How to Implement SEBI CSCRF Cybersecurity Compliance for Regulated Entities in India
- Kaustav Chowdhury

- 6 minutes ago
- 2 min read
Who Needs to Comply and When
The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), issued on August 20, 2024, applies to all SEBI-regulated entities (REs) operating in the Indian securities market. This includes stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, alternative investment funds (AIFs), investment advisers, research analysts, registrars and transfer agents, KYC registration agencies, and credit rating agencies.
The implementation deadline was August 31, 2025. Entities that have not yet implemented the framework are in non-compliance and face enforcement action. For entities that have implemented the framework, the ongoing obligation is the half-yearly cyber audit cycle and continuous compliance reporting.
Step 1: Classify Your Entity
The CSCRF classifies REs into five categories based on scale, systemic importance, and operational complexity. Your category determines the stringency of requirements:
In practice, many entities struggle with self-classification because the thresholds are scattered across different SEBI circulars. The safest approach is to cross-check your entity type against the CSCRF Annexure I classification table and, if in doubt, classify yourself one tier higher to avoid under-compliance.
Step 2: Conduct a Gap Assessment
Before implementing the framework, conduct a gap assessment against the six CSCRF cybersecurity functions, which are aligned with NIST CSF 2.0:
Step 3: Implement Core Technical Controls
The CSCRF mandates specific technical controls that go beyond generic cybersecurity hygiene. Key requirements include:
Practitioners should note
highlighted cybersecurity failures in market infrastructure. The CSCRF directly addresses the gaps identified in that proceeding by mandating network-level controls and audit trails for all system access.
Step 4: Set Up Reporting and Audit Compliance
The ongoing compliance cycle requires:
Step 5: Establish Third-Party Risk Management
In practice,
a significant proportion of cybersecurity incidents in the securities market originate from third-party vendors and service providers.
The CSCRF requires REs to:
Common Mistakes to Avoid
The framework requires continuous compliance with recurring audits, reports, and updates. Entities that implement controls once and do not maintain them will fail subsequent audits.
Sources and References
1. SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, dated August 20, 2024 (CSCRF)
3. Regulation 30(6), SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015
4. Regulation 17(8), SEBI LODR Regulations, 2015 (Compliance certification)
5. NSE co-location enforcement order (WTM/GM/EFD-DRA-1/24/2019-20)
6. ISO 27001:2022, Annex A (Information Security Controls)
This article is for informational purposes only and does not constitute legal advice. For specific legal guidance on SEBI CSCRF compliance or cybersecurity regulation, consult a qualified legal professional.

Comments