RegulatoryIndia

SEBI CSCRF compliance

SEBI Cyber Security & Cyber Resilience Framework

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) consolidates cyber requirements for regulated entities into a single, structured mandate spanning governance, identification, protection, detection, response and recovery. Pelta helps you implement CSCRF controls, keep them mapped to evidence, and demonstrate the cyber resilience regulators now expect.

Who it's for

Does SEBI CSCRF apply to you?

  • SEBI-regulated entities in the securities market
  • Stock brokers, depositories, AMCs and market infrastructure institutions
  • Firms that must demonstrate cyber resilience to SEBI

What the SEBI CSCRF covers

The Cyber Security and Cyber Resilience Framework consolidates SEBI's cyber expectations into a single, structured baseline organised around the widely used functions of govern, identify, protect, detect, respond and recover. Its defining emphasis is cyber resilience, not just preventing incidents, but being able to keep critical operations running through one and recover within defined tolerances.

The six CSCRF functions

Govern

Policy & accountability

Identify

Assets & risk

Protect

Controls & hardening

Detect

Monitoring & alerts

Respond

Incident handling

Recover

Resilience & restore

Rather than a scattered set of circulars, CSCRF gives regulated entities one coherent structure. It formalises expectations that were previously spread across multiple documents, governance and board accountability, security operations and monitoring, incident detection and reporting, periodic audits and testing, and the management of third-party and outsourcing risk.

Who must comply, and the role of entity categories

CSCRF applies to SEBI-regulated entities across the securities market. SEBI has taken a proportionate, category-based approach: the depth of obligations scales with the size, interconnectedness and criticality of the entity. Larger market infrastructure institutions carry the most comprehensive requirements, while smaller entities have a lighter (but still meaningful) baseline to meet.

Indicative view of CSCRF's proportionate approach
Entity tierIndicative expectation
Market Infrastructure Institutions (MIIs)The most comprehensive obligations, full framework coverage with the deepest monitoring, testing and reporting expectations.
Qualified / larger regulated entitiesBroad framework coverage, including structured security operations and regular independent assurance.
Mid-size regulated entitiesSubstantial coverage of the framework with proportionate monitoring and audit expectations.
Smaller / self-certification entitiesA lighter, baseline set of obligations, typically evidenced through self-certification.
Your exact obligations and timelines depend on your entity category and the applicable SEBI circular. This page is a general overview, not legal advice, always validate against the current official text for your classification.

Key requirements at a glance

The specifics vary by category, but most regulated entities will need to address the following areas:

  • Governance: a board-approved cyber security and cyber resilience policy, defined roles, and a senior officer accountable for cyber security.
  • Risk assessment: a maintained view of assets, data and the critical services they support, with periodic risk assessment.
  • Protective controls: access control, strong authentication, secure configuration, patching and encryption of sensitive data.
  • Security monitoring: the ability to continuously monitor, log and alert, with more comprehensive SOC expectations for larger entities.
  • Incident detection and reporting: processes to detect, respond to and report incidents within regulatory timelines.
  • Cyber resilience: business continuity, disaster recovery and defined recovery objectives for critical services.
  • Assurance: periodic audits, vulnerability assessment and penetration testing (VAPT), and control testing.
  • Third-party risk: oversight of vendors, service providers and outsourced arrangements.

How to approach CSCRF compliance

A practical route to CSCRF compliance (and, more importantly, to staying compliant) looks like this:

  1. 1Scope and categorise: confirm your entity category and the obligations that apply to you.
  2. 2Run a gap assessment against the CSCRF control set to see where you stand today.
  3. 3Prioritise and remediate the gaps, starting with the highest-risk critical services.
  4. 4Map every control to the evidence that proves it, in one place, so nothing lives in scattered drives.
  5. 5Stand up continuous monitoring and the reporting needed to meet regulatory timelines.
  6. 6Test and rehearse: run VAPT, audits and response-and-recovery exercises against your critical services.

Common pitfalls to avoid

  • Treating CSCRF as a one-time project instead of an operating rhythm you sustain and report on.
  • Leaving evidence in scattered folders and inboxes, so every audit becomes a multi-week scramble.
  • Over-investing in preventative controls while under-investing in resilience, recovery and testing.
  • Overlooking third-party and outsourced dependencies that sit outside your direct control.
  • Rebuilding from scratch for each mandate instead of reusing overlapping controls from ISO 27001, PCI DSS and DPDPA.
How Pelta helps

Run SEBI CSCRF on one connected platform

CSCRF as a first-class framework

The full framework is built into Pelta, so you manage controls against CSCRF directly rather than mapping from a generic baseline.

Governance and reporting

Maintain board-approved policies and report cyber posture on a defined cadence.

Resilience by service

Model critical services with recovery objectives to evidence the resilience CSCRF requires.

Continuous evidence

Every control links to the evidence that proves it, so inspections become a filter, not a fire drill.

SEBI CSCRF FAQs

Who does SEBI CSCRF apply to?+

CSCRF applies to SEBI-regulated entities in the securities market. Specific requirements and timelines vary by entity category, confirm the applicable SEBI circular for your class of entity.

What are the main functions of SEBI CSCRF?+

CSCRF is organised around the functions of govern, identify, protect, detect, respond and recover, with a defining emphasis on cyber resilience, the ability to keep critical operations running through an incident and recover within defined tolerances.

Does SEBI CSCRF apply the same way to every entity?+

No. SEBI takes a proportionate, category-based approach, so obligations scale with the size and criticality of the entity. Larger market infrastructure institutions face the most comprehensive requirements; smaller entities have a lighter baseline.

Does CSCRF require continuous monitoring or a SOC?+

Most entities are expected to have security monitoring, logging and alerting appropriate to their category, with more comprehensive SOC expectations for larger entities. Confirm the specifics for your classification.

How is CSCRF different from ISO 27001?+

ISO 27001 is a voluntary international standard for an information security management system. CSCRF is a mandatory regulatory framework with an explicit focus on cyber resilience for regulated entities in India. Their controls overlap, so evidence can be reused across both.

What's the hardest part of CSCRF compliance?+

For most teams it's evidencing controls continuously and demonstrating resilience (showing you can recover critical services within defined tolerances) rather than implementing the controls themselves.

How does Pelta help with SEBI CSCRF?+

Pelta ships CSCRF as a built-in framework, maps your controls to evidence, supports governance and reporting, and models critical services with recovery objectives to demonstrate cyber resilience, reusing controls that overlap with ISO 27001, PCI DSS and DPDPA.

Guides & articles

Go deeper on SEBI CSCRF

All resources →
Compliance

SEBI CSCRF Incident Response and Reporting Requirements

Under CSCRF, how you handle and report an incident is itself a compliance obligation. Late or missing reports are a violation in their own right. Here's what a compliant response and reporting process looks like.

Read
Compliance

SEBI CSCRF Audit and VAPT Requirements

CSCRF does not take your word for it. It builds in independent assurance through cyber audits, VAPT and, for larger entities, a Cyber Capability Index. Here's what each involves and how often.

Read
Compliance

SEBI CSCRF Timelines and Deadlines: How to Find Yours

There isn't one SEBI CSCRF deadline. Dates have been phased and revised, and yours depends on your entity type and category. Here's how to find your date and plan back from it.

Read
Compliance

SEBI CSCRF Logging and SOC Requirements Explained

CSCRF's detect function turns logging and a SOC from nice-to-haves into obligations. Here's what to log, how long to keep it, the SOC coverage expected of your category, and the Market SOC option for smaller entities.

Read
Compliance

Data Localisation Under SEBI CSCRF: What Must Stay in India

One of the least understood parts of SEBI's CSCRF is where your data is allowed to live. For any regulated entity running on foreign cloud or SaaS, data localisation is where compliance quietly breaks, here's what actually has to stay in India, and how to prove it.

Read
Compliance

SEBI CSCRF Penalties: What Non-Compliance Actually Costs

SEBI CSCRF doesn't come with its own rupee-value penalty schedule, but non-compliance is very much enforceable. Here's what SEBI can actually do, from a deficiency letter to a cancelled registration, and the costs that dwarf the fine.

Read
Compliance

SEBI CSCRF Applicability: Which Regulated Entities Must Comply

The most common question about SEBI's Cyber Security and Cyber Resilience Framework isn't how to comply, it's whether it even applies to you, and by when. Here's how to place your entity in the right category.

Read
Compliance

SEBI CSCRF Compliance Checklist: What Regulated Entities Need

SEBI's CSCRF raises the bar for regulated entities across six functions. Here's a plain-English, item-by-item checklist of what you need in place, plus the SOC, VAPT and audit expectations, and how to prove each one.

Read

See SEBI CSCRF compliance on Pelta

Achieve and evidence SEBI CSCRF compliance on Pelta, governance, controls, resilience and continuous evidence for regulated entities in India's securities market.