Skip to main content
SEBI CSCRF · Intermediaries

SEBI CSCRF for Registrar & Share Transfer Agent (RTA)

1 tiers are reachable, decided by number of folios serviced and number of clients (sub-100 → soc/m-soc exemption).

Classification

What decides a Registrar & Share Transfer Agent (RTA)'s tier

Registrars are classified on folios serviced, and the largest of them are lifted into the tier the framework reserves for market infrastructure. That escalation is a statement about what an RTA holds: the register of ownership for a large part of the retail investing public, together with the bank details those investors are paid into.

Number of folios serviced

<10,000 folios → excluded entirely. ≥2 Cr folios → QRTA at MII tier. <100 clients → SOC/M-SOC exemption.

Number of clients (sub-100 → SOC/M-SOC exemption)

Some answers put a Registrar & Share Transfer Agent (RTA) outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.

Obligations

What the Small-size tier requires

Only the tiers a Registrar & Share Transfer Agent (RTA) can actually land in are listed.

Small-size REs

Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).

VAPT

Once a year

Cyber audit

Once a year (twice a year if providing IBT or Algo trading)

Drill

Annually

  • Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
  • Designated CISO or equivalent officer
  • IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
  • Annual cyber resilience posture evaluation

M-SOC

Market SOC mandatory unless you run your own

HSM for key storage

Risk-assessed alternative permitted

CISO reporting line

Designated officer is sufficient

IT Committee

Not mandated

RTO

As set in your CCMP

RPO

As set in your CCMP

Incident reporting

6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).

Scope

What a CSCRF VAPT has to reach at a Registrar & Share Transfer Agent (RTA)

The payout file is the asset. An RTA does not need to be breached spectacularly for money to move — a change to bank details on a set of folios, or an alteration between the point a payout file is generated and the point banking acts on it, achieves the same thing quietly. The register itself is the second exposure, because a change to ownership records is hard to reverse once corporate actions have run against it.

Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.

The scope spans the register, the servicing surface and the payout files:

  • The folio and unit-holder register, including the audit trail on changes to it
  • Investor servicing portals and the self-service change workflows within them
  • Bank-mandate, nomination and address change processing, including document verification
  • Dividend, interest and redemption payout file generation and its handoff to banking
  • Issue and IPO processing, allotment and refunds
  • Interfaces with KRAs, depositories and the AMCs or issuers being serviced
  • e-voting and investor communication systems

Where this goes wrong

Verifying the portal and not the file handoff

Assessments cover the investor-facing portal thoroughly and treat the payout pipeline as back-office plumbing. It is the part that touches money. Where the file is written, who can read or modify it in transit, what integrity check the receiving bank performs, and whether an out-of-band change would be detected are all in-scope questions and are frequently unanswered.

Submission

Where a Registrar & Share Transfer Agent (RTA) files, and by when

Reports go to SEBI. CSCRF Tables 17 and 23 route MIIs and all remaining regulated entities to SEBI.

Within 1 month

Report submitted

The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.

Within 3 months

Findings closed

Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.

Within 5 months

Revalidation complete

Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.

Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.

How we help

CERT-In empanelled, and the report is written for the submission

We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.

Verified against the source circulars as of 3 August 2026.