Regulation · Capital markets · India

SEBI CSCRF compliance: categories, cyber audits and the CCI

SEBI CSCRF compliance means meeting the Cybersecurity and Cyber Resilience Framework that SEBI issued on 20 August 2024 for all regulated entities. Requirements scale across five categories, from MIIs to self-certification REs, and cover governance, SBOMs, VAPT, SOC monitoring, a 2-hour RTO and periodic cyber audits.

Key takeaways

What you need to know about SEBI CSCRF

Category drives effortObligations scale with your RE category, reset each financial year.
NIST CSF structureStandards follow Govern, Identify, Protect, Detect, Respond and Recover.
SBOM requiredFor all software needed for core and critical operations.
SOC for everyoneSmaller REs can use the NSE and BSE Market SOC.
Audits under CSCRFCyber audits from FY 2025-26 follow the framework.

Who must comply with SEBI CSCRF?

Every SEBI-regulated entity, with requirements that depend on its category.

Market infrastructure institutionsStock exchanges, clearing corporations and depositories.
Stock brokers and DPsIncluding Qualified Stock Brokers, with half-yearly VAPT and audits.
Mutual funds and AMCsAsset management companies and their registrars.
Portfolio managers and AIFsInvestment managers registered with SEBI.
KRAs, RTAs and othersRegistrars, KYC registration agencies and other REs.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the framework requires

What does SEBI CSCRF require?

SEBI CSCRF requires regulated entities to govern cyber risk under a qualified CISO, manage supply chain and SBOMs, test and patch, monitor through a SOC, report incidents, recover within set targets, and pass periodic cyber audits.

GV Govern

Governance and CISO

Board oversight, CISO standing, category, CCI.

In QULDEX: Roles and approvals tracked
GV.SC Supply chain

SBOM and outsourcing

SBOMs and accountable outsourcing.

In QULDEX: SBOM per application
ID.RA Identify

VAPT and patching

Close findings within three months.

In QULDEX: Three-month CAPA timers
PR Protect

Access, data, ISO 27001

MFA, logs, certified sites.

In QULDEX: ISO 27001 evidence reused
DE Detect

SOC and threat intel

Own SOC or Market SOC.

In QULDEX: SOC efficacy metrics
RS/RC Respond and recover

Incidents and DR

Report incidents; RTO 2 h, RPO 15 min.

In QULDEX: Drill results stored
Audit Assure

Cyber audit

By qualifying auditors, per category.

In QULDEX: Controlled auditor access
Standard explorer

Which SEBI CSCRF standards matter most?

These 18 standards and rules carry the work most REs face, grouped by CSCRF function. Select any one to see what it asks for, typical evidence and the matching ISO 27001 reference.

Aug 2024CSCRF issued
Apr 2025clarifications
Jun 2025FAQs and timeline extension
FY 2025-26audits under CSCRF

Showing up to 6 per group. Search, filter, or open a group to see all 18.

Govern 5

  1. GV.RRCISO and governance

    Appoint a full-time CISO (at least CTO or CIO standing for MIIs and Qualified REs) and board-level oversight of cyber risk; a group-level or dedicated remote CISO is allowed in some cases.

    In QULDEXGovernance roles and approvals are recorded per entity.

    Typical evidence
    CISO appointment, board minutes
    Maps to
    ISO 27001 5.3NIST CSF GV.RR

  2. CategoriesRE categorisation

    REs fall into five categories: MIIs, Qualified, Mid-size, Small-size and Self-certification, decided at the start of each financial year from the previous year's data.

    In QULDEXCategory and thresholds are recorded each financial year.

    Typical evidence
    Category assessment

  3. GV.OVCyber Capability Index (CCI)Frequent audit finding

    MIIs assess their cyber resilience using the CCI half-yearly through a third party; Qualified REs self-assess yearly.

    In QULDEXCCI parameters are tracked with evidence and scores.

    Typical evidence
    CCI assessment

  4. GV.SCSupply chain and SBOM

    Manage cybersecurity supply chain risk and obtain an SBOM for all software needed for core and critical business operations.

    In QULDEXSBOMs are stored per application with review dates.

    Typical evidence
    SBOMs, vendor assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

  5. OutsourcingOutsourcing and cloud

    REs stay accountable for outsourced services and must meet SEBI's cloud adoption framework for cloud and hosted services.

    In QULDEXEach provider is assessed against the outsourcing and cloud rules.

    Typical evidence
    Outsourcing register
    Maps to
    ISO 27001 A.5.23

Identify 2

  1. ID.AMAsset inventory and classification

    Keep an inventory of IT assets and classify systems as critical or non-critical.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

    Typical evidence
    Asset inventory
    Maps to
    ISO 27001 A.5.9

  2. ID.RAVAPT and patch managementFrequent audit finding

    Run vulnerability assessment and penetration testing at the frequency for your category, and close findings within three months of the VAPT report.

    In QULDEXVAPT findings become CAPA items with a three-month due date.

    Typical evidence
    VAPT reports, closure evidence
    Maps to
    ISO 27001 A.8.8

Protect 4

  1. PR.AAIdentity and access management

    Strong identity, authentication and access control, including MFA and privileged access management.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

    Typical evidence
    Access reviews, MFA settings
    Maps to
    ISO 27001 A.5.15–A.5.18

  2. PR.IPISO 27001 certification

    Hold ISO 27001 certification covering the primary and DR data centres, near-DR site, SOC and co-location, including outsourced providers of these.

    In QULDEXISO 27001 evidence is reused directly.

    Typical evidence
    ISO 27001 certificate and scope
    Maps to
    ISO 27001

  3. PR.DSData security and logs

    Protect data and logs, with log management feeding the SOC.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

    Typical evidence
    Log management evidence
    Maps to
    ISO 27001 A.8.15

  4. PR.PTCOTS and application testing

    Test COTS and in-house software (SAST/DAST as applicable) before deployment.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

    Typical evidence
    Test reports
    Maps to
    ISO 27001 A.8.29

Detect 2

  1. DE.CMSecurity Operations Centre

    Run a SOC with continuous monitoring and report its efficacy; smaller REs can use the Market SOC set up by NSE and BSE.

    In QULDEXSOC efficacy metrics are tracked on the dashboard.

    Typical evidence
    SOC efficacy report

  2. DE.TIThreat intelligence

    Collect and act on threat intelligence relevant to your environment.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

Respond and recover 4

  1. RS.MAIncident classification and reporting

    Classify cybersecurity incidents and report them to SEBI and CERT-In within the prescribed timelines.

    In QULDEXIncidents carry reporting timers and classification records.

    Typical evidence
    Incident reports
    Maps to
    CERT-In Directions 2022

  2. RC.RPRecovery: RTO 2 hours, RPO 15 minutes

    Declare a disaster within 30 minutes of disruption to critical systems; recover with an RTO of 2 hours and an RPO of 15 minutes.

    In QULDEXRTO and RPO are tested in DR drills with results stored.

    Typical evidence
    DR drill reports
    Maps to
    ISO 22301

  3. RC.RP.S1Golden images and spare hardware

    MIIs and Qualified REs keep updated golden images of critical systems and isolated spare hardware (or cloud high availability).

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

  4. DrillsScenario-based cyber drills

    Run live scenario-based drills to test response and recovery, separate from red and blue teaming.

    In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.

    Typical evidence
    Drill reports

Assure 1

  1. AuditCyber auditFrequent audit finding

    Cyber audits are run against CSCRF by auditors meeting SEBI's selection norms, at the frequency for your category, based on the financial year.

    In QULDEXAudit evidence and findings are shared through controlled, logged access.

    Typical evidence
    Cyber audit report

Codes follow CSCRF's Govern, Identify, Protect, Detect, Respond and Recover structure. Summaries are QULDEX paraphrases of the circular and SEBI's FAQs, not legal advice.

Compliance path

How do you comply with SEBI CSCRF?

Confirm your category for the financial year, close the gaps for it, set up SOC monitoring and recovery, then evidence everything for the cyber audit. Most REs need 3 to 9 months, depending on category.

  1. Confirm your category

    Apply the thresholds to last year's data and record the category.

  2. Gap assessment against CSCRF

    Assess each standard for your category, reusing ISO 27001 evidence.

  3. Governance, SBOM and outsourcing

    CISO standing, board oversight, SBOMs and outsourcing contracts.

    1–3 monthsRisk register →
  4. SOC, VAPT and patching

    Onboard to a SOC or Market SOC; run VAPT and close findings within three months.

  5. Recovery and drills

    Meet RTO 2 hours and RPO 15 minutes for critical systems and run live drills.

  6. Cyber audit and CCI

    MIIsThird-party CCI half-yearly
    Qualified REsCCI self-assessment yearly
    All REsCyber audit at category frequency

Periodicities follow the financial year. Durations are QULDEX planning ranges.

Records to keep

Which documents does SEBI CSCRF need?

Auditors and SEBI expect these records.

DocumentStandardWhere it lives in QULDEX
Category assessment for the yearThresholdsRisk register
Cyber security and resilience policyGVPolicy library
CISO appointment and board reviewsGV.RRPolicy library
Asset inventory with criticalityID.AMRisk register
SBOMs for critical softwareGV.SCEvidence vault
VAPT reports and closure evidenceID.RACAPA automation
ISO 27001 certificate and scopePR.IPEvidence vault
SOC efficacy reportsDE.CMEvidence vault
Incident reportsRS.MACAPA automation
DR drill reports (RTO/RPO)RC.RPEvidence vault
Cyber audit report and CCIAudit, GV.OVAudit workspace

Document names follow CSCRF and SEBI's FAQs; storage locations are QULDEX recommendations.

Time and cost

How long does SEBI CSCRF compliance take and what drives the effort?

Most REs need 3 to 9 months. Category, the number of critical systems, and whether you already hold ISO 27001 and a SOC drive the effort.

Where the time goes

Category and gap assessment4–8 wk
Governance and SBOM1–3 mo
SOC and VAPT1–3 mo
Recovery and drills1–2 mo
Audit preparation3–4 wk

Bars show the upper end of each range on one scale (9 months = full width).

What changes the effort

  • Category: MIIs and Qualified REs carry the most standards
  • Critical systems: each needs RTO, RPO and drills
  • Software estate: SBOMs for every critical application
  • Existing ISO 27001: required for key sites anyway
  • Group structure: banks with DP licences share controls with RBI rules
Readiness check · 2 minutes

How ready are you for SEBI CSCRF?

Check these eight things first. Nothing you enter leaves this page.

CategoryHave you recorded your RE category for this financial year?
GV.RRIs a full-time CISO in place with the required standing?
GV.SCDo you have SBOMs for software supporting critical operations?
ID.RAAre VAPT findings closed within three months?
PR.IPDoes ISO 27001 cover your DC, DR, SOC and co-location sites?
DE.CMAre you monitored by a SOC or the Market SOC?
RC.RPHave drills shown RTO 2 hours and RPO 15 minutes for critical systems?
AuditIs your next cyber audit planned with a qualifying auditor?
Crosswalk

How SEBI CSCRF maps to NIST CSF 2.0, ISO 27001 and the RBI Directions

CSCRF follows NIST CSF 2.0 functions and expects ISO 27001 for key sites. Banks that also hold SEBI licences meet RBI's 2026 Directions too, so one control set should serve both.

CSCRF crosswalk

SEBI CSCRFNIST CSF 2.0ISO 27001:2022RBI Directions 2026Shared evidence
GV.RR CISOGV.RR5.3CISO and ISCAppointments
GV.SC SBOMGV.SCA.5.19–A.5.22Third-party arrangementsSBOMs, vendor reviews
ID.AM InventoryID.AMA.5.9IT asset managementAsset inventory
ID.RA VAPTID.RAA.8.8VA and PTTest reports
PR.AA AccessPR.AAA.5.15–A.5.18User access managementAccess reviews
DE.CM SOCDE.CMA.8.16C-SOCSOC reports
RS.MA IncidentsRS.MAA.5.24–A.5.26Incident reportingIncident reports
RC.RP RecoveryRC.RPA.5.30BCP and DRDrill reports

Indicative mapping for planning, not legal advice. RBI vs SEBI requirements are compared in full on the blog.

Where QULDEX fits

How QULDEX runs SEBI CSCRF from category to cyber audit

QULDEX is SEBI CSCRF compliance and audit management software built from EGV Group's audit delivery, used by regulated entities, their advisors and the cyber auditors who test them. Pick your role to see who does what.

For MIIs, brokers, AMCs, DPs and other REs.

  1. CategoryConfirm your categoryCategory record per financial year
  2. GovernSet CISO and oversightRoles and board reviews recorded
  3. ProtectClose control gapsStandards mapped to evidence
  4. TestRun VAPT and drillsThree-month closure timers
  5. ReportReport incidentsIncident timers and records
  6. AuditHost the cyber auditControlled evidence sharing
Without one systemWith QULDEX
Category checked when the auditor asksCategory recorded each financial year
SBOMs requested ad hocSBOM per critical application
VAPT findings drift past 3 monthsClosure timers on every finding
RBI and SEBI evidence kept twiceOne control set mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

SEBI CSCRF questions people ask

Who must comply with SEBI CSCRF?

All SEBI-regulated entities, including MIIs, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, KRAs and RTAs. Requirements depend on the entity's category.

What are the CSCRF categories?

Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The category is set at the start of each financial year from the previous year's data.

How often must the Cyber Capability Index be assessed?

MIIs assess their cyber resilience using the CCI through a third party every half-year; Qualified REs self-assess every year.

What are the CSCRF recovery targets?

For critical systems, declare a disaster within 30 minutes of disruption and recover with an RTO of 2 hours and an RPO of 15 minutes.

Does CSCRF require ISO 27001?

Yes, for the primary and DR data centres, near-DR site, SOC and co-location facility, including third parties providing those services.

Sources

References

  1. SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, CSCRF, 20 Aug 2024. sebi.gov.in
  2. SEBI clarifications to CSCRF, CIR/2025/60, 30 Apr 2025. sebi.gov.in
  3. SEBI extension circular CIR/2025/96, 30 Jun 2025. sebi.gov.in
  4. SEBI FAQs on CSCRF and cloud adoption, Jun 2025. sebi.gov.in
  5. ISO/IEC 27001:2022. iso.org

Reviewed by

Swati Chaturvedi

Framework reviewer · QULDEX

Reviewed this page against SEBI's CSCRF circular, clarifications and FAQs: categories, standards, recovery targets and audits.

Page history
  • : Page first built: standard explorer by CSCRF function, categories, recovery targets and readiness check

Walk into your next cyber audit prepared

Answer a short readiness check and get a gap summary by function. No sales call needed to see the result.

Schedule
Book a Demo