Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Credit Rating Agency (CRA)

Credit Rating Agency (CRA) are always Self-cert under CSCRF. No threshold test applies.

Classification

What decides the tier for a Credit Rating Agency (CRA)

Credit Rating Agencies are placed on self-certification directly with no threshold test. The tier reflects operational footprint, not importance: a CRA is not a transaction processor. Even so, the information it holds before a rating action is published is as market-sensitive as anything in the sector.

No measurement applies. Credit Rating Agency (CRA) are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the Self-cert tier requires

Only the tiers a Credit Rating Agency (CRA) can land in are listed.

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC: MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Credit Rating Agency (CRA)

A rating action is price-moving, and it exists in a knowable state inside the agency before anyone outside knows it. The window between committee decision and publication is the asset an attacker or an insider is after. Issuer-supplied confidential financials are the second exposure, held under an expectation of confidentiality that survives the rating.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.

The scope is the rating pipeline from issuer data to dissemination:

  • Issuer data intake and the document repository behind it
  • The rating workflow and rating committee systems, including drafts and minutes
  • Embargo and dissemination controls between a decision and its publication
  • The public website and press-release publishing path
  • Surveillance systems tracking rated entities
  • Analyst endpoints and collaboration tools

Where this goes wrong

Publication infrastructure treated as marketing

The website that carries rating actions is frequently owned outside the compliance perimeter and scoped as a brochure site. It is the dissemination mechanism for price-sensitive information. Both directions matter: content reachable before its release time, and content alterable after it.

Submission

Where a Credit Rating Agency (CRA) files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.

At self-certification, the VAPT is the only audit owed and no cyber audit is required. It still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.

Verified against the source circulars as of 3 August 2026.

FAQ

Common questions

These are the questions we are asked most often about this category.

Talk to our team
Does SEBI CSCRF apply to Credit Rating Agency (CRA)?+
Yes. Credit Rating Agency (CRA) fall under CSCRF. Credit Rating Agency (CRA) are always Self-cert under CSCRF. No threshold test applies.
How often does a Credit Rating Agency (CRA) need VAPT under CSCRF?+
At the Self-cert tier: Once a year. Cyber audit: Once a year.
Where does a Credit Rating Agency (CRA) submit its CSCRF reports?+
To SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Which SEBI circular sets this out?+
As per SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20-Aug-2024 read with CIR/2024/184, CIR/2025/45, CIR/2025/60, CIR/2025/96, CIR/2025/119, the SEBI FAQ (11-Jun-2025), and the May 2026 AI Vulnerability Detection Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026.