SEBI CSCRF Practitioner Certification
The Cyber Capability Index, the M-SOC decision, the auditor evidence pack, and the board deck
A citation-anchored, exam-backed practitioner course on the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), master circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, read alongside all subsequent SEBI instruments through August 2026: the December 2024 PR.DS.S2 abeyance, 28 March 2025 first extension, 30 April 2025 clarifications, 11 June 2025 FAQ (76 questions in 17 sections), 30 June 2025 second extension, and 28 August 2025 Technical Clarifications (introducing the Principle of Exclusivity and Principle of Equivalence, making ISO 27001 voluntary, reaffirming the 2-hour RTO and 15-minute RPO), and the 5 May 2026 SEBI Advisory on AI-assisted vulnerability detection, M-SOC onboarding acceleration and SBOM / asset-inventory upkeep (advisory not mandatory, but material to the M-SOC, VAPT and CCI teaching in this course). Built for the senior CISO, DPO, Head of IT Risk or Head of Cyber Compliance at a SEBI Regulated Entity. Assumes a working infosec background. Every module ships with practitioner artefacts: the 23-parameter CCI methodology walkthrough, the M-SOC vs Market SOC decision matrix, the CERT-In empanelled auditor evidence pack, the 6-hour incident report template that satisfies SEBI and CERT-In in one artefact, the cross-regulator crosswalk (CSCRF ↔ CERT-In ↔ RBI ↔ DPDP ↔ NCIIPC), and category-specific playbooks for MII vs Qualified RE vs Mid-size vs Small-size vs Self-Certification REs.
What you will learn
- Read the 7-instrument CSCRF document stack (20 Aug 2024 → 28 Aug 2025) as a single coherent regime
- Score, submit and defend a Cyber Capability Index submission for a MII or Qualified RE
- Design a Board Technology Committee governance rhythm that meets CSCRF cadence and satisfies IT Committee scrutiny
- Decide between in-house SOC, M-SOC, and Market SOC using cost, scope and vendor benchmarks
- Scope a CSCRF-compliant VAPT engagement, evaluate CERT-In empanelled auditors, and manage remediation to the 3-month cap
- Fire a 6-hour incident notification to SEBI and CERT-In in parallel from a single incident record
- Design a cloud architecture that satisfies MeitY empanelment, STQC audit, and CSCRF residency expectations
- Apply the Principle of Exclusivity and Principle of Equivalence to reduce duplicate audit effort across multiple financial-sector regulators
- Run a category-specific implementation playbook for MII, Qualified RE, Mid-size, Small-size or Self-Certification RE
- Prepare a board deck the IT Committee will approve without amendments
Prerequisites
- Working experience as a CISO, Head of Cyber, Head of IT Risk, senior privacy or compliance lead — 8+ years in an information security context recommended
- Familiarity with cyber security frameworks (NIST CSF 2.0 or ISO 27001) or completion of the NISM Cyber Security e-module as pre-reading
- Working knowledge of the CERT-In Directions 2022 and DPDP Rules 2025 (both are covered as free or paid courses on dcomply Academy)
Who this is for
- Chief Information Security Officers at Market Infrastructure Institutions (NSE, BSE, NSDL, CDSL, clearing corporations)
- CISOs at Qualified REs: large brokers (Angel One, Zerodha, Groww, HDFC Securities, ICICI Securities), QRTAs (KFin, CAMS), KRAs, large mutual funds, large custodians
- Heads of Cyber Compliance / IT Risk at mid-size REs: mutual funds, PMS, portfolio managers, investment advisers, research analysts
- CERT-In empanelled auditors and their teams engaging SEBI REs
- Big 4 and MSSP consultants working on SEBI RE cyber compliance mandates
- DPOs at SEBI REs who need to reconcile the DPDP and CSCRF regimes for the same entity
- Board members serving on IT Committees of SEBI REs
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 28 lessons. Click any module to expand.
The seven SEBI instruments that together define CSCRF as it stands on your desk today. The 5 resilience goals mapped to 6 NIST CSF 2.0 functions. Five-tier RE categorisation from MII through Self-Certification.
The SEBI RE ecosystem map that tells you exactly which of the 4,900 registered brokers, 300 depository participants and 45 AMCs your entity sits with. Free preview so senior buyers can validate depth before purchasing.
The single most under-taught part of CSCRF. Every vendor mentions CCI exists; nobody walks the 23-parameter methodology, the six maturity bands, the MII half-yearly third-party assessment cadence, the Qualified RE annual self-assessment cadence, the 15-day submission window, or how REs game CCI and how SEBI is countering that. This module ships the CCI Calculator spreadsheet as course collateral.
- 1. What the CCI is and why SEBI cares 10 min
- 2. The 23 CCI parameters and their weightages 12 min
- 3. The submission workflow and the 15-day rule 9 min
- 4. How REs game CCI and what SEBI is doing about it 9 min
The CISO role as CSCRF defines it, and what the Indian market actually pays. Reporting line rules that prevent the CISO from sitting under the CTO. Board Technology Committee cadence for MIIs and Qualified REs.
Cyber Crisis Management Plan design. Certifications that move the CISO shortlist (CISM + CISSP + ISO 27001 LA). Salary bands from ₹35 lakh (mid) through ₹3.5 crore (MII Group CISO).
- 1. The CISO mandate under CSCRF 9 min
- 2. The Board Technology Committee cadence 8 min
- 3. Cyber Crisis Management Plan and drills 8 min
- 4. CISO career: salary bands, certifications, career map 10 min
The single most consequential architecture decision under CSCRF. In-house 24×7 SOC at ₹3-8 crore/year vs Managed SOC at ₹40 lakh-₹2 crore/year vs Market SOC operated by BSE (Blue Sapphire) and NSE (Aujas). Named M-SOC vendors serving SEBI REs (Aujas, Sequretek, TCS, Wipro, IBM, LTIMindtree, K7, SISA, SecurityHQ).
SIEM stack choices from Splunk Enterprise Security through Wazuh. The 10 contract clauses to negotiate with your M-SOC provider.
- 1. The three approved SOC architectures 9 min
- 2. Cost economics: in-house vs M-SOC 9 min
- 3. M-SOC vendor selection and contract 10 min
- 4. SIEM stack selection 9 min
Audit cadence by RE class (twice a year for MII/Qualified/IBT-Algo, once a year for others, self-cert exempt). 100% critical + 25% non-critical scope rule. VAPT scope across web, mobile, infrastructure, APIs, cloud and third-party integrations.
Cost bands from ₹8 lakh (SME broker) through ₹2 crore (MII). 3-month remediation cap. 6-month revalidation.
Named CERT-In empanelled auditors. Sample RFP. Auditor evidence pack you can adapt.
- 1. Cyber audit cadence and scope 8 min
- 2. VAPT scope and cost bands 9 min
- 3. Named CERT-In empanelled auditors and how to evaluate them 9 min
- 4. Managing findings to closure and the NSE Inspection ATR 8 min
The 6-hour SEBI + CERT-In dual clock and the incident report template that satisfies both regulators from one incident record. Cloud framework: MeitY-empanelled CSP requirement plus STQC audit plus Indian data residency. Status of PR.DS.S2 data-localisation control (in abeyance since December 2024).
RTO 2 hours / RPO 15 minutes for critical operations. SEBI Interoperability Framework (live 1 April 2025): 75-min intimation + 15-min alt-venue invoke. Real case studies: Angel One February 2025 AWS breach (₹8 million users, stock -11%), NSE February 2021 outage (₹72.64 crore settlement).
- 1. The 6-hour dual clock: SEBI and CERT-In 9 min
- 2. Cloud, MeitY empanelment, and data residency 8 min
- 3. RTO 2 hours, RPO 15 minutes, and the interoperability framework 8 min
- 4. Real incident case studies at SEBI REs 10 min
The Principle of Exclusivity and Principle of Equivalence from the 28 August 2025 Technical Clarifications, and how to use them to reduce duplicate audit effort across multiple financial-sector regulators. Single-view crosswalk of CSCRF ↔ CERT-In Directions 2022 ↔ RBI IT Framework and PDS Direction 2018 ↔ DPDP Rules 2025 ↔ NCIIPC Protected Systems. Category-specific playbooks: Broker vs AMC vs KRA vs Depository vs MII.
SBOM obligation. The board deck template a CISO can adapt for the next quarterly IT Committee.
- 1. The Principle of Exclusivity and the Principle of Equivalence 9 min
- 2. The single-view cross-regulator crosswalk 9 min
- 3. Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII 10 min
- 4. SBOM and the quarterly board deck template 8 min
Final certification exam covering all seven content modules. Every question is anchored to a specific SEBI circular clause, FAQ answer, sectoral overlay or case study cited in the course. Randomised order, shuffled options, explanations shown after each question and cite the source.
Lessons coming soon.
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme aimed at senior CISO, DPO, Head of IT Risk and Head of Cyber Compliance roles at SEBI Regulated Entities. Every substantive claim is anchored to a primary SEBI circular, SEBI FAQ, sectoral regulator instrument or public disclosure. As of August 2026 several items require ongoing verification: the exact list of 23 CCI parameters and weightages (Annexure K of the master circular is not machine-readable and needs manual transcription), the exact SEBI circular number that placed control PR.DS.S2 in abeyance, and any enforcement orders SEBI has issued against named REs under CSCRF since September 2025. The course flags each of these forward-looking items in the lesson where they appear and maintains a 16-item manual-verification checklist.
This is not legal advice and does not create a lawyer-client relationship. For specific compliance decisions, consult a qualified securities and technology lawyer or a CERT-In empanelled information security auditor.
SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications); SEBI Circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 (5 May 2026 AI Vulnerability Detection Advisory, advisory not mandatory; supplements the M-SOC, VAPT, SBOM and Cyber Capability Index teaching with AI-assisted detection guidance). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.