SEBI CSCRF for Stock Brokers
4 tiers are reachable, decided by number of registered (active) clients per ucc and annual clientele trading volume (inr crores).
Covers Depository Participants that are also registered Stock Brokers, who take the same two-parameter test — CSCRF applies one rule to all three.
Classification
What decides a Stock Broker's tier
The stock-broker rule is the most-amended part of CSCRF, and the shape of the current test says why: SEBI measures both how many clients a broker holds and how much it trades, then applies whichever answer is more onerous. A small client base moving large volume and a large client base moving little are different risks, and a single-parameter test would let one of them through.
Number of registered (active) clients per UCC
Higher of (clients OR trading volume) determines your tier.
Annual clientele trading volume (INR crores)
<1,000 clients AND <₹1,000 Cr trading volume → exempt from CSCRF entirely.
Some answers put a Stock Broker outside CSCRF entirely. The wizard states the exact threshold and shows the exemption alongside the result.
Obligations
What each reachable tier requires
Only the tiers a Stock Broker can actually land in are listed.
Qualified REs
KRAs (post Apr 2025), Institutional DPs not registered as Stock Brokers, Stock Brokers >10L clients OR >₹10L Cr trading volume, AMCs ≥₹1L Cr AUM, Custodians ≥₹10L Cr AUC.
VAPT
Once a year (twice a year if CII)
Cyber audit
Twice a year
Red team
Half-yearly
Drill
Half-yearly
- ISO 27001 — recommended (Aug 2025 made voluntary; was mandatory in master)
- CCI self-assessment — annually
- IT Committee with external cybersecurity expert — mandatory, quarterly meetings
- 24×7 SOC (own / group / Market SOC / 3P-managed); half-yearly functional efficacy review
- HSM mandatory under cloud framework
- Direct CISO reporting line to MD/CEO; grade ≥ CTO/CIO
- RTO 2 hours / RPO 15 minutes
ISO 27001
Recommended, not mandatory
Cyber Capability Index
Self-assessment, annually
M-SOC
Eligible for SEBI M-SOC, encouraged
HSM for key storage
Mandatory
CISO reporting line
CISO reports directly to MD/CEO
IT Committee
Mandatory, meets quarterly
RTO
2 hours (IOSCO)
RPO
15 minutes
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Mid-size REs
Stock Brokers 1-10L clients OR ₹1-10L Cr volume, AMCs ₹10k-1L Cr AUM, Custodians ₹1-10L Cr AUC, Portfolio Managers ≥₹10k Cr AUM, AIF+VCF managers >₹10k Cr corpus, RTAs 1-2 Cr folios.
VAPT
Once a year (commences Q1 of FY)
Cyber audit
Once a year (twice a year if providing IBT or Algo trading)
Drill
Annually
- IT Committee with external cybersecurity expert — mandatory, quarterly meetings
- 24×7 SOC (own / Market SOC / 3P-managed); annual functional efficacy review
- HSM — risk-assessed alternative permitted (Board approval required)
- Designated CISO or equivalent officer
- Annual cyber resilience posture evaluation (EV.ST.S5)
M-SOC
Eligible for SEBI M-SOC, encouraged
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Mandatory, meets quarterly
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Small-size REs
Stock Brokers 10k-1L clients OR ₹10k-1L Cr volume, AMCs <₹10k Cr AUM, Custodians <₹1L Cr AUC, Portfolio Managers ₹3k-10k Cr AUM, AIF+VCF managers ₹3k-10k Cr corpus, RTAs 10k-1Cr folios, all active Merchant Bankers, Non-individual IAs (registered in another category).
VAPT
Once a year
Cyber audit
Once a year (twice a year if providing IBT or Algo trading)
Drill
Annually
- Onboard to Market SOC (NSE/BSE) — MANDATORY, unless RE has own SOC and submits efficacy reports
- Designated CISO or equivalent officer
- IT Committee optional (otherwise MD/CEO/Board approves CSCRF compliance)
- Annual cyber resilience posture evaluation
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Self-certification REs
Stock Brokers 1k-10k clients OR ₹1k-10k Cr volume, Portfolio Managers ≤₹3k Cr AUM, AIF+VCF managers ≤₹3k Cr corpus, CIS, CRAs, Debenture Trustees with new clients in last 3 FYs.
VAPT
Once a year
Cyber audit
Once a year
Drill
Annually
- Onboard to Market SOC — MANDATORY, unless RE has own SOC
- Designated CISO or equivalent officer
- IT Committee optional
M-SOC
Market SOC mandatory unless you run your own
HSM for key storage
Risk-assessed alternative permitted
CISO reporting line
Designated officer is sufficient
IT Committee
Not mandated
RTO
As set in your CCMP
RPO
As set in your CCMP
Incident reporting
6 hr to SEBI Incident Reporting portal + [email protected] AND CERT-In (per April 2022 Directions). Interim report 3d, mitigation 7d, RCA 30d, incident-VAPT 45d (CSCRF Annexure-O).
Scope
What a CSCRF VAPT has to reach at a Stock Broker
Account takeover at a broker converts directly into money movement, which makes authentication and session handling the load-bearing controls rather than supporting ones. The second exposure is the API surface: algo clients authenticate with long-lived keys, often stored in places nobody inventoried, and an order path reached with a valid key looks legitimate to every control in front of it.
Cyber audit covers 100% of critical systems and a 25% sample of the rest, so what is classified as critical is a scoping decision with consequences rather than a labelling exercise.
The testable surface at a broking firm is wider than the trading application:
- Trading front-ends across web, desktop and mobile, and the session handling that connects them
- Order management and risk management systems, including the limits that sit between a client and the exchange
- Algo and API gateways, which authenticate machines rather than people and are often exempted from the controls applied to human logins
- The UCC database and the client master behind it
- Back-office systems — settlement, payouts, contract notes and ledger
- Digital onboarding, e-mandate and payment paths
- Mobile applications as artefacts, including what the build leaks and what it stores on device
Where this goes wrong
Scoping the app and leaving out the machine paths
A broker VAPT scoped as "the trading platform" routinely covers the interface a human uses and omits the API and algo gateways that carry the larger orders. Those paths deserve the harder look, not the lighter one — they run without a person watching, they authenticate with credentials that rarely rotate, and a flaw in them is exploitable at machine speed. Payout and back-office systems get left out for the same reason, and that is where a fraud lands rather than merely starts.
Submission
Where a Stock Broker files, and by when
Reports go to your Stock Exchange or Depository. CSCRF Tables 17 and 23 route Stock Brokers and Depository Participants through the exchange or depository they are registered with, not directly to SEBI.
Within 1 month
Report submitted
The VAPT report is filed within a month of the activity completing, after your IT Committee has approved it where one is mandated, together with the MD/CEO declaration the format requires.
Within 3 months
Findings closed
Closure runs from submission, graded by criticality. Anything still open at three months needs IT Committee approval to stay open and has to be closed before the next cycle starts.
Within 5 months
Revalidation complete
Revalidation runs from completion of the VAPT, not from submission — which is why a cycle started late in the year rarely leaves room to finish it.
Plan the cycle at the start of the financial year rather than against the deadline. No audit period may be left unaudited because a category changed mid-year: an unaudited stretch has to be pulled into the current cycle.
How we help
CERT-In empanelled, and the report is written for the submission
We run the VAPT and cyber-audit scope your tier requires, and the deliverable is written to be filed — mapped to the CSCRF control set rather than handed over as a generic findings list that someone then has to translate.
Verified against the source circulars as of 3 August 2026.