Every CSCRF conversation eventually turns to "who else is doing this?" and "what does my peer look like?" The answer requires knowing the SEBI RE ecosystem in numbers. This lesson gives you the map.
Market Infrastructure Institutions (7)
The top of the pyramid. Under CSCRF, MIIs are the highest tier of obligation. They must operate a dedicated in-house 24×7 SOC, submit half-yearly third-party CCI assessments to a minimum score of 71, and have full-time CISOs reporting to MD/CEO.
- Stock exchanges (2): National Stock Exchange of India (NSE), BSE (formerly Bombay Stock Exchange)
- Clearing corporations (3): NSE Clearing Limited (NCL), Indian Clearing Corporation Limited (ICCL, for BSE), MCX Clearing Corporation Limited
- Depositories (2): National Securities Depository Limited (NSDL), Central Depository Services (India) Limited (CDSL)
Qualified Registrar and Share Transfer Agents (2)
QRTAs. Historically treated at MII intensity by SEBI.
- KFin Technologies
- Computer Age Management Services (CAMS)
KYC Registration Agencies (5, moved to Qualified RE Apr 2025)
- CDSL Ventures Limited (CVL)
- NSDL Database Management Limited (NDML)
- DOTEX International
- CAMS Investor Services
- Karvy Data Management Services (Karvy-KRA)
Plus KFin's new KRA registration IN/KRA/007/2025.
Registered intermediaries — indicative counts
From the SEBI Sep 2025 Bulletin and adjacent industry data (all figures approximate as of August 2026):
- Stock brokers: ~4,900+ SEBI-registered, ~350 active on NSE
- Depository participants: 300+
- Asset Management Companies (mutual funds): 45+
- Portfolio Managers: 400+
- Registered Investment Advisers: 967 (SEBI proposed to grow this in Aug 2024 with relaxed entry norms)
- Research Analysts: ~1,500
- Alternative Investment Funds: ~1,000+ across three categories
- Merchant bankers: ~200+
- Mutual fund distributors: 2.7 lakh+
- Credit rating agencies: 6
- Debenture trustees: ~30
The regulatory hierarchy under CSCRF
Every RE has a defined reporting chain for compliance filings:
- SEBI → MII (for MIIs, KRAs, QRTAs — direct reporting to SEBI)
- SEBI → Exchange → Broker (for brokers, who report CSCRF compliance to NSE / BSE, not directly to SEBI)
- SEBI → Depository → DP (for depository participants, who report to NSDL / CDSL)
- SEBI → AMC (for mutual funds, direct)
- SEBI → PMS / IA / RA (direct)
But incident reports go via the SEBI Incident Reporting portal + CERT-In in parallel, regardless of reporting chain [L4-C1]. This is the practitioner rule: CSCRF compliance follows the chain; incidents jump the chain.
Where your entity likely sits
Practitioner readers of this course are typically CISOs, DPOs, Heads of IT Risk or Heads of Cyber Compliance at:
- NSE, BSE, NSDL, CDSL (MII CISOs) — expect ₹1.5-3.5 crore comp; Group CISO / Head-InfoSec title; direct MD/CEO reporting
- KFin, CAMS (QRTA CISOs) — similar band
- Angel One, Zerodha, Groww, HDFC Securities, ICICI Securities (Qualified RE brokers) — ₹80 lakh - ₹2 crore comp
- Large mutual funds (SBI MF, HDFC MF, ICICI Prudential MF, Nippon India MF, Axis MF) — Qualified RE band
- Mid-size PMS, RIA firms — Mid-size RE band; ₹35-70 lakh comp; often VP-InfoSec or SVP-InfoSec title rather than "CISO"
Why the ecosystem map matters for your programme
Three practical uses:
- Peer benchmarking. SEBI does not publish RE-level CCI scores, but auditor networks share peer bands informally. Knowing who your peers are lets you request peer benchmarks from your CERT-In empanelled auditor.
- Vendor negotiation. M-SOC vendors serve tiers of clients. Naming your peers signals your expected commercial band.
- Regulatory dialogue. When SEBI holds industry consultations on CSCRF revisions, participation happens through industry bodies (BSE-BOI, NSE-ICCL member forums, AMFI, APMI). Knowing your place in the ecosystem lets you engage the right forum.