SEBI CSCRF· Certification & compliance guide
SEBI CSCRF Cyber Resilience Compliance Guide
Cybersecurity & cyber resilience for capital market entities
What is SEBI CSCRF?
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) sets expectations for regulated entities in Indian capital markets — covering governance, identification, protection, detection, response, recovery, and shared responsibilities including third-party and cloud risk.
Who needs SEBI CSCRF certification or compliance?
SEBI-regulated entities — brokers, depositories, mutual funds, portfolio managers, and market infrastructure institutions — plus their critical technology vendors subject to CSCRF-aligned due diligence.
Key requirements & topics
- Cyber governance and board oversight
- Asset inventory and vulnerability management
- Security monitoring and SOC operations
- Incident response and recovery testing
- Third-party and cloud service provider risk
- Periodic audit and SEBI reporting
How to get SEBI CSCRF ready — step by step
- Gap assess against CSCRF domains and SEBI circulars
- Establish cyber governance and RACI
- Implement monitoring, vulnerability, and access controls
- Run tabletop exercises and recovery tests
- Assess third-party vendors with TPRM workflows
- Prepare evidence for SEBI inspection and internal audit
Typical timeline
CSCRF compliance is ongoing with periodic SEBI review. Most entities plan 6–12 months for initial program maturation depending on starting security posture.
How ComplAI helps with SEBI CSCRF
Related compliance guides
Deep control mapping and implementation detail: SEBI CSCRF help center guide. Canonical URL: https://propelreadysolutions.in/resources/sebi-cscrf
