Cyber Security and Cyber Resilience Framework for SEBI Regulated Entities
Sep 03, 2025/
Complinova Team/
SEBI-Regulations
The CSCRF notified on August 20, 2024, supersedes all the earlier framework, circulars, guidelines on the captioned subject, thereby bringing all the REs under a single umbrella of a consolidated framework, to align with the industry standards, encourage efficient audits and ensure compliance by SEBI REs.
The CSCRF classifies Regulated Entities into five categories based on their span of operations and thresholds such as number of clients, trade volume, asset under management, etc. These categories are:
- Market Infrastructure Institutions (MIIs)
- Qualified REs
- Mid-size REs
- Small-size REs
- Self-certification REs
The category of REs shall be decided at the beginning of the financial year based on the data of the previous financial year. A number of entities such as Collective Investment Schemes, Credit Rating Agencies shall be under Self-certification REs category. For the rest, the CSCRF also provides entity-wise categorization and corresponding thresholds.
REs for whom a cybersecurity and cyber resilience circular has been issued by SEBI in the past should adopt the CSCRF by January 01, 2025. All other REs should adopt the CSCRF by August 31, 2025.
Key Compliance Obligations-
- IT Committee for REs-
While it is not mandatory for Small-size REs and Self-certification REs to setup an IT Committee for REs, it is desirable to include and IT expert in CSCRF decision-making given the ever-expanding role of IT in securities market. In the absence of IT Committee for REs for Small-size REs and Self-certification REs, the compliance to CSCRF shall be reviewed and approved by MD/ CEO/ Board member/ Partners/ Proprietor.
The brief Terms of Reference (ToRs) of IT Committee for REs with respect to CSCRF shall be as follows:
- The committee shall undertake periodic reviews of implementation of cybersecurity and cyber resilience policy of the RE.
- The committee shall also perform periodic reviews of cybersecurity incident (if any), its impact, RCA and plans to strengthen the cyber resilience in order to mitigate re-occurrence of such incidents in future.
- The committee shall deliberate on the matters which may be referred by the Board/ Partners/ Proprietor of the RE and/ or SEBI.
- The committee shall review various compliances as part of CSCRF and make recommendations to the Board/ Partners/ Proprietor of the RE.
- ISO Audit and Certification –
MIIs and Qualified REs shall obtain ISO 27001 (latest version) certification.
- VAPT-
The VAPT reporting format has been provided in Annexure-A of the Circular. It may be noted that along with the VAPT report, SEBI REs shall also submit the declaration from MD/ CEO (as given in Annexure-A). The reporting authority for VAPT report is as follows:
|
S. No.
|
Regulated Entity
|
Reporting authority
|
|
1.
|
Stock Brokers / Depository Participants
|
Stock Exchanges / Depositories
|
|
2.
|
IAs
|
BASL
|
|
3.
|
MIIs and rest of the REs
|
SEBI
|
VAPT periodicity of REs
|
S. No.
|
Regulated Entity
|
Periodicity
|
|
1.
|
REs which have been identified as ‘Protected systems’ and/ or CII by NCIIPC
|
At least twice in a financial year
One VAPT activity shall be completed (including report submission, closure, and revalidation) in each half of the financial year (April to September and October to March)
|
|
2.
|
Rest of the REs
|
At least once in a financial year
VAPT activity shall commence in the first quarter of the financial year
Ideally the audit should be completed by October. Since as per Clause 4.3.4 of the Circular, any open vulnerabilities after 3 months of VAPT activity shall be approved by IT Committee(Board/Other Committees in case of Smaller REs) for REs and shall be closed before start of next VAPT exercise and revalidation of VAPT shall be completed within 5 months of the VAPT audit.
|
The timeline for VAPT activity for SEBI REs shall be as follows:
|
S. No.
|
Activity
|
Timeline
|
|
1.
|
Report submission of VAPT
|
VAPT report shall be submitted after approval from respective IT Committee for REs (Board/Other Committees in case of Smaller REs), within one (1) month of completion of VAPT activity.
|
|
2.
|
Closure of findings identified during VAPT activity
|
Within 3 months of submission of VAPT report
A graded approach (based on the criticality of observations) shall be followed for closure of the observations found during VAPT.
|
|
3.
|
Revalidation of VAPT
|
Revalidation of VAPT shall be completed within 5 months of completion of VAPT.
|
- Cyber Audit –
The periodicity of conducting cyber audit for SEBI REs in a financial year shall be as follows:
|
S. No.
|
Regulated Entity
|
Periodicity
|
|
1.
|
MIIs, Qualified REs
|
At least twice in a financial year
|
|
2.
|
Mid-size REs and Small-size REs who are providing IBT or Algo trading facility
|
|
3.
|
Rest of the REs
|
At least once in a financial year
Ideally the audit should be completed by October, since the follow-on audit is required to be completed within 5 months of completion of cyber audit.
|
Cyber audit report submission and observations closure timeline
|
S. No.
|
Activity
|
Timeline
|
|
1.
|
Cyber audit report submission
|
The final cyber audit report shall be submitted after approval from respective IT Committee for REs (Board/Other Committees in case of Smaller REs), within 1 month of completion of cyber audit.
|
|
2.
|
Closure of findings identified during cyber audit
|
Within 3 months of cyber audit report submission
A graded approach (based on the criticality of observation) shall be followed for closure of the observation found during cyber audit.
|
|
3.
|
Follow-on audit
|
The follow-on audit shall be completed within 5 months of completion of cyber audit.
|
Cyber audit report shall be submitted by all applicable REs. The auditor selection norms and format for CSCRF compliance submission has been provided as Annexure-B of the Circular. Along with the cyber audit report, SEBI REs shall also submit the required declaration from MD/ CEO (as given in Annexure-B).
Reporting authority for cyber audit report submission
|
S. No.
|
Regulated Entity
|
Reporting authority
|
|
1.
|
Stock Brokers / Depository Participants
|
Stock Exchanges / Depositories
|
|
2.
|
IAs
|
BASL
|
|
3.
|
MIIs and rest of the REs
|
SEBI
|
- Other Requirements –
The compliance reporting for CSCRF shall be done by the REs to their respective authority(ies) as per the existing mechanism, for example, MIIs shall submit the compliance with CSCRF to SEBI, stock brokers shall submit the compliance with CSCRF to stock exchanges, depository participants to shall submit the compliance with CSCRF to depositories, etc. Further, the compliance with the applicable standards and mandatory guidelines mentioned in CSCRF shall be as follows
|
S. No.
|
Standard/ Guidelines and Clause
|
Applicability
|
Periodicity
|
|
1.
|
REs Cybersecurity and cyber resilience policy review
|
All REs
|
Annually
|
|
2.
|
REs Cybersecurity risk management policy
|
All REs
|
Annually
|
|
3.
|
User access rights, delegated access and
unused tokens review
|
MIIs and Qualified REs
|
Quarterly
|
|
Other REs
|
Half-yearly
|
|
4.
|
Review of privileged users’ activities
|
MIIs and Qualified REs
|
Quarterly
|
|
Other REs
|
Half-yearly
|
|
5.
|
Cybersecurity training program
|
All REs
|
Annually
|
|
6.
|
Review of RE’s systems managed by third-party service providers
|
MIIs and Qualified REs
|
Half-yearly
|
|
Other REs
|
Annually
|
|
7.
|
Functional Efficacy of SOC
|
MIIs and Qualified REs
|
Half-yearly
|
|
Other REs who are utilizing third-party managed SOC or Market SOC services
|
Annually
|
|
8.
|
Cybersecurity scenario-based drill exercise for testing adequacy and effectiveness of recovery plan
|
MIIs and Qualified REs
|
Half-yearly
|
|
Other REs
|
Annually
|
|
9.
|
Review of periodically and update their contingency plan, continuity of operations plan
|
MIIs and Qualified REs
|
Half-yearly
|
|
Mid-size and small-size REs
|
Annually
|
|
10.
|
Evaluation of cyber resilience posture
|
Mid-size and Small-size REs
|
Annually
|
- Constitution of Security Operation Centre (SOC)-
- All REs are required to establish appropriate security monitoring mechanisms through Security Operation Centre (SOC). The onboarding of SOC can be done through RE’s own/ group SOC or Market SOC or any other third-party managed SOC for continuous monitoring of security events and timely detection of anomalous activities.
- As compliance with the cybersecurity guidelines may be onerous for smaller REs due to the lack of knowledge and expertise in cybersecurity and the cost factor involved in setting up own SOC. Therefore, CSCRF mandates NSE and BSE to set up Market SOC (M-SOC) with the objective of providing cybersecurity solutions to such categories of REs.
Any comments / feedback / corrections, most welcome. Please contact:
Team Complinova
https://www.complinova.com/
Mobile: +91 95773 96773