SEBI CSCRF for Credit Rating Agency (CRA)
Always Self-cert. No threshold test applies.
Classification
What decides a Credit Rating Agency (CRA)'s tier
Credit Rating Agencies are placed on self-certification directly with no threshold test. The tier reflects operational footprint rather than importance — a CRA is not a transaction processor — but the information it holds before a rating action is published is as market-sensitive as anything in the sector.
No measurement applies. Credit Rating Agency (CRA) are classified directly by the framework, so the tier does not change with size, client count or assets.
Obligations
What the Self-cert tier requires
Only the tiers a Credit Rating Agency (CRA) can actually land in are listed.
Self-certification REs
Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.
VAPT
Once a year
Cyber audit
Once a year
Drill
Annually
- Onboard to Market SOC — MANDATORY, unless RE has own SOC
- Designated CISO or equivalent officer
- IT Committee optional
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Credit Rating Agency (CRA)
A rating action is price-moving, and it exists in a knowable state inside the agency before anyone outside knows it. The window between committee decision and publication is the asset an attacker or an insider is after. Issuer-supplied confidential financials are the second exposure, held under an expectation of confidentiality that survives the rating.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
The scope is the rating pipeline from issuer data to dissemination:
- Issuer data intake and the document repository behind it
- The rating workflow and rating committee systems, including drafts and minutes
- Embargo and dissemination controls between a decision and its publication
- The public website and press-release publishing path
- Surveillance systems tracking rated entities
- Analyst endpoints and collaboration tools
Where this goes wrong
Publication infrastructure treated as marketing
The website that carries rating actions is frequently owned outside the compliance perimeter and scoped as a brochure site. It is the dissemination mechanism for price-sensitive information. Both directions matter — content reachable before its release time, and content alterable after it.
Submission
Where a Credit Rating Agency (CRA) files, and by when
Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
At self-certification, the VAPT is the only audit owed — but it still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory. No cyber audit is required.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.