Skip to main content
SEBI CSCRF · Funds

SEBI CSCRF for Collective Investment Scheme (CIS)

Collective Investment Scheme (CIS) are always Self-cert under CSCRF. No threshold test applies.

Classification

What decides the tier for a Collective Investment Scheme (CIS)

Collective Investment Schemes are placed in their tier directly, with no measurement applied and nothing about the scheme's size changing the answer. The obligation is proportionate: an assessment by a CERT-In empanelled organisation and a signed compliance position in place of a full audit programme. It attaches to a structure that raises money from the public without the intermediation layer most other categories here sit behind.

No measurement applies. Collective Investment Scheme (CIS) are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the Self-cert tier requires

Only the tiers a Collective Investment Scheme (CIS) can land in are listed.

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC: MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Collective Investment Scheme (CIS)

Retail investors subscribe directly, which puts the collection path and the investor record system in the same place: money coming in, and the records that say who is owed it. Public-facing scheme material is also an impersonation target, because a convincing fake subscription page needs no access to your systems at all.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.

The scope is scheme administration and the money paths around it:

  • Scheme and investor record systems
  • Subscription, collection and redemption processing
  • Investor communication and statement generation
  • Any public or investor-facing website through which subscriptions are solicited
  • Banking interfaces and collection account controls

Where this goes wrong

Two entities, one estate

A collective investment scheme is structurally split: the management company runs the scheme while the trustee holds the scheme property. The systems follow that split across two sets of books, two banking relationships and often two IT arrangements. Each side tends to assume the other's assessment covers the join between them. Fix which entity owns the investor record, the collection account and the reconciliation between them before scoping anything, because that boundary is where an assessment silently ends.

Submission

Where a Collective Investment Scheme (CIS) files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.

At self-certification, the VAPT is the only audit owed and no cyber audit is required. It still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.

Verified against the source circulars as of 3 August 2026.

FAQ

Common questions

These are the questions we are asked most often about this category.

Talk to our team
Does SEBI CSCRF apply to Collective Investment Scheme (CIS)?+
Yes. Collective Investment Scheme (CIS) fall under CSCRF. Collective Investment Scheme (CIS) are always Self-cert under CSCRF. No threshold test applies.
How often does a Collective Investment Scheme (CIS) need VAPT under CSCRF?+
At the Self-cert tier: Once a year. Cyber audit: Once a year.
Where does a Collective Investment Scheme (CIS) submit its CSCRF reports?+
To SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Which SEBI circular sets this out?+
As per SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20-Aug-2024 read with CIR/2024/184, CIR/2025/45, CIR/2025/60, CIR/2025/96, CIR/2025/119, the SEBI FAQ (11-Jun-2025), and the May 2026 AI Vulnerability Detection Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026.