Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Merchant Bankers

For Merchant Bankers, 1 tiers are reachable, decided by have you undertaken any merchant-banking activity in the review period.

Classification

What decides the tier for a Merchant Banker

The merchant-banker rule was simplified to a single question about whether the firm did any merchant-banking work in the review period, which makes activity the trigger instead of scale. It is a sensible fit for the business: a merchant banker's risk comes from what passes through it during a transaction, not from a permanent operational footprint.

Have you undertaken any merchant-banking activity in the review period?

Active MBs → Small-size REs. Inactive MBs → exempt from CSCRF.

Some answers put a Merchant Banker outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.

Obligations

What the Small-size tier requires

Only the tiers a Merchant Banker can land in are listed.

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE): MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Merchant Banker

A merchant banker holds unpublished price-sensitive information, and the loss event is disclosure rather than disruption. Leakage ahead of an announcement is both a market-abuse matter and a client-relationship ending one, and the paths it travels are ordinary: a shared mailbox, an over-permissioned data room, a document forwarded to a personal address. The estate is usually small, which makes thorough testing of it affordable.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what you classify as critical decides how much of the estate gets tested.

The scope follows the transaction and the information it generates:

  • Deal data rooms and document repositories holding draft offer documents
  • Email and file transfer, which is where price-sensitive material actually moves
  • Issue management systems and the coordination interfaces with registrars, bankers to the issue and exchanges
  • Endpoints belonging to the deal team, including anything used away from the office
  • Collaboration platforms used with issuers and legal advisers

Where this goes wrong

Assuming an inactive year settles the question

The test is about the review period, so a firm can be in scope one year and out the next while its systems and the information sitting in them do not change at all. Treating a quiet year as a permanent exemption leaves an untested estate holding historical deal material, and leaves the firm reconstructing a compliance position under time pressure the year a mandate lands.

Submission

Where a Merchant Banker files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission, so a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year, not backwards from the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the report is mapped to the CSCRF control set so it can be filed as written.

Verified against the source circulars as of 3 August 2026.

FAQ

Common questions

These are the questions we are asked most often about this category.

Talk to our team
Does SEBI CSCRF apply to Merchant Bankers?+
Yes. Merchant Bankers fall under CSCRF, unless they are below the threshold set out below, in which case they are excluded entirely. For Merchant Bankers, 1 tiers are reachable, decided by have you undertaken any merchant-banking activity in the review period.
How often does a Merchant Banker need VAPT under CSCRF?+
At the Small-size tier: Once a year. Cyber audit: Once a year (twice a year if providing IBT or Algo trading).
Where does a Merchant Banker submit its CSCRF reports?+
To SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.
Which SEBI circular sets this out?+
As per SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20-Aug-2024 read with CIR/2024/184, CIR/2025/45, CIR/2025/60, CIR/2025/96, CIR/2025/119, the SEBI FAQ (11-Jun-2025), and the May 2026 AI Vulnerability Detection Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026.