Skip to main content
SEBI Advisory on AI Vulnerability Detection (May 2026) View advisory
CERT-In Empanelled Since 2008 — Mandatory for SEBI cyber audits and critical infrastructure assessments

SEBI CSCRF Compliance for Stock Brokers, AMCs, Mutual Funds, and Market Infrastructure Institutions

Security Brigade is the only CERT-In empanelled firm that delivers SEBI CSCRF compliance as a single bundled engagement covering VAPT, Attack Surface Management, Breach Attack Simulation, and compliance reporting for every category of SEBI regulated entity.

CSCRF
Compliance Framework
SEBI-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

The SEBI Cyber Security and Cyber Resilience Framework mandates comprehensive cyber resilience controls for all SEBI regulated entities. Non-compliance risks SEBI enforcement action, trading restrictions, and reputational damage. Security Brigade has helped capital markets firms, depositories, and asset management companies achieve SEBI CSCRF compliance with structured methodology, in-house tooling, and regulator-ready deliverables backed by CERT-In empanelled audit experience.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The moving target

The master circular is one of five documents, and four of them changed it

CSCRF has been amended continuously since August 2024. An engagement scoped against the master circular alone is scoped against a text that no longer governs.

01 Data localisation paused

December 2024

What moved
The Data Security standard on Data Localisation, PR.DS.S2, was kept in abeyance until further notification following feedback on its provisions.
Why it matters
Abeyance is not repeal. It is a provision that exists, is suspended, and can be restored by notification, so architecture decisions taken now should be taken with it in view and not against its absence.
02 Who you are was rewritten

April 2025

What moved
KYC Registration Agencies were re-categorised from Market Infrastructure Institutions to Qualified REs. Stock broker thresholds were restated on a two-parameter basis, with clientele and trading volume both in play.
Why it matters
Tier decides the control set, the audit depth and the cost. An entity that classified itself in 2024 and has not revisited it may be preparing for obligations that are no longer its own, or missing ones that now are.
03 Clause-level technical clarifications

August 2025

What moved
Eleven clauses were restated, including the critical-systems definition, the zero-trust standard, mobile application security, supply chain assessment, ISO 27001 for Qualified REs and the security-solutions guideline that had named BAS and CART.
Why it matters
This is the amendment most often missed, and the one that changes what an assessment should actually test. The table below reads it clause by clause.
04 AI vulnerability advisory

May 2026

What moved
SEBI issued an advisory on AI vulnerability detection addressed to nineteen RE categories, to be read alongside CSCRF, with directives at Annexure-A.
Where we cover it
It has its own page, because it is an advisory read in conjunction with CSCRF, not an amendment to it.

Read clause by clause

What the August 2025 clarifications actually changed

Each row is the CSCRF clause, what it said, and what it now reads as. These are the sentences an assessment should be scoped against.

ClauseAs issuedAs clarified
DE.CM.S3, guideline 3.c REs shall deploy solutions such as BAS, CART, decoy, vulnerability management and similar, to enhance their cybersecurity posture. It is recommended that REs consider deploying a range of security solutions in consultation with their IT Committee: threat simulation, vulnerability management and decoy systems. The obligation is softened and the two acronyms no longer appear.
PR.IP.S16 ISO 27001 certification mandatory for MIIs and Qualified REs, to be obtained within one year of issuance. Qualified REs are encouraged and recommended to obtain ISO 27001 certification. Market Infrastructure Institutions are unchanged.
PR.AA.S16 Mobile application security guidelines stated as obligations. Recommendatory in nature, in SEBI’s own characterisation.
PR.AA.S4 / S5 REs shall follow a zero-trust security model such that access to critical systems is denied by default. REs shall implement suggested strategies and methodologies (zero-trust networks, segmentation, no single point of failure, high availability) approved by the IT committee.
Critical systems definition Included all ancillary systems used for accessing or communicating with critical systems. Reads as any other system on the same network segment where the critical systems are deployed. A narrower and far more testable boundary, and it changes scope directly.
GV.SC.S2 Suppliers and third parties shall be identified, prioritised and assessed through a cyber-supply-chain risk assessment process. That process may be done in consultation with the RE’s IT committee.
Recovery objectives Recovery objectives stated in the framework. RPO for critical systems is 15 minutes, anchored to the SEBI circular of 22 March 2021 on BCP and DR for MIIs. Recovery plans are to be scenario-based, including scenarios where the objective is not achieved.

DE.CM.S3, guideline 3.c

As issued
REs shall deploy solutions such as BAS, CART, decoy, vulnerability management and similar, to enhance their cybersecurity posture.
As clarified
It is recommended that REs consider deploying a range of security solutions in consultation with their IT Committee: threat simulation, vulnerability management and decoy systems. The obligation is softened and the two acronyms no longer appear.

PR.IP.S16

As issued
ISO 27001 certification mandatory for MIIs and Qualified REs, to be obtained within one year of issuance.
As clarified
Qualified REs are encouraged and recommended to obtain ISO 27001 certification. Market Infrastructure Institutions are unchanged.

PR.AA.S16

As issued
Mobile application security guidelines stated as obligations.
As clarified
Recommendatory in nature, in SEBI’s own characterisation.

PR.AA.S4 / S5

As issued
REs shall follow a zero-trust security model such that access to critical systems is denied by default.
As clarified
REs shall implement suggested strategies and methodologies (zero-trust networks, segmentation, no single point of failure, high availability) approved by the IT committee.

Critical systems definition

As issued
Included all ancillary systems used for accessing or communicating with critical systems.
As clarified
Reads as any other system on the same network segment where the critical systems are deployed. A narrower and far more testable boundary, and it changes scope directly.

GV.SC.S2

As issued
Suppliers and third parties shall be identified, prioritised and assessed through a cyber-supply-chain risk assessment process.
As clarified
That process may be done in consultation with the RE’s IT committee.

Recovery objectives

As issued
Recovery objectives stated in the framework.
As clarified
RPO for critical systems is 15 minutes, anchored to the SEBI circular of 22 March 2021 on BCP and DR for MIIs. Recovery plans are to be scenario-based, including scenarios where the objective is not achieved.

If more than one regulator applies

Exclusivity and Equivalence, and why they are worth reading carefully

A great many SEBI-regulated entities are regulated somewhere else as well: a bank that is also a depository participant, an insurer that is also a portfolio manager, a group running a broking arm beside an NBFC. The August 2025 clarifications addressed this directly with two principles. Exclusivity means CSCRF applies to the SEBI-regulated activity, not to everything the legal entity does, which makes the scope boundary a question about business lines and not about infrastructure. Equivalence means that where another regulator’s framework already covers the same ground, the duplicate exercise need not be repeated. Both are useful and both are routinely over-read. They reduce duplicated audit effort; they do not merge two compliance positions into one, and they do not decide themselves. An entity claiming equivalence has to be able to show the mapping that supports it, control by control, to a supervisor who is entitled to disagree. In practice this is the most valuable hour of a scoping conversation for a multi-regulator group, because it is where the difference between one assessment and three is decided, and because getting it wrong in the generous direction is the version that is discovered during an inspection.

How we scope it

Classification first, because everything downstream is priced off it

CSCRF is not one control set. What applies to you is decided by category and tier before any testing is scoped.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade delivers SEBI CSCRF compliance through a structured methodology refined across multiple audit cycles for stock brokers, depository participants, AMCs, mutual funds, and other SEBI regulated entities. Every phase is tracked through our Lemon audit management platform with full evidence traceability.

Discovery
01

Scoping and Entity Classification

Identify your SEBI CSCRF tier based on entity type, scale, and systemic importance. Map applicable controls for stock brokers, depository participants, AMCs, mutual funds, MIIs, or other regulated entities. Define audit scope, systems inventory, and timeline.

02

Gap Assessment and Risk Analysis

Evaluate current cybersecurity posture against all applicable SEBI CSCRF controls. Assess SOC/M-SOC readiness, vulnerability management maturity, DC/DR preparedness, incident handling capability, and governance reporting. ShadowMap scan identifies external attack surface exposure.

Testing
03

Technical Security Testing

Execute VAPT across applications, APIs, networks, and infrastructure. Conduct Breach Attack Simulation to validate SOC detection. Perform red team assessment for MII-tier entities. Run ShadowMap for continuous attack surface monitoring and dark web credential exposure checks.

Delivery
04

Remediation Support and Verified Closure

Deliver prioritised remediation roadmap with actionable guidance. Track all findings through Lemon with developer-friendly PoCs and specific remediation steps. Retest every fix with confirmed closure status, generating evidence that satisfies SEBI CSCRF audit requirements.

05

SEBI CSCRF Compliance Reporting

Produce regulator-ready SEBI CSCRF compliance audit report with control mapping, evidence references, executive summary, and board presentation pack. CERT-In empanelled auditor attestation. Governance documentation aligned to SEBI reporting requirements.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

CSCRF keeps several testing obligations apart and they run to different clocks, which is where most scoping errors on this framework start. B-52 takes them one at a time and says which a continuous platform can serve.

See the B-52 platform Built and run by Security Brigade

FAQ

CSCRF, against the text currently in force

Answers that track the amendments, not the master circular alone. Talk to our team about your category and tier.

Contact us
Are BAS and CART required under CSCRF?+
They are recommended, not obligatory, and the wording changed. DE.CM.S3 guideline 3.c originally read that REs shall deploy solutions such as BAS, CART, decoy and vulnerability management. The technical clarifications of 28 August 2025 restated it: it is recommended that REs consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems. The acronyms were dropped from the text. We run both capabilities and think they are worth having on their merits. But a buyer should know they are choosing them, not complying with them.
Is ISO 27001 certification mandatory under CSCRF?+
For Market Infrastructure Institutions, yes: PR.IP.S16 of the master circular states it, and nothing since has changed it. For Qualified REs the position moved: the master circular required both MIIs and Qualified REs to certify within a year, and the technical clarifications of 28 August 2025 restated it so that Qualified REs are encouraged and recommended to do so. Other REs are directed to incorporate best practices from standards such as ISO 27001 and ISO 27002 instead of certifying.
What happened to the CSCRF data localisation requirement?+
The Data Security standard on Data Localisation, PR.DS.S2, was kept in abeyance until further notification by the clarifications of 31 December 2024, following feedback on its provisions. Abeyance is a suspension, not a removal: the provision exists and can be restored by notification. Know where your data actually sits before that conversation starts, and not after.
Does CERT-In empanelment matter for a CSCRF audit?+
Yes. Empanelment is the precondition Indian regulators apply to who may perform the assessment, and it attaches to the auditing firm for a defined period instead of to a report. Security Brigade has been CERT-In empanelled continuously since 2008. The practical question a supervisor asks is a question about dates: whether the firm held empanelment on the days the work was performed.
Our group is regulated by SEBI and by another regulator. Do we run two audits?+
Not necessarily, and the answer is settled before scoping, not after. Exclusivity confines CSCRF to the SEBI-regulated activity and not to everything the legal entity does. Equivalence allows a duplicate exercise to be avoided where another regulator’s framework covers the same ground. Both depend on a mapping you can show, control by control, so the saving is real but it is earned by evidence instead of asserted.
How long does a CSCRF engagement take?+
Six to eight weeks is typical from scoping to final report for a mid-size entity, and the variables are the number of systems inside the critical-systems boundary and how fast remediation can be verified, not the framework itself. Classification is the first week and it is the one that moves the estimate most, because tier decides both the control set and the depth of testing expected.

Get SEBI CSCRF Compliant with India's Only Bundled Compliance Provider

CERT-In empanelled since 2008. VAPT, ASM, BAS, Red Team, Dark Web Monitoring, and compliance reporting from one team.

Typically responds within 1 business day · No commitment required

Request a Scoping Call

Our reading of the circulars

What the text actually requires

Sept 2026SEBI's MII subsidiary proposal: three tests, one narrow exemptionThree tests decide whether an MII's IT and cyber framework reaches a subsidiary. SEBI's proposal, and the one narrow exemption.May 2026SEBI CSCRF for Custodians: AUC Tiers & CCI ObligationsCustodians under SEBI CSCRF: Assets Under Custody drives three-tier classification (₹1L Cr, ₹10L Cr thresholds), CCI self-assessment at QRE, and what custodians of every size must do.May 2026SEBI CSCRF for KRAs & QRTAs: The April 2025 Demotion & What It MeansKYC Registration Agencies were reclassified from MII to Qualified RE in April 2025. QRTAs (≥2 Cr folios) remain at MII tier. What changed, what stayed, and what KRAs and QRTAs must do now.May 2026SEBI CSCRF for AIFs & VCFs: Manager-Level Corpus RuleCSCRF for Alternative Investment Funds and Venture Capital Funds: the April 2025 manager-level classification, corpus thresholds, sub-100-client exemptions, and what AIF/VCF managers must do.May 2026SEBI CSCRF for AMCs & Mutual Funds: AUM-Tiered Classification & Qualified RE ObligationsAsset Management Companies under SEBI CSCRF: AUM-tiered classification (₹10k Cr, ₹1L Cr thresholds), Qualified RE obligations, ISO 27001 voluntary status, and what AMCs of every size must do.May 2026SEBI CSCRF for Stock Brokers: The Two-Parameter Rule, Thresholds & QSB → QRE LinkSEBI's April 2025 CSCRF amendment rewrote stock-broker classification: clients OR trading volume determines your tier, and the higher of the two wins. How the two-parameter rule works, what each tier requires, and the QSB auto-classification.May 2026The Principle of Exclusivity and Equivalence Under SEBI CSCRF: A Guide for Multi-Regulator EntitiesSEBI's August 2025 clarifications introduced two principles for entities regulated by multiple bodies: Exclusivity (CSCRF covers only SEBI-regulated activities) and Equivalence (duplicate audits not required if the other regulator's framework matches). Here's how they work.May 2026SEBI CSCRF Data Localisation in Abeyance: What Regulated Entities Should KnowSEBI's Data Localisation mandate (PR.DS.S2) has been in regulatory abeyance since December 2024. What this means for compliance planning, what stays binding, and what to do instead of building a localisation programme that may never activate.May 2026August 2025 SEBI CSCRF Technical Clarifications: ISO 27001, PM Revision & MoreSEBI's August 2025 technical clarifications made ISO 27001 voluntary for QREs, downgraded Mobile App Security and BAS/CART to recommendatory, narrowed critical-systems scope, and introduced multi-regulator principles. Decoded.May 2026What Changed in the April 2025 SEBI CSCRF AmendmentSEBI's April 2025 CSCRF amendment rewrote stock-broker thresholds with a two-parameter rule, reclassified KRAs from MII to QRE, clubbed AIFs+VCFs at the manager level, and introduced the HSM mandate. Here's what every regulated entity needs to know.May 2026SEBI CSCRF in 2026: A Complete Guide for SEBI Regulated EntitiesSEBI's Cybersecurity and Cyber Resilience Framework, covered in one place: the 5-tier model, 22 entity types, amendment history through Aug 2025, and what every regulated entity needs to do in FY 2026-27.May 2026SEBI's May 2026 AI Vulnerability Detection Advisory: What Every Regulated Entity Must Do NowSEBI has issued an advisory on AI tools like Claude Mythos that find vulnerabilities at speed and scale. What its 10 directives require, how they apply across the 19 regulated-entity categories, and a 90-day path to readiness.