If you run a broker, an AMC, a depository, or any SEBI-regulated business, SEBI CSCRF Compliance is no longer a project with an end date. The deadlines have passed, and the framework is fully in force. Examiners now ask a sharper question: not whether you are ready, but what your evidence shows. This guide walks through the requirements, the deadlines, a working checklist, and how to pick the CERT-In auditor who signs it all off.
Why This Guide Exists
Most write-ups on this topic still quote a superseded deadline and stop there. That is not much help when a real inspection is coming. The SEBI CSCRF framework is dense, tiered, and full of clarifications issued after the original circular. Working out what applies to your firm, and by when, is genuinely hard. What follows is the practical version, verified against SEBI’s own circulars, aimed at the person who actually has to get audited and stay compliant.
What Is SEBI CSCRF?
SEBI issued the Cybersecurity and Cyber Resilience Framework on 20 August 2024, and it replaced a messy patchwork of older cyber circulars- one for brokers, one for portfolio managers, one for KYC agencies- with a single standard for the whole securities market (SEBI CSCRF). That consolidation is the whole point.
The Objective
The aim is simple to state. SEBI wants every regulated entity not just to prevent cyberattacks, but to keep operating through one and recover quickly. The framework leans on the idea of resilience, not just defence, which is why testing and evidence matter as much as controls on paper.
Built on NIST CSF 2.0
Rather than invent something from scratch, SEBI mapped the SEBI cybersecurity framework onto NIST Cybersecurity Framework 2.0. It runs across six familiar functions: Govern, Identify, Protect, Detect, Respond, and Recover, with an added emphasis on anticipating threats before they land. If your security team already knows NIST, the structure will feel recognisable.
Who Must Comply
The framework binds every SEBI-regulated entity, but it does not treat them all the same. Obligations scale with a five-tier classification, and your tier is re-fixed each April using the prior financial year’s data. That means two firms can both be honestly “CSCRF compliant” while carrying very different obligations.
The Five Compliance Categories
Your category decides almost everything that follows, so it is the first thing to nail down. The table below summarises the tiers and the broad level of obligation. Confirm your own classification against the latest SEBI thresholds, as they were revised through 2025.
| Category | Who Falls Here & Obligation Level |
|---|---|
| MIIs | Stock exchanges, clearing corporations, and depositories. Highest obligations, no deadline relaxation. |
| Qualified REs | Larger intermediaries, including re-categorised KRAs. Near-full controls, SOC and audits. |
| Mid-size REs | Mid-tier brokers, AMCs, and similar. Substantial controls, cyber audit and VAPT. |
| Small-size REs | Smaller intermediaries. Lighter but real controls and periodic testing. |
| Self-certification REs | The smallest entities. Baseline controls with self-certification. |
Core Compliance Requirements
Across the tiers, SEBI CSCRF Compliance pulls together a broad set of obligations. Higher tiers carry more of them, but the core list is worth knowing in full. In practice, these are the domains an auditor will expect to see addressed:
- Governance and policy. A board-approved cybersecurity policy, defined roles, and a designated senior officer accountable for security.
- Asset inventory and classification. A complete, current register of hardware, software, and data, including internet-facing assets. SEBI fined CDSL ₹1 crore over exactly this gap.
- Access control and identity. Least-privilege access, multi-factor authentication, and disciplined management of privileged accounts.
- SOC or Market-SOC monitoring. Continuous security monitoring, either in-house or via a Market-SOC, depending on tier.
- VAPT and cyber audits. Regular vulnerability assessment and penetration testing, plus periodic cyber audits by an empanelled auditor.
- Incident response and 6-hour reporting. A tested response plan, with significant incidents reported to SEBI within six hours.
- Data protection and encryption. Encryption of sensitive data at rest and in transit, aligned with the DPDP regime.
- Resilience and recovery. Business continuity, backups, and tested recovery so critical operations survive disruption.
VAPT Requirements Under CSCRF
VAPT is not a side task in the SEBI CSCRF framework; it is a named, recurring obligation. A few specifics matter for planning.
Scope and Frequency
VAPT must cover your critical systems, public-facing applications, and supporting infrastructure. Most REs test at least annually, while MIIs and higher tiers face more frequent cycles and additional measures such as red teaming. Testing is also expected after any major change to a critical system.
Empanelment Is Mandatory
This is the non-negotiable part. VAPT and cyber audits under CSCRF must be carried out by a CERT-In empanelled organisation (CERT-In). A report from a non-empanelled firm will not be accepted, whatever its technical quality.
Closure Timelines
Findings do not sit open indefinitely. Vulnerabilities identified during VAPT must be remediated within three months of the report, and anything still open is escalated to the entity’s IT committee. Qualified Stock Brokers and market infrastructure run on a tighter, half-yearly rhythm.
What a CSCRF VAPT Actually Tests
Scope aside, the testing itself goes well beyond a checklist. A proper assessment probes the OWASP Top 10, authentication and session handling, authorisation and privilege escalation, API security, injection flaws, misconfigurations, and sensitive-data exposure. Most importantly, it chases business-logic flaws and chained attack paths, the multi-step weaknesses a scanner never connects. It is also worth knowing how the acronyms differ. DAST tests a running application from the outside, and SAST reviews source code from the inside. VAPT combines automated and manual techniques into the exploit-driven assessment CSCRF actually expects. DAST and SAST are useful inputs, but neither one satisfies the VAPT requirement on its own.
Cyber Audit vs VAPT: Not the Same Thing
These two get conflated, and it causes real confusion at inspection time. A cyber audit is a broad assessment of your controls, policies, and processes against the framework. VAPT is a focused technical test that actively probes systems for exploitable weaknesses. You need both, and CSCRF treats them as distinct deliverables rather than interchangeable ones.
Facing a CSCRF audit deadline? Qualysec is a CERT-In empanelled auditor delivering manual-first VAPT with SEBI-ready reporting. Talk to Qualysec about your assessment.
Deadlines: Where Things Actually Stand in 2026
Here is the part most articles get wrong. SEBI moved the compliance date more than once, and both extensions have now expired. The timeline below is the verified sequence.
| Date | What Happened |
|---|---|
| 20 Aug 2024 | CSCRF issued, superseding legacy cyber circulars. |
| 1 Jan 2025 | Deadline for MIIs, KRAs, and QRTAs. No relaxation given. |
| 28 Mar 2025 | First extension for other REs, moved to 30 June 2025. |
| 30 Jun 2025 | Second extension for most REs, moved to 31 August 2025. |
| 31 Aug 2025 | Final compliance deadline for the majority of REs. Now passed. |
| FY 2025-26 | Recurring cyber-audit cycle; half-yearly reports due 31 Mar 2026, next 30 Jun 2026. |
The takeaway is blunt. There is no live grace period. Two extensions in a row taught some firms to wait for a third, and that third never came. The obligation now is the recurring audit and reporting cycle, and examiners are looking at your evidence for the period since the deadline.
The SEBI CSCRF Compliance Checklist
Use this as a working checklist to pressure-test your SEBI CSCRF Compliance before an auditor does.
- Confirm your current category using the latest April re-classification, and document how you reached it.
- Ensure a board-approved cybersecurity policy exists, with a named accountable officer.
- Complete a full asset inventory, including internet-facing assets the register may not describe.
- Stand up SOC or Market-SOC monitoring appropriate to your tier.
- Schedule VAPT and cyber audit with a CERT-In empanelled auditor for the current cycle.
- Verify a tested incident-response plan with a working six-hour SEBI reporting path.
- Close VAPT findings within three months, and escalate anything open to the IT committee.
- Retain audit reports, action-taken reports, and evidence for the full period since the deadline.
What a Compliant VAPT Report Contains
Not every report clears an audit. A strong one includes an executive summary for leadership and a full technical breakdown of each vulnerability, with proof-of-concept detail. It also carries CVSS severity ratings, developer-ready remediation steps, and re-testing evidence confirming closure. If a report is just raw scanner output, it will not satisfy a SEBI examiner.
The CSCRF VAPT Process, Step by Step
A compliance-grade engagement follows a predictable path. Knowing it helps you plan and hold your auditor to a standard:
- Scoping and NDA, agreeing on assets, rules of engagement, and confidentiality.
- Reconnaissance and threat modelling to map the real attack surface.
- Vulnerability assessment for a broad baseline, then deep manual penetration testing to find the flaws scanners miss.
- Reporting with CVSS ratings and remediation guidance, followed by developer support to fix issues correctly.
- Re-testing and closure, confirming fixes hold, and issuing the final report and certificate.
How to Choose a CERT-In Auditor for CSCRF
Empanelment is the entry ticket, not the whole decision. Once you have confirmed a firm is actively CERT-In empanelled, weigh these factors:
- Active empanelment, verified on the official CERT-In roster against the exact legal entity name.
- SEBI CSCRF experience, ideally with firms in your category, so the auditor knows what examiners expect.
- Genuine manual testing depth, not automated scanning dressed up as a penetration test.
- Clear, SEBI-ready reporting, with severity ratings, remediation, and closure evidence.
- Remediation support and re-testing, so findings are fixed and verified, not just listed.
Common Mistakes That Fail Audits
A handful of errors account for most CSCRF audit problems, and each is avoidable:
- Waiting for another extension, or treating compliance as a one-off rather than a recurring cycle.
- Relying on automated scans, which miss the business-logic and access-control flaws examiners expect to be addressed.
- An incomplete asset inventory, the exact failure that cost CDSL a ₹1 crore penalty.
- Hiring a non-empanelled or lapsed-empanelment firm, so the report cannot be submitted.
- Leaving findings open past the three-month window, or losing the evidence trail an examiner asks for.
CSCRF VAPT vs a Regular Penetration Test
A regular pentest can be scoped however you like. A CSCRF VAPT must be performed by a CERT-In empanelled auditor, mapped to the framework’s controls, and documented to a standard SEBI will accept. The testing techniques overlap, but the empanelment, mapping, and evidentiary bar are what make it a compliance exercise rather than a general one.
What CSCRF VAPT Typically Costs
There is no flat rate, because cost tracks scope. The main drivers are the number of critical systems and applications, and the count of APIs. Source-code review, the hours of manual testing, and your category’s obligations also move the price. Treat unusually cheap quotes with caution, since a rejected audit and a re-test almost always cost more than doing it properly the first time.
Why Firms Choose Qualysec for CSCRF
Qualysec is a CERT-In empanelled provider built for exactly this kind of regulated engagement. It combines automated discovery with deep manual penetration testing. The flaws that matter- broken access control, business-logic errors, and exposed APIs- actually get found. Reports are validated to strip out false positives and written with step-by-step fixes for developers. Post-remediation re-testing is included, so your final report is clean and submission-ready. For firms navigating SEBI CSCRF Compliance under audit pressure, that combination of empanelled authority and practical delivery is the point.
Conclusion
The honest summary is that SEBI CSCRF Compliance is no longer about a deadline; it is about a cycle. The framework is in force, and the extensions are gone. What protects you now is a clean audit trail. That means the correct category, controls in place, a genuine VAPT from an empanelled auditor, findings closed on time, and evidence retained. Get those right, and an inspection becomes a formality rather than a scramble.
If you take one thing away, make it this. Do not wait, do not lean on automated scans, and do not treat the asset inventory as an afterthought. That last gap has already cost a major depository a crore. Handled well, the SEBI CSCRF framework stops being a burden and becomes evidence that your firm can be trusted with the market’s data.
Ready to clear your CSCRF audit with confidence? Book a manual-first VAPT with Qualysec’s CERT-In-empanelled team and get a SEBI-ready report. Contact Qualysec today.
Frequently Asked Questions
Is SEBI CSCRF mandatory for all regulated entities?
Yes. The SEBI CSCRF framework binds every SEBI-regulated entity, from MIIs down to the smallest intermediaries. What differs is the level of obligation, which scales with your five-tier classification, re-fixed each April on prior-year data.
Has the CSCRF compliance deadline been extended again?
No. SEBI extended it twice, to 30 June 2025 and then 31 August 2025 for most REs, and both have passed with no further blanket extension. The live obligation now is the recurring cyber-audit and reporting cycle.
Can we use any VAPT vendor for CSCRF, or must it be CERT-In empanelled?
It must be a CERT-In empanelled organisation. A report from a non-empanelled firm will be rejected at submission, regardless of technical quality. Always verify active empanelment on the official CERT-In roster before engaging.
Does an automated scan satisfy the CSCRF VAPT requirement?
No. Automated scans miss business-logic, consent, and access-control flaws, and SEBI expects genuine manual penetration testing. A scanner report presented as a pen test is a common reason audits are questioned.
How quickly must we fix vulnerabilities found during VAPT?
Findings must be remediated within three months of the report, with anything still open escalated to your IT committee. Qualified Stock Brokers and market infrastructure follow a tighter half-yearly cycle.








