A CERT-In Empanelled Auditing Organization
SEBI CSCRF Audit

SEBI CSCRF cyber audits for the securities market.

CERT-In empanelled cyber audits and VAPT mapped to SEBI's Cybersecurity and Cyber Resilience Framework — for market infrastructure institutions, brokers, mutual funds, intermediaries and every regulated entity in between. Scoped precisely to your CSCRF category.

Overview

One framework for the whole securities market.

Issued on 20 August 2024, SEBI's Cybersecurity and Cyber Resilience Framework replaced the earlier patchwork of entity-specific cyber circulars with a single, graded model that scales obligations to each regulated entity's size and operational footprint. It is the most comprehensive cybersecurity regulation an Indian financial regulator has issued.

CSCRF grades every regulated entity into one of five categories and frames every control around five resilience goals — Anticipate, Withstand, Contain, Recover and Evolve. It mandates periodic cyber audits and VAPT by CERT-In empanelled auditors, in SEBI's standardized formats, with strict closure timelines.

As a CERT-In empanelled auditing organization with a dedicated BFSI practice, we deliver the CSCRF cyber audit end to end — control assessment, VAPT, the prescribed reports and the MD/CEO declaration — scoped exactly to your category, so you neither under- nor over-comply.

Who must comply

SEBI CSCRF regulated entities

CSCRF applies to all SEBI regulated entities, graded into five categories by asset size, trading volume, client base or AUM. Your category is fixed at the start of each financial year on the previous year's data.

Market Infrastructure InstitutionsStock exchanges, clearing corporations and depositories.
Stock Brokers & DPsStock brokers and depository participants.
Mutual Funds & AMCsAsset management companies and their funds.
KRAs, RTAs & CustodiansKYC registration agencies, registrars and custodians.
IAs, RAs & Portfolio ManagersInvestment advisers, research analysts and PMS.
AIFs, Merchant Bankers & CRAsAlternative investment funds, merchant bankers and rating agencies.
CSCRF categoryExample regulated entitiesCyber audit & key obligations
Market Infrastructure Institutions (MIIs)Stock exchanges, clearing corporations, depositoriesTwice a year
In-house SOCISO 27001CCIRed teaming
Qualified REsKRAs, qualified stock brokers and other large REs above thresholdTwice a year
SOCISO 27001CCICISO
Mid-size REsEntities above the mid-size thresholds by AUM, clients or volume2×/yr if IBT/Algo, else annual
IT CommitteeSOC
Small-size REsSmaller brokers, advisers, RTAs and similar above the self-cert threshold2×/yr if IBT/Algo, else annual
Self-certification REsThe smallest REs and lowest-threshold entitiesVAPT + self-certification
CERT-In empanelled VAPT

Categories, thresholds and obligations were revised through 2025 (April 2025 clarifications and subsequent FAQs) and are set annually on prior-year data; an entity registered in multiple capacities takes its highest applicable category. Certain entities — including FPIs, FVCIs, individual investment advisers, LPCC, QDPs, vault managers, RTAs servicing under 10,000 folios, REITs and InvITs — are outside CSCRF. We confirm your exact category and obligations during scoping.

Regulatory requirements

What CSCRF requires.

We map your audit to the obligations that apply to your category.

Circular · Aug 2024

Cybersecurity & Cyber Resilience Framework

The consolidated CSCRF master circular, replacing the 2015 and 2018 broad guidelines with a single, graded standard for all SEBI regulated entities.

Graded model

Five-category classification

Obligations scale across MIIs, Qualified, Mid-size, Small-size and Self-certification REs, fixed annually on prior-year data.

Detection

SOC & Market-SOC

24×7 monitoring via an own, group, Market-SOC or managed SOC — with an in-house SOC expected of MIIs.

Top tiers

ISO 27001, CCI & Red Teaming

MIIs and Qualified REs obtain ISO 27001, use the Cyber Capability Index, and conduct red-teaming exercises.

Assurance

Cyber Audit & VAPT

Periodic cyber audit covering 100% of critical and 25% of non-critical systems, plus VAPT, by a CERT-In empanelled auditor in SEBI's formats.

Timelines

Reporting & Closure

Audit report with MD/CEO declaration within one month, findings closed within three months, and a follow-on audit within six months.

The CSCRF model

Five cyber resilience goals.

Every CSCRF control maps to one of five goals — the lens our audit assesses you against.

Anticipate

Threat intelligence, risk assessment and asset and data classification.

Withstand

Preventive controls, segmentation, hardening and access management.

Contain

Detection through the SOC, monitoring and incident response.

Recover

Business continuity, disaster recovery and post-incident learning.

Evolve

Continuous improvement and adaptive, measurable resilience.

Audit scope

What our CSCRF cyber audit covers.

Full coverage of the control domains CSCRF examines — 100% of critical systems and a sample of non-critical systems.

Governance & IT Committee

Board-approved policy, CISO function and an IT Committee with an external cyber expert.

Cyber Risk Management

Identification, evaluation, prioritisation and monitoring of cyber risks.

SOC, Monitoring & SIEM

24×7 security operations, log retention and the functional efficacy of the SOC.

Access & Identity Management

Least privilege, privileged-access control and segregation of duties.

Network & Endpoint Security

Segmentation, hardening and endpoint protection across the estate.

Application & API Security

Secure development and API controls — rate limiting, throttling, authentication and authorization.

Data Classification & Localization

Classification, encryption and data-localization of sensitive market data.

SBOM & Supply Chain

Software Bill of Materials and supply-chain risk across software components.

VAPT

Vulnerability assessment and penetration testing in SEBI's standardized formats.

Incident Response & SEBI Reporting

Incident handling and immediate reporting via the dedicated SEBI portal and to CERT-In.

Business Continuity & DR

BCP and disaster recovery with defined RTO/RPO and tested drills.

CCI & Resilience Testing

Cyber Capability Index measurement and scenario-based resilience and red-team testing.

How we work

An audit scoped to your CSCRF category.

A compliance-first lifecycle that produces SEBI's standardized reports.

Classification & scoping

We confirm your CSCRF category and the obligations and audit cadence that apply to you.

Governance & documentation review

Policy, IT Committee, CISO, SOC arrangements and prior audit reports and declarations.

Control assessment

Testing across the five resilience goals — 100% of critical systems and 25% of non-critical, sampled.

VAPT & resilience testing

VAPT in SEBI formats, plus red-teaming and CCI assessment for MIIs and Qualified REs.

Reporting & declaration

Findings risk-rated in CSCRF formats, with support for the MD/CEO declaration and board presentation.

Closure & follow-on audit

Remediation within three months and a follow-on audit within six months to verify closure.

Checklists

CSCRF audit readiness checklists.

The first gets you ready for the engagement; the second is the control checklist we assess, grouped by CSCRF's five goals.

Pre-audit readiness checklist

CSCRF category determined for the financial year (prior-year data)
Board-approved cybersecurity & cyber resilience policy, current
IT Committee constituted with an external cyber expert (where applicable)
CISO appointed (MII/Qualified) or senior officer designated
SOC onboarded (own / group / Market-SOC / managed) and operational
ISO 27001 certification in place or planned (MII/Qualified)
Cyber risk management framework documented
Latest VAPT reports and vulnerability-closure status
Data classification, localization and SBOM maintained
Incident register and SEBI-portal / CERT-In reporting records
Prior cyber audit report, MD/CEO declaration and closure evidence
BCP / DR plan and latest DR-drill evidence

Control checklist — by resilience goal

Anticipate

Threat intelligence and periodic cyber-risk assessment
Asset inventory and data classification
SBOM and supply-chain register

Withstand

Access control, segmentation and hardening
API and endpoint security controls
ISO 27001 controls (MII / Qualified)

Contain

SOC / SIEM detection and 24×7 monitoring
Incident response plan and runbooks
Reporting via the SEBI portal and to CERT-In

Recover & Evolve

BCP / DR with tested RTO / RPO
Post-incident lessons learned
CCI monitoring and red teaming (MII / Qualified)
What you receive

Documentation in SEBI's standardized formats.

  • CSCRF cyber audit reportIn the standardized format, with risk ratings and recommendations.
  • VAPT reportVulnerability findings in SEBI's prescribed VAPT format.
  • MD/CEO declaration supportDocumentation to accompany your compliance submission.
  • Compliance mappingYour posture mapped to CSCRF standards and the five resilience goals.
  • CCI assessmentCyber Capability Index measurement for MIIs and Qualified REs.
  • Remediation tracker & follow-on auditClosure within three months and verification within six.

Frameworks & references

Your audit is mapped to CSCRF and the standards it draws on.

SEBI CSCRF 2024ISO 27001NIST SP 800-53CIS v8 CERT-InCyber Capability IndexVAPT formats
FAQ

SEBI CSCRF audit — frequently asked questions

What is a SEBI CSCRF cyber audit?
It's an independent audit of a SEBI regulated entity's cybersecurity and cyber resilience controls against the CSCRF, covering 100% of critical systems and a sample of non-critical systems, framed around the five resilience goals — and producing the cyber audit and VAPT reports in SEBI's standardized formats.
Which entities must comply with CSCRF?
All SEBI regulated entities — stock exchanges, clearing corporations and depositories (MIIs), stock brokers, depository participants, mutual funds and AMCs, KRAs, RTAs, custodians, investment advisers, research analysts, portfolio managers, AIFs, merchant bankers and credit rating agencies, among others. A few categories such as FPIs, FVCIs, individual investment advisers, LPCC, QDPs, vault managers, RTAs servicing under 10,000 folios, REITs and InvITs are excluded.
What are the five CSCRF categories?
Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. Obligations scale up by category, with MIIs carrying the highest bar.
How is my category determined?
Your category is fixed at the start of each financial year based on the previous year's data — such as AUM, client base or trading volume — and you remain in it for the whole year. If you are registered in multiple capacities, the highest applicable category applies.
How often is the cyber audit required?
MIIs and Qualified REs undergo a cyber audit at least twice a year, as do Mid-size and Small-size REs that provide internet-based trading or algo-trading facilities. Other Mid-size and Small-size REs undergo it at least once a year. Self-certification REs are required to conduct VAPT through a CERT-In empanelled organisation and submit a self-certification.
Do we need a CERT-In empanelled auditor?
Yes. CSCRF cyber audits must be conducted by a CERT-In empanelled auditing organization, with auditors holding recognised certifications and relevant BFSI IT-audit experience. We meet those requirements as a CERT-In empanelled firm.
What are the reporting and closure timelines?
The audit report, with an MD/CEO declaration, is submitted within one month of completion; findings are closed within three months; and a follow-on audit to verify closure is completed within six months. Findings still open after six months require IT Committee approval.
Do MIIs and Qualified REs have extra obligations?
Yes. In addition to the cyber audit, they must obtain ISO 27001 certification, operate a SOC (in-house for MIIs), appoint a CISO, use the Cyber Capability Index, and conduct red-teaming exercises.
What is the Cyber Capability Index (CCI)?
The CCI is a structured index that MIIs and Qualified REs use to periodically measure and monitor their cyber resilience. We assess and report your CCI as part of the engagement where it applies.
How long does a CSCRF audit take, and can you help with closure?
Most engagements run three to six weeks depending on your category and systems in scope. Beyond the audit we provide remediation support, the follow-on audit to verify closure, and standardized reporting to your respective authority — SEBI for MIIs, the stock exchange or depository for brokers and DPs.
Related services

Continue exploring

Ready for your CSCRF audit?

Talk to our CERT-In empanelled team about a cyber audit scoped precisely to your CSCRF category.