SEBI CSCRF Compliance Guide: Categories, Audits, VAPT and SOC
How SEBI's CSCRF applies: the five RE categories, the extended deadlines, VAPT and cyber audit cadence, SOC rules and CERT-In empanelled auditor norms.
17 min readBy Sachin Shirish, Director
Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) applies to 19 types of SEBI regulated entities and sorts each into one of five categories. The category decides how often you run VAPT and a cyber audit, whether you need your own SOC or the Market SOC, and what you report. After two extensions, the compliance date for most entities was August 31, 2025. Every audit must be done by a CERT-In empanelled IS auditing organisation. This guide sets out each obligation and where it comes from.
The framework at a glance
SEBI issued the framework through circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. It supersedes the earlier sector-specific cybersecurity circulars for MIIs, stock brokers and depository participants, mutual funds and AMCs, KRAs, QRTAs and portfolio managers. It is built on five cyber resiliency goals adopted from CERT-In's Cyber Crisis Management Plan.
Later instruments amend it and must be read together:
| Date | Instrument | What it changed |
|---|---|---|
| August 20, 2024 | CIR/2024/113 | Issued CSCRF; glide path to January 1, 2025 or April 1, 2025 |
| December 31, 2024 | CIR/2024/184 | Forbearance to March 31, 2025; KRAs and DPs moved to April 1, 2025; data localisation standard held in abeyance |
| March 28, 2025 | CIR/2025/45 | Extended to June 30, 2025, except MIIs, KRAs and QRTAs |
| April 30, 2025 | CIR/2025/60 | Revised thresholds and categories; exemptions for small brokers, standalone IAs and RAs |
| June 11, 2025 | CSCRF FAQs | Audit period, QSB cadence and M-SOC questions answered |
| June 30, 2025 | CIR/2025/96 | Extended to August 31, 2025, same exceptions |
| August 28, 2025 | CIR/2025/119 | Exclusivity and equivalence principles; technical clarifications; portfolio manager and merchant banker re-categorisation |
Who CSCRF applies to, and the five categories
The August 2024 circular covers 19 entity types, from stock exchanges and depositories to brokers, AMCs, portfolio managers, AIFs, RTAs and merchant bankers. It places each entity in one of five categories based on thresholds such as client count, trading volume and assets under management: Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs and Self-certification REs.
The April 30, 2025 circular set out how categorisation works in practice:
- Timing. The category is decided at the start of each financial year using the previous year's data, a rule first set in CIR/2024/113 and repeated in April 2025.
- Stock brokers. Two parameters apply independently, and the higher result wins. Qualified means more than 10 lakh registered clients or more than Rs. 10,00,000 crore of clientele trading volume a year. Self-certification starts above 1,000 clients or Rs. 1,000 crore. Brokers below both 1,000 clients and Rs. 1,000 crore are exempt.
- Depository participants. A DP that is also a stock broker follows the broker criteria. Other DPs are Qualified REs. DPs with fewer than 100 clients are exempt from the SOC and Market SOC requirement.
- Investment advisers and research analysts. Those registered with SEBI in no other capacity are exempt. Others follow their highest other category.
- KRAs moved from MII to Qualified RE.
- AIFs and VCFs are categorised at manager level on combined corpus.
The August 28, 2025 circular then revised two more groups. For portfolio managers, AUM of Rs. 10,000 crore and above is Mid-size, more than Rs. 3,000 crore and below Rs. 10,000 crore is Small-size, and Rs. 3,000 crore and below is Self-certification. All active merchant bankers are Small-size REs, and inactive ones are exempt.
Compliance timeline and the extensions
The original glide path had two dates. REs that already had a SEBI cybersecurity circular were to comply by January 1, 2025. REs covered for the first time had until April 1, 2025 (CIR/2024/113).
In December 2024, SEBI granted regulatory forbearance to March 31, 2025 for requirements effective January 1, 2025. No action would follow if an entity could show meaningful progress. The same circular moved KRAs and DPs to April 1, 2025. It also held the data localisation standard (PR.DS.S2) in abeyance until further notification.
Two extensions followed, and neither applied to MIIs, KRAs or QRTAs. The first moved the deadline by three months to June 30, 2025. The second added two months, to August 31, 2025.
That date is behind us, so the practical question now is audit timing. The CSCRF FAQs say the cyber audit runs after the audit period closes. An entity on an annual cycle starts its audit of April 2025 to March 2026 after March 2026.
VAPT cadence and closure timelines
The VAPT scope is defined in standard DE.CM.S5 and Annexure-A of the framework. It covers all critical systems, infrastructure components and other IT systems as defined.
| Entity | Minimum VAPT frequency |
|---|---|
| REs with systems identified as protected systems or CII by NCIIPC | At least twice a year, one in each half (April to September, October to March), including report, closure and revalidation |
| All other REs | At least once a year, starting in the first quarter of the financial year |
| Qualified Stock Brokers, per the FAQs | Half-yearly, whatever their CSCRF category |
After testing, the framework sets three deadlines:
- Report. Submitted within one month of completing the VAPT, after IT Committee approval, with an MD/CEO declaration.
- Closure. Findings closed within three months of the report, prioritised by criticality.
- Revalidation. Completed within five months of the VAPT.
Anything still open after three months needs IT Committee approval and must be closed before the next VAPT. Stock brokers and DPs report to the exchanges or depositories, and most other REs report to SEBI. The August 2025 clarification adds that REs submit a summary in the prescribed format and never the explicit vulnerabilities, unless SEBI asks.
The same clarification changed the definition of "critical systems", which drives VAPT scope. Internet-facing and client-facing systems were in the definition from the start (CIR/2024/113). What the August 2025 circular replaced was the last limb: the test of ancillary systems used to access or communicate with critical systems gave way to any other system on the same network segment as the systems in the earlier limbs. That is a different test, not an addition, so re-derive the list rather than appending to it. Build a VAPT engagement from that approved list, not last year's asset register.
Cyber audit cadence and the auditor rules
A cyber audit verifies compliance with CSCRF. It covers 100% of critical systems and a 25% sample of non-critical systems (CIR/2024/113).
| Entity | Cyber audit frequency |
|---|---|
| MIIs and Qualified REs | At least twice a year |
| Mid-size and Small-size REs providing internet-based trading or algo trading | At least twice a year |
| Qualified Stock Brokers, per the FAQs | Half-yearly, whatever their CSCRF category |
| Rest of the REs | At least once a year |
| Self-certification REs | No cyber audit; VAPT by a CERT-In empanelled auditor plus a signed self-certification |
The post-audit deadlines mirror VAPT:
- Report. Submitted within one month, after IT Committee approval.
- Closure. Observations closed within three months of submission.
- Follow-on audit. Completed within five months of the cyber audit.
The auditor rules are specific. Unless the framework says otherwise, every audit and certification under CSCRF must be done by a CERT-In empanelled IS auditing organisation. The same firm can audit an entity for no more than three consecutive years. After that it can audit that entity again only after a two-year cooling-off period (CIR/2024/113). The August 2025 circular also directs REs to follow CERT-In's Cyber Security Audit Policy Guidelines.
In practice, verify the auditor's current CERT-In empanelment before signing, and track rotation from your first CSCRF audit.
SOC requirements and the Market SOC
CSCRF requires every RE to monitor security events continuously through a SOC. The original framework exempted only client-based stock brokers with fewer than 100 clients; the April 2025 circular added DPs and RTAs with fewer than 100 clients (CIR/2025/60). Three models are allowed: your own or group SOC, the Market SOC, or a third-party managed SOC (CIR/2024/113). NSE and BSE must run a Market SOC, and NSDL and CDSL may. Small-size and Self-certification REs are to be onboarded to it.
The August 2025 clarification, citing FAQ 60, lets a Small-size or Self-certification RE that already runs its own SOC keep using it. It must still submit the SOC efficacy report. Portfolio managers in the Self-certification category with fewer than 100 clients are exempt from mandatory Market SOC onboarding (CIR/2025/60).
SOC efficacy is measured, not assumed. MIIs and Qualified REs assess their SOC's functional efficacy half-yearly. Other REs obtain a yearly efficacy report from their SOC provider, using the method in Annexure-N (CIR/2024/113). Our guide to managed SOC services in India covers what to ask a provider, and our SOC as a service page describes how we run monitoring.
MIIs and Qualified REs must also run red teaming exercises. The difference between red teaming and penetration testing matters here, because one cannot stand in for the other.
Other obligations that catch teams out
- ISO 27001. The framework made ISO 27001 mandatory for MIIs and Qualified REs. The August 2025 clarification now says Qualified REs are encouraged, not required, to obtain it.
- Multiple regulators. Under the principle of exclusivity, CSCRF scope is limited to systems used only for SEBI-regulated activity. Shared infrastructure, network, technology stack and security solutions do not simply drop out: SEBI will bring them into its audit or inspection scope if the primary regulator's audit does not cover them. Under the principle of equivalence, a control that matches the primary regulator's framework, such as RBI's for a bank, is deemed compliant. The RE must show which principle it relies on for each control (CIR/2025/119).
- Incidents. All cybersecurity incidents are reported through SEBI's incident reporting portal (CIR/2024/113).
How an entity prepares
- Fix the category. Apply the current thresholds to last year's data and record the result. Check all three circulars: the original, April 2025 and August 2025.
- Build the critical systems list using the August 2025 definition, including same-segment systems, and get Board or partner approval.
- Map the applicable standards for your category. If another regulator also covers you, record exclusivity or equivalence against each control.
- Decide the SOC model, and make sure the efficacy reporting cadence is in the contract.
- Schedule VAPT in Q1 of the financial year, or in each half if you have CII or are a QSB, and book revalidation inside five months.
- Appoint a CERT-In empanelled auditor for the cyber audit, verify the empanelment, and start the three-year rotation count.
- Set up IT Committee tracking for findings, the risk register and approvals, so the three-month closure dates are managed, not discovered.
Where no senior security owner exists, a virtual CISO can run this programme.
Where SecureRoot fits
SecureRoot is certified to ISO/IEC 27001:2022 and ISO 9001:2015. We help REs with the work that comes before and around the audit: scoping critical systems, VAPT and revalidation, SOC monitoring, and vCISO support for IT Committee governance. We are not a CERT-In empanelled IS auditing organisation. Where CSCRF requires an empanelled auditor, your cyber audit and audit-grade VAPT must go to a firm that holds that empanelment. We can help you prepare for that audit.
Frequently asked questions
What is SEBI CSCRF and who must comply?
CSCRF is the Cybersecurity and Cyber Resilience Framework SEBI issued on August 20, 2024 under circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. It replaces the earlier separate cybersecurity circulars with a single framework. It covers 19 types of regulated entity: stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, AIFs and VCFs, KRAs, RTAs, custodians, merchant bankers, credit rating agencies, debenture trustees, bankers to an issue, CIS, designated depository participants, and investment advisers and research analysts. Some entities are carved out. Stock brokers below both 1,000 registered clients and Rs. 1,000 crore of annual clientele trading volume are exempt. So are investment advisers and research analysts registered with SEBI in no other capacity, and inactive merchant bankers. Everyone else is placed in one of five categories, and the category sets the depth of controls, audit frequency and reporting. Start by working out your category from last year's data.
What was the final CSCRF compliance deadline?
For most regulated entities the final date was August 31, 2025, set by SEBI circular CIR/2025/96 of June 30, 2025. The original glide path gave January 1, 2025 to entities that already had a SEBI cybersecurity circular and April 1, 2025 to newly covered entities. In December 2024, SEBI granted regulatory forbearance to March 31, 2025 and moved KRAs and depository participants to April 1, 2025. The March 28, 2025 circular extended the deadline to June 30, 2025, and the June circular extended it again to August 31, 2025. Neither extension applied to Market Infrastructure Institutions, KYC Registration Agencies or Qualified RTAs, so those entities stayed on the earlier dates. With the deadline passed, the live issue is audit timing. SEBI's FAQs say an annual cyber audit covering April 2025 to March 2026 starts after March 2026, so evidence from that whole period counts.
How often do SEBI regulated entities need VAPT under CSCRF?
Most regulated entities need VAPT at least once a year, starting in the first quarter of the financial year. Entities with systems that NCIIPC has identified as protected systems or critical information infrastructure must test at least twice a year, once in each half. Each of those rounds must finish report submission, closure and revalidation within its half. SEBI's June 2025 FAQs add that Qualified Stock Brokers run VAPT half-yearly, whatever their CSCRF category. The deadlines after testing are the same for everyone. The report is submitted within one month, after IT Committee approval and with an MD or CEO declaration. Findings are closed within three months of the report, and revalidation is completed within five months of the VAPT. Scope follows the critical systems list, which always included internet-facing and client-facing systems. Since August 2025 a same-network-segment test replaces the old ancillary systems test, so revisit scope before booking testers.
Does the CSCRF cyber audit have to be done by a CERT-In empanelled auditor?
Yes. Unless the framework says otherwise, every audit and certification under CSCRF must be done by a CERT-In empanelled IS auditing organisation, and that includes the cyber audit and VAPT. The same auditing organisation can audit an entity for no more than three consecutive years, then must wait two years before auditing it again. In August 2025, SEBI also directed entities to follow CERT-In's Cyber Security Audit Policy Guidelines. Self-certification entities are the exception on scope, not on the auditor rule. They skip the cyber audit but must still have VAPT done by a CERT-In empanelled organisation, and they submit a self-certification signed by the MD, CEO, a Board member, partner or proprietor. Before signing an engagement letter, check the firm's current empanelment status with CERT-In. Also record the start year so the rotation limit does not catch you mid-cycle, especially if you switched auditors when CSCRF began.
Do small SEBI regulated entities have to join the Market SOC?
Small-size and Self-certification entities are mandated to onboard to the Market SOC that NSE and BSE must set up. NSDL and CDSL may also run one. The rule is less rigid than it first reads. SEBI's June 2025 FAQ 60, repeated in the August 2025 clarification, lets a Small-size or Self-certification entity that already runs its own SOC keep using it. It must still submit the SOC efficacy report as CSCRF requires. There are also exemptions. Depository participants with fewer than 100 clients do not need SOC services at all. Neither do client-based stock brokers or RTAs with fewer than 100 clients. Self-certification portfolio managers and AIF or VCF managers with fewer than 100 clients are exempt from mandatory Market SOC onboarding. Whichever route you take, responsibility for compliance stays with your entity, not the SOC operator. Other entities not on the Market SOC must obtain a yearly efficacy report from their provider.
Next step
If you need to confirm your CSCRF category, rebuild your critical systems scope or get VAPT and SOC evidence ready before your CERT-In empanelled auditor arrives, book a 30 minute scoping call. You will get a written scope, a timeline and a fixed price.
Have a Question About This?
If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.
We reply within one business day.


