India Regulatory Hub
SEBISEBI Act 1992 · CSCRF Circular Aug 2024 · est. 1992 · Capital Markets · MIIs · Intermediaries

Securities and Exchange Board of India

The Cybersecurity & Cyber Resilience Framework (CSCRF) — a tiered standard for every market participant.

Regulated entities
MIIs, QRTAs, RE-T1, RE-T2/T3
Key circular
CSCRF — SEBI/HO/ITD-PoD-2/P/CIR/2023/193 (Aug 2024)
Recent enforcement
Adjudication under SEBI Act §15 — active 2024-25
Next key deadline
CCI submission — 30 September
Layer 0 — Framework overview · free

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued in August 2024, is the single consolidated cyber standard for India's capital markets. It supersedes every earlier SEBI cybersecurity circular and is organised around five NIST-style functions — Governance, Identify, Protect, Detect, Respond and Recover — applied through a tiered compliance model.

The four tiers are: Market Infrastructure Institutions (MIIs — exchanges, clearing corporations, depositories), Qualified Registrars to an Issue and Share Transfer Agents (QRTAs), larger intermediaries (RE-T1) and smaller intermediaries (RE-T2/T3). Obligations scale by tier: MIIs face quarterly VAPT, 24x7 SOCs and twice-yearly DR drills; smaller intermediaries may use shared SOCs and annual cycles.

Signature CSCRF mechanisms include the Cyber Capability Index (CCI) — an annual self-assessment maturity score submitted to SEBI — mandatory CISO appointments with board reporting lines, board-level cybersecurity committees, and 6-hour incident reporting to SEBI's Cybercell run in parallel with CERT-In.

Enforcement flows through SEBI's adjudication machinery under the SEBI Act: monetary penalties, directions, suspension of activities and — for repeat offenders — cancellation of registration. Because most SEBI REs are also Data Fiduciaries under the DPDP Act, a single investor-data breach can now trigger SEBI, CERT-In and Data Protection Board proceedings simultaneously.

Work through the layers below to map your tier, your control gaps, your filing calendar and your penalty exposure.

Primary sources: SEBI Circular SEBI/HO/ITD-PoD-2/P/CIR/2023/193, August 20, 2024 — Cybersecurity and Cyber Resilience Framework (CSCRF). Supersedes all earlier SEBI cybersecurity circulars and introduces a tiered compliance model for four Regulated Entity (RE) categories.

The deep-dive layers

Version history
Last verified: 2026-06-17
VersionDateUpdated byWhat changed
v1.0June 2026Hemant SahayInitial publication — all 5 regulator pages (RBI, SEBI, IRDAI, CERT-In, DPDP), control catalogues, applicability matrices, calendars, penalties, cross-regulator content, 12 templates, 18 glossary terms

Made with Emergent