SEBI CSCRF for Depository Participant — not a Stock Brokers
1 tiers are reachable, decided by number of clients (used only to check sub-100 soc exemption).
Always Qualified RE per Apr 2025 (CIR/2025/60 §2.2).
Classification
What decides a Depository Participant — not a Stock Broker's tier
A Depository Participant that does not also broke is classified on what it is rather than what it moves, because the risk it carries is custodial. A DP is the operational point at which securities leave an investor account, and the controls that matter are the ones standing between an instruction and a debit.
Number of clients (used only to check sub-100 SOC exemption)
Obligations
What the QRE tier requires
Only the tiers a Depository Participant — not a Stock Broker can actually land in are listed.
Qualified REs
KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.
VAPT
Once a year (twice a year if CII)
Cyber audit
Twice a year
Red team
Half-yearly
Drill
Half-yearly
- ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
- CCI self-assessment — annually
- IT Committee with external cybersecurity expert — mandatory, quarterly meetings
- 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
- HSM mandatory under cloud framework
- Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
- RTO 2 hours / RPO 15 minutes
ISO 27001
Recommended, not mandatory
Cyber Capability Index
Self-assessment, annually
M-SOC
Eligible for SEBI M-SOC, encouraged
HSM for key storage
Mandatory
CISO reporting line
CISO reports directly to MD/CEO
IT Committee
Mandatory, meets quarterly
RTO
2 hours (IOSCO)
RPO
15 minutes
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Depository Participant — not a Stock Broker
The characteristic incident is an unauthorised debit of securities, executed through a legitimate instruction path. That makes the authorisation chain — who can raise an instruction, what proves the holder approved it, and what would flag an instruction that does not fit the account — more important than the perimeter around it. Static holdings also mean a fraud can go unnoticed for far longer at a DP than at a trading intermediary.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
The scope follows the instruction, from where it is raised to where it settles:
- The DP front-end and its integration with the depository
- Account opening and modification workflows, including bank and nomination changes
- e-DIS, DDPI and power-of-attorney authorisation flows
- OTP and TPIN delivery paths, and everything that can intercept or replay them
- Pledge, margin-pledge and unpledge processing
- Statement generation and investor-facing portals
- Corporate action and credit processing
Where this goes wrong
Assuming the depository validates what you did not
Controls at the depository end are frequently assumed to catch a malformed or unauthorised instruction, and testing is scoped accordingly. The depository validates the instruction, not the authority behind it. Whether a modification to bank details, contact details or authorisation state could be made without the holder participating is a question that has to be answered inside the DP's own systems.
Submission
Where a Depository Participant — not a Stock Broker files, and by when
Reports go to your Stock Exchange or Depository. CSCRF Tables 17 and 23 route Stock Brokers and Depository Participants through the exchange or depository they are registered with, not directly to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.