Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · SEBI CSCRF

SEBI CSCRF compliance support

CSCRF brings SEBI's earlier cyber security circulars into a single framework for SEBI-regulated entities (REs). It is built around standard cyber security functions — governance, identification, protection, detection, response and recovery — and sets expectations for cyber resilience, not only compliance.

Overview

In plain English

Obligations are graded by category. Larger and more critical entities face more requirements, while smaller entities have a lighter, proportionate set. Knowing your category is the first step.

Instruments covered

  • SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities — circular dated 20 August 2024, with subsequent clarifications

Last reviewed:

Key requirements

What SEBI CSCRF expects

  1. Governance

    Board-approved cyber security and cyber resilience policy, defined roles and oversight proportionate to your category.

  2. Asset identification and risk assessment

    Inventory of critical systems and data, with risk assessment of those assets.

  3. Protection controls

    Access control, data security, network security, patch and configuration management.

  4. Security monitoring

    Log collection and monitoring through a security operations centre, which may be own, third-party or market SOC depending on category.

  5. VAPT

    Periodic vulnerability assessment and penetration testing, with remediation tracked and reported.

  6. Cyber audit

    Periodic cyber audit and reporting of compliance to SEBI as specified for your category.

  7. Cyber Capability Index

    MIIs and Qualified REs measure their cyber resilience maturity using the Cyber Capability Index.

  8. Incident response and reporting

    A response and recovery plan, and reporting of cyber incidents to SEBI and CERT-In within prescribed timelines.

How TrustNet helps

From gap to evidence

  • Category check to confirm which obligations apply
  • Gap assessment against CSCRF requirements
  • VAPT on the cadence your category requires
  • Audit reporting and evidence preparation
  • SOC and log retention support
  • Policy and incident response plan drafting

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to SEBI CSCRF

FAQ

SEBI CSCRF FAQ

How do we know our CSCRF category?

Categories depend on entity type and thresholds defined by SEBI. We help you confirm your category and map the obligations that follow.

Do small brokers need a SOC?

Security monitoring is expected across categories, but the form differs. Smaller entities may use a market SOC or third-party SOC. We help you choose what fits.

Who can conduct the CSCRF cyber audit?

SEBI specifies auditor requirements, such as CERT-In empanelment for certain audits. We tell you clearly what we deliver and where a qualified auditor signs.

Book a consultation

Get SEBI CSCRF-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us