SEBI CSCRF for Market Infrastructure Institutions
Always MII. No threshold test applies.
Covers Stock Exchanges, Depositories and Clearing Corporations — CSCRF applies one rule to all three.
Classification
What decides a Market Infrastructure Institutions's tier
Market Infrastructure Institutions are the only entities CSCRF names a tier after, and the framework asks nothing about size before placing them in it. An exchange, a depository and a clearing corporation are not regulated by how large they are but by what stops if they stop — price discovery, ownership of record, and settlement finality respectively. That is also why the recovery objectives set for this tier are stated in hours and minutes rather than left to the entity to determine.
No measurement applies. Market Infrastructure Institutions are classified directly by the framework, so the tier does not change with size, client count or assets.
Obligations
What the MII tier requires
Only the tiers a Market Infrastructure Institutions can actually land in are listed.
Market Infrastructure Institutions (MIIs)
Stock Exchanges (BSE, NSE, MSEI), Depositories (NSDL, CDSL), Clearing Corporations (NSCCL, ICCL, MCXCCL) and Qualified RTAs (QRTAs servicing ≥2 Cr folios).
VAPT
Twice a year (CII / Protected Systems per NCIIPC); else once a year
Cyber audit
Twice a year
Red team
Half-yearly
Drill
Half-yearly
- ISO 27001 certification — mandatory
- CCI third-party assessment — half-yearly
- IT Committee with external cybersecurity expert — mandatory, quarterly meetings
- Operates Market SOC (NSE/BSE) or runs own 24×7 SOC
- HSM mandatory under cloud framework
- Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
- RTO 2 hours / RPO 15 minutes (per IOSCO + Mar 2021 SEBI BCP)
ISO 27001
Certification mandatory
Cyber Capability Index
Third-party assessment, half-yearly
M-SOC
Operates its own M-SOC
HSM for key storage
Mandatory
CISO reporting line
CISO reports directly to MD/CEO
IT Committee
Mandatory, meets quarterly
RTO
2 hours (IOSCO)
RPO
15 minutes
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Market Infrastructure Institutions
The failure that matters at an MII is rarely data theft. It is an integrity or availability event during market hours, where the cost is measured in the sessions that could not settle and the positions that could not be valued. Systems here are also the likeliest in the sector to be designated Protected Systems by NCIIPC, which changes the testing calendar rather than merely adding a control.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
A CSCRF VAPT at an MII reaches well past the public-facing surface:
- The matching or settlement engine and the order gateways in front of it, including colocation and direct market access paths
- Member, participant and clearing-member portals — the interfaces through which the market interacts with the institution
- Risk management and margining systems, where an integrity failure is more damaging than an availability one
- Market data dissemination and feed handlers
- Depository-side account and corporate-action systems, e-voting and pledge processing
- The disaster recovery site as a tested environment, not as a diagram
Where this goes wrong
Testing the DR site as an architecture review
The recovery objectives at this tier are only meaningful if the failover has been exercised under the load and data volumes the primary carries. A DR site that has been reviewed on paper, or cut over during a quiet window with a subset of services, produces a recovery time that does not survive a real incident. The same applies to the interfaces the DR site depends on — if members reconnect to a gateway that was never part of the drill, the drill did not test recovery.
Submission
Where a Market Infrastructure Institutions files, and by when
Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.