Skip to main content
SEBI CSCRF · Funds

SEBI CSCRF for Collective Investment Scheme (CIS)

Always Self-cert. No threshold test applies.

Classification

What decides a Collective Investment Scheme (CIS)'s tier

Collective Investment Schemes are placed in their tier directly, with no measurement applied and nothing about the scheme's size changing the answer. The obligation is real but proportionate — an assessment by a CERT-In empanelled organisation and a signed compliance position, rather than a full audit programme — and it attaches to a structure that raises money from the public without the intermediation layer most other categories here sit behind.

No measurement applies. Collective Investment Scheme (CIS) are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the Self-cert tier requires

Only the tiers a Collective Investment Scheme (CIS) can actually land in are listed.

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC — MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Collective Investment Scheme (CIS)

Retail investors subscribe directly, which puts the collection path and the investor record system in the same sentence — the exposure is money in and records that say who is owed it. Public-facing scheme material is also an impersonation target, because a convincing fake subscription page needs no access to your systems at all.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope is scheme administration and the money paths around it:

  • Scheme and investor record systems
  • Subscription, collection and redemption processing
  • Investor communication and statement generation
  • Any public or investor-facing website through which subscriptions are solicited
  • Banking interfaces and collection account controls

Where this goes wrong

Two entities, one estate

A collective investment scheme is structurally split — the management company runs the scheme while the trustee holds the scheme property — and the systems follow that split across two sets of books, two banking relationships and often two IT arrangements. Each side tends to assume the other's assessment covers the join between them. Fix which entity owns the investor record, the collection account and the reconciliation between them before scoping anything, because that boundary is where an assessment silently ends.

Submission

Where a Collective Investment Scheme (CIS) files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

At self-certification, the VAPT is the only audit owed — but it still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory. No cyber audit is required.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.