CSCRF: SEBI Cybersecurity and Cyber Resilience Framework

CSCRF Cybersecurity and Cyber Resilience Framework requirements for SEBI-regulated entities

CSCRF is SEBI’s common cybersecurity rulebook for regulated entities in India’s securities market, covering governance, protection, monitoring, incident response, recovery, audits and reporting.

  • Glossary
  • SEBI compliance
  • Cyber resilience

The short answer

CSCRF stands for Cybersecurity and Cyber Resilience Framework. Issued by SEBI in August 2024, it replaces multiple earlier cybersecurity circulars with one standards-based framework for SEBI-regulated entities. Requirements vary by the entity’s category, but the framework expects every entity to govern cyber risk, identify assets, protect systems, detect attacks, respond quickly and recover services.

CSCRF is not only an IT checklist. It connects board oversight, vendor risk, application and API security, SOC monitoring, incident reporting, cyber audits, VAPT and recovery testing. The evidence must show that these controls operate, not merely that policies exist.

What CSCRF means

Cybersecurity

Prevent and detect

Protect systems, applications, networks, data and users against unauthorised access, disruption and attack.

Cyber resilience

Continue and recover

Maintain critical services during an incident and restore them safely within defined objectives.

Compliance evidence

Prove and report

Use standard reporting, audits, VAPT, incident records and closure evidence to show that controls work.

The framework is standards-based and aligns cyber resilience with CERT-In’s Cyber Crisis Management Plan. It also standardises how regulated entities report compliance and audit outcomes.

Who does CSCRF apply to?

CSCRF covers a wide set of SEBI-regulated entities, including stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, AIFs, portfolio managers, investment advisers, research analysts, merchant bankers, credit rating agencies, custodians, KRAs, RTAs, debenture trustees and other securities-market intermediaries named by SEBI.

CSCRF categoryHow the framework treats it
Market Infrastructure InstitutionsThe most systemically important market institutions, subject to the broadest requirements and CCI assessment.
Qualified REsLarger regulated entities crossing the relevant operational thresholds, also covered by CCI requirements.
Mid-size REsEntities in the middle threshold band, with requirements scaled to their size and exposure.
Small-size REsSmaller entities with a reduced but still substantive control baseline.
Self-certification REsThe smallest category, allowed a simplified compliance route but still required to complete applicable controls and VAPT.

The category changes the depth, not the need for security

CSCRF follows a graded approach based on factors such as client count, trading volume and assets under management. Smaller entities receive proportionate requirements; they are not exempt from cybersecurity or resilience.

The CSCRF operating model

SIX CYBERSECURITY FUNCTIONSGovernanceIdentifyProtectDetectRespondRecoverFIVE RESILIENCE GOALSAnticipateWithstandContainRecoverEvolveSecurity is a cycle: prepare, resist, limit impact, restore service and improve.
Swipe to see the full diagram. The six operating functions organise the controls; the five goals describe the resilience outcome.

Governance assigns ownership and oversight. Identify maps assets, data and risks. Protect deploys controls. Detect monitors for anomalies. Respond contains and manages incidents. Recover restores services and feeds lessons back into the programme.

What the framework requires

Control areaWhat implementation looks like
Governance and riskBoard and IT Committee oversight, named accountability, policies, a current cyber risk assessment, risk treatment and periodic review.
Asset and data managementInventories of hardware, software, information assets and dependencies; data classification, retention and localisation controls.
Identity and accessLeast privilege, segregation of duties, privileged-access governance, periodic access review and multi-factor authentication.
Application and API securitySecure development, separated production and non-production environments, change controls, testing, and API security.
Vulnerability managementScanning, patching, configuration review and VAPT covering infrastructure, web applications, APIs, mobile apps, cloud and segmentation.
Cloud, SaaS and suppliersDue diligence, contractual responsibilities, hosted-service controls, supply-chain risk management and continuous cloud posture monitoring.
Software supply chainMaintain a software bill of materials, manage dependencies and address third-party component risk.
Data protectionEncryption, backups, access controls and data loss prevention appropriate to the data classification.
Security monitoringContinuous event monitoring through an own, group, market or managed SOC, supported by endpoint and network telemetry such as EDR.
Incident and recoveryDocumented response, containment, communications, evidence preservation, recovery plans, exercises and post-incident improvement.

Every regulated entity needs monitoring

CSCRF requires appropriate security monitoring through a Security Operations Centre. The entity may use its own SOC, a group SOC, a market SOC or another managed SOC, depending on its category and operating model.

Where the framework goes beyond a basic security policy

Coverage

Critical systems first

Cyber audits must cover 100% of critical systems and document the sampling approach for non-critical systems.

Testing

Not only web apps

VAPT scope includes infrastructure, APIs, mobile apps, Wi-Fi, databases, cloud implementation and segmentation.

Evidence

Keep the proof

Audit evidence, observations, remediation decisions and closure records may be scrutinised during regulatory inspection.

Incident reporting and cyber audit timelines

6 hoursspecified incidentsSEBI and CERT-In24 hoursportal detail / otherreportable incidents1 monthafter audit completionsubmit final report3 monthsafter report submissionclose findings5 monthsafter cyber auditfollow-on auditThe incident and audit clocks are separate; both require evidence and named ownership.
Swipe to see the full timeline. Exact applicability and reporting route depend on the incident and the RE category.
EventCore CSCRF timeline
CERT-In Directions incident6 hours Notify SEBI and CERT-In after noticing, detecting or being informed of the incident.
SEBI incident portal detail24 hours Submit the necessary incident details through the prescribed portal.
Other cybersecurity incidents24 hours Report to SEBI, CERT-In and NCIIPC where applicable.
Final cyber audit report1 month Submit after cyber-audit completion and IT Committee approval.
Audit finding closure3 months Close observations after report submission, following a graded criticality approach.
Follow-on audit5 months Complete after the original cyber audit.

Do not wait for the reporting clock to start

Six-hour reporting is impossible without a defined severity model, monitored alert sources, current contact details, an escalation matrix and pre-approved reporting steps. Build and rehearse that workflow before an incident.

Cyber Capability Index

MIIs and Qualified REs use the Cyber Capability Index (CCI) to assess cybersecurity preparedness and resilience periodically. The index uses weighted parameters to turn maturity into a measurable score, so progress can be tracked rather than described only in narrative form.

Practical CSCRF readiness checklist

  1. Confirm the entity category. Record why the RE is an MII, Qualified, Mid-size, Small-size or Self-certification entity and map the applicable standards.
  2. Build a compliance matrix. Assign an owner, implementation, evidence source and review frequency to every applicable standard and mandatory guideline.
  3. Inventory assets and data. Include cloud accounts, endpoints, applications, APIs, databases, network devices, vendors, SaaS systems and critical dependencies.
  4. Complete cyber risk assessment. Link priority risks to controls, budgets, owners, due dates and accepted residual risk.
  5. Deploy prevention and detection. Cover identity, endpoints, networks, applications, APIs, cloud posture, email, data and logs.
  6. Establish SOC coverage. Define monitoring scope, alert severity, triage ownership, escalation and evidence retention.
  7. Run complete VAPT. Use the applicable CERT-In-empanelled audit route and cover the entire required scope, not only the public website.
  8. Test response and recovery. Exercise a realistic incident, measure detection and recovery, and record what changed afterwards.
  9. Prepare reporting. Keep SEBI, CERT-In, NCIIPC, exchange and depository routes current, with a workflow capable of meeting six-hour and 24-hour deadlines.
  10. Track audit closure. Route findings through the IT Committee, preserve remediation proof and close observations before the next audit.

How Osto supports CSCRF readiness

Osto brings the technical controls behind CSCRF into one operating view across cloud, applications, APIs, code, endpoints, identities, data and networks. Web application protection, API protection, CSPM, SAST, SBOM, DLP, endpoint detection and vulnerability testing generate evidence while they run.

That evidence can be mapped to the applicable CSCRF standards, assigned to owners and tracked through remediation. Instead of reconstructing the audit trail from separate dashboards and vendor reports, the RE can connect the requirement, the live control, the finding and the closure record.

Free CSCRF readiness assessment

Turn CSCRF controls into live evidence

Map the applicable requirements, deploy the security controls and keep audit-ready evidence across one platform.

Get a free security assessmentBook a platform walkthrough

Security controls · Audit evidence · One platform, everything

Frequently asked questions

What does CSCRF stand for?

CSCRF stands for Cybersecurity and Cyber Resilience Framework. It is SEBI’s consolidated cybersecurity framework for regulated entities in India’s securities market.

Who must comply with CSCRF?

SEBI-regulated entities covered by the framework, including market infrastructure institutions and securities-market intermediaries. The exact requirements depend on the RE’s category and applicable thresholds.

What are the six CSCRF functions?

Governance, Identify, Protect, Detect, Respond and Recover. Together they organise the cybersecurity controls across the full lifecycle.

What are the five cyber resilience goals?

Anticipate, Withstand, Contain, Recover and Evolve. They describe how an entity should prepare for an attack, limit its effect, restore services and improve afterwards.

Does every regulated entity need a SOC?

Every RE needs appropriate security monitoring through a SOC mechanism. Depending on its category and model, it may use its own SOC, a group SOC, a market SOC or a third-party managed SOC.

Does CSCRF require VAPT?

Yes, for applicable entities. The prescribed scope extends beyond a website to infrastructure, applications, APIs, mobile applications, Wi-Fi, network segmentation, operating systems, databases, cloud implementation and configuration.

How quickly must a cyber incident be reported?

Specified incidents falling under CERT-In directions must be notified to SEBI and CERT-In within six hours. Necessary portal details follow within 24 hours, while other cybersecurity incidents generally have a 24-hour reporting requirement. The exact route depends on the entity and incident.

What is the Cyber Capability Index?

CCI is SEBI’s index for rating the cybersecurity preparedness and resilience of MIIs and Qualified REs using weighted maturity parameters.

Is ISO 27001 enough for CSCRF compliance?

No. ISO 27001 provides a strong security-management foundation, but CSCRF adds SEBI-specific categorisation, mandatory controls, reporting formats, incident timelines, audit rules, SOC expectations and CCI requirements.