SEBI CSCRF
SEBI Cybersecurity and Cyber Resilience Framework
Cybersecurity and cyber-resilience for India's securities-market entities.
Issuer
SEBI
Region
India
Version
CSCRF, 2024
Applies to
Exchanges, depositories, AMCs, brokers
Overview
What is SEBI CSCRF?
The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF, 2024) standardises cyber security across SEBI Regulated Entities. It is organised around the cyber-resilience goals — anticipate, withstand, contain, recover and evolve — and the security functions of govern, identify, protect, detect, respond and recover.
It brings sharper, market-specific expectations: a Security Operations Centre (including a Market SOC option for smaller entities), periodic VAPT and cyber audit, ISO 27001 for Market Infrastructure Institutions, a Software Bill of Materials for critical systems, and incident reporting to SEBI and CERT-In.
Who needs it: SEBI Regulated Entities — stock exchanges, clearing corporations, depositories, asset-management companies / mutual funds, stock brokers, KRAs and registrars / transfer agents.
Inside the framework
What it covers
Governance & resilience
Board-approved policy, a designated officer, and the five cyber-resilience goals.
Identify & protect
Asset inventory, risk assessment, access control, encryption and secure configuration.
Detect
A Security Operations Centre, logging, and periodic VAPT.
Respond & recover
Incident response, reporting to SEBI / CERT-In, BCP/DR and drills.
Evolve & assure
Cyber audit, ISO 27001 for MIIs, and SBOM for critical systems.
With RegShield
Get SEBI CSCRF-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right SEBI CSCRF controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for SEBI CSCRF is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your SEBI CSCRF readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who must comply with CSCRF?
SEBI Regulated Entities — exchanges, depositories, clearing corporations, AMCs/mutual funds, brokers, KRAs and RTAs. Requirements are graded by entity category.
What's the Market SOC?
CSCRF lets smaller entities meet the Security Operations Centre requirement via a shared Market SOC rather than building their own. RegShield tracks the SOC arrangement as evidence either way.
How does RegShield help?
It maps your evidence to the CSCRF functions, scores readiness, and flags gaps — reusing your SOC 2 / ISO 27001 work. It's a readiness tool; the cyber audit and SEBI filings are yours to complete.