Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for KYC Registration Agency (KRA)

Always QRE. No threshold test applies.

Recategorised from MII to Qualified RE in Apr 2025 (CIR/2025/60 §2.5).

Classification

What decides a KYC Registration Agency (KRA)'s tier

A KYC Registration Agency holds the identity records the rest of the market relies on, which is why its recategorisation was a change of tier rather than a change of substance. The obligations follow from what a KRA is: a central store of verified identity documents that hundreds of intermediaries read from and write to, through interfaces those intermediaries operate.

No measurement applies. KYC Registration Agency (KRA) are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the QRE tier requires

Only the tiers a KYC Registration Agency (KRA) can actually land in are listed.

Qualified REs

KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.

VAPT

Once a year (twice a year if CII)

Cyber audit

Twice a year

Red team

Half-yearly

Drill

Half-yearly

  • ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
  • CCI self-assessment — annually
  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
  • HSM mandatory under cloud framework
  • Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
  • RTO 2 hours / RPO 15 minutes

ISO 27001

Recommended, not mandatory

Cyber Capability Index

Self-assessment, annually

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Mandatory

CISO reporting line

CISO reports directly to MD/CEO

IT Committee

Mandatory, meets quarterly

RTO

2 hours (IOSCO)

RPO

15 minutes

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a KYC Registration Agency (KRA)

The concentration is the exposure. A KRA is a single system holding verified identity documents for a large share of the investing public, reachable by every registered intermediary that has been entitled to it. The realistic worst case is not a breach of the KRA perimeter but the abuse of a legitimately issued intermediary credential to enumerate records at volume.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope that matters at a KRA is the interface layer as much as the repository:

  • The KYC record repository itself, including document images and the retention controls around them
  • Intermediary-facing upload, download and search APIs — the largest and least-controlled attack surface here
  • Bulk fetch interfaces, where a rate-limiting or authorisation gap becomes a mass-disclosure event
  • Identity verification integrations and the credentials that authenticate them
  • Inter-KRA interoperability paths
  • The intermediary onboarding and entitlement process that decides who can read which records

Where this goes wrong

Treating entitled intermediaries as trusted

Testing that stops at the perimeter and treats every authenticated intermediary as in-bounds skips the question that decides the blast radius: what can one compromised intermediary credential actually reach, and would anyone notice it reaching it? Authorisation testing between intermediary contexts, and detection on anomalous fetch volumes, belong in scope explicitly — they are not covered by a network-layer assessment.

Submission

Where a KYC Registration Agency (KRA) files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.