SEBI CSCRF Compliance is now an operating requirement for regulated entities, covering governance, critical systems, continuous monitoring, VAPT, incident response, recovery and evidence. The practical challenge is not reading one circular. It is keeping the right controls live and proving that they work.
TL;DR
SEBI CSCRF Compliance requires a regulated entity to confirm its category, maintain current asset and risk inventories, operate appropriate security controls and SOC monitoring, conduct prescribed VAPT and cyber audits, report incidents on time, test recovery and retain audit-ready evidence.
Start with applicability. SEBI uses a graded model, so the exact control depth and assurance cadence depend on the entity type and category.
What SEBI CSCRF Compliance actually means
The Cybersecurity and Cyber Resilience Framework gives SEBI-regulated entities a common cybersecurity structure. It links governance, asset management, identity and access, application and API security, cloud and supplier risk, vulnerability management, monitoring, incident response and recovery.
The framework is designed around five resilience outcomes. A regulated entity should be able to anticipate risk, withstand disruption, contain an incident, recover critical services and improve after the event.
This is why SEBI CSCRF Compliance cannot be demonstrated with policies alone. An access-control policy needs operating evidence such as MFA configuration, access reviews and privileged-access records. A vulnerability policy needs asset coverage, testing results, remediation and verified closure.
On mobile, the same diagram stacks into two columns for readability.
Who is covered by SEBI CSCRF?
The framework applies across a wide range of securities-market participants. This includes market infrastructure institutions and intermediaries such as stock brokers, mutual funds, portfolio managers, investment advisers, custodians and Depository Participants. The exact obligations depend on how the entity is classified.
Classification affects control depth, audit frequency and the assurance route. Before building a checklist, confirm the current category against SEBI’s latest circulars and any entity-specific instructions. The Osto glossary on SEBI Regulated Entities explains the distinction between entity type and CSCRF category.
9 critical steps for SEBI CSCRF Compliance
Confirm applicability and category
Record the legal entity, SEBI registration, RE type, CSCRF category, reporting route and applicable assurance cadence. This becomes the basis for the rest of the programme.
Map critical assets and dependencies
Maintain an inventory covering applications, APIs, cloud workloads, endpoints, networks, databases, third-party services and critical business dependencies.
Assign governance and ownership
Define accountable owners for cybersecurity risk, IT Committee review, policy approval, exceptions, audit findings, incidents and regulatory reporting.
Protect identities, systems and data
Translate the framework into operating controls such as MFA, least privilege, secure configuration, endpoint protection, encryption, application security, API protection and software-supply-chain controls.
Operate continuous security monitoring
Use the SOC model applicable to the entity and ensure critical telemetry is connected. The SOC and Market SOC glossary explains the recognised operating models and the accountability that remains with the RE.
Run vulnerability management continuously
Keep scanning, patching and configuration review active throughout the year so critical findings do not accumulate between formal assurance cycles.
Complete VAPT and revalidation
Test the full in-scope attack surface, track findings by severity, close them within the applicable timeline and retain evidence of retesting. See the Osto glossary on SEBI VAPT requirements for scope and process detail.
Prepare incident reporting before an incident
Define who decides whether an event is reportable, who approves notification, which authorities must be contacted and what evidence must be preserved.
Keep evidence audit-ready
Retain approvals, inventories, access reviews, SOC records, VAPT reports, cyber-audit findings, remediation evidence, incident records and recovery-test results as the work happens.
VAPT and cyber-audit timelines under SEBI CSCRF Compliance
VAPT is one of the most visible assurance requirements, but a compliant cycle includes more than a scanner report. Scope, auditor route, management review, remediation and revalidation all matter.
A cyber audit is separate from VAPT. VAPT tests weaknesses and exploitability. The cyber audit tests compliance with the applicable control framework. Frequency depends on the RE category and, for some entities, the services they provide.
Practical SEBI CSCRF Compliance checklist
| Area | What to verify | Evidence |
|---|---|---|
| Applicability | Correct RE category and reporting route | Applicability note and classification rationale |
| Assets | Complete inventory and critical-system mapping | Asset register, owners, architecture |
| Access | MFA, least privilege and periodic reviews | Configurations, approvals, review logs |
| Monitoring | Critical telemetry reaches the selected SOC model | Coverage, alerts, cases, escalation records |
| VAPT | Scope, frequency, remediation and revalidation | Reports, tickets, retest evidence |
| Cyber audit | Applicable controls tested at the right cadence | Audit report and closure register |
| Incidents | Escalation and reporting workflow is usable | IR plan, exercises, notifications |
| Recovery | Critical services can be restored and tested | BCP/DR results and action items |
Five mistakes that weaken SEBI CSCRF Compliance
- Starting with a generic checklist. The entity category should determine the requirement set, not the other way around.
- Buying tools without proving coverage. A SIEM, EDR or scanner is useful only when it covers the in-scope systems, is monitored and produces usable evidence.
- Testing an incomplete attack surface. A clean report is misleading if APIs, cloud assets or critical integrations were missing from scope.
- Closing findings without retesting. Remediation is stronger when closure is independently revalidated and retained as evidence.
- Preparing evidence only before an audit. Reconstructing months of approvals and logs creates avoidable gaps and slows remediation.
Turn CSCRF from a checklist into a working security programme
For lean security and compliance teams, the hard part is usually fragmentation. One tool protects applications, another monitors endpoints, another scans cloud posture, a separate vendor runs VAPT, and evidence is rebuilt in spreadsheets before every audit.
Osto brings security and compliance into one operating layer across cloud, code, endpoints, networks, applications and evidence. That gives teams a clearer path from requirement to live control, finding, owner and verified closure.
Make SEBI CSCRF Compliance easier to operate.
See how Osto can connect security controls, VAPT, remediation and audit-ready evidence across one platform.
Book a Demo →Frequently asked questions
What is SEBI CSCRF Compliance?
SEBI CSCRF Compliance is the process of implementing and evidencing the cybersecurity and cyber-resilience requirements that apply to a SEBI-regulated entity under the CSCRF and subsequent clarifications.
What are the five CSCRF categories?
The broad categories are Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The applicable requirements vary by category.
Does every regulated entity need a SOC?
CSCRF requires appropriate security monitoring. Depending on category and operating model, an RE may use its own SOC, a group SOC, the Market SOC or another managed SOC route, subject to current SEBI instructions.
How often is VAPT required?
The frequency depends on applicability and criticality. Most covered REs have an annual cycle, while protected systems or Critical Information Infrastructure can have higher-frequency requirements. Always verify the current SEBI instructions for the entity.
Is VAPT the same as a cyber audit?
No. VAPT tests vulnerabilities and exploitability across technical assets. A cyber audit assesses whether the regulated entity meets the applicable CSCRF control requirements.
How quickly must certain cyber incidents be reported?
For incidents falling under CERT-In cybersecurity directions, CSCRF includes a six-hour notification requirement to SEBI and CERT-In after detection or notice. Teams should also use SEBI’s current Cyber Incident Reporting Portal process.
Is ISO 27001 enough for SEBI CSCRF Compliance?
No. ISO 27001 can support the management-system layer, but it does not replace direct mapping, implementation and evidence against the CSCRF requirements that apply to the RE.

