One of the most common questions about SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) is simply: when is the deadline? The honest answer is that there is no single date. CSCRF has been implemented in phases, SEBI has revised the effective dates more than once during rollout, and the date that applies to you depends on your entity type and your category. This guide explains why the timeline works that way, how to find the date that applies to you, and how to plan back from it so you are ready with room to spare rather than scrambling at the last minute.
Why there isn't one CSCRF deadline
CSCRF applies across many types of regulated entity, from the largest market infrastructure institutions to the smallest self-certification REs, and it would make little sense to hold all of them to the same date. Instead, SEBI has phased the rollout, set dates that differ by entity type and category, and adjusted those dates through circulars as the framework matured. The result is a moving target that you have to pin down for your own entity rather than read off a single headline date.
What determines your compliance date
- Your entity type: the class of intermediary you are registered as with SEBI.
- Your category: where you fall in the graded structure, from MII down to self-certification.
- Any glide path or extension: SEBI has granted additional time in some circulars, which may or may not apply to you.
Because category drives so much, confirming it is the first step. Our applicability guide walks through how the graded categories work and how to place your entity in the right one.
How to find your CSCRF deadline
- 1Confirm your entity type from your SEBI registration.
- 2Determine your category using the graded thresholds for your entity type.
- 3Find the compliance date for that type and category in the current SEBI circular.
- 4Check whether any glide-path extension applies to you, and note the revised date if so.
- 5Record the date and its source, and set a reminder to re-check, since dates have moved before.
A work-back plan from your deadline
Whatever your date, the work to get ready takes longer than teams expect, mostly because evidence has to accumulate over time. Plan back from the deadline rather than forward from today.
Confirm date
Type & category
Gap assessment
Against your category
Implement
Close the gaps
Test
VAPT & audit
Evidence
Build the proof
Go-live
Compliant, on time
The step teams underestimate is evidence. A control implemented the week before the deadline has no track record behind it, and CSCRF assurance looks for evidence over time. Starting early is what turns the deadline from a cliff edge into a plan. For the controls to work through, see the compliance checklist, and for the detection capability that takes longest to stand up, the logging and SOC guide.
Don't wait for the deadline
Even if your date has been extended, the extension is best treated as breathing room to do the work properly, not a reason to defer it. Entities that use the extra time to build evidence and test their response walk into inspection ready; those that treat it as a reprieve tend to arrive at the new date in the same position they were in at the old one.
Putting it together
There is no universal CSCRF deadline, only the one that applies to your entity type and category, and it may have been revised. Confirm your category, find your date in the current circular, check for any glide path, and plan back from it with time for evidence to accumulate. Treat the date as the end of a plan you started early, and CSCRF stops being a scramble. If you would rather have the timeline and the work managed for you, see our SEBI CSCRF compliance services.
Frequently asked questions
What is the SEBI CSCRF deadline?+
There is no single deadline. CSCRF has been rolled out in phases with dates that differ by entity type and category, and SEBI has revised them during rollout. You need to confirm the compliance date for your specific entity type and category against the current SEBI circular.
Has SEBI extended the CSCRF timelines?+
SEBI has revised CSCRF effective dates through circulars during the rollout, including extensions for some entities. Whether an extension applies to you depends on your entity type and category, so confirm the current date and any glide path against the latest circular.
Does the CSCRF deadline vary by entity?+
Yes. The applicable date depends on your entity type and your graded category, from market infrastructure institutions down to self-certification REs. Confirming your category is the first step to finding your date.
How long does it take to become CSCRF compliant?+
It depends on your category, current maturity and the scope of your IT estate, but plan for months rather than weeks, because CSCRF assurance looks for evidence accumulated over time. Starting well before your deadline is what makes the difference between walking in ready and scrambling.
About the author
Nilesh Wagh
Co-Founder, Pelta Technologies
Former CISO · 10+ years in information security & GRC
Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.
Connect on LinkedIn →