SEBI CSCRF 2024: A Compliance Roadmap for Stock Brokers and Market Infrastructure Institutions
SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) is not new, but the 2024 revision materially sharpened the obligations for stock brokers, depository participants, mutual funds, and Market Infrastructure Institutions (MIIs) including stock exchanges, clearing corporations, and depositories. SEBI issued the updated circular in August 2024 with staggered compliance timelines — and many firms are still deciphering what "qualified" VAPT means in practice, how often audits must happen, and what an auditor actually needs to deliver.
Who is covered: CSCRF entity categories
SEBI classifies regulated entities into five categories under CSCRF — Market Infrastructure Institutions (exchanges, clearing corporations, depositories), Qualified Stock Brokers (QSBs, i.e., the largest brokers by client count and trading volume), stock brokers, depository participants, and other SEBI-registered intermediaries. The obligations differ by category. MIIs face the most stringent requirements: 24x7 Security Operations Centre (SOC), a formally empanelled cyber audit, and annual comprehensive VAPT. QSBs must conduct at least bi-annual vulnerability assessments and annual penetration tests. Smaller stock brokers face lighter-touch but still mandatory annual assessments.
VAPT cadence and depth requirements
The framework is explicit that VAPT must be conducted by a CERT-In empanelled information security auditing organisation. SEBI does not accept self-assessments or reports from non-empanelled vendors. For MIIs, the scope must cover the entire trading platform, member-facing APIs, clearing systems, and the SOC infrastructure itself. For QSBs, the minimum scope is the client-facing trading application, back-office systems, and network perimeter. VAPT must include both vulnerability assessment (systematic enumeration of weaknesses) and penetration testing (attempted exploitation to validate impact). A scan report alone does not satisfy the framework.
The revised CSCRF also introduces a requirement for API security testing. Brokers and exchanges expose a significant attack surface through their trading APIs — REST and FIX gateway interfaces used by algorithmic traders, third-party fintech applications, and institutional clients. API authentication flaws, broken object-level authorisation (BOLA), and rate-limiting gaps are among the most common findings in exchange API assessments. These must be enumerated, exploited in a controlled manner, and reported with CVSS scores. Learn more about our approach to penetration testing and the full range of VAPT services we offer.
Audit documentation SEBI actually expects
A recurring pain point for compliance officers is audit report format. SEBI's examination teams, during inspection of MIIs and QSBs, look for specific evidence: a scoping statement signed by both the entity and the auditor, an asset register with IP ranges and application URLs tested, a findings register with severity classification (CVSS v3.1 or v4.0), evidence screenshots or proof-of-concept code, and a remediation plan with target dates. The final report must be issued on the auditing firm's letterhead, and the empanelment status of the firm must be current as at the date of audit.
Beyond the technical findings register, the framework asks for a cyber-resilience posture assessment — a structured evaluation of governance maturity, incident response readiness, and vendor risk management. This is not the same as a VAPT report; it is a broader narrative that feeds into the entity's cyber risk dashboard, which must now be submitted to SEBI's Market Surveillance division on a periodic basis.
Timelines and what happens if you miss them
The August 2024 circular set compliance timelines: MIIs were required to be compliant by January 2025; QSBs by April 2025; remaining intermediaries by July 2025. Firms that missed early milestones are now in the scrutiny window — SEBI's inspection calendar for FY2026 has already included CSCRF adherence as a review checkpoint. Non-compliance findings during SEBI inspections have resulted in administrative warnings, enhanced monitoring, and in repeated cases, monetary penalties under SEBI Act Section 15HB.
Integrating CSCRF into your security calendar
The most efficient way to manage CSCRF obligations is to treat the CERT-In empanelled VAPT as the anchor event in a security calendar. Schedule the audit window 90 days before the compliance cycle end date to allow time for remediation and retest. Supplement the annual pentest with quarterly vulnerability scans — ideally automated and integrated into your change management process so that new deployments trigger a scan before going live. The SOC obligation for MIIs requires that findings from vulnerability scans feed into the SIEM within a defined SLA; this creates a closed loop between the external audit and internal monitoring.
If your organisation needs to structure a CSCRF-aligned security programme, our team can help scope a CERT-In audit engagement that satisfies SEBI's requirements end to end. Talk to an expert to get a scoping call on the calendar.
Put this into action.
Book a 30-minute scoping call with a CERT-In empanelled security expert.
Talk to an ExpertMore articles
IRDAI Cyber Security Guidelines: What Annual IS Audits and VAPT Mean for Insurers
IRDAI IS audit and VAPT obligations for insurers explained: annual audit scope, CERT-In empanelment, DPDP Act implications, and what regulators examine.
May 12, 2026What CERT-In Empanelment Means for Your Security Audit
CERT-In empanelment explained: what it is, why it matters for RBI/SEBI/IRDAI regulated entities, Safe-to-Host certificates, and what to expect from a compliant audit.
May 5, 2026Cloud Penetration Testing: What It Actually Covers Across AWS, Azure, and GCP
Cloud pentest vs config review: IAM escalation paths, exposed services, SSRF-to-metadata attacks, and CIS Benchmark limitations across AWS, Azure, and GCP.
