SEBI CSCRF for Collective Investment Scheme (CIS)
Collective Investment Scheme (CIS) are always Self-cert under CSCRF. No threshold test applies.
Classification
What decides the tier for a Collective Investment Scheme (CIS)
Collective Investment Schemes are placed in their tier directly, with no measurement applied and nothing about the scheme's size changing the answer. The obligation is proportionate: an assessment by a CERT-In empanelled organisation and a signed compliance position in place of a full audit programme. It attaches to a structure that raises money from the public without the intermediation layer most other categories here sit behind.
No measurement applies. Collective Investment Scheme (CIS) are classified directly by the framework, so the tier does not change with size, client count or assets.
Obligations
What the Self-cert tier requires
Only the tiers a Collective Investment Scheme (CIS) can land in are listed.
Self-certification REs
Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.
VAPT
Once a year
Cyber audit
Once a year
Drill
Annually
- Onboard to Market SOC: MANDATORY, unless RE has own SOC
- Designated CISO or equivalent officer
- IT Committee optional
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Collective Investment Scheme (CIS)
Retail investors subscribe directly, which puts the collection path and the investor record system in the same place: money coming in, and the records that say who is owed it. Public-facing scheme material is also an impersonation target, because a convincing fake subscription page needs no access to your systems at all.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.
The scope is scheme administration and the money paths around it:
- Scheme and investor record systems
- Subscription, collection and redemption processing
- Investor communication and statement generation
- Any public or investor-facing website through which subscriptions are solicited
- Banking interfaces and collection account controls
Where this goes wrong
Two entities, one estate
A collective investment scheme is structurally split: the management company runs the scheme while the trustee holds the scheme property. The systems follow that split across two sets of books, two banking relationships and often two IT arrangements. Each side tends to assume the other's assessment covers the join between them. Fix which entity owns the investor record, the collection account and the reconciliation between them before scoping anything, because that boundary is where an assessment silently ends.
Submission
Where a Collective Investment Scheme (CIS) files, and by when
Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.
At self-certification, the VAPT is the only audit owed and no cyber audit is required. It still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.
Verified against the source circulars as of 3 August 2026.
FAQ
Common questions
These are the questions we are asked most often about this category.
Talk to our team