{"id":1016,"date":"2026-08-24T19:35:07","date_gmt":"2026-08-24T19:35:07","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1016"},"modified":"2026-08-24T19:35:07","modified_gmt":"2026-08-24T19:35:07","slug":"resources-glossary-sebi-regulated-entity","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-sebi-regulated-entity\/","title":{"rendered":"Regulated Entity (SEBI): Meaning, Types and Compliance Requirements"},"content":{"rendered":"\n<!-- OSTO GLOSSARY: SEBI Regulated Entity. Paste into one Custom HTML block. Page title is intentionally excluded. -->\n<style>\n.og{--navy:#1c267a;--text:#0f1538;--divider:#eceef5;--white:#fff;--blue-50:#f4f5fd;--blue-100:#e9ecfa;--blue-200:#cfd5f2;--blue-700:#4a52a8;--sage-50:#f2f8f5;--sage-100:#e3f0e9;--sage-200:#c3ddce;--sage-700:#3a6f5d;--apri-50:#fdf6f0;--apri-100:#fbe9dc;--apri-200:#f2cdb2;--apri-700:#a2603a;--sky-50:#f1f7fb;--sky-100:#e2eff7;--sky-200:#bfd9e9;--sky-700:#2f6a89;--shadow:0 6px 22px rgba(15,21,56,.05);font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-size:17px;line-height:1.75;color:var(--text)}\n.og p{margin:0 0 22px}.og h2{font:700 clamp(25px,3vw,31px)\/1.25 'Inter',sans-serif;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}.og h2:after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--blue-200)}.og h2.c-sage:after{background:var(--sage-200)}.og h2.c-apri:after{background:var(--apri-200)}.og h2.c-sky:after{background:var(--sky-200)}.og h3{font:700 20px\/1.4 'Inter',sans-serif;color:var(--navy);margin:28px 0 8px}.og ul,.og ol{padding-left:22px;margin:0 0 24px}.og li{margin-bottom:9px}.og strong{font-weight:600}.og a{color:var(--navy);text-underline-offset:3px}\n.og .dek{font-size:20px;line-height:1.6;margin:0 0 18px}.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}.og .tags li{margin:0}.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}.og .t-blue{background:var(--blue-100);color:var(--blue-700)}.og .t-sage{background:var(--sage-100);color:var(--sage-700)}.og .t-apri{background:var(--apri-100);color:var(--apri-700)}\n.og .short{background:linear-gradient(135deg,var(--blue-100),var(--sage-100));border-radius:22px;padding:28px 32px;margin:0 0 30px}.og .short .k,.og .toc .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--blue-700);margin:0 0 10px}.og .short p{font-size:19px;line-height:1.65;margin:0}.og .toc{background:var(--blue-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}.og .toc a{text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}.og .callout.soft{border:none;border-radius:20px;background:var(--blue-50)}.og .callout.apri{border:none;border-radius:20px;background:var(--apri-50)}.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}.og .callout.apri .k{color:var(--apri-700)}.og .callout p:last-child{margin-bottom:0}\n.og figure{margin:0 0 30px}.og .sx{overflow-x:auto;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}.og .sx svg{display:block;width:100%;height:auto;min-width:650px}.og figcaption{font-size:14px;line-height:1.6;margin-top:12px}.og .swipe{display:none}\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}.og tr:last-child td{border-bottom:none}.og .h-blue th{background:var(--blue-100);color:var(--blue-700)}.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}.og .h-apri th{background:var(--apri-100);color:var(--apri-700)}\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}.og .tcard{border-radius:18px;padding:20px 22px}.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}.og .tcard p{font-size:14px;line-height:1.55;margin:0}.og .tcard.a{background:var(--sky-50)}.og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}.og .tcard.b{background:var(--sage-50)}.og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}.og .tcard.c{background:var(--blue-50)}.og .tcard.c .n,.og .tcard.c .g{color:var(--navy)}\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px}.og summary::-webkit-details-marker{display:none}.og summary:after{content:\"+\";font-size:22px;line-height:1;color:var(--blue-700)}.og details[open] summary:after{content:\"\\2013\"}.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}.og .related{font-size:15px;border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n@media(max-width:700px){.og{font-size:16px}.og .dek{font-size:18px}.og .short p{font-size:17px}.og .short,.og .toc,.og .callout{padding:22px 20px}.og .toc ol{columns:1}.og .trio{grid-template-columns:1fr}.og .swipe{display:inline;font-weight:600;color:var(--blue-700)}.og table{font-size:14px}.og th,.og td{padding:11px 12px}}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">A SEBI Regulated Entity is a securities-market participant that operates under SEBI registration, recognition or supervision and must follow the rules attached to its activity.<\/p>\n<ul class=\"tags\"><li><span class=\"tag t-blue\">Glossary<\/span><\/li><li><span class=\"tag t-sage\">SEBI compliance<\/span><\/li><li><span class=\"tag t-apri\">Securities market<\/span><\/li><\/ul>\n<div class=\"short\"><p class=\"k\">The short answer<\/p><p>A <strong>SEBI Regulated Entity (RE)<\/strong> is an organisation or person that SEBI registers, recognises or otherwise regulates for carrying out a securities-market activity. Stock exchanges, clearing corporations, depositories, brokers, mutual funds, portfolio managers, investment advisers and several other intermediaries can be REs. \u201cRE\u201d is an umbrella label: the licence, duties and reporting route depend on what the entity does and which SEBI regulation, circular or framework applies.<\/p><\/div>\n<p>Being a regulated entity affects more than permission to enter the market. It creates continuing obligations around governance, investor protection, books and records, disclosures, grievance handling, outsourcing, technology risk, cybersecurity, audits and regulatory reporting. The precise combination is different for each entity type.<\/p>\n<div class=\"toc\"><p class=\"k\">On this page<\/p><ol><li><a href=\"#meaning\">What a SEBI RE means<\/a><\/li><li><a href=\"#types\">Who counts as an RE<\/a><\/li><li><a href=\"#terms\">RE, intermediary and MII<\/a><\/li><li><a href=\"#obligations\">How obligations are decided<\/a><\/li><li><a href=\"#cscrf\">RE categories under CSCRF<\/a><\/li><li><a href=\"#security\">Security responsibilities<\/a><\/li><li><a href=\"#checklist\">Practical checklist<\/a><\/li><li><a href=\"#osto\">How Osto supports REs<\/a><\/li><li><a href=\"#faq\">FAQ<\/a><\/li><\/ol><\/div>\n\n<h2 id=\"meaning\">What does Regulated Entity mean under SEBI?<\/h2>\n<p>SEBI uses \u201cregulated entity\u201d as a practical collective term for entities within its regulatory perimeter. The perimeter includes institutions that operate the market, intermediaries that connect issuers and investors, pooled investment vehicles and professional advisers or service providers.<\/p>\n<div class=\"trio\"><div class=\"tcard a\"><p class=\"n\">Entry permission<\/p><p class=\"g\">Registration or recognition<\/p><p>The entity must hold the approval required for its specific securities-market activity.<\/p><\/div><div class=\"tcard b\"><p class=\"n\">Continuing supervision<\/p><p class=\"g\">Rules while operating<\/p><p>It must maintain eligibility, controls, records, disclosures and investor-facing processes.<\/p><\/div><div class=\"tcard c\"><p class=\"n\">Evidence and reporting<\/p><p class=\"g\">Prove compliance<\/p><p>It must produce prescribed filings, audit records and incident or grievance information when required.<\/p><\/div><\/div>\n<div class=\"callout soft\"><p class=\"k\">There is no single universal \u201cRE licence\u201d<\/p><p>An entity becomes regulated because of the activity it performs and the legal route governing that activity. A stock broker\u2019s obligations are not identical to an AMC\u2019s, a credit rating agency\u2019s or a stock exchange\u2019s.<\/p><\/div>\n\n<h2 id=\"types\" class=\"c-sage\">Who counts as a SEBI Regulated Entity?<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 430\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SEBI regulated entity ecosystem showing market infrastructure, trading and custody, funds and managers, advisers and analysts, and issue and information services.\"><defs><marker id=\"reArrow\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#4a52a8\"\/><\/marker><\/defs><circle cx=\"390\" cy=\"204\" r=\"74\" fill=\"#1c267a\"\/><text x=\"390\" y=\"195\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"24\" font-weight=\"700\" fill=\"#fff\">SEBI<\/text><text x=\"390\" y=\"220\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"12\" fill=\"#dfe2f4\">regulatory perimeter<\/text><g stroke=\"#4a52a8\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#reArrow)\"><path d=\"M340 151L236 96\"\/><path d=\"M440 151L544 96\"\/><path d=\"M315 207L221 207\"\/><path d=\"M465 207L559 207\"\/><path d=\"M350 263L260 338\"\/><path d=\"M430 263L520 338\"\/><\/g><g font-family=\"Inter\"><rect x=\"38\" y=\"38\" width=\"210\" height=\"82\" rx=\"18\" fill=\"#e9ecfa\"\/><text x=\"58\" y=\"67\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Market infrastructure<\/text><text x=\"58\" y=\"91\" font-size=\"12\" fill=\"#0f1538\">Exchanges \u00b7 clearing corporations<\/text><text x=\"58\" y=\"108\" font-size=\"12\" fill=\"#0f1538\">depositories<\/text><rect x=\"532\" y=\"38\" width=\"210\" height=\"82\" rx=\"18\" fill=\"#e2eff7\"\/><text x=\"552\" y=\"67\" font-size=\"14\" font-weight=\"700\" fill=\"#2f6a89\">Trading and custody<\/text><text x=\"552\" y=\"91\" font-size=\"12\" fill=\"#0f1538\">Brokers \u00b7 DPs \u00b7 custodians<\/text><text x=\"552\" y=\"108\" font-size=\"12\" fill=\"#0f1538\">bankers to an issue<\/text><rect x=\"28\" y=\"166\" width=\"210\" height=\"82\" rx=\"18\" fill=\"#e3f0e9\"\/><text x=\"48\" y=\"195\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Funds and managers<\/text><text x=\"48\" y=\"219\" font-size=\"12\" fill=\"#0f1538\">Mutual funds \u00b7 AMCs \u00b7 AIFs<\/text><text x=\"48\" y=\"236\" font-size=\"12\" fill=\"#0f1538\">portfolio managers \u00b7 CIS<\/text><rect x=\"542\" y=\"166\" width=\"210\" height=\"82\" rx=\"18\" fill=\"#fbe9dc\"\/><text x=\"562\" y=\"195\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">Advice and analysis<\/text><text x=\"562\" y=\"219\" font-size=\"12\" fill=\"#0f1538\">Investment advisers \u00b7 research<\/text><text x=\"562\" y=\"236\" font-size=\"12\" fill=\"#0f1538\">analysts \u00b7 rating agencies<\/text><rect x=\"70\" y=\"326\" width=\"230\" height=\"72\" rx=\"18\" fill=\"#f1f7fb\"\/><text x=\"90\" y=\"355\" font-size=\"14\" font-weight=\"700\" fill=\"#2f6a89\">Issue and investor services<\/text><text x=\"90\" y=\"379\" font-size=\"12\" fill=\"#0f1538\">Merchant bankers \u00b7 RTAs \u00b7 trustees<\/text><rect x=\"480\" y=\"326\" width=\"230\" height=\"72\" rx=\"18\" fill=\"#f4f5fd\"\/><text x=\"500\" y=\"355\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Market information and KYC<\/text><text x=\"500\" y=\"379\" font-size=\"12\" fill=\"#0f1538\">KRAs \u00b7 CRAs \u00b7 designated participants<\/text><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The perimeter is broad, but the legal and operational obligations are activity-specific.<\/figcaption><\/figure>\n<table class=\"h-sage\"><thead><tr><th>Common RE type<\/th><th>Role in the securities market<\/th><\/tr><\/thead><tbody><tr><td><strong>Stock exchanges, clearing corporations and depositories<\/strong><\/td><td>Provide core trading, clearing, settlement and securities-holding infrastructure.<\/td><\/tr><tr><td><strong>Stock brokers and depository participants<\/strong><\/td><td>Give investors access to trading and depository services.<\/td><\/tr><tr><td><strong>Mutual funds and AMCs<\/strong><\/td><td>Pool investor money and manage schemes under the mutual-fund framework.<\/td><\/tr><tr><td><strong>AIFs, portfolio managers and CIS<\/strong><\/td><td>Manage pooled or client-specific investment strategies under their respective regimes.<\/td><\/tr><tr><td><strong>Investment advisers and research analysts<\/strong><\/td><td>Provide regulated investment advice or securities research.<\/td><\/tr><tr><td><strong>Merchant bankers, RTAs and debenture trustees<\/strong><\/td><td>Support issues, investor records, transfers and debenture-holder interests.<\/td><\/tr><tr><td><strong>Custodians, KRAs and credit rating agencies<\/strong><\/td><td>Safeguard assets, maintain KYC records or provide regulated credit opinions.<\/td><\/tr><\/tbody><\/table>\n<p>This is a representative list, not a substitute for checking the regulation or circular relevant to a particular business model. One corporate group may also contain several separately registered entities.<\/p>\n\n<h2 id=\"terms\" class=\"c-sky\">Regulated Entity, intermediary and MII: the difference<\/h2>\n<table class=\"h-blue\"><thead><tr><th>Term<\/th><th>What it describes<\/th><th>Relationship<\/th><\/tr><\/thead><tbody><tr><td><strong>Regulated Entity (RE)<\/strong><\/td><td>The broad collective label for an entity within SEBI\u2019s regulatory perimeter.<\/td><td>Can include intermediaries, market infrastructure institutions, funds and other regulated participants.<\/td><\/tr><tr><td><strong>Intermediary<\/strong><\/td><td>A participant performing a regulated service between issuers, investors or market systems.<\/td><td>Many intermediaries are REs, but \u201cRE\u201d is the broader term in frameworks such as CSCRF.<\/td><\/tr><tr><td><strong>Market Infrastructure Institution (MII)<\/strong><\/td><td>A stock exchange, clearing corporation or depository forming core market infrastructure.<\/td><td>An MII is an RE with heightened systemic importance and correspondingly extensive obligations.<\/td><\/tr><\/tbody><\/table>\n\n<h2 id=\"obligations\" class=\"c-apri\">How an RE\u2019s obligations are decided<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 270\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Five-step process for determining the obligations of a SEBI regulated entity.\"><defs><marker id=\"dArrow\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#1c267a\"\/><\/marker><\/defs><g font-family=\"Inter\" text-anchor=\"middle\"><g stroke=\"#1c267a\" stroke-width=\"2\" marker-end=\"url(#dArrow)\"><line x1=\"152\" y1=\"122\" x2=\"182\" y2=\"122\"\/><line x1=\"300\" y1=\"122\" x2=\"330\" y2=\"122\"\/><line x1=\"448\" y1=\"122\" x2=\"478\" y2=\"122\"\/><line x1=\"596\" y1=\"122\" x2=\"626\" y2=\"122\"\/><\/g><rect x=\"18\" y=\"72\" width=\"134\" height=\"100\" rx=\"18\" fill=\"#e9ecfa\"\/><text x=\"85\" y=\"104\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">1 \u00b7 ACTIVITY<\/text><text x=\"85\" y=\"130\" font-size=\"11.5\" fill=\"#0f1538\">What service is<\/text><text x=\"85\" y=\"147\" font-size=\"11.5\" fill=\"#0f1538\">being performed?<\/text><rect x=\"182\" y=\"72\" width=\"118\" height=\"100\" rx=\"18\" fill=\"#e2eff7\"\/><text x=\"241\" y=\"104\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">2 \u00b7 STATUS<\/text><text x=\"241\" y=\"130\" font-size=\"11.5\" fill=\"#0f1538\">Registration or<\/text><text x=\"241\" y=\"147\" font-size=\"11.5\" fill=\"#0f1538\">recognition type<\/text><rect x=\"330\" y=\"72\" width=\"118\" height=\"100\" rx=\"18\" fill=\"#e3f0e9\"\/><text x=\"389\" y=\"104\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">3 \u00b7 SCALE<\/text><text x=\"389\" y=\"130\" font-size=\"11.5\" fill=\"#0f1538\">Clients, volume,<\/text><text x=\"389\" y=\"147\" font-size=\"11.5\" fill=\"#0f1538\">AUM and reach<\/text><rect x=\"478\" y=\"72\" width=\"118\" height=\"100\" rx=\"18\" fill=\"#fbe9dc\"\/><text x=\"537\" y=\"104\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">4 \u00b7 RULES<\/text><text x=\"537\" y=\"130\" font-size=\"11.5\" fill=\"#0f1538\">Regulations, circulars<\/text><text x=\"537\" y=\"147\" font-size=\"11.5\" fill=\"#0f1538\">and frameworks<\/text><rect x=\"626\" y=\"72\" width=\"136\" height=\"100\" rx=\"18\" fill=\"#f4f5fd\"\/><text x=\"694\" y=\"104\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">5 \u00b7 EVIDENCE<\/text><text x=\"694\" y=\"130\" font-size=\"11.5\" fill=\"#0f1538\">Filings, audits,<\/text><text x=\"694\" y=\"147\" font-size=\"11.5\" fill=\"#0f1538\">records and reports<\/text><text x=\"390\" y=\"222\" font-size=\"12.5\" fill=\"#0f1538\">Start with the regulated activity; the resulting control and reporting map follows from it.<\/text><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Applicability should be documented, owned and reviewed when the business or regulatory perimeter changes.<\/figcaption><\/figure>\n<p>A sound compliance map begins with the entity\u2019s exact registration and activities. It then identifies the governing regulations, master circulars, operational circulars and cross-cutting frameworks. Scale or systemic importance may determine which tier, frequency or reporting path applies.<\/p>\n<div class=\"callout apri\"><p class=\"k\">Registration is the start, not the finish<\/p><p>An RE must maintain the conditions of registration throughout its operations. New products, outsourcing arrangements, technology changes, acquisitions or threshold movements can change the applicable obligations.<\/p><\/div>\n\n<h2 id=\"cscrf\">RE categories under SEBI\u2019s CSCRF<\/h2>\n<p>For cybersecurity and cyber resilience, SEBI\u2019s <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">CSCRF<\/a> follows a graded approach. It classifies covered REs using their span of operations and thresholds such as client count, trade volume and assets under management.<\/p>\n<table class=\"h-blue\"><thead><tr><th>CSCRF category<\/th><th>Practical meaning<\/th><\/tr><\/thead><tbody><tr><td><strong>Market Infrastructure Institutions<\/strong><\/td><td>Systemically important exchanges, clearing corporations and depositories; subject to the broadest requirements.<\/td><\/tr><tr><td><strong>Qualified REs<\/strong><\/td><td>Larger entities crossing the relevant operational threshold; also included in Cyber Capability Index assessment.<\/td><\/tr><tr><td><strong>Mid-size REs<\/strong><\/td><td>Entities in the middle threshold band, with controls and assurance scaled to their exposure.<\/td><\/tr><tr><td><strong>Small-size REs<\/strong><\/td><td>Smaller entities subject to a proportionate but substantive cybersecurity baseline.<\/td><\/tr><tr><td><strong>Self-certification REs<\/strong><\/td><td>The smallest category, using a simplified assurance path for applicable requirements rather than an exemption from security.<\/td><\/tr><\/tbody><\/table>\n<div class=\"callout\"><p class=\"k\">CSCRF category is not the same as entity type<\/p><p>\u201cStock broker\u201d describes the regulated activity. \u201cQualified RE\u201d or \u201cSmall-size RE\u201d describes how the CSCRF baseline is graded for that entity. Both labels may apply at the same time.<\/p><\/div>\n\n<h2 id=\"security\" class=\"c-sage\">What cybersecurity responsibility means for an RE<\/h2>\n<table class=\"h-sage\"><thead><tr><th>Responsibility<\/th><th>What operating evidence may look like<\/th><\/tr><\/thead><tbody><tr><td><strong>Governance and risk<\/strong><\/td><td>Named accountability, committee oversight, a current <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a>, treatment decisions and periodic review.<\/td><\/tr><tr><td><strong>Identity and access<\/strong><\/td><td>Least privilege, access reviews, privileged-access control and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a>.<\/td><\/tr><tr><td><strong>Applications and APIs<\/strong><\/td><td>Secure development, change control, testing, web protection and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a>.<\/td><\/tr><tr><td><strong>Cloud and suppliers<\/strong><\/td><td>Due diligence, contractual controls, dependency mapping, posture monitoring and supplier-risk review.<\/td><\/tr><tr><td><strong>Endpoints and data<\/strong><\/td><td>Endpoint monitoring, encryption, classification, backups and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a>.<\/td><\/tr><tr><td><strong>Detection and response<\/strong><\/td><td>Centralised logs, continuous monitoring, alert triage, escalation, incident reporting and retained evidence through a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> and SOC process.<\/td><\/tr><tr><td><strong>Assurance and recovery<\/strong><\/td><td>Audits, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a>, remediation records, recovery testing and post-incident improvement.<\/td><\/tr><\/tbody><\/table>\n<p>CSCRF connects these areas through Governance, Identify, Protect, Detect, Respond and Recover. It also requires appropriate SOC-based security monitoring for covered REs, with delivery possible through an own, group, market or managed SOC.<\/p>\n\n<h2 id=\"checklist\" class=\"c-sky\">Practical checklist for a SEBI RE<\/h2>\n<ol><li><strong>Confirm every regulated activity.<\/strong> Map each registration, recognition, approval and responsible legal entity.<\/li><li><strong>Build the applicability register.<\/strong> List the regulations, circulars, frameworks, filings and responsible owners that attach to each activity.<\/li><li><strong>Record the current category.<\/strong> Where a graded framework applies, retain the data and reasoning supporting the category.<\/li><li><strong>Map critical systems and data.<\/strong> Include applications, APIs, cloud services, endpoints, vendors, market connections and investor information.<\/li><li><strong>Link controls to evidence.<\/strong> For every requirement, identify the live control, evidence source, review frequency and exception route.<\/li><li><strong>Monitor third parties.<\/strong> Treat outsourced technology and service providers as part of the control environment, not as a transfer of accountability.<\/li><li><strong>Rehearse incidents and reporting.<\/strong> Keep contacts, escalation paths, decision rights and reporting templates ready before an event.<\/li><li><strong>Close findings visibly.<\/strong> Track audit and VAPT findings to validated remediation, with risk acceptance approved at the right level.<\/li><li><strong>Review when the business changes.<\/strong> Reassess applicability after a new product, acquisition, system migration or threshold movement.<\/li><\/ol>\n<p>The broader <a href=\"https:\/\/www.osto.one\/resources\/blog\/indian-fintech-compliance-map-mandatory-license\/\">Indian fintech compliance map<\/a> is useful when the same group also falls within RBI, CERT-In, data-protection or payment-security requirements.<\/p>\n\n<h2 id=\"osto\" class=\"c-sage\">How Osto supports SEBI Regulated Entities<\/h2>\n<p>Osto brings preventive controls, continuous monitoring and compliance evidence into one operating view across cloud, applications, APIs, code, endpoints, identities, networks and data. Live controls can be mapped to the applicable requirement, owner, finding and closure record.<\/p>\n<p>This reduces the gap between policy and proof. Instead of rebuilding the audit trail from separate tools and vendor reports, an RE can show the current control state, the issue identified, the remediation owner and the evidence that the issue was closed.<\/p>\n<p class=\"related\"><strong>Primary sources:<\/strong> <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI CSCRF Circular, 20 August 2024<\/a> and <a href=\"https:\/\/investor.sebi.gov.in\/hindi\/smart_orr.html\" target=\"_blank\" rel=\"noopener\">SEBI Investor SMART ODR regulated-entity list<\/a>. This glossary is a practical overview, not legal advice.<\/p>\n\n<div style=\"background:#1C267A;border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.22);text-align:center\"><p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#fff;font:700 11px Inter,sans-serif;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px\">Free security assessment<\/p><p style=\"color:#fff;font:700 26px\/1.3 Inter,sans-serif;letter-spacing:-.4px;margin:0 0 12px\">Turn SEBI requirements into live controls<\/p><p style=\"color:#dfe2f4;font:16px\/1.65 Inter,sans-serif;margin:0 auto 26px;max-width:520px\">Map the applicable obligations, deploy the security stack and keep audit-ready evidence across one platform.<\/p><a href=\"https:\/\/www.osto.one\/contact\" style=\"display:inline-block;background:#fff;color:#1c267a;font:700 16px Inter,sans-serif;text-decoration:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px\" target=\"_blank\" rel=\"noopener\">Get a free security assessment<\/a><p style=\"color:#cfd3ea;font:13px Inter,sans-serif;margin:14px 0 0\">Security controls \u00b7 Continuous evidence \u00b7 One platform, everything<\/p><\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details><summary>What is a SEBI Regulated Entity?<\/summary><p>It is an organisation or person operating within SEBI\u2019s regulatory perimeter under the registration, recognition or supervision applicable to a securities-market activity.<\/p><\/details>\n<details><summary>Is a Regulated Entity the same as a SEBI-registered intermediary?<\/summary><p>Not always. Many intermediaries are REs, but \u201cregulated entity\u201d is broader and can also include market infrastructure institutions, funds and other participants covered by a particular SEBI framework.<\/p><\/details>\n<details><summary>Which entities are regulated by SEBI?<\/summary><p>Examples include stock exchanges, clearing corporations, depositories, brokers, depository participants, mutual funds and AMCs, AIFs, portfolio managers, investment advisers, research analysts, merchant bankers, RTAs, custodians, KRAs, credit rating agencies and debenture trustees.<\/p><\/details>\n<details><summary>Does every SEBI RE follow the same rules?<\/summary><p>No. The rules depend on the entity\u2019s regulated activity, governing instrument, scale, systemic importance and the framework in question. Cross-cutting requirements may apply to many entity types, but not always in the same form.<\/p><\/details>\n<details><summary>What is an MII under SEBI?<\/summary><p>A Market Infrastructure Institution is a stock exchange, clearing corporation or depository. MIIs provide systemically important market infrastructure and are treated as a distinct, high-obligation category.<\/p><\/details>\n<details><summary>What are the five RE categories under CSCRF?<\/summary><p>Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The category is based on the span of operations and relevant thresholds.<\/p><\/details>\n<details><summary>Is a small or self-certification RE exempt from cybersecurity?<\/summary><p>No. CSCRF uses proportional requirements, but its stated aim includes ensuring that smaller REs have adequate cybersecurity measures and resilience.<\/p><\/details>\n<details><summary>Does outsourcing transfer an RE\u2019s regulatory responsibility?<\/summary><p>Generally, outsourcing a service does not remove the RE\u2019s responsibility for overseeing risks and complying with applicable obligations. The exact contractual, due-diligence and monitoring duties depend on the relevant rules.<\/p><\/details>\n<details><summary>How should an RE prove compliance?<\/summary><p>By maintaining current policies, registers, system and access records, risk decisions, control evidence, filings, audit and VAPT reports, incident records and verified remediation evidence appropriate to its obligations.<\/p><\/details>\n<p class=\"related\"><strong>Continue reading:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/blog\/indian-fintech-compliance-map-mandatory-license\/\">Indian Fintech Compliance Map<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A SEBI Regulated Entity is a securities-market participant that operates under SEBI registration, recognition or supervision and must follow the\u2026<\/p>\n","protected":false},"author":8,"featured_media":1017,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[467,466,468,465],"class_list":["post-1016","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sebi","tag-sebi-compliance-requirements","tag-sebi-re-meaning","tag-sebi-regulated-entity"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1016"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1016\/revisions"}],"predecessor-version":[{"id":1018,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1016\/revisions\/1018"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1017"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}