Skip to main content
SEBI CSCRF · Funds

SEBI CSCRF for Portfolio Managers

3 tiers are reachable, decided by aum (inr crores) and number of clients (sub-100 → m-soc exemption if self-cert).

Classification

What decides a Portfolio Manager's tier

Portfolio Managers were rescoped into a shorter tier ladder with no qualified tier at the top, which reflects how the business runs: discretionary mandates over a concentrated set of clients, executed through brokers and held with custodians rather than settled in-house. The obligations scale with assets, and the smallest managers land on self-certification and a VAPT rather than a full audit programme.

AUM (INR crores)

Aug 2025 revision: Self-cert ≤₹3,000 Cr · Small-size >₹3,000-<₹10,000 Cr · Mid-size ≥₹10,000 Cr.

Number of clients (sub-100 → M-SOC exemption if Self-cert)

Obligations

What each reachable tier requires

Only the tiers a Portfolio Manager can actually land in are listed.

Mid-size REs

Stock Brokers 1-10L clients OR ₹1-10L Cr volume, AMCs ₹10k-1L Cr AUM, Custodians ₹1-10L Cr AUC, Portfolio Managers ≥₹10k Cr AUM, AIF+VCF managers >₹10k Cr corpus, RTAs 1-2 Cr folios.

VAPT

Once a year (commences Q1 of FY)

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • IT Committee with external cybersecurity expert — mandatory, quarterly meetings
  • 24×7 SOC (own / Market SOC / 3P-managed); annual functional efficacy review
  • HSM — risk-assessed alternative permitted (Board approval required)
  • Designated CISO or equivalent officer
  • Annual cyber resilience posture evaluation (EV.ST.S5)

M-SOC

Eligible for SEBI M-SOC, encouraged

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Mandatory, meets quarterly

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Self-certification REs

Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.

VAPT

Once a year

Cyber audit

Once a year

Drill

Annually

  • Onboard to Market SOC — MANDATORY, unless RE has own SOC
  • Designated CISO or equivalent officer
  • IT Committee optional

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Portfolio Manager

Client concentration cuts both ways. A portfolio manager holds relatively few clients, each with a large mandate, which makes targeted compromise of a single client relationship worth real effort to an attacker. Fee and performance computation is the integrity exposure — figures that flow into a client statement and into a regulatory filing without an independent check on the way.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope is the mandate lifecycle and the client-visible surface:

  • The portfolio management and accounting platform, including performance and fee computation
  • Broker and custodian interfaces, and the instruction paths that run over them
  • Client reporting portals and the periodic statements they issue
  • Onboarding, KYC and agreement execution workflows
  • Order management and any research or model-portfolio systems feeding it
  • The document repository holding client agreements and disclosures

Where this goes wrong

Excluding the platform because it is a vendor product

A hosted portfolio management platform is routinely treated as the vendor's responsibility and left out of scope. The tenant configuration is yours: user entitlements, segregation between client books, API keys, report exposure, and the integrations you enabled. Testing the tenant is neither testing the vendor's product nor duplicating their assurance, and it is the part that produces findings.

Submission

Where a Portfolio Manager files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.