For most teams, the hardest question about SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) isn't how to comply — it's whether the framework applies to them at all, which category they fall into, and by when they need to be ready. Get that wrong and you either over-invest in controls you don't need, or discover a mandatory obligation weeks before an inspection. This guide explains SEBI CSCRF applicability in plain English: who is in scope, how the graded categories work, how to find yours, and what changes once you're covered.
What SEBI CSCRF is, in one paragraph
CSCRF is SEBI's consolidated cyber security and cyber resilience mandate for regulated entities (REs) in India's securities market. Rather than a separate cyber circular for each type of intermediary, CSCRF brings the requirements into one structured framework built around familiar functions — governance, identify, protect, detect, respond and recover — with an explicit emphasis on resilience: the ability to keep critical services running and recover them within defined tolerances. Crucially, it applies a graded approach, so the depth of what you must do scales with the size and nature of your operations. For a fuller breakdown of the controls themselves, see our SEBI CSCRF compliance checklist.
Who does SEBI CSCRF apply to?
CSCRF applies broadly across SEBI-regulated entities in the securities market. If you are registered with SEBI and handle client data, funds, orders or market infrastructure, you should assume you are in scope until you have confirmed otherwise. Entity types typically covered include:
- Stock exchanges, clearing corporations and depositories (the market infrastructure institutions)
- Stock brokers and depository participants
- Mutual funds and asset management companies (AMCs)
- KYC Registration Agencies (KRAs) and Registrars to an Issue / Share Transfer Agents (RTAs)
- Investment advisers, research analysts and portfolio managers
- Alternative Investment Funds (AIFs), merchant bankers and debenture trustees
- Credit rating agencies and other registered intermediaries
The practical takeaway: the question is rarely whether CSCRF applies, but which category you fall into — because that determines how much of the framework applies to you.
The five graded categories
CSCRF's graded approach sorts REs into categories, with obligations that get progressively heavier as size and systemic importance increase. The categories, from most to least intensive, are typically:
Market Infrastructure Institutions
Exchanges, clearing corporations, depositories
Qualified REs
Larger REs above key thresholds
Mid-size REs
Mid-tier REs by size
Small-size REs
Below the mid-size thresholds
Self-certification REs
Smallest REs & specified categories
| Category | Who it typically covers | Compliance intensity |
|---|---|---|
| Market Infrastructure Institutions (MIIs) | Stock exchanges, clearing corporations, depositories | Highest — the full framework, dedicated security operations, frequent audits and testing |
| Qualified REs | Larger REs above defined client, volume or asset thresholds | High — security operations coverage, VAPT, periodic cyber audits |
| Mid-size REs | Mid-tier REs by the relevant size thresholds | Moderate — proportionate controls, testing and audit cadence |
| Small-size REs | Smaller REs below the mid-size thresholds | Lighter — core controls at a reduced frequency |
| Self-certification REs | The smallest REs and specified categories | Baseline — self-certified compliance against core requirements |
The exact thresholds that separate one category from the next are defined per RE type — an AMC is measured differently from a stock broker or an investment adviser. That is why two firms of similar headcount can land in different categories, and why category placement should be documented, not assumed.
How to determine your CSCRF category
Placing your entity in the right category is a short but important exercise. Work through it deliberately and keep a record of your reasoning — it is exactly the kind of thing an inspection will ask you to justify.
- 1Identify your registration type. Start from how you are registered with SEBI (broker, AMC, RTA, investment adviser, and so on) — the applicable thresholds are defined per registration type.
- 2Gather the measurement parameters. Depending on your type, this may include number of clients or investors, trading or transaction volume, assets under management or custody, and similar operational measures.
- 3Compare against the thresholds in the current circular. Map your figures to the bands SEBI defines for your entity type to arrive at your category.
- 4Document the determination. Record the parameters, the date, and the resulting category — and set a reminder to re-check, since crossing a threshold can move you into a heavier category.
- 5Confirm your timeline. Note the compliance date that applies to your category and entity type, and work back from it.
What applies once you're in scope
Being in scope means the CSCRF functions apply to you — but the depth is proportionate to your category. Broadly, higher categories take on more of the following, more often:
- Board-approved governance: a cyber security and cyber resilience policy, a designated accountable officer, and regular reporting of cyber risk to leadership.
- Asset and service identification: an accurate inventory of critical systems and data, and a mapping of critical services to the assets and third parties they depend on.
- Protective controls: access control and strong authentication, secure configuration and patching, encryption, and staff awareness.
- Detection and monitoring: continuous logging and alerting, with security operations coverage that scales up for larger entities.
- Testing: vulnerability assessment and penetration testing (VAPT) and periodic cyber audits, at a frequency set by category.
- Response and recovery: a tested incident response plan, recovery objectives for critical services, and incident reporting aligned to regulatory timelines.
Smaller and self-certification REs are not exempt from these ideas — they are expected to meet the core of them at a lighter cadence, and to attest that they do.
Timelines: know your date
CSCRF has been implemented on a phased basis, and SEBI has revised the effective dates during rollout. Because the applicable date depends on both your entity type and your category — and because these dates have moved — you should treat the timeline as something to verify directly rather than assume. Find the compliance date for your specific class of entity in the current circular, confirm whether any glide-path extension applies to you, and plan your program back from that date with room for testing and evidence collection.
The real challenge isn't the controls — it's scope and evidence
Once you know your category, two problems remain, and they are where teams lose the most time. The first is scoping: translating your category into the exact set of controls and testing obligations that apply to you, without doing more than required or missing something mandatory. The second is evidence: proving, on demand, that each applicable control is actually in place. The entities that struggle at inspection time are rarely the ones with weak controls — they are the ones whose proof is scattered across folders, inboxes and spreadsheets.
And because CSCRF shares a large control base with international standards, the work isn't single-use. Once your CSCRF program is running, the same controls and evidence map onto frameworks like ISO 27001 — so a firm that starts with its regional mandate can extend to a global certification for a fraction of the effort of starting over.
Putting it together
SEBI CSCRF applicability comes down to three questions: which entity type are you, which graded category do you fall into, and what is your compliance date. Answer those with documented reasoning, scope the applicable controls to your category, and keep each one tied to live evidence — and CSCRF stops being an annual fire drill and becomes an operating rhythm you can demonstrate at any time. Start from your category, and the rest of the framework becomes a plan rather than a puzzle.
Frequently asked questions
Who does SEBI CSCRF apply to?+
CSCRF applies to SEBI-regulated entities in the securities market — including stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, KRAs, RTAs, investment advisers, research analysts, portfolio managers, AIFs and more. The depth of the requirements depends on which graded category your entity falls into.
What are the SEBI CSCRF entity categories?+
CSCRF uses a graded approach with categories that typically run from Market Infrastructure Institutions (MIIs) at the most intensive, through Qualified REs, Mid-size REs and Small-size REs, to Self-certification REs at the baseline. Obligations scale up with size and systemic importance.
How do I know which CSCRF category I fall into?+
Start from your SEBI registration type, gather the relevant measurement parameters for that type (such as number of clients, trading volume, or assets under management or custody), and compare them against the thresholds in the current SEBI circular. Document the determination, because crossing a threshold can move you into a heavier category.
When did SEBI CSCRF come into effect?+
CSCRF has been implemented on a phased basis and SEBI has revised the effective dates during rollout, with the applicable date depending on entity type and category. Confirm the current compliance date for your specific class of entity against the latest SEBI circular.
Is SEBI CSCRF mandatory for small entities?+
Smaller entities are not exempt. The framework's graded approach means the smallest REs and specified categories meet the core requirements at a lighter cadence, often through self-certification, rather than being outside the framework entirely.