SEBI CSCRF for Debenture Trustees
1 tiers are reachable, decided by have you added any new debt issuer client in the last 3 financial years?.
Classification
What decides a Debenture Trustee's tier
The debenture-trustee test asks whether the firm has taken on a new debt issuer client in the last three financial years. Trusteeship is a long-tail business in which a firm can hold live obligations for years without new activity, so the framework uses recent client acquisition as its proxy for an operating estate rather than measuring size.
Have you added any new debt issuer client in the last 3 financial years?
No → excluded entirely from CSCRF.
Some answers put a Debenture Trustee outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.
Obligations
What the Self-cert tier requires
Only the tiers a Debenture Trustee can actually land in are listed.
Self-certification REs
Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.
VAPT
Once a year
Cyber audit
Once a year
Drill
Annually
- Onboard to Market SOC — MANDATORY, unless RE has own SOC
- Designated CISO or equivalent officer
- IT Committee optional
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Debenture Trustee
A debenture trustee's core asset is evidentiary. The records establishing what security exists, in whose favour and on what terms are the thing relied on when an issuer defaults — which is precisely when they will be scrutinised and precisely when their integrity matters most. Availability failures are survivable here; a record that cannot be shown to be unaltered is not.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
The scope is the record of security and the communications around it:
- Charge, security and covenant records for each issue
- Issuer communication and periodic compliance certificate collection
- Investor grievance handling and the records it produces
- Recovery expense fund records
- Document repositories holding trust deeds and security documents
- Any investor or issuer-facing portal
Where this goes wrong
A three-year window that moves
The test looks back over the last three financial years, so a firm that stops taking new issuer mandates does not leave scope on any announcement — it leaves quietly, when the last qualifying year rolls out of the window, and returns just as quietly with one new mandate. The status has to be re-derived each year rather than recorded once.
Submission
Where a Debenture Trustee files, and by when
Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
At self-certification, the VAPT is the only audit owed — but it still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory. No cyber audit is required.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.