Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Designated Depository Participant (DDP)

Always QRE. No threshold test applies.

DDP categorisation = highest of DP and Custodian. Defaults to QRE; refine in result if you also operate as a broker or have a tier-driving Custodian footprint.

Classification

What decides a Designated Depository Participant (DDP)'s tier

A Designated Depository Participant takes the higher of its depository-participant and custodian classifications, because DDP activity sits on top of one or both of those businesses rather than replacing them. The function itself — registering and maintaining foreign portfolio investors — is where the distinctive exposure is.

No measurement applies. Designated Depository Participant (DDP) are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the QRE tier requires

Only the tiers a Designated Depository Participant (DDP) can actually land in are listed.

Qualified REs

KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.

VAPT

Once a year (twice a year if CII)

Cyber audit

Twice a year

Red team

Half-yearly

Drill

Half-yearly

  • ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
  • CCI self-assessment — annually
  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
  • HSM mandatory under cloud framework
  • Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
  • RTO 2 hours / RPO 15 minutes

ISO 27001

Recommended, not mandatory

Cyber Capability Index

Self-assessment, annually

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Mandatory

CISO reporting line

CISO reports directly to MD/CEO

IT Committee

Mandatory, meets quarterly

RTO

2 hours (IOSCO)

RPO

15 minutes

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Designated Depository Participant (DDP)

A DDP holds beneficial ownership and structural information on foreign investors that is sensitive commercially, politically and for tax purposes — a category of data with a specific set of interested parties. The integrity exposure is the registration record itself: FPI status and category determine market access and tax treatment, so an altered record has consequences beyond the disclosure.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope is the FPI lifecycle in addition to the underlying DP or custody estate:

  • FPI registration, renewal and category-change workflows
  • Common application form processing and the supporting documentation held with it
  • Beneficial ownership records and the verification behind them
  • Tax and regulatory reporting interfaces
  • Depository and custody interfaces the DDP function depends on
  • The underlying DP or custodian estate, which is what sets the tier

Where this goes wrong

Classifying on the DDP function alone

The rule takes the highest of the applicable classifications, and the DDP function is rarely the one that produces it. Firms that classify on DDP activity in isolation land on a lighter tier than the underlying custody or depository-participant business actually attracts. Work out the underlying classification first, then confirm the DDP function does not lift it.

Submission

Where a Designated Depository Participant (DDP) files, and by when

Reports go to your Stock Exchange or Depository. CSCRF Tables 17 and 23 route Stock Brokers and Depository Participants through the exchange or depository they are registered with, not directly to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.