Live Founding Cohort open, limited seats remaining Back to main site →

RE categorisation: five tiers and the post-April 2025 shuffle

Every obligation in CSCRF depends on which of the five categories your entity sits in. Get the categorisation wrong and every subsequent decision is misaligned. This lesson tells you exactly how to categorise your entity and where the April 2025 clarifications moved the boundaries.

Free preview 10 min read Verified
Legal basis
SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.

CSCRF is a scaled framework. What a MII must do is not what a mid-size mutual fund must do. The five-tier categorisation is therefore the single most consequential decision under CSCRF. Get it right and you have a proportionate compliance programme. Get it wrong and you either over-invest by ten times or under-invest and get flagged in your next SEBI inspection.

The five tiers

TierWhoCCI required?Audit cadence
MIIStock exchanges (NSE, BSE), clearing corporations (NCL, ICCL, MCX Clearing), depositories (NSDL, CDSL) [L3-C1]Yes, minimum 71 (Manageable); half-yearly third-partyTwice a year
Qualified REQRTAs (KFin, CAMS), KRAs (5 — moved from MII in Apr 2025), large brokers, large mutual funds, large depository participants, large custodiansYes, minimum 61 (Developing); annual self-assessmentTwice a year
Mid-size REAIFs, PMS, merchant bankers, debenture trustees, credit rating agencies, RTAs, IAs and RAs above thresholdNoOnce a year (twice if IBT or Algo)
Small-size REBelow Mid thresholdNoOnce a year
Self-Certification REBrokers < 1,000 clients AND < ₹1,000 crore annual trading volume (April 2025 clarifications) [L3-C2]. Very small IAs, RAs, similarNoExempt from periodic audit; VAPT-only + self-certification

The Broker Exemption threshold (April 2025)

The 30 April 2025 clarifications introduced a dual-parameter test that carved out the smallest brokers from full CSCRF. A broker qualifies as Self-Certification only if it meets BOTH conditions:

  1. Fewer than 1,000 active clients, AND
  2. Annual trading volume below ₹1,000 crore

A broker that meets one condition but not the other falls into Small-size RE, not Self-Certification. Watch this in year-end reviews. A rapidly growing broker that crosses either threshold mid-year must re-categorise at the start of the next financial year.

The KRA reclassification (April 2025)

The 30 April 2025 clarifications moved KYC Registration Agencies (KRAs) from MII status to Qualified RE status. Five KRAs are affected: CVL, NDML, DOTEX, CAMS-KRA, and Karvy-KRA (plus KFin's new KRA registration IN/KRA/007/2025). Consequences of the move:

  • CCI submission moves from half-yearly third-party to annual self-assessment.
  • Minimum CCI drops from 71 to 61.
  • The dedicated in-house 24×7 SOC requirement relaxes to permit M-SOC.
  • Audit cadence remains twice a year (same as MII).

Practitioner check: your KRA-linked filings for FY 2024-25 may reference MII obligations. Filings from FY 2025-26 onwards align to Qualified RE. This transition is subtle but material for evidence packs.

How to categorise your entity

A three-step test:

  1. What type of entity are you? Broker, DP, MF, AMC, PMS, IA, RA, RTA, KRA, custodian, exchange, clearing corp, depository. This determines the applicable category ladder.
  2. What is your scale? Client count, AUM, trading volume, or the metric applicable to your entity type. Cross-check against the April 2025 clarifications and the categorisation annexure to the master circular.
  3. What is your business complexity? Do you offer Internet-Based Trading (IBT) or Algorithmic Trading (Algo)? If yes, your audit cadence moves to twice a year regardless of other Mid/Small categorisation.

Category placement is annual

Category placement is fixed at the start of the financial year using prior-year data. A Mid-size RE that grows into Qualified RE thresholds mid-year does not re-categorise until 1 April of the next financial year. This creates a planned window to build the additional obligations of the new tier.

Consequences of getting it wrong

Over-categorising (claiming Qualified RE when you are Mid-size): you spend money on obligations you do not owe. Under-categorising (claiming Mid-size when you are Qualified RE): SEBI inspection findings, potential SEBI Act §15HB penalty up to ₹1 crore per violation, and reputational damage that flows into the CCI in the next cycle.

The rule of thumb: when in doubt, up-categorise. It is cheaper to over-comply than to defend an under-categorisation in a SEBI inspection.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
SEBI CSCRF 2024, RE Categorisation (Five-tier Regulated Entity categorisation) L3-C1
CSCRF categorises SEBI REs into five tiers: (1) Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations, depositories. (2) Qualified REs — QRTAs, KRAs (moved from MII in Apr 2025), large brokers, large mutual funds, large DPs, large custodians. (3) Mid-size REs — AIFs, PMS, merchant bankers, debenture trustees, credit rating agencies, RTAs, IAs and RAs above threshold. (4) Small-size REs — below mid threshold. (5) Self-Certification REs — brokers below 1,000 clients AND below ₹1,000 crore trading volume (per Apr 2025 clarifications). Category placement is fixed annually at start of the financial year using prior-year data.
SEBI CSCRF Clarifications Apr 2025, Clarifications Circular 2025/60 (April 2025 clarifications: broker exemption + AIF categorisation) L3-C2
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 dated 30 April 2025. Introduced the dual-parameter broker exemption: brokers with fewer than 1,000 clients AND under ₹1,000 crore annual trading volume are exempt from CSCRF as Self-Certification REs. Also revised AIF and PMS categorisation criteria. Reclassified KRAs from MII to Qualified RE.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The CSCRF Framework and the 7-Instrument Document Stack
Module 2: The Cyber Capability Index (CCI) Deep Dive
  • What the CCI is and why SEBI cares
  • The 23 CCI parameters and their weightages
  • The submission workflow and the 15-day rule
  • How REs game CCI and what SEBI is doing about it
Module 3: Governance, the CISO Role, and Board Oversight
  • The CISO mandate under CSCRF
  • The Board Technology Committee cadence
  • Cyber Crisis Management Plan and drills
  • CISO career: salary bands, certifications, career map
Module 4: SOC, M-SOC, and Market SOC Architecture
  • The three approved SOC architectures
  • Cost economics: in-house vs M-SOC
  • M-SOC vendor selection and contract
  • SIEM stack selection
Module 5: Cyber Audit, VAPT, and CERT-In Empanelled Auditors
  • Cyber audit cadence and scope
  • VAPT scope and cost bands
  • Named CERT-In empanelled auditors and how to evaluate them
  • Managing findings to closure and the NSE Inspection ATR
Module 6: Incident Reporting, Cloud, Data Localisation, Business Continuity
  • The 6-hour dual clock: SEBI and CERT-In
  • Cloud, MeitY empanelment, and data residency
  • RTO 2 hours, RPO 15 minutes, and the interoperability framework
  • Real incident case studies at SEBI REs
Module 7: Cross-Regulator Crosswalk and Category-Specific Playbooks
  • The Principle of Exclusivity and the Principle of Equivalence
  • The single-view cross-regulator crosswalk
  • Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII
  • SBOM and the quarterly board deck template
Module 8: Final Exam and Certificate