Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Banker to an Issue / SCSBs

Always Small-size. No threshold test applies.

Special — submit RBI cyber compliance certificate to SEBI; if listed, also intimate Stock Exchanges.

Classification

What decides a Banker to an Issue / SCSB's tier

Bankers to an Issue and Self-Certified Syndicate Banks are placed in a fixed tier with no measurement, and they carry a submission route no other entity has: the RBI cyber compliance certificate goes to SEBI, and a listed entity intimates the exchanges as well. That reflects the position — these are banks already supervised for cyber resilience, performing a specific role in the issue process.

No measurement applies. Banker to an Issue / SCSBs are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the Small-size tier requires

Only the tiers a Banker to an Issue / SCSB can actually land in are listed.

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Banker to an Issue / SCSB

The blocked amount is the exposure. Funds committed but not yet transferred, held across a very large number of retail applications on a fixed timetable, create a window in which a failure to block, release or unblock correctly is simultaneously a customer harm, a market event and a regulatory one. Application data is also concentrated and time-boxed, which makes it an unusually attractive target during an issue.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The SEBI-relevant scope is the issue-processing function rather than the whole bank:

  • Application blocking and release mechanics, including the UPI mandate path
  • Escrow and public issue account controls
  • Interfaces with registrars, lead managers and exchanges
  • Refund and unblocking processing
  • Application data handling and the retention around it
  • Branch and channel access to issue-related functions

Where this goes wrong

Two supervisors, one estate

The banking-side cyber assurance programme and the SEBI-facing obligation are usually run by different teams reading different circulars, and the issue-processing function falls between them — covered by the bank's programme in principle and by nobody in scope terms. Establish which assessment actually covers the blocking and unblocking path before assuming one of them does.

Submission

Where a Banker to an Issue / SCSB files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route all remaining regulated entities to SEBI.

Bankers to an Issue and SCSBs submit their RBI cyber compliance certificate to SEBI. A listed banker also intimates the Stock Exchanges.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.