Compliance

SEBI CSCRF Timelines and Deadlines: How to Find Yours

There isn't one SEBI CSCRF deadline. Dates have been phased and revised, and yours depends on your entity type and category. Here's how to find your date and plan back from it.

Nilesh Wagh · Co-Founder, Pelta Technologies9 min readUpdated Part of SEBI CSCRF

One of the most common questions about SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) is simply: when is the deadline? The honest answer is that there is no single date. CSCRF has been implemented in phases, SEBI has revised the effective dates more than once during rollout, and the date that applies to you depends on your entity type and your category. This guide explains why the timeline works that way, how to find the date that applies to you, and how to plan back from it so you are ready with room to spare rather than scrambling at the last minute.

This article deliberately avoids quoting specific dates, because SEBI has revised CSCRF timelines during rollout and any fixed date risks going stale. Always confirm the current compliance date for your entity type and category against the latest SEBI circular. This is general guidance, not legal advice.

Why there isn't one CSCRF deadline

CSCRF applies across many types of regulated entity, from the largest market infrastructure institutions to the smallest self-certification REs, and it would make little sense to hold all of them to the same date. Instead, SEBI has phased the rollout, set dates that differ by entity type and category, and adjusted those dates through circulars as the framework matured. The result is a moving target that you have to pin down for your own entity rather than read off a single headline date.

What determines your compliance date

  • Your entity type: the class of intermediary you are registered as with SEBI.
  • Your category: where you fall in the graded structure, from MII down to self-certification.
  • Any glide path or extension: SEBI has granted additional time in some circulars, which may or may not apply to you.

Because category drives so much, confirming it is the first step. Our applicability guide walks through how the graded categories work and how to place your entity in the right one.

How to find your CSCRF deadline

  1. 1Confirm your entity type from your SEBI registration.
  2. 2Determine your category using the graded thresholds for your entity type.
  3. 3Find the compliance date for that type and category in the current SEBI circular.
  4. 4Check whether any glide-path extension applies to you, and note the revised date if so.
  5. 5Record the date and its source, and set a reminder to re-check, since dates have moved before.

A work-back plan from your deadline

Whatever your date, the work to get ready takes longer than teams expect, mostly because evidence has to accumulate over time. Plan back from the deadline rather than forward from today.

Working back from your CSCRF deadline

Confirm date

Type & category

Gap assessment

Against your category

Implement

Close the gaps

Test

VAPT & audit

Evidence

Build the proof

Go-live

Compliant, on time

The step teams underestimate is evidence. A control implemented the week before the deadline has no track record behind it, and CSCRF assurance looks for evidence over time. Starting early is what turns the deadline from a cliff edge into a plan. For the controls to work through, see the compliance checklist, and for the detection capability that takes longest to stand up, the logging and SOC guide.

Don't wait for the deadline

Even if your date has been extended, the extension is best treated as breathing room to do the work properly, not a reason to defer it. Entities that use the extra time to build evidence and test their response walk into inspection ready; those that treat it as a reprieve tend to arrive at the new date in the same position they were in at the old one.

Putting it together

There is no universal CSCRF deadline, only the one that applies to your entity type and category, and it may have been revised. Confirm your category, find your date in the current circular, check for any glide path, and plan back from it with time for evidence to accumulate. Treat the date as the end of a plan you started early, and CSCRF stops being a scramble. If you would rather have the timeline and the work managed for you, see our SEBI CSCRF compliance services.

Frequently asked questions

What is the SEBI CSCRF deadline?+

There is no single deadline. CSCRF has been rolled out in phases with dates that differ by entity type and category, and SEBI has revised them during rollout. You need to confirm the compliance date for your specific entity type and category against the current SEBI circular.

Has SEBI extended the CSCRF timelines?+

SEBI has revised CSCRF effective dates through circulars during the rollout, including extensions for some entities. Whether an extension applies to you depends on your entity type and category, so confirm the current date and any glide path against the latest circular.

Does the CSCRF deadline vary by entity?+

Yes. The applicable date depends on your entity type and your graded category, from market infrastructure institutions down to self-certification REs. Confirming your category is the first step to finding your date.

How long does it take to become CSCRF compliant?+

It depends on your category, current maturity and the scope of your IT estate, but plan for months rather than weeks, because CSCRF assurance looks for evidence accumulated over time. Starting well before your deadline is what makes the difference between walking in ready and scrambling.

About the author

N

Nilesh Wagh

Co-Founder, Pelta Technologies

Former CISO · 10+ years in information security & GRC

Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.

Connect on LinkedIn →

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.