Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Debenture Trustees

For Debenture Trustees, 1 tiers are reachable, decided by have you added any new debt issuer client in the last 3 financial years.

Classification

What decides the tier for a Debenture Trustee

The debenture-trustee test asks whether the firm has taken on a new debt issuer client in the last three financial years. Trusteeship is a long-tail business in which a firm can hold live obligations for years without new activity, so the framework uses recent client acquisition as its proxy for an operating estate instead of measuring size.

Have you added any new debt issuer client in the last 3 financial years?

No → excluded entirely from CSCRF.

Some answers put a Debenture Trustee outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.

Obligations

What the Self-cert tier requires

Only the tiers a Debenture Trustee can land in are listed.

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC: MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Debenture Trustee

A debenture trustee's core asset is evidentiary. The records establishing what security exists, in whose favour and on what terms are the thing relied on when an issuer defaults, which is precisely when they will be scrutinised and when their integrity matters most. Availability failures are survivable here; a record that cannot be shown to be unaltered is not.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.

The scope is the record of security and the communications around it:

  • Charge, security and covenant records for each issue
  • Issuer communication and periodic compliance certificate collection
  • Investor grievance handling and the records it produces
  • Recovery expense fund records
  • Document repositories holding trust deeds and security documents
  • Any investor or issuer-facing portal

Where this goes wrong

A three-year window that moves

The test looks back over the last three financial years, so a firm that stops taking new issuer mandates leaves scope quietly, when the last qualifying year rolls out of the window, and returns just as quietly with one new mandate. The status has to be re-derived each year, not recorded once.

Submission

Where a Debenture Trustee files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.

At self-certification, the VAPT is the only audit owed and no cyber audit is required. It still has to be carried out by a CERT-In empanelled organisation, and the compliance position is signed by an authorised signatory.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.

Verified against the source circulars as of 3 August 2026.

FAQ

Common questions

These are the questions we are asked most often about this category.

Talk to our team
Does SEBI CSCRF apply to Debenture Trustees?+
Yes. Debenture Trustees fall under CSCRF, unless they are below the threshold set out below, in which case they are excluded entirely. For Debenture Trustees, 1 tiers are reachable, decided by have you added any new debt issuer client in the last 3 financial years.
How often does a Debenture Trustee need VAPT under CSCRF?+
At the Self-cert tier: Once a year. Cyber audit: Once a year.
Where does a Debenture Trustee submit its CSCRF reports?+
To SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Which SEBI circular sets this out?+
As per SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20-Aug-2024 read with CIR/2024/184, CIR/2025/45, CIR/2025/60, CIR/2025/96, CIR/2025/119, the SEBI FAQ (11-Jun-2025), and the May 2026 AI Vulnerability Detection Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026.