{"id":1061,"date":"2026-09-01T06:10:13","date_gmt":"2026-09-01T06:10:13","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1061"},"modified":"2026-09-01T06:10:13","modified_gmt":"2026-09-01T06:10:13","slug":"sebi-cscrf-for-stock-brokers","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/sebi-cscrf-for-stock-brokers\/","title":{"rendered":"SEBI CSCRF Compliance for Stock Brokers"},"content":{"rendered":"\n<style>\n.osto-stock-cscrf{\n  --osto:#1C267A;\n  --blue:#3445C5;\n  --text:#15172A;\n  --body:#45495A;\n  --muted:#707589;\n  --line:#E7E9F2;\n  --soft:#F8F9FC;\n  --soft-blue:#F2F5FF;\n  --mint:#EAF8F4;\n  --lilac:#F3EEFF;\n  --peach:#FFF3E9;\n  color:var(--text);\n  font-family:Inter, ui-sans-serif, -apple-system, BlinkMacSystemFont, \"Segoe UI\", sans-serif;\n  font-size:17px;\n  line-height:1.72;\n  max-width:900px;\n  margin:0 auto;\n}\n.osto-stock-cscrf *{box-sizing:border-box}\n.osto-stock-cscrf p{margin:0 0 18px;color:var(--body)}\n.osto-stock-cscrf strong{color:var(--text)}\n.osto-stock-cscrf a{color:var(--osto);text-decoration:underline;text-decoration-thickness:1px;text-underline-offset:3px}\n.osto-stock-cscrf h2{\n  margin:48px 0 16px;\n  font-size:30px;\n  line-height:1.24;\n  letter-spacing:-.02em;\n  font-weight:700;\n  color:var(--text)\n}\n.osto-stock-cscrf h3{\n  margin:0 0 7px;\n  font-size:20px;\n  line-height:1.35;\n  font-weight:700;\n  color:var(--text)\n}\n.osto-stock-cscrf .lead{font-size:19px;line-height:1.65;color:#333744;margin:0 0 30px}\n\n.osto-stock-cscrf .tldr{\n  border:1px solid #DDE4FF;\n  border-radius:14px;\n  padding:24px 26px;\n  margin:30px 0;\n  background:linear-gradient(135deg,#F8FAFF 0%,#F1F5FF 100%)\n}\n.osto-stock-cscrf .tldr h2{font-size:20px;line-height:1.3;color:var(--osto);margin:0 0 9px;letter-spacing:0}\n.osto-stock-cscrf .tldr p{margin-bottom:10px}\n.osto-stock-cscrf .tldr p:last-child{margin-bottom:0}\n\n.osto-stock-cscrf .toc{\n  margin:32px 0 38px;\n  padding:20px 0;\n  border-top:1px solid var(--line);\n  border-bottom:1px solid var(--line)\n}\n.osto-stock-cscrf .toc-title{font-size:14px;font-weight:700;color:var(--text);margin-bottom:10px}\n.osto-stock-cscrf .toc ol{margin:0;padding-left:20px;columns:2;column-gap:38px}\n.osto-stock-cscrf .toc li{margin:6px 0;break-inside:avoid;color:var(--body)}\n.osto-stock-cscrf .toc a{text-decoration:none;color:#34384A}\n\n.osto-stock-cscrf .diagram{\n  margin:26px 0 36px;\n  padding:24px;\n  border:1px solid #E1E5F4;\n  border-radius:16px;\n  background:linear-gradient(180deg,#FFFFFF 0%,#FBFCFF 100%);\n  overflow:hidden;\n  box-shadow:0 8px 28px rgba(28,38,122,.05)\n}\n.osto-stock-cscrf .diagram-kicker{\n  font-size:12px;\n  font-weight:700;\n  text-transform:uppercase;\n  letter-spacing:.08em;\n  color:var(--osto);\n  margin-bottom:7px\n}\n.osto-stock-cscrf .diagram-title{font-size:18px;line-height:1.35;font-weight:700;color:var(--text);margin-bottom:18px}\n.osto-stock-cscrf .diagram-note{font-size:13px;color:var(--muted);margin:14px 0 0}\n\n.osto-stock-cscrf .five{display:grid;grid-template-columns:repeat(5,1fr);gap:8px}\n.osto-stock-cscrf .five-card{text-align:center;padding:17px 8px 15px;border-radius:10px;min-height:92px}\n.osto-stock-cscrf .five-card:nth-child(1){background:var(--soft-blue)}\n.osto-stock-cscrf .five-card:nth-child(2){background:var(--mint)}\n.osto-stock-cscrf .five-card:nth-child(3){background:var(--lilac)}\n.osto-stock-cscrf .five-card:nth-child(4){background:var(--peach)}\n.osto-stock-cscrf .five-card:nth-child(5){background:var(--soft-blue)}\n.osto-stock-cscrf .five-card .num{\n  display:flex;align-items:center;justify-content:center;\n  width:28px;height:28px;border-radius:50%;\n  background:var(--osto);color:#fff;font-size:11px;font-weight:700;\n  margin:0 auto 8px\n}\n.osto-stock-cscrf .five-card span{font-size:13px;font-weight:700;color:#262A38}\n\n.osto-stock-cscrf .category-grid{display:grid;grid-template-columns:repeat(4,1fr);gap:10px;margin:20px 0 8px}\n.osto-stock-cscrf .category-card{border:1px solid var(--line);border-radius:12px;padding:16px;background:#fff}\n.osto-stock-cscrf .category-card:nth-child(1){background:var(--lilac)}\n.osto-stock-cscrf .category-card:nth-child(2){background:var(--soft-blue)}\n.osto-stock-cscrf .category-card:nth-child(3){background:var(--mint)}\n.osto-stock-cscrf .category-card:nth-child(4){background:var(--peach)}\n.osto-stock-cscrf .category-card strong{display:block;color:var(--osto);font-size:14px;margin-bottom:5px}\n.osto-stock-cscrf .category-card span{font-size:12px;line-height:1.45;color:#515666}\n\n.osto-stock-cscrf .table-wrap{overflow-x:auto;margin:22px 0 32px;border:1px solid var(--line);border-radius:10px;box-shadow:0 7px 24px rgba(28,38,122,.04)}\n.osto-stock-cscrf table{width:100%;border-collapse:collapse;font-size:14px;line-height:1.5;background:#fff;margin:0}\n.osto-stock-cscrf th,.osto-stock-cscrf td{padding:13px 14px;border-bottom:1px solid var(--line);vertical-align:top;text-align:left}\n.osto-stock-cscrf th{background:#1C267A;font-size:13px;font-weight:700;color:#FFFFFF}\n.osto-stock-cscrf tr:nth-child(even) td{background:#FCFCFE}\n.osto-stock-cscrf tr:last-child td{border-bottom:0}\n\n.osto-stock-cscrf .steps{margin:22px 0 10px;border-top:1px solid var(--line)}\n.osto-stock-cscrf .step{display:grid;grid-template-columns:48px 1fr;gap:14px;padding:18px 0;border-bottom:1px solid var(--line)}\n.osto-stock-cscrf .step-no{font-size:14px;font-weight:700;color:var(--osto);padding-top:3px}\n.osto-stock-cscrf .step p{font-size:15px;line-height:1.62;margin:0;color:var(--body)}\n\n.osto-stock-cscrf .timeline{display:grid;grid-template-columns:repeat(4,1fr);gap:10px;margin-top:8px}\n.osto-stock-cscrf .milestone{padding:18px;border:1px solid var(--line);border-radius:10px}\n.osto-stock-cscrf .milestone:nth-child(1){background:var(--soft-blue)}\n.osto-stock-cscrf .milestone:nth-child(2){background:var(--mint)}\n.osto-stock-cscrf .milestone:nth-child(3){background:var(--lilac)}\n.osto-stock-cscrf .milestone:nth-child(4){background:var(--peach)}\n.osto-stock-cscrf .milestone strong{display:block;font-size:22px;line-height:1.1;color:var(--osto);margin-bottom:6px}\n.osto-stock-cscrf .milestone span{display:block;font-size:13px;line-height:1.48;color:#555B69}\n\n.osto-stock-cscrf .mistakes{list-style:none;padding:0;margin:20px 0 10px;border-top:1px solid var(--line);counter-reset:item}\n.osto-stock-cscrf .mistakes li{\n  counter-increment:item;display:grid;grid-template-columns:34px 1fr;gap:10px;\n  padding:14px 0;border-bottom:1px solid var(--line);font-size:15px;color:var(--body)\n}\n.osto-stock-cscrf .mistakes li:before{\n  content:counter(item,decimal-leading-zero);font-size:12px;font-weight:700;color:var(--osto);padding-top:3px\n}\n\n.osto-stock-cscrf .cta{\n  margin:28px 0 46px;\n  padding:28px 30px;\n  border-radius:12px;\n  background:linear-gradient(135deg,#1C267A 0%,#3445C5 100%);\n  color:#fff;\n  box-shadow:0 14px 36px rgba(28,38,122,.18)\n}\n.osto-stock-cscrf .cta .kicker{font-size:12px;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:#DDE1FF;margin-bottom:8px}\n.osto-stock-cscrf .cta h3{font-size:24px;line-height:1.25;color:#fff;margin:0 0 10px}\n.osto-stock-cscrf .cta p{max-width:680px;color:#F3F4FF;margin-bottom:17px}\n.osto-stock-cscrf .cta a{\n  display:inline-flex;align-items:center;background:#fff;color:var(--osto);\n  text-decoration:none;font-size:14px;font-weight:700;padding:11px 18px;border-radius:999px\n}\n\n.osto-stock-cscrf .faq{border-top:1px solid var(--line)}\n.osto-stock-cscrf details{border-bottom:1px solid var(--line);padding:15px 0}\n.osto-stock-cscrf summary{cursor:pointer;list-style:none;position:relative;padding-right:32px;font-size:16px;line-height:1.45;font-weight:700;color:var(--text)}\n.osto-stock-cscrf summary::-webkit-details-marker{display:none}\n.osto-stock-cscrf summary:after{content:'+';position:absolute;right:2px;top:-4px;color:var(--osto);font-size:24px;font-weight:400}\n.osto-stock-cscrf details[open] summary:after{content:'\\2212'}\n.osto-stock-cscrf details p{font-size:15px;margin:10px 0 0;color:var(--body)}\n.osto-stock-cscrf .sources{margin-top:34px;padding-top:18px;border-top:1px solid var(--line);font-size:13px;line-height:1.6;color:var(--muted)}\n.osto-stock-cscrf .sources a{font-size:13px}\n\n@media(max-width:760px){\n  .osto-stock-cscrf{font-size:16px;line-height:1.68}\n  .osto-stock-cscrf .lead{font-size:17px}\n  .osto-stock-cscrf h2{font-size:25px;margin-top:40px}\n  .osto-stock-cscrf .toc ol{columns:1}\n  .osto-stock-cscrf .five{grid-template-columns:repeat(2,1fr)}\n  .osto-stock-cscrf .five-card:last-child{grid-column:1\/-1}\n  .osto-stock-cscrf .category-grid{grid-template-columns:1fr 1fr}\n  .osto-stock-cscrf .timeline{grid-template-columns:1fr 1fr}\n  .osto-stock-cscrf .step{grid-template-columns:36px 1fr;gap:10px}\n  .osto-stock-cscrf .cta{padding:24px 22px}\n}\n<\/style>\n\n<article class=\"osto-stock-cscrf\">\n  <p class=\"lead\"><strong>SEBI CSCRF Compliance for Stock Brokers<\/strong> is no longer a generic cybersecurity checklist. Stock brokers must first determine the correct CSCRF category, then operate the governance, monitoring, VAPT, cyber audit, incident response and evidence requirements that apply to that category.<\/p>\n\n  <section class=\"tldr\">\n    <h2>TL;DR<\/h2>\n    <p><strong>SEBI CSCRF Compliance for Stock Brokers<\/strong> uses a graded model. For client-based brokers, category is determined using registered clients and annual clientele trading volume, with the higher category applying when the two parameters point to different tiers.<\/p>\n    <p>For Qualified Stock Brokers, VAPT and cyber audit are half-yearly regardless of the CSCRF category. Every broker should keep asset inventories, security controls, SOC monitoring, remediation and regulatory evidence continuously ready rather than reconstructing them before an audit.<\/p>\n  <\/section>\n\n  <div class=\"toc\">\n    <div class=\"toc-title\">On this page<\/div>\n    <nav aria-label=\"On this page\">\n      <ol>\n        <li><a href=\"#what-applies\">What applies to stock brokers<\/a><\/li>\n        <li><a href=\"#classification\">Stock broker categorisation<\/a><\/li>\n        <li><a href=\"#steps\">7 implementation steps<\/a><\/li>\n        <li><a href=\"#vapt\">VAPT and cyber audit<\/a><\/li>\n        <li><a href=\"#soc\">SOC and Market SOC<\/a><\/li>\n        <li><a href=\"#evidence\">Evidence checklist<\/a><\/li>\n        <li><a href=\"#mistakes\">Common mistakes<\/a><\/li>\n        <li><a href=\"#faq\">FAQs<\/a><\/li>\n      <\/ol>\n    <\/nav>\n  <\/div>\n\n  <h2 id=\"what-applies\">What SEBI CSCRF Compliance for Stock Brokers actually requires<\/h2>\n  <p>SEBI&#8217;s <a href=\"https:\/\/www.osto.one\/resources\/?p=1010\">Cybersecurity and Cyber Resilience Framework<\/a> creates one common cyber resilience structure for regulated entities, but it does not apply every requirement identically. A stock broker&#8217;s obligations depend on its category, operating model and any additional designation such as Qualified Stock Broker.<\/p>\n  <p>The framework connects board and senior-management oversight with operational security. That means a broker needs more than policies. It needs current asset visibility, controlled access, secure applications and APIs, vulnerability management, monitoring, incident handling, recovery capability and evidence that each control is actually operating.<\/p>\n\n  <div class=\"diagram\">\n    <div class=\"diagram-kicker\">The operating model<\/div>\n    <div class=\"diagram-title\">Five outcomes behind broker cyber resilience<\/div>\n    <div class=\"five\">\n      <div class=\"five-card\"><div class=\"num\">01<\/div><span>Govern risk<\/span><\/div>\n      <div class=\"five-card\"><div class=\"num\">02<\/div><span>Protect systems<\/span><\/div>\n      <div class=\"five-card\"><div class=\"num\">03<\/div><span>Detect attacks<\/span><\/div>\n      <div class=\"five-card\"><div class=\"num\">04<\/div><span>Respond fast<\/span><\/div>\n      <div class=\"five-card\"><div class=\"num\">05<\/div><span>Recover safely<\/span><\/div>\n    <\/div>\n  <\/div>\n\n  <h2 id=\"classification\">SEBI CSCRF Compliance for Stock Brokers: get the category right first<\/h2>\n  <p>SEBI revised the stock-broker classification in April 2025. Client-based stock brokers are assessed on two independent parameters: total registered clients and annual clientele trading volume. If the two parameters place the broker in different categories, the higher category applies.<\/p>\n  <p>The current registered-client count includes active and inactive clients based on unique PAN and excludes clients marked closed in the UCC database. The category is determined at the beginning of the financial year using previous-year data and remains unchanged for that financial year.<\/p>\n\n  <div class=\"category-grid\" aria-label=\"CSCRF categories for stock brokers\">\n    <div class=\"category-card\"><strong>Qualified RE<\/strong><span>Largest brokers or brokers meeting the highest applicable threshold.<\/span><\/div>\n    <div class=\"category-card\"><strong>Mid-size RE<\/strong><span>Higher-volume brokers below the Qualified RE thresholds.<\/span><\/div>\n    <div class=\"category-card\"><strong>Small-size RE<\/strong><span>Growing brokers with a meaningful client base or annual trading volume.<\/span><\/div>\n    <div class=\"category-card\"><strong>Self-certification RE<\/strong><span>Smaller covered brokers following the proportionate assurance route.<\/span><\/div>\n  <\/div>\n\n  <div class=\"table-wrap\">\n    <table>\n      <thead>\n        <tr>\n          <th>Parameter<\/th>\n          <th>Self-certification<\/th>\n          <th>Small-size<\/th>\n          <th>Mid-size<\/th>\n          <th>Qualified<\/th>\n        <\/tr>\n      <\/thead>\n      <tbody>\n        <tr>\n          <td>Total registered clients<\/td>\n          <td>More than 1,000 and up to 10,000<\/td>\n          <td>More than 10,000 and up to 1 lakh<\/td>\n          <td>More than 1 lakh and up to 10 lakh<\/td>\n          <td>More than 10 lakh<\/td>\n        <\/tr>\n        <tr>\n          <td>Clientele trading volume in a financial year<\/td>\n          <td>More than &#8377;1,000 crore and up to &#8377;10,000 crore<\/td>\n          <td>More than &#8377;10,000 crore and up to &#8377;1 lakh crore<\/td>\n          <td>More than &#8377;1 lakh crore and up to &#8377;10 lakh crore<\/td>\n          <td>More than &#8377;10 lakh crore<\/td>\n        <\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n\n  <p>Stock brokers with less than &#8377;1,000 crore of annual clientele trading volume and fewer than 1,000 registered clients are exempt from CSCRF under the April 2025 clarification. Proprietary-only brokers use a separate collateral or assets-with-clearing-corporations threshold. A broker that also operates as a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-depository-participant\/\">Depository Participant<\/a> should check the highest category triggered by its registrations.<\/p>\n\n  <h2 id=\"steps\">7 easy proven steps for SEBI CSCRF Compliance for Stock Brokers<\/h2>\n  <div class=\"steps\">\n    <div class=\"step\"><div class=\"step-no\">01<\/div><div><h3>Confirm classification and reporting route<\/h3><p>Record the broker model, registered-client count, annual clientele trading volume, proprietary activity, QSB status and any additional SEBI registrations. Keep the classification calculation as audit evidence.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">02<\/div><div><h3>Build a complete asset and critical-system inventory<\/h3><p>Include trading applications, APIs, cloud resources, endpoints, databases, network devices, privileged identities, third-party connections and cryptographic assets. Identify which systems are critical and obtain the required governance approval.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">03<\/div><div><h3>Map each CSCRF clause to a live control<\/h3><p>For every applicable requirement, document the control, owner, evidence source, review frequency and exception path. This prevents a policy from being mistaken for proof of implementation.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">04<\/div><div><h3>Protect identities, applications and trading infrastructure<\/h3><p>Enforce strong authentication, least privilege, secure configuration, patching, application security and network segmentation. Brokers providing algorithmic trading should isolate and secure the perimeter and connectivity around algo-trading servers.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">05<\/div><div><h3>Operate continuous monitoring<\/h3><p>Centralise security-relevant logs, define alert and escalation rules and ensure suspicious events are investigated. Depending on category and operating model, the broker may use its own SOC, a group SOC, a managed SOC or the Market SOC route.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">06<\/div><div><h3>Run VAPT, cyber audit and remediation as one cycle<\/h3><p>Scope testing to the real attack surface, record findings by severity, assign owners, close vulnerabilities within the applicable timeline and retain revalidation evidence. Treat testing as an operating control rather than a certificate exercise.<\/p><\/div><\/div>\n    <div class=\"step\"><div class=\"step-no\">07<\/div><div><h3>Keep incident and recovery evidence ready<\/h3><p>Maintain current playbooks, escalation contacts, regulatory reporting routes, backup and recovery evidence, drill results and post-incident actions. SEBI&#8217;s CyberSuraksha portal and reporting formats should be checked for the current incident-reporting workflow.<\/p><\/div><\/div>\n  <\/div>\n\n  <h2 id=\"vapt\">VAPT and cyber audit under SEBI CSCRF Compliance for Stock Brokers<\/h2>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-sebi-vapt-requirements\/\">SEBI VAPT requirements<\/a> are more than a scanner output. The broker should use the applicable CERT-In-empanelled audit route, cover relevant critical systems and attack surfaces, obtain governance approval for the report, track remediation and complete revalidation.<\/p>\n  <p>SEBI&#8217;s June 2025 FAQs clarify that Qualified Stock Brokers must conduct both VAPT and cyber audit half-yearly, irrespective of the CSCRF category they otherwise fall into. The same FAQs state that non-patch VAPT observations are generally validated against the three-month closure timeline, while high-severity patch-related gaps are tested against the applicable patch-management timeline.<\/p>\n\n  <div class=\"diagram\">\n    <div class=\"diagram-kicker\">Testing cycle<\/div>\n    <div class=\"diagram-title\">What a defensible VAPT trail should show<\/div>\n    <div class=\"timeline\">\n      <div class=\"milestone\"><strong>Scope<\/strong><span>Critical systems, apps, APIs, cloud, network and other in-scope assets<\/span><\/div>\n      <div class=\"milestone\"><strong>Test<\/strong><span>Independent assessment and penetration testing with evidence<\/span><\/div>\n      <div class=\"milestone\"><strong>Fix<\/strong><span>Owners, deadlines, risk treatment and verified remediation<\/span><\/div>\n      <div class=\"milestone\"><strong>Prove<\/strong><span>Retest, closure record, approvals and submission evidence<\/span><\/div>\n    <\/div>\n  <\/div>\n\n  <h2 id=\"soc\">SOC and Market SOC for stock brokers<\/h2>\n  <p>A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-soc-market-soc\/\">SOC or Market SOC<\/a> is the operational layer that turns logs into detection and response. The important compliance question is not only where the SOC runs. It is whether the right systems send telemetry, alerts are investigated, escalation works and records can prove what happened.<\/p>\n  <p>Smaller brokers should not assume that using Market SOC transfers responsibility. The broker remains accountable for asset coverage, onboarding the required log sources, investigating escalations, closing findings and maintaining evidence of response.<\/p>\n\n  <h2 id=\"evidence\">SEBI CSCRF Compliance for Stock Brokers: evidence checklist<\/h2>\n  <p>The strongest compliance file connects each requirement to operating proof. Evidence should be dated, attributable and retrievable without rebuilding the story months later.<\/p>\n\n  <div class=\"table-wrap\">\n    <table>\n      <thead>\n        <tr><th>Control area<\/th><th>Useful evidence<\/th><\/tr>\n      <\/thead>\n      <tbody>\n        <tr><td>Governance<\/td><td>Approved policies, classification note, committee records, risk decisions and exception approvals<\/td><\/tr>\n        <tr><td>Assets and access<\/td><td>Asset inventory, critical-system approval, user reviews, MFA evidence and privileged-access records<\/td><\/tr>\n        <tr><td>Security operations<\/td><td>Log-source coverage, alerts, investigation tickets, escalation records and incident timelines<\/td><\/tr>\n        <tr><td>VAPT and patches<\/td><td>Scope, report, severity, remediation owner, patch record, retest and closure validation<\/td><\/tr>\n        <tr><td>Resilience<\/td><td>Backup results, restore tests, recovery objectives, drills and post-exercise actions<\/td><\/tr>\n        <tr><td>Third parties<\/td><td>Due diligence, contractual security terms, risk reviews, audit rights and closure tracking<\/td><\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n\n  <h2 id=\"mistakes\">The mistakes that lower broker readiness<\/h2>\n  <ul class=\"mistakes\">\n    <li><span><strong>Using the old active-client classification.<\/strong> The April 2025 model uses total registered clients and annual clientele trading volume, with later clarification on how registered clients are counted.<\/span><\/li>\n    <li><span><strong>Assuming the lower of two thresholds applies.<\/strong> When client count and trading volume lead to different categories, the higher category governs.<\/span><\/li>\n    <li><span><strong>Running VAPT on only the public website.<\/strong> Trading apps, APIs, cloud, network, mobile and connected critical systems may all matter to the real scope.<\/span><\/li>\n    <li><span><strong>Treating Market SOC as outsourced accountability.<\/strong> Shared monitoring can provide capability, but the broker still owns coverage, response and compliance evidence.<\/span><\/li>\n    <li><span><strong>Closing findings without revalidation.<\/strong> A ticket marked done is weaker than proof that the exploit path or vulnerable condition was actually removed.<\/span><\/li>\n  <\/ul>\n\n  <div class=\"cta\">\n    <div class=\"kicker\">One platform, continuous proof<\/div>\n    <h3>Run security and CSCRF evidence together.<\/h3>\n    <p>Osto brings cloud, endpoint, network, code, VAPT and compliance workflows into one platform so stock brokers can keep controls, findings, remediation and evidence connected between audits.<\/p>\n    <a href=\"https:\/\/www.osto.one\/book-demo\">Book a Demo &#8594;<\/a>\n  <\/div>\n\n  <h2 id=\"faq\">Frequently asked questions<\/h2>\n  <div class=\"faq\">\n    <details>\n      <summary>Does CSCRF apply to every stock broker?<\/summary>\n      <p>Not identically. Client-based brokers are classified using total registered clients and annual clientele trading volume. The April 2025 clarification exempts brokers below both the stated minimum client and trading-volume thresholds. Proprietary-only brokers use a separate categorisation route.<\/p>\n    <\/details>\n    <details>\n      <summary>How is a client-based stock broker classified under CSCRF?<\/summary>\n      <p>SEBI applies the registered-client and annual clientele trading-volume parameters independently. If they produce different categories, the higher category applies. The category is fixed at the beginning of the financial year based on the previous financial year&#8217;s data.<\/p>\n    <\/details>\n    <details>\n      <summary>How often must a Qualified Stock Broker conduct VAPT?<\/summary>\n      <p>SEBI&#8217;s June 2025 FAQs clarify that Qualified Stock Brokers conduct VAPT and cyber audit half-yearly regardless of the CSCRF category they otherwise fall into.<\/p>\n    <\/details>\n    <details>\n      <summary>Can a stock broker use Market SOC?<\/summary>\n      <p>Yes, where applicable. Market SOC can provide shared monitoring capability, but the broker remains responsible for correct onboarding, telemetry coverage, investigation, remediation and compliance evidence.<\/p>\n    <\/details>\n    <details>\n      <summary>Is a stock broker that is also a Depository Participant assessed separately?<\/summary>\n      <p>The broker should evaluate all registrations and apply the highest relevant CSCRF category. A Depository Participant that is also registered as a stock broker is classified using the stock-broker criteria for that DP route.<\/p>\n    <\/details>\n    <details>\n      <summary>What is the first step in SEBI CSCRF Compliance for Stock Brokers?<\/summary>\n      <p>Start with a documented classification and applicability note. Record the broker model, client count, trading volume, proprietary activity, QSB status, other registrations, applicable controls and reporting authority before implementing or testing controls.<\/p>\n    <\/details>\n  <\/div>\n\n  <div class=\"sources\">\n    <strong>Primary regulatory references:<\/strong>\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI CSCRF, 20 August 2024<\/a>;\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/apr-2025\/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93734.html\" target=\"_blank\" rel=\"noopener\">SEBI clarification, 30 April 2025<\/a>;\n    <a href=\"https:\/\/www.sebi.gov.in\/sebi_data\/faqfiles\/jun-2025\/1749647139924.pdf\" target=\"_blank\" rel=\"noopener\">SEBI CSCRF FAQs, 11 June 2025<\/a>;\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2025\/technical-clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_96329.html\" target=\"_blank\" rel=\"noopener\">technical clarifications, 28 August 2025<\/a>;\n    and the current <a href=\"https:\/\/cybersuraksha-ai.sebi.gov.in\/\" target=\"_blank\" rel=\"noopener\">SEBI CyberSuraksha portal<\/a>. Confirm current applicability for the broker before relying on this guide as a compliance interpretation.\n  <\/div>\n<\/article>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SEBI CSCRF Compliance for Stock Brokers is no longer a generic cybersecurity checklist. Stock brokers must first determine the correct\u2026<\/p>\n","protected":false},"author":8,"featured_media":1063,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[496,494,495],"class_list":["post-1061","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-sebi-cscrf-audit-for-stock-brokers","tag-sebi-cscrf-compliance-for-stock-brokers","tag-sebi-cscrf-stock-brokers"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1061","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1061"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1061\/revisions"}],"predecessor-version":[{"id":1064,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1061\/revisions\/1064"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1063"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}