RegulatoryIndia

SEBI CSCRF compliance

SEBI Cyber Security & Cyber Resilience Framework

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) consolidates cyber requirements for regulated entities into a single, structured mandate spanning governance, identification, protection, detection, response and recovery. Pelta helps you implement CSCRF controls, keep them mapped to evidence, and demonstrate the cyber resilience regulators now expect.

Who it's for

Does SEBI CSCRF apply to you?

  • SEBI-regulated entities in the securities market
  • Stock brokers, depositories, AMCs and market infrastructure institutions
  • Firms that must demonstrate cyber resilience to SEBI

What the SEBI CSCRF covers

The Cyber Security and Cyber Resilience Framework consolidates SEBI's cyber expectations into a single, structured baseline organised around the widely used functions of govern, identify, protect, detect, respond and recover. Its defining emphasis is cyber resilience — not just preventing incidents, but being able to keep critical operations running through one and recover within defined tolerances.

The six CSCRF functions

Govern

Policy & accountability

Identify

Assets & risk

Protect

Controls & hardening

Detect

Monitoring & alerts

Respond

Incident handling

Recover

Resilience & restore

Rather than a scattered set of circulars, CSCRF gives regulated entities one coherent structure. It formalises expectations that were previously spread across multiple documents — governance and board accountability, security operations and monitoring, incident detection and reporting, periodic audits and testing, and the management of third-party and outsourcing risk.

Who must comply — and the role of entity categories

CSCRF applies to SEBI-regulated entities across the securities market. SEBI has taken a proportionate, category-based approach: the depth of obligations scales with the size, interconnectedness and criticality of the entity. Larger market infrastructure institutions carry the most comprehensive requirements, while smaller entities have a lighter — but still meaningful — baseline to meet.

Indicative view of CSCRF's proportionate approach
Entity tierIndicative expectation
Market Infrastructure Institutions (MIIs)The most comprehensive obligations — full framework coverage with the deepest monitoring, testing and reporting expectations.
Qualified / larger regulated entitiesBroad framework coverage, including structured security operations and regular independent assurance.
Mid-size regulated entitiesSubstantial coverage of the framework with proportionate monitoring and audit expectations.
Smaller / self-certification entitiesA lighter, baseline set of obligations, typically evidenced through self-certification.
Your exact obligations and timelines depend on your entity category and the applicable SEBI circular. This page is a general overview, not legal advice — always validate against the current official text for your classification.

Key requirements at a glance

The specifics vary by category, but most regulated entities will need to address the following areas:

  • Governance: a board-approved cyber security and cyber resilience policy, defined roles, and a senior officer accountable for cyber security.
  • Risk assessment: a maintained view of assets, data and the critical services they support, with periodic risk assessment.
  • Protective controls: access control, strong authentication, secure configuration, patching and encryption of sensitive data.
  • Security monitoring: the ability to continuously monitor, log and alert — with more comprehensive SOC expectations for larger entities.
  • Incident detection and reporting: processes to detect, respond to and report incidents within regulatory timelines.
  • Cyber resilience: business continuity, disaster recovery and defined recovery objectives for critical services.
  • Assurance: periodic audits, vulnerability assessment and penetration testing (VAPT), and control testing.
  • Third-party risk: oversight of vendors, service providers and outsourced arrangements.

How to approach CSCRF compliance

A practical route to CSCRF compliance — and, more importantly, to staying compliant — looks like this:

  1. 1Scope and categorise: confirm your entity category and the obligations that apply to you.
  2. 2Run a gap assessment against the CSCRF control set to see where you stand today.
  3. 3Prioritise and remediate the gaps, starting with the highest-risk critical services.
  4. 4Map every control to the evidence that proves it, in one place, so nothing lives in scattered drives.
  5. 5Stand up continuous monitoring and the reporting needed to meet regulatory timelines.
  6. 6Test and rehearse: run VAPT, audits and response-and-recovery exercises against your critical services.

Common pitfalls to avoid

  • Treating CSCRF as a one-time project instead of an operating rhythm you sustain and report on.
  • Leaving evidence in scattered folders and inboxes, so every audit becomes a multi-week scramble.
  • Over-investing in preventative controls while under-investing in resilience, recovery and testing.
  • Overlooking third-party and outsourced dependencies that sit outside your direct control.
  • Rebuilding from scratch for each mandate instead of reusing overlapping controls from ISO 27001, PCI DSS and DPDPA.
How Pelta helps

Run SEBI CSCRF on one connected platform

CSCRF as a first-class framework

The full framework is built into Pelta, so you manage controls against CSCRF directly rather than mapping from a generic baseline.

Governance and reporting

Maintain board-approved policies and report cyber posture on a defined cadence.

Resilience by service

Model critical services with recovery objectives to evidence the resilience CSCRF requires.

Continuous evidence

Every control links to the evidence that proves it — so inspections become a filter, not a fire drill.

SEBI CSCRF FAQs

Who does SEBI CSCRF apply to?+

CSCRF applies to SEBI-regulated entities in the securities market. Specific requirements and timelines vary by entity category — confirm the applicable SEBI circular for your class of entity.

What are the main functions of SEBI CSCRF?+

CSCRF is organised around the functions of govern, identify, protect, detect, respond and recover, with a defining emphasis on cyber resilience — the ability to keep critical operations running through an incident and recover within defined tolerances.

Does SEBI CSCRF apply the same way to every entity?+

No. SEBI takes a proportionate, category-based approach, so obligations scale with the size and criticality of the entity. Larger market infrastructure institutions face the most comprehensive requirements; smaller entities have a lighter baseline.

Does CSCRF require continuous monitoring or a SOC?+

Most entities are expected to have security monitoring, logging and alerting appropriate to their category, with more comprehensive SOC expectations for larger entities. Confirm the specifics for your classification.

How is CSCRF different from ISO 27001?+

ISO 27001 is a voluntary international standard for an information security management system. CSCRF is a mandatory regulatory framework with an explicit focus on cyber resilience for regulated entities in India. Their controls overlap, so evidence can be reused across both.

What's the hardest part of CSCRF compliance?+

For most teams it's evidencing controls continuously and demonstrating resilience — showing you can recover critical services within defined tolerances — rather than implementing the controls themselves.

How does Pelta help with SEBI CSCRF?+

Pelta ships CSCRF as a built-in framework, maps your controls to evidence, supports governance and reporting, and models critical services with recovery objectives to demonstrate cyber resilience — reusing controls that overlap with ISO 27001, PCI DSS and DPDPA.

See SEBI CSCRF compliance on Pelta

Achieve and evidence SEBI CSCRF compliance on Pelta — governance, controls, resilience and continuous evidence for regulated entities in India's securities market.