SEBI CSCRF Compliance for Stock Brokers

SEBI CSCRF Compliance for Stock Brokers guide

SEBI CSCRF Compliance for Stock Brokers is no longer a generic cybersecurity checklist. Stock brokers must first determine the correct CSCRF category, then operate the governance, monitoring, VAPT, cyber audit, incident response and evidence requirements that apply to that category.

TL;DR

SEBI CSCRF Compliance for Stock Brokers uses a graded model. For client-based brokers, category is determined using registered clients and annual clientele trading volume, with the higher category applying when the two parameters point to different tiers.

For Qualified Stock Brokers, VAPT and cyber audit are half-yearly regardless of the CSCRF category. Every broker should keep asset inventories, security controls, SOC monitoring, remediation and regulatory evidence continuously ready rather than reconstructing them before an audit.

What SEBI CSCRF Compliance for Stock Brokers actually requires

SEBI’s Cybersecurity and Cyber Resilience Framework creates one common cyber resilience structure for regulated entities, but it does not apply every requirement identically. A stock broker’s obligations depend on its category, operating model and any additional designation such as Qualified Stock Broker.

The framework connects board and senior-management oversight with operational security. That means a broker needs more than policies. It needs current asset visibility, controlled access, secure applications and APIs, vulnerability management, monitoring, incident handling, recovery capability and evidence that each control is actually operating.

The operating model
Five outcomes behind broker cyber resilience
01
Govern risk
02
Protect systems
03
Detect attacks
04
Respond fast
05
Recover safely

SEBI CSCRF Compliance for Stock Brokers: get the category right first

SEBI revised the stock-broker classification in April 2025. Client-based stock brokers are assessed on two independent parameters: total registered clients and annual clientele trading volume. If the two parameters place the broker in different categories, the higher category applies.

The current registered-client count includes active and inactive clients based on unique PAN and excludes clients marked closed in the UCC database. The category is determined at the beginning of the financial year using previous-year data and remains unchanged for that financial year.

Qualified RELargest brokers or brokers meeting the highest applicable threshold.
Mid-size REHigher-volume brokers below the Qualified RE thresholds.
Small-size REGrowing brokers with a meaningful client base or annual trading volume.
Self-certification RESmaller covered brokers following the proportionate assurance route.
Parameter Self-certification Small-size Mid-size Qualified
Total registered clients More than 1,000 and up to 10,000 More than 10,000 and up to 1 lakh More than 1 lakh and up to 10 lakh More than 10 lakh
Clientele trading volume in a financial year More than ₹1,000 crore and up to ₹10,000 crore More than ₹10,000 crore and up to ₹1 lakh crore More than ₹1 lakh crore and up to ₹10 lakh crore More than ₹10 lakh crore

Stock brokers with less than ₹1,000 crore of annual clientele trading volume and fewer than 1,000 registered clients are exempt from CSCRF under the April 2025 clarification. Proprietary-only brokers use a separate collateral or assets-with-clearing-corporations threshold. A broker that also operates as a Depository Participant should check the highest category triggered by its registrations.

7 easy proven steps for SEBI CSCRF Compliance for Stock Brokers

01

Confirm classification and reporting route

Record the broker model, registered-client count, annual clientele trading volume, proprietary activity, QSB status and any additional SEBI registrations. Keep the classification calculation as audit evidence.

02

Build a complete asset and critical-system inventory

Include trading applications, APIs, cloud resources, endpoints, databases, network devices, privileged identities, third-party connections and cryptographic assets. Identify which systems are critical and obtain the required governance approval.

03

Map each CSCRF clause to a live control

For every applicable requirement, document the control, owner, evidence source, review frequency and exception path. This prevents a policy from being mistaken for proof of implementation.

04

Protect identities, applications and trading infrastructure

Enforce strong authentication, least privilege, secure configuration, patching, application security and network segmentation. Brokers providing algorithmic trading should isolate and secure the perimeter and connectivity around algo-trading servers.

05

Operate continuous monitoring

Centralise security-relevant logs, define alert and escalation rules and ensure suspicious events are investigated. Depending on category and operating model, the broker may use its own SOC, a group SOC, a managed SOC or the Market SOC route.

06

Run VAPT, cyber audit and remediation as one cycle

Scope testing to the real attack surface, record findings by severity, assign owners, close vulnerabilities within the applicable timeline and retain revalidation evidence. Treat testing as an operating control rather than a certificate exercise.

07

Keep incident and recovery evidence ready

Maintain current playbooks, escalation contacts, regulatory reporting routes, backup and recovery evidence, drill results and post-incident actions. SEBI’s CyberSuraksha portal and reporting formats should be checked for the current incident-reporting workflow.

VAPT and cyber audit under SEBI CSCRF Compliance for Stock Brokers

SEBI VAPT requirements are more than a scanner output. The broker should use the applicable CERT-In-empanelled audit route, cover relevant critical systems and attack surfaces, obtain governance approval for the report, track remediation and complete revalidation.

SEBI’s June 2025 FAQs clarify that Qualified Stock Brokers must conduct both VAPT and cyber audit half-yearly, irrespective of the CSCRF category they otherwise fall into. The same FAQs state that non-patch VAPT observations are generally validated against the three-month closure timeline, while high-severity patch-related gaps are tested against the applicable patch-management timeline.

Testing cycle
What a defensible VAPT trail should show
ScopeCritical systems, apps, APIs, cloud, network and other in-scope assets
TestIndependent assessment and penetration testing with evidence
FixOwners, deadlines, risk treatment and verified remediation
ProveRetest, closure record, approvals and submission evidence

SOC and Market SOC for stock brokers

A SOC or Market SOC is the operational layer that turns logs into detection and response. The important compliance question is not only where the SOC runs. It is whether the right systems send telemetry, alerts are investigated, escalation works and records can prove what happened.

Smaller brokers should not assume that using Market SOC transfers responsibility. The broker remains accountable for asset coverage, onboarding the required log sources, investigating escalations, closing findings and maintaining evidence of response.

SEBI CSCRF Compliance for Stock Brokers: evidence checklist

The strongest compliance file connects each requirement to operating proof. Evidence should be dated, attributable and retrievable without rebuilding the story months later.

Control areaUseful evidence
GovernanceApproved policies, classification note, committee records, risk decisions and exception approvals
Assets and accessAsset inventory, critical-system approval, user reviews, MFA evidence and privileged-access records
Security operationsLog-source coverage, alerts, investigation tickets, escalation records and incident timelines
VAPT and patchesScope, report, severity, remediation owner, patch record, retest and closure validation
ResilienceBackup results, restore tests, recovery objectives, drills and post-exercise actions
Third partiesDue diligence, contractual security terms, risk reviews, audit rights and closure tracking

The mistakes that lower broker readiness

  • Using the old active-client classification. The April 2025 model uses total registered clients and annual clientele trading volume, with later clarification on how registered clients are counted.
  • Assuming the lower of two thresholds applies. When client count and trading volume lead to different categories, the higher category governs.
  • Running VAPT on only the public website. Trading apps, APIs, cloud, network, mobile and connected critical systems may all matter to the real scope.
  • Treating Market SOC as outsourced accountability. Shared monitoring can provide capability, but the broker still owns coverage, response and compliance evidence.
  • Closing findings without revalidation. A ticket marked done is weaker than proof that the exploit path or vulnerable condition was actually removed.
One platform, continuous proof

Run security and CSCRF evidence together.

Osto brings cloud, endpoint, network, code, VAPT and compliance workflows into one platform so stock brokers can keep controls, findings, remediation and evidence connected between audits.

Book a Demo →

Frequently asked questions

Does CSCRF apply to every stock broker?

Not identically. Client-based brokers are classified using total registered clients and annual clientele trading volume. The April 2025 clarification exempts brokers below both the stated minimum client and trading-volume thresholds. Proprietary-only brokers use a separate categorisation route.

How is a client-based stock broker classified under CSCRF?

SEBI applies the registered-client and annual clientele trading-volume parameters independently. If they produce different categories, the higher category applies. The category is fixed at the beginning of the financial year based on the previous financial year’s data.

How often must a Qualified Stock Broker conduct VAPT?

SEBI’s June 2025 FAQs clarify that Qualified Stock Brokers conduct VAPT and cyber audit half-yearly regardless of the CSCRF category they otherwise fall into.

Can a stock broker use Market SOC?

Yes, where applicable. Market SOC can provide shared monitoring capability, but the broker remains responsible for correct onboarding, telemetry coverage, investigation, remediation and compliance evidence.

Is a stock broker that is also a Depository Participant assessed separately?

The broker should evaluate all registrations and apply the highest relevant CSCRF category. A Depository Participant that is also registered as a stock broker is classified using the stock-broker criteria for that DP route.

What is the first step in SEBI CSCRF Compliance for Stock Brokers?

Start with a documented classification and applicability note. Record the broker model, client count, trading volume, proprietary activity, QSB status, other registrations, applicable controls and reporting authority before implementing or testing controls.

Primary regulatory references: SEBI CSCRF, 20 August 2024; SEBI clarification, 30 April 2025; SEBI CSCRF FAQs, 11 June 2025; technical clarifications, 28 August 2025; and the current SEBI CyberSuraksha portal. Confirm current applicability for the broker before relying on this guide as a compliance interpretation.