Live Founding Cohort open, limited seats remaining Back to main site →
Cybersecurity

SEBI CSCRF Practitioner Certification

The Cyber Capability Index, the M-SOC decision, the auditor evidence pack, and the board deck

₹9,999 Advanced 5.5 hours 8 modules Founding Cohort: 836 seats left
Founding Cohort, DPDP Class of 2026. The first 1,000 learners to pass the final exam receive a permanent "Founding #N" badge on their certificate. 836 seats remaining.
8
Modules
28
Lessons
40
Exam questions
75%
Pass mark

A citation-anchored, exam-backed practitioner course on the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), master circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, read alongside all subsequent SEBI instruments through August 2026: the December 2024 PR.DS.S2 abeyance, 28 March 2025 first extension, 30 April 2025 clarifications, 11 June 2025 FAQ (76 questions in 17 sections), 30 June 2025 second extension, and 28 August 2025 Technical Clarifications (introducing the Principle of Exclusivity and Principle of Equivalence, making ISO 27001 voluntary, reaffirming the 2-hour RTO and 15-minute RPO), and the 5 May 2026 SEBI Advisory on AI-assisted vulnerability detection, M-SOC onboarding acceleration and SBOM / asset-inventory upkeep (advisory not mandatory, but material to the M-SOC, VAPT and CCI teaching in this course). Built for the senior CISO, DPO, Head of IT Risk or Head of Cyber Compliance at a SEBI Regulated Entity. Assumes a working infosec background. Every module ships with practitioner artefacts: the 23-parameter CCI methodology walkthrough, the M-SOC vs Market SOC decision matrix, the CERT-In empanelled auditor evidence pack, the 6-hour incident report template that satisfies SEBI and CERT-In in one artefact, the cross-regulator crosswalk (CSCRF ↔ CERT-In ↔ RBI ↔ DPDP ↔ NCIIPC), and category-specific playbooks for MII vs Qualified RE vs Mid-size vs Small-size vs Self-Certification REs.

What you will learn
  • Read the 7-instrument CSCRF document stack (20 Aug 2024 → 28 Aug 2025) as a single coherent regime
  • Score, submit and defend a Cyber Capability Index submission for a MII or Qualified RE
  • Design a Board Technology Committee governance rhythm that meets CSCRF cadence and satisfies IT Committee scrutiny
  • Decide between in-house SOC, M-SOC, and Market SOC using cost, scope and vendor benchmarks
  • Scope a CSCRF-compliant VAPT engagement, evaluate CERT-In empanelled auditors, and manage remediation to the 3-month cap
  • Fire a 6-hour incident notification to SEBI and CERT-In in parallel from a single incident record
  • Design a cloud architecture that satisfies MeitY empanelment, STQC audit, and CSCRF residency expectations
  • Apply the Principle of Exclusivity and Principle of Equivalence to reduce duplicate audit effort across multiple financial-sector regulators
  • Run a category-specific implementation playbook for MII, Qualified RE, Mid-size, Small-size or Self-Certification RE
  • Prepare a board deck the IT Committee will approve without amendments
Prerequisites
  • Working experience as a CISO, Head of Cyber, Head of IT Risk, senior privacy or compliance lead — 8+ years in an information security context recommended
  • Familiarity with cyber security frameworks (NIST CSF 2.0 or ISO 27001) or completion of the NISM Cyber Security e-module as pre-reading
  • Working knowledge of the CERT-In Directions 2022 and DPDP Rules 2025 (both are covered as free or paid courses on dcomply Academy)
Who this is for
  • Chief Information Security Officers at Market Infrastructure Institutions (NSE, BSE, NSDL, CDSL, clearing corporations)
  • CISOs at Qualified REs: large brokers (Angel One, Zerodha, Groww, HDFC Securities, ICICI Securities), QRTAs (KFin, CAMS), KRAs, large mutual funds, large custodians
  • Heads of Cyber Compliance / IT Risk at mid-size REs: mutual funds, PMS, portfolio managers, investment advisers, research analysts
  • CERT-In empanelled auditors and their teams engaging SEBI REs
  • Big 4 and MSSP consultants working on SEBI RE cyber compliance mandates
  • DPOs at SEBI REs who need to reconcile the DPDP and CSCRF regimes for the same entity
  • Board members serving on IT Committees of SEBI REs
About the author
dA
dcomply Academy
Course authored by the dcomply Cyber Practice

This course is authored institutionally by the dcomply Cyber Practice. It is built for the senior CISO, DPO, Head of IT Risk or Head of Cyber Compliance at a SEBI Regulated Entity. It assumes 8+ years of infosec background and skips foundational material that a shortlisted CISO would already know. Every claim is anchored to a primary source (SEBI circular, FAQ, sectoral overlay, or public disclosure).

The 16-item manual-verification checklist inside the course flags every forward-looking item (Annexure K parameter list, enforcement orders, upcoming abeyance reactivations) that a serving CISO should re-check against the SEBI legal repository before acting.

No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 75%.
Curriculum

Syllabus

8 modules, 28 lessons. Click any module to expand.

The seven SEBI instruments that together define CSCRF as it stands on your desk today. The 5 resilience goals mapped to 6 NIST CSF 2.0 functions. Five-tier RE categorisation from MII through Self-Certification.

The SEBI RE ecosystem map that tells you exactly which of the 4,900 registered brokers, 300 depository participants and 45 AMCs your entity sits with. Free preview so senior buyers can validate depth before purchasing.

  1. 1. The seven-instrument CSCRF document stack 10 min
  2. 2. The framework shape: five goals, six NIST CSF 2.0 functions 8 min
  3. 3. RE categorisation: five tiers and the post-April 2025 shuffle 10 min
  4. 4. The SEBI RE ecosystem map 8 min

The single most under-taught part of CSCRF. Every vendor mentions CCI exists; nobody walks the 23-parameter methodology, the six maturity bands, the MII half-yearly third-party assessment cadence, the Qualified RE annual self-assessment cadence, the 15-day submission window, or how REs game CCI and how SEBI is countering that. This module ships the CCI Calculator spreadsheet as course collateral.

  1. 1. What the CCI is and why SEBI cares 10 min
  2. 2. The 23 CCI parameters and their weightages 12 min
  3. 3. The submission workflow and the 15-day rule 9 min
  4. 4. How REs game CCI and what SEBI is doing about it 9 min

The CISO role as CSCRF defines it, and what the Indian market actually pays. Reporting line rules that prevent the CISO from sitting under the CTO. Board Technology Committee cadence for MIIs and Qualified REs.

Cyber Crisis Management Plan design. Certifications that move the CISO shortlist (CISM + CISSP + ISO 27001 LA). Salary bands from ₹35 lakh (mid) through ₹3.5 crore (MII Group CISO).

  1. 1. The CISO mandate under CSCRF 9 min
  2. 2. The Board Technology Committee cadence 8 min
  3. 3. Cyber Crisis Management Plan and drills 8 min
  4. 4. CISO career: salary bands, certifications, career map 10 min

The single most consequential architecture decision under CSCRF. In-house 24×7 SOC at ₹3-8 crore/year vs Managed SOC at ₹40 lakh-₹2 crore/year vs Market SOC operated by BSE (Blue Sapphire) and NSE (Aujas). Named M-SOC vendors serving SEBI REs (Aujas, Sequretek, TCS, Wipro, IBM, LTIMindtree, K7, SISA, SecurityHQ).

SIEM stack choices from Splunk Enterprise Security through Wazuh. The 10 contract clauses to negotiate with your M-SOC provider.

  1. 1. The three approved SOC architectures 9 min
  2. 2. Cost economics: in-house vs M-SOC 9 min
  3. 3. M-SOC vendor selection and contract 10 min
  4. 4. SIEM stack selection 9 min

Audit cadence by RE class (twice a year for MII/Qualified/IBT-Algo, once a year for others, self-cert exempt). 100% critical + 25% non-critical scope rule. VAPT scope across web, mobile, infrastructure, APIs, cloud and third-party integrations.

Cost bands from ₹8 lakh (SME broker) through ₹2 crore (MII). 3-month remediation cap. 6-month revalidation.

Named CERT-In empanelled auditors. Sample RFP. Auditor evidence pack you can adapt.

  1. 1. Cyber audit cadence and scope 8 min
  2. 2. VAPT scope and cost bands 9 min
  3. 3. Named CERT-In empanelled auditors and how to evaluate them 9 min
  4. 4. Managing findings to closure and the NSE Inspection ATR 8 min

The 6-hour SEBI + CERT-In dual clock and the incident report template that satisfies both regulators from one incident record. Cloud framework: MeitY-empanelled CSP requirement plus STQC audit plus Indian data residency. Status of PR.DS.S2 data-localisation control (in abeyance since December 2024).

RTO 2 hours / RPO 15 minutes for critical operations. SEBI Interoperability Framework (live 1 April 2025): 75-min intimation + 15-min alt-venue invoke. Real case studies: Angel One February 2025 AWS breach (₹8 million users, stock -11%), NSE February 2021 outage (₹72.64 crore settlement).

  1. 1. The 6-hour dual clock: SEBI and CERT-In 9 min
  2. 2. Cloud, MeitY empanelment, and data residency 8 min
  3. 3. RTO 2 hours, RPO 15 minutes, and the interoperability framework 8 min
  4. 4. Real incident case studies at SEBI REs 10 min

The Principle of Exclusivity and Principle of Equivalence from the 28 August 2025 Technical Clarifications, and how to use them to reduce duplicate audit effort across multiple financial-sector regulators. Single-view crosswalk of CSCRF ↔ CERT-In Directions 2022 ↔ RBI IT Framework and PDS Direction 2018 ↔ DPDP Rules 2025 ↔ NCIIPC Protected Systems. Category-specific playbooks: Broker vs AMC vs KRA vs Depository vs MII.

SBOM obligation. The board deck template a CISO can adapt for the next quarterly IT Committee.

  1. 1. The Principle of Exclusivity and the Principle of Equivalence 9 min
  2. 2. The single-view cross-regulator crosswalk 9 min
  3. 3. Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII 10 min
  4. 4. SBOM and the quarterly board deck template 8 min

Final certification exam covering all seven content modules. Every question is anchored to a specific SEBI circular clause, FAQ answer, sectoral overlay or case study cited in the course. Randomised order, shuffled options, explanations shown after each question and cite the source.

Lessons coming soon.

Frequently Asked

Everything a buyer usually asks

Who is this course for?
Chief Information Security Officers at Market Infrastructure Institutions (NSE, BSE, NSDL, CDSL, clearing corporations) Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 8 modules covering 28 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 75% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹9,999 founding-cohort price (list price ₹24,999) One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme aimed at senior CISO, DPO, Head of IT Risk and Head of Cyber Compliance roles at SEBI Regulated Entities. Every substantive claim is anchored to a primary SEBI circular, SEBI FAQ, sectoral regulator instrument or public disclosure. As of August 2026 several items require ongoing verification: the exact list of 23 CCI parameters and weightages (Annexure K of the master circular is not machine-readable and needs manual transcription), the exact SEBI circular number that placed control PR.DS.S2 in abeyance, and any enforcement orders SEBI has issued against named REs under CSCRF since September 2025. The course flags each of these forward-looking items in the lesson where they appear and maintains a 16-item manual-verification checklist.

This is not legal advice and does not create a lawyer-client relationship. For specific compliance decisions, consult a qualified securities and technology lawyer or a CERT-In empanelled information security auditor.