Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Custodians

3 tiers are reachable, decided by assets under custody (auc) in inr crores.

Classification

What decides a Custodian's tier

Custodians are classified on assets under custody, on bands wide enough that most firms sit clearly inside one. The framework is measuring concentration: a custodian does not trade, but it instructs settlement, processes entitlements and holds the record on which a large number of institutional investors rely.

Assets Under Custody (AUC) in INR crores

Some answers put a Custodian outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.

Obligations

What each reachable tier requires

Only the tiers a Custodian can actually land in are listed.

Qualified REs

KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.

VAPT

Once a year (twice a year if CII)

Cyber audit

Twice a year

Red team

Half-yearly

Drill

Half-yearly

  • ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
  • CCI self-assessment — annually
  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
  • HSM mandatory under cloud framework
  • Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
  • RTO 2 hours / RPO 15 minutes

ISO 27001

Recommended, not mandatory

Cyber Capability Index

Self-assessment, annually

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Mandatory

CISO reporting line

CISO reports directly to MD/CEO

IT Committee

Mandatory, meets quarterly

RTO

2 hours (IOSCO)

RPO

15 minutes

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Mid-size REs

Stock Brokers 1-10L clients OR ₹1-10L Cr volume, AMCs ₹10k-1L Cr AUM, Custodians ₹1-10L Cr AUC, Portfolio Managers ≥₹10k Cr AUM, AIF+VCF managers >₹10k Cr corpus, RTAs 1-2 Cr folios.

VAPT

Once a year (commences Q1 of FY)

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / Market SOC / 3P-managed); annual functional efficacy review
  • HSM — risk-assessed alternative permitted (Board approval required)
  • Designated CISO or equivalent officer
  • Annual cyber resilience posture evaluation (EV.ST.S5)

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Mandatory, meets quarterly

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Custodian

A custodian's exposure is integrity before confidentiality. An altered settlement instruction or a manipulated corporate-action entitlement moves assets while looking entirely routine, and reconciliation is often the only control that would catch it. Straight-through processing raises the stakes further: paths designed so no human touches them are paths where no human notices.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope is the instruction and reconciliation chain rather than a customer journey:

  • Settlement instruction capture, matching and release
  • Financial-messaging interfaces and the credentials, certificates and message validation around them
  • Corporate action processing — announcement capture through to entitlement and payment
  • Client reporting and holdings-statement generation
  • Reconciliation against depositories and clearing corporations, and the exception queues it produces
  • Client onboarding and standing-instruction management
  • Where the same firm acts as a Designated Depository Participant, the FPI account structures alongside it

Where this goes wrong

Leaving the reconciliation exception queue out of scope

Testing concentrates on the instruction path and stops short of the exception handling behind it, which is where manual intervention, elevated privilege and weaker logging all collect. If someone can reach the queue that fixes failed instructions, they can reach the instructions — and that route is usually quieter than the one through the front door.

Submission

Where a Custodian files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.