Skip to main content
SEBI CSCRF · Market Infrastructure Institutions

SEBI CSCRF for Market Infrastructure Institutions

Always MII. No threshold test applies.

Covers Stock Exchanges, Depositories and Clearing Corporations — CSCRF applies one rule to all three.

Classification

What decides a Market Infrastructure Institutions's tier

Market Infrastructure Institutions are the only entities CSCRF names a tier after, and the framework asks nothing about size before placing them in it. An exchange, a depository and a clearing corporation are not regulated by how large they are but by what stops if they stop — price discovery, ownership of record, and settlement finality respectively. That is also why the recovery objectives set for this tier are stated in hours and minutes rather than left to the entity to determine.

No measurement applies. Market Infrastructure Institutions are classified directly by the framework, so the tier does not change with size, client count or assets.

Obligations

What the MII tier requires

Only the tiers a Market Infrastructure Institutions can actually land in are listed.

Market Infrastructure Institutions (MIIs)

Stock Exchanges (BSE, NSE, MSEI), Depositories (NSDL, CDSL), Clearing Corporations (NSCCL, ICCL, MCXCCL) and Qualified RTAs (QRTAs servicing ≥2 Cr folios).

VAPT

Twice a year (CII / Protected Systems per NCIIPC); else once a year

Cyber audit

Twice a year

Red team

Half-yearly

Drill

Half-yearly

  • ISO 27001 certification — mandatory
  • CCI third-party assessment — half-yearly
  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • Operates Market SOC (NSE/BSE) or runs own 24×7 SOC
  • HSM mandatory under cloud framework
  • Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
  • RTO 2 hours / RPO 15 minutes (per IOSCO + Mar 2021 SEBI BCP)

ISO 27001

Certification mandatory

Cyber Capability Index

Third-party assessment, half-yearly

M-SOC

Operates its own M-SOC

HSM for key storage

Mandatory

CISO reporting line

CISO reports directly to MD/CEO

IT Committee

Mandatory, meets quarterly

RTO

2 hours (IOSCO)

RPO

15 minutes

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Market Infrastructure Institutions

The failure that matters at an MII is rarely data theft. It is an integrity or availability event during market hours, where the cost is measured in the sessions that could not settle and the positions that could not be valued. Systems here are also the likeliest in the sector to be designated Protected Systems by NCIIPC, which changes the testing calendar rather than merely adding a control.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

A CSCRF VAPT at an MII reaches well past the public-facing surface:

  • The matching or settlement engine and the order gateways in front of it, including colocation and direct market access paths
  • Member, participant and clearing-member portals — the interfaces through which the market interacts with the institution
  • Risk management and margining systems, where an integrity failure is more damaging than an availability one
  • Market data dissemination and feed handlers
  • Depository-side account and corporate-action systems, e-voting and pledge processing
  • The disaster recovery site as a tested environment, not as a diagram

Where this goes wrong

Testing the DR site as an architecture review

The recovery objectives at this tier are only meaningful if the failover has been exercised under the load and data volumes the primary carries. A DR site that has been reviewed on paper, or cut over during a quiet window with a subset of services, produces a recovery time that does not survive a real incident. The same applies to the interfaces the DR site depends on — if members reconnect to a gateway that was never part of the drill, the drill did not test recovery.

Submission

Where a Market Infrastructure Institutions files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.