Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Depository Participant — not a Stock Brokers

1 tiers are reachable, decided by number of clients (used only to check sub-100 soc exemption).

Always Qualified RE per Apr 2025 (CIR/2025/60 §2.2).

Classification

What decides a Depository Participant — not a Stock Broker's tier

A Depository Participant that does not also broke is classified on what it is rather than what it moves, because the risk it carries is custodial. A DP is the operational point at which securities leave an investor account, and the controls that matter are the ones standing between an instruction and a debit.

Number of clients (used only to check sub-100 SOC exemption)

Obligations

What the QRE tier requires

Only the tiers a Depository Participant — not a Stock Broker can actually land in are listed.

Qualified REs

KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.

VAPT

Once a year (twice a year if CII)

Cyber audit

Twice a year

Red team

Half-yearly

Drill

Half-yearly

  • ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
  • CCI self-assessment — annually
  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
  • HSM mandatory under cloud framework
  • Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
  • RTO 2 hours / RPO 15 minutes

ISO 27001

Recommended, not mandatory

Cyber Capability Index

Self-assessment, annually

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Mandatory

CISO reporting line

CISO reports directly to MD/CEO

IT Committee

Mandatory, meets quarterly

RTO

2 hours (IOSCO)

RPO

15 minutes

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Depository Participant — not a Stock Broker

The characteristic incident is an unauthorised debit of securities, executed through a legitimate instruction path. That makes the authorisation chain — who can raise an instruction, what proves the holder approved it, and what would flag an instruction that does not fit the account — more important than the perimeter around it. Static holdings also mean a fraud can go unnoticed for far longer at a DP than at a trading intermediary.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope follows the instruction, from where it is raised to where it settles:

  • The DP front-end and its integration with the depository
  • Account opening and modification workflows, including bank and nomination changes
  • e-DIS, DDPI and power-of-attorney authorisation flows
  • OTP and TPIN delivery paths, and everything that can intercept or replay them
  • Pledge, margin-pledge and unpledge processing
  • Statement generation and investor-facing portals
  • Corporate action and credit processing

Where this goes wrong

Assuming the depository validates what you did not

Controls at the depository end are frequently assumed to catch a malformed or unauthorised instruction, and testing is scoped accordingly. The depository validates the instruction, not the authority behind it. Whether a modification to bank details, contact details or authorisation state could be made without the holder participating is a question that has to be answered inside the DP's own systems.

Submission

Where a Depository Participant — not a Stock Broker files, and by when

Reports go to your Stock Exchange or Depository. CSCRF Tables 17 and 23 route Stock Brokers and Depository Participants through the exchange or depository they are registered with, not directly to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.