SEBI CSCRF for Research Analysts
1 tiers are reachable, decided by are you registered with sebi in another category?.
Non-registered RAs → exempt (SaaS declaration only). Institutional RAs in another category → tier of that other category. Reporting to BSE Ltd.
Classification
What decides a Research Analyst's tier
Research Analysts follow the same shape as non-individual advisers: a standalone registration falls outside the framework, and a second SEBI registration pulls the firm into whatever that category attracts. Supervision and reporting for analysts moved to the same administering body that oversees advisers, which is a change from where the master circular originally sent them — a firm following the original text alone would file to the wrong place.
Are you registered with SEBI in another category?
Some answers put a Research Analyst outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.
Obligations
What the Small-size tier requires
Only the tiers a Research Analyst can actually land in are listed.
Small-size REs
Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).
VAPT
Once a year
Cyber audit
Once a year (twice a year if providing IBT or Algo trading)
Drill
Annually
- Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
- Designated CISO or equivalent officer
- IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
- Annual cyber resilience posture evaluation
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Research Analyst
Unpublished research is price-sensitive for exactly as long as it is unpublished, and the window is where the exposure lives. Early access to a rating or target change — through a distribution list, a shared drafting folder, or a staging site that is reachable before release — is tradeable. The reputational failure mode is the mirror image: published research altered or impersonated after the fact.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
The estate is small and the sensitive part of it is the publication path:
- The research authoring, review and publication platform
- Distribution lists and the mechanism that releases a report to them
- Embargo handling between a report being finalised and being published
- Client and subscriber records
- The public website or application carrying published research
- Systems belonging to any other registered activity, which is what determines the tier
Where this goes wrong
The staging environment is the leak
Research is commonly staged before release on infrastructure that is reachable, indexable or predictably named, and treated as internal because nobody links to it. Predictable URLs and unauthenticated preview paths are the recurring finding here, and they defeat every control applied to the release process itself.
Submission
Where a Research Analyst files, and by when
Reports go to BSE Ltd. The Apr 2025 clarification (CIR/2025/60 §2.4.1) moved Investment Advisers and Research Analysts to BSE Ltd as reporting authority, from BASL and SEBI respectively.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.