready evidence, is a heavy lift for a broking firm without a large security team. Assembling it from separate tools and consultants is slow and hard to keep current. The efficient path is a single platform that runs the security work and organises the evidence together.

Meet SEBI CSCRF compliance for stock brokers without a big team.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups and lean financial teams. Run VAPT, stand up monitoring, and keep audit-ready evidence on the right cadence, on one platform. No security team required.

Book a Demo →

Frequently asked questions

Does CSCRF apply to all stock brokers?

Not all. Brokers below both a client-count and a trading-volume threshold are exempt. Trip either threshold and the framework applies, at the tier set by whichever parameter is higher.

How is a broker’s CSCRF tier decided?

By a two-parameter rule, your number of clients or your trading volume, whichever puts you in the higher tier. The category is re-fixed each April on the previous year’s data, so a growing broker can move up a tier the next year.

What is a Qualified Stock Broker under CSCRF?

A separate designation for the largest, most systemically important brokers, created under a 2023 circular. It overrides the CSCRF category for testing: a Qualified Stock Broker runs VAPT and cyber audit half-yearly, not annually.

What is the incident reporting timeline for brokers?

Brokers must report cyber incidents to the SEBI incident reporting portal within six hours of detection. The clock runs from detection, so continuous monitoring through a SOC is essential.

Who can conduct a broker’s CSCRF audit?

Only a CERT-In empanelled information-security auditing organisation. The audit covers governance, control testing, VAPT reconciliation, SOC effectiveness, vendor risk, and SBOM, annually for most brokers and half-yearly for Qualified Stock Brokers.

My broking firm is also an NBFC. Do I run two programmes?

Often not. SEBI’s Exclusivity and Equivalence principle lets an equivalent RBI programme satisfy the corresponding CSCRF requirement, so one well-scoped testing programme by a CERT-In empanelled auditor can serve both, provided it covers the SEBI-regulated systems.