India

SEBI CSCRF

SEBI Cybersecurity and Cyber Resilience Framework

Cybersecurity and cyber-resilience for India's securities-market entities.

Map your SEBI CSCRF evidence →All frameworks

Issuer

SEBI

Region

India

Version

CSCRF, 2024

Applies to

Exchanges, depositories, AMCs, brokers

Overview

What is SEBI CSCRF?

The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF, 2024) standardises cyber security across SEBI Regulated Entities. It is organised around the cyber-resilience goals — anticipate, withstand, contain, recover and evolve — and the security functions of govern, identify, protect, detect, respond and recover.

It brings sharper, market-specific expectations: a Security Operations Centre (including a Market SOC option for smaller entities), periodic VAPT and cyber audit, ISO 27001 for Market Infrastructure Institutions, a Software Bill of Materials for critical systems, and incident reporting to SEBI and CERT-In.

Who needs it: SEBI Regulated Entities — stock exchanges, clearing corporations, depositories, asset-management companies / mutual funds, stock brokers, KRAs and registrars / transfer agents.

Inside the framework

What it covers

1

Governance & resilience

Board-approved policy, a designated officer, and the five cyber-resilience goals.

2

Identify & protect

Asset inventory, risk assessment, access control, encryption and secure configuration.

3

Detect

A Security Operations Centre, logging, and periodic VAPT.

4

Respond & recover

Incident response, reporting to SEBI / CERT-In, BCP/DR and drills.

5

Evolve & assure

Cyber audit, ISO 27001 for MIIs, and SBOM for critical systems.

With RegShield

Get SEBI CSCRF-ready in a fraction of the time

AI evidence mapping

Upload a policy, screenshot, or config and RegShield maps it to the right SEBI CSCRF controls in seconds — with confidence scores you can defend in front of an auditor.

Reuse across frameworks

Evidence you collect for SEBI CSCRF is automatically reused across every other framework you've activated — so the work compounds instead of repeating.

Gaps & audit-ready reports

See your SEBI CSCRF readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.

FAQ

Common questions

Who must comply with CSCRF?

SEBI Regulated Entities — exchanges, depositories, clearing corporations, AMCs/mutual funds, brokers, KRAs and RTAs. Requirements are graded by entity category.

What's the Market SOC?

CSCRF lets smaller entities meet the Security Operations Centre requirement via a shared Market SOC rather than building their own. RegShield tracks the SOC arrangement as evidence either way.

How does RegShield help?

It maps your evidence to the CSCRF functions, scores readiness, and flags gaps — reusing your SOC 2 / ISO 27001 work. It's a readiness tool; the cyber audit and SEBI filings are yours to complete.

Make compliance
disappear.

Twenty-minute demo. Bring a policy document. We'll map it live.

Book a demo →info@regshield.in