For most teams, the hardest question about SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) isn't how to comply, it's whether the framework applies to them at all, which category they fall into, and by when they need to be ready. Get that wrong and you either over-invest in controls you don't need, or discover a mandatory obligation weeks before an inspection. This guide explains SEBI CSCRF applicability in plain English: who is in scope, how the graded categories work, which category your entity type typically lands in, and what changes once you're covered. For the framework itself and how to implement it, see the SEBI CSCRF framework overview.
What SEBI CSCRF is, in one paragraph
CSCRF is SEBI's consolidated cyber security and cyber resilience mandate for regulated entities (REs) in India's securities market. Rather than a separate cyber circular for each type of intermediary, CSCRF brings the requirements into one structured framework built around familiar functions (governance, identify, protect, detect, respond and recover) with an explicit emphasis on resilience: the ability to keep critical services running and recover them within defined tolerances. Crucially, it applies a graded approach, so the depth of what you must do scales with the size and nature of your operations. For a fuller breakdown of the controls themselves, see our SEBI CSCRF compliance checklist.
Who does SEBI CSCRF apply to?
CSCRF applies broadly across SEBI-regulated entities in the securities market. If you are registered with SEBI and handle client data, funds, orders or market infrastructure, you should assume you are in scope until you have confirmed otherwise. Entity types typically covered include:
- Stock exchanges, clearing corporations and depositories (the market infrastructure institutions)
- Stock brokers and depository participants
- Mutual funds and asset management companies (AMCs)
- KYC Registration Agencies (KRAs) and Registrars to an Issue / Share Transfer Agents (RTAs)
- Investment advisers, research analysts and portfolio managers
- Alternative Investment Funds (AIFs), merchant bankers and debenture trustees
- Credit rating agencies and other registered intermediaries
The practical takeaway: the question is rarely whether CSCRF applies, but which category you fall into, because that determines how much of the framework applies to you.
The five graded categories
CSCRF's graded approach sorts REs into categories, with obligations that get progressively heavier as size and systemic importance increase. The categories, from most to least intensive, are typically:
Market Infrastructure Institutions
Exchanges, clearing corporations, depositories
Qualified REs
Larger REs above key thresholds
Mid-size REs
Mid-tier REs by size
Small-size REs
Below the mid-size thresholds
Self-certification REs
Smallest REs & specified categories
| Category | Who it typically covers | Compliance intensity |
|---|---|---|
| Market Infrastructure Institutions (MIIs) | Stock exchanges, clearing corporations, depositories | Highest, the full framework, dedicated security operations, frequent audits and testing |
| Qualified REs | Larger REs above defined client, volume or asset thresholds | High, security operations coverage, VAPT, periodic cyber audits |
| Mid-size REs | Mid-tier REs by the relevant size thresholds | Moderate, proportionate controls, testing and audit cadence |
| Small-size REs | Smaller REs below the mid-size thresholds | Lighter, core controls at a reduced frequency |
| Self-certification REs | The smallest REs and specified categories | Baseline, self-certified compliance against core requirements |
The exact thresholds that separate one category from the next are defined per RE type, an AMC is measured differently from a stock broker or an investment adviser. That is why two firms of similar headcount can land in different categories, and why category placement should be documented, not assumed.
SEBI CSCRF by entity type
The graded categories are defined per registration type, so the first question most firms ask is a specific one: does SEBI CSCRF apply to me, and where do I sit? The short answer for every entity type below is that CSCRF applies, and your category is driven by your own size and activity thresholds. Use this as a starting point, then confirm your exact category and timeline against the current circular for your registration.
SEBI CSCRF for stock brokers and depository participants
Stock brokers and depository participants are squarely in scope. Their category is determined by size measures such as the number of active clients and trading or transaction volume, so a large retail broker can land in a Qualified or Mid-size tier with security operations, VAPT and periodic cyber-audit obligations, while a small broker may fall into Small-size or Self-certification with a lighter cadence. Confirm your client and volume figures against the current thresholds before you scope your program, then work from the compliance checklist.
SEBI CSCRF for RTAs and share transfer agents
Registrars to an Issue and Share Transfer Agents (RTAs) are covered, with Qualified RTAs (QRTAs) that serve large issuer and investor bases carrying heavier obligations than smaller RTAs. Because RTAs hold large volumes of investor data, expect emphasis on data protection, access control and evidence of resilience for the services investors depend on.
SEBI CSCRF for KRAs and QRTAs
KYC Registration Agencies (KRAs) and Qualified RTAs sit toward the more intensive end because of the sensitivity and scale of the identity and investor data they manage. Assume comprehensive governance, monitoring and testing obligations, and confirm the specific category assigned to your entity.
SEBI CSCRF for mutual funds and AMCs
Asset management companies and mutual funds are in scope, with category driven by assets under management and operational scale. Larger AMCs typically fall into higher tiers with fuller security-operations, testing and audit expectations. Note that an AMC is measured on different parameters than a broker, so headcount is a poor proxy for category.
SEBI CSCRF for investment advisers and research analysts
Investment advisers, research analysts and portfolio managers are covered, and many of the smaller ones fall into the Small-size or Self-certification categories, meeting the core of the framework at a lighter, often self-certified cadence. Smaller does not mean exempt: the baseline governance, protective controls and incident-reporting expectations still apply.
How to determine your CSCRF category
Placing your entity in the right category is a short but important exercise. Work through it deliberately and keep a record of your reasoning, it is exactly the kind of thing an inspection will ask you to justify.
- 1Identify your registration type. Start from how you are registered with SEBI (broker, AMC, RTA, investment adviser, and so on), the applicable thresholds are defined per registration type.
- 2Gather the measurement parameters. Depending on your type, this may include number of clients or investors, trading or transaction volume, assets under management or custody, and similar operational measures.
- 3Compare against the thresholds in the current circular. Map your figures to the bands SEBI defines for your entity type to arrive at your category.
- 4Document the determination. Record the parameters, the date, and the resulting category, and set a reminder to re-check, since crossing a threshold can move you into a heavier category.
- 5Confirm your timeline. Note the compliance date that applies to your category and entity type, and work back from it.
What applies once you're in scope
Being in scope means the CSCRF functions apply to you, but the depth is proportionate to your category. Broadly, higher categories take on more of the following, more often:
- Board-approved governance: a cyber security and cyber resilience policy, a designated accountable officer, and regular reporting of cyber risk to leadership.
- Asset and service identification: an accurate inventory of critical systems and data, and a mapping of critical services to the assets and third parties they depend on.
- Protective controls: access control and strong authentication, secure configuration and patching, encryption, and staff awareness.
- Detection and monitoring: continuous logging and alerting, with security operations coverage that scales up for larger entities.
- Testing: vulnerability assessment and penetration testing (VAPT) and periodic cyber audits, at a frequency set by category.
- Response and recovery: a tested incident response plan, recovery objectives for critical services, and incident reporting aligned to regulatory timelines.
Smaller and self-certification REs are not exempt from these ideas, they are expected to meet the core of them at a lighter cadence, and to attest that they do.
Timelines: know your date
CSCRF has been implemented on a phased basis, and SEBI has revised the effective dates during rollout. Because the applicable date depends on both your entity type and your category (and because these dates have moved) you should treat the timeline as something to verify directly rather than assume. Find the compliance date for your specific class of entity in the current circular, confirm whether any glide-path extension applies to you, and plan your program back from that date with room for testing and evidence collection.
The real challenge isn't the controls, it's scope and evidence
Once you know your category, two problems remain, and they are where teams lose the most time. The first is scoping: translating your category into the exact set of controls and testing obligations that apply to you, without doing more than required or missing something mandatory. The second is evidence: proving, on demand, that each applicable control is actually in place. The entities that struggle at inspection time are rarely the ones with weak controls, they are the ones whose proof is scattered across folders, inboxes and spreadsheets.
And because CSCRF shares a large control base with international standards, the work isn't single-use. Once your CSCRF program is running, the same controls and evidence map onto frameworks like ISO 27001, so a firm that starts with its regional mandate can extend to a global certification for a fraction of the effort of starting over.
Putting it together
SEBI CSCRF applicability comes down to three questions: which entity type are you, which graded category do you fall into, and what is your compliance date. Answer those with documented reasoning, scope the applicable controls to your category, and keep each one tied to live evidence, and CSCRF stops being an annual fire drill and becomes an operating rhythm you can demonstrate at any time. Start from your category, and the rest of the framework becomes a plan rather than a puzzle. If you would rather have applicability, scoping and evidence handled end to end, see our SEBI CSCRF compliance services.
Frequently asked questions
Who does SEBI CSCRF apply to?+
CSCRF applies to SEBI-regulated entities in the securities market, including stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, KRAs, RTAs, investment advisers, research analysts, portfolio managers, AIFs and more. The depth of the requirements depends on which graded category your entity falls into.
What are the SEBI CSCRF entity categories?+
CSCRF uses a graded approach with categories that typically run from Market Infrastructure Institutions (MIIs) at the most intensive, through Qualified REs, Mid-size REs and Small-size REs, to Self-certification REs at the baseline. Obligations scale up with size and systemic importance.
How do I know which CSCRF category I fall into?+
Start from your SEBI registration type, gather the relevant measurement parameters for that type (such as number of clients, trading volume, or assets under management or custody), and compare them against the thresholds in the current SEBI circular. Document the determination, because crossing a threshold can move you into a heavier category.
When did SEBI CSCRF come into effect?+
CSCRF has been implemented on a phased basis and SEBI has revised the effective dates during rollout, with the applicable date depending on entity type and category. Confirm the current compliance date for your specific class of entity against the latest SEBI circular.
Is SEBI CSCRF mandatory for small entities?+
Smaller entities are not exempt. The framework's graded approach means the smallest REs and specified categories meet the core requirements at a lighter cadence, often through self-certification, rather than being outside the framework entirely.
Does SEBI CSCRF apply to stock brokers?+
Yes. Stock brokers and depository participants are in scope for CSCRF. Which graded category they fall into is driven by size measures such as active clients and trading volume, so a large broker faces heavier obligations (security operations, VAPT, periodic cyber audits) than a small one, which may sit in Small-size or Self-certification. Confirm your figures against the current thresholds.
Does SEBI CSCRF apply to RTAs and KRAs?+
Yes. Registrars and Share Transfer Agents (RTAs), Qualified RTAs (QRTAs) and KYC Registration Agencies (KRAs) are all covered. Because they hold large volumes of sensitive investor and identity data, they typically carry more intensive data-protection, monitoring and resilience obligations. Confirm the specific category assigned to your entity.
About the author
Nilesh Wagh
Co-Founder, Pelta Technologies
Former CISO · 10+ years in information security & GRC
Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.
Connect on LinkedIn →