SEBI CSCRF Compliance for Stock Brokers is no longer a generic cybersecurity checklist. Stock brokers must first determine the correct CSCRF category, then operate the governance, monitoring, VAPT, cyber audit, incident response and evidence requirements that apply to that category.
TL;DR
SEBI CSCRF Compliance for Stock Brokers uses a graded model. For client-based brokers, category is determined using registered clients and annual clientele trading volume, with the higher category applying when the two parameters point to different tiers.
For Qualified Stock Brokers, VAPT and cyber audit are half-yearly regardless of the CSCRF category. Every broker should keep asset inventories, security controls, SOC monitoring, remediation and regulatory evidence continuously ready rather than reconstructing them before an audit.
What SEBI CSCRF Compliance for Stock Brokers actually requires
SEBI’s Cybersecurity and Cyber Resilience Framework creates one common cyber resilience structure for regulated entities, but it does not apply every requirement identically. A stock broker’s obligations depend on its category, operating model and any additional designation such as Qualified Stock Broker.
The framework connects board and senior-management oversight with operational security. That means a broker needs more than policies. It needs current asset visibility, controlled access, secure applications and APIs, vulnerability management, monitoring, incident handling, recovery capability and evidence that each control is actually operating.
SEBI CSCRF Compliance for Stock Brokers: get the category right first
SEBI revised the stock-broker classification in April 2025. Client-based stock brokers are assessed on two independent parameters: total registered clients and annual clientele trading volume. If the two parameters place the broker in different categories, the higher category applies.
The current registered-client count includes active and inactive clients based on unique PAN and excludes clients marked closed in the UCC database. The category is determined at the beginning of the financial year using previous-year data and remains unchanged for that financial year.
| Parameter | Self-certification | Small-size | Mid-size | Qualified |
|---|---|---|---|---|
| Total registered clients | More than 1,000 and up to 10,000 | More than 10,000 and up to 1 lakh | More than 1 lakh and up to 10 lakh | More than 10 lakh |
| Clientele trading volume in a financial year | More than ₹1,000 crore and up to ₹10,000 crore | More than ₹10,000 crore and up to ₹1 lakh crore | More than ₹1 lakh crore and up to ₹10 lakh crore | More than ₹10 lakh crore |
Stock brokers with less than ₹1,000 crore of annual clientele trading volume and fewer than 1,000 registered clients are exempt from CSCRF under the April 2025 clarification. Proprietary-only brokers use a separate collateral or assets-with-clearing-corporations threshold. A broker that also operates as a Depository Participant should check the highest category triggered by its registrations.
7 easy proven steps for SEBI CSCRF Compliance for Stock Brokers
Confirm classification and reporting route
Record the broker model, registered-client count, annual clientele trading volume, proprietary activity, QSB status and any additional SEBI registrations. Keep the classification calculation as audit evidence.
Build a complete asset and critical-system inventory
Include trading applications, APIs, cloud resources, endpoints, databases, network devices, privileged identities, third-party connections and cryptographic assets. Identify which systems are critical and obtain the required governance approval.
Map each CSCRF clause to a live control
For every applicable requirement, document the control, owner, evidence source, review frequency and exception path. This prevents a policy from being mistaken for proof of implementation.
Protect identities, applications and trading infrastructure
Enforce strong authentication, least privilege, secure configuration, patching, application security and network segmentation. Brokers providing algorithmic trading should isolate and secure the perimeter and connectivity around algo-trading servers.
Operate continuous monitoring
Centralise security-relevant logs, define alert and escalation rules and ensure suspicious events are investigated. Depending on category and operating model, the broker may use its own SOC, a group SOC, a managed SOC or the Market SOC route.
Run VAPT, cyber audit and remediation as one cycle
Scope testing to the real attack surface, record findings by severity, assign owners, close vulnerabilities within the applicable timeline and retain revalidation evidence. Treat testing as an operating control rather than a certificate exercise.
Keep incident and recovery evidence ready
Maintain current playbooks, escalation contacts, regulatory reporting routes, backup and recovery evidence, drill results and post-incident actions. SEBI’s CyberSuraksha portal and reporting formats should be checked for the current incident-reporting workflow.
VAPT and cyber audit under SEBI CSCRF Compliance for Stock Brokers
SEBI VAPT requirements are more than a scanner output. The broker should use the applicable CERT-In-empanelled audit route, cover relevant critical systems and attack surfaces, obtain governance approval for the report, track remediation and complete revalidation.
SEBI’s June 2025 FAQs clarify that Qualified Stock Brokers must conduct both VAPT and cyber audit half-yearly, irrespective of the CSCRF category they otherwise fall into. The same FAQs state that non-patch VAPT observations are generally validated against the three-month closure timeline, while high-severity patch-related gaps are tested against the applicable patch-management timeline.
SOC and Market SOC for stock brokers
A SOC or Market SOC is the operational layer that turns logs into detection and response. The important compliance question is not only where the SOC runs. It is whether the right systems send telemetry, alerts are investigated, escalation works and records can prove what happened.
Smaller brokers should not assume that using Market SOC transfers responsibility. The broker remains accountable for asset coverage, onboarding the required log sources, investigating escalations, closing findings and maintaining evidence of response.
SEBI CSCRF Compliance for Stock Brokers: evidence checklist
The strongest compliance file connects each requirement to operating proof. Evidence should be dated, attributable and retrievable without rebuilding the story months later.
| Control area | Useful evidence |
|---|---|
| Governance | Approved policies, classification note, committee records, risk decisions and exception approvals |
| Assets and access | Asset inventory, critical-system approval, user reviews, MFA evidence and privileged-access records |
| Security operations | Log-source coverage, alerts, investigation tickets, escalation records and incident timelines |
| VAPT and patches | Scope, report, severity, remediation owner, patch record, retest and closure validation |
| Resilience | Backup results, restore tests, recovery objectives, drills and post-exercise actions |
| Third parties | Due diligence, contractual security terms, risk reviews, audit rights and closure tracking |
The mistakes that lower broker readiness
- Using the old active-client classification. The April 2025 model uses total registered clients and annual clientele trading volume, with later clarification on how registered clients are counted.
- Assuming the lower of two thresholds applies. When client count and trading volume lead to different categories, the higher category governs.
- Running VAPT on only the public website. Trading apps, APIs, cloud, network, mobile and connected critical systems may all matter to the real scope.
- Treating Market SOC as outsourced accountability. Shared monitoring can provide capability, but the broker still owns coverage, response and compliance evidence.
- Closing findings without revalidation. A ticket marked done is weaker than proof that the exploit path or vulnerable condition was actually removed.
Run security and CSCRF evidence together.
Osto brings cloud, endpoint, network, code, VAPT and compliance workflows into one platform so stock brokers can keep controls, findings, remediation and evidence connected between audits.
Book a Demo →Frequently asked questions
Does CSCRF apply to every stock broker?
Not identically. Client-based brokers are classified using total registered clients and annual clientele trading volume. The April 2025 clarification exempts brokers below both the stated minimum client and trading-volume thresholds. Proprietary-only brokers use a separate categorisation route.
How is a client-based stock broker classified under CSCRF?
SEBI applies the registered-client and annual clientele trading-volume parameters independently. If they produce different categories, the higher category applies. The category is fixed at the beginning of the financial year based on the previous financial year’s data.
How often must a Qualified Stock Broker conduct VAPT?
SEBI’s June 2025 FAQs clarify that Qualified Stock Brokers conduct VAPT and cyber audit half-yearly regardless of the CSCRF category they otherwise fall into.
Can a stock broker use Market SOC?
Yes, where applicable. Market SOC can provide shared monitoring capability, but the broker remains responsible for correct onboarding, telemetry coverage, investigation, remediation and compliance evidence.
Is a stock broker that is also a Depository Participant assessed separately?
The broker should evaluate all registrations and apply the highest relevant CSCRF category. A Depository Participant that is also registered as a stock broker is classified using the stock-broker criteria for that DP route.
What is the first step in SEBI CSCRF Compliance for Stock Brokers?
Start with a documented classification and applicability note. Record the broker model, client count, trading volume, proprietary activity, QSB status, other registrations, applicable controls and reporting authority before implementing or testing controls.

