Live Founding Cohort open, limited seats remaining Back to main site →

The SEBI RE ecosystem map

Before you can locate your entity in CSCRF, you have to locate it in the wider SEBI ecosystem. This lesson maps the 7 MIIs, 5 KRAs, and thousands of other REs that CSCRF now covers.

Free preview 8 min read Verified
Legal basis
SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.

Every CSCRF conversation eventually turns to "who else is doing this?" and "what does my peer look like?" The answer requires knowing the SEBI RE ecosystem in numbers. This lesson gives you the map.

Market Infrastructure Institutions (7)

The top of the pyramid. Under CSCRF, MIIs are the highest tier of obligation. They must operate a dedicated in-house 24×7 SOC, submit half-yearly third-party CCI assessments to a minimum score of 71, and have full-time CISOs reporting to MD/CEO.

  • Stock exchanges (2): National Stock Exchange of India (NSE), BSE (formerly Bombay Stock Exchange)
  • Clearing corporations (3): NSE Clearing Limited (NCL), Indian Clearing Corporation Limited (ICCL, for BSE), MCX Clearing Corporation Limited
  • Depositories (2): National Securities Depository Limited (NSDL), Central Depository Services (India) Limited (CDSL)

Qualified Registrar and Share Transfer Agents (2)

QRTAs. Historically treated at MII intensity by SEBI.

  • KFin Technologies
  • Computer Age Management Services (CAMS)

KYC Registration Agencies (5, moved to Qualified RE Apr 2025)

  • CDSL Ventures Limited (CVL)
  • NSDL Database Management Limited (NDML)
  • DOTEX International
  • CAMS Investor Services
  • Karvy Data Management Services (Karvy-KRA)

Plus KFin's new KRA registration IN/KRA/007/2025.

Registered intermediaries — indicative counts

From the SEBI Sep 2025 Bulletin and adjacent industry data (all figures approximate as of August 2026):

  • Stock brokers: ~4,900+ SEBI-registered, ~350 active on NSE
  • Depository participants: 300+
  • Asset Management Companies (mutual funds): 45+
  • Portfolio Managers: 400+
  • Registered Investment Advisers: 967 (SEBI proposed to grow this in Aug 2024 with relaxed entry norms)
  • Research Analysts: ~1,500
  • Alternative Investment Funds: ~1,000+ across three categories
  • Merchant bankers: ~200+
  • Mutual fund distributors: 2.7 lakh+
  • Credit rating agencies: 6
  • Debenture trustees: ~30

The regulatory hierarchy under CSCRF

Every RE has a defined reporting chain for compliance filings:

  • SEBI → MII (for MIIs, KRAs, QRTAs — direct reporting to SEBI)
  • SEBI → Exchange → Broker (for brokers, who report CSCRF compliance to NSE / BSE, not directly to SEBI)
  • SEBI → Depository → DP (for depository participants, who report to NSDL / CDSL)
  • SEBI → AMC (for mutual funds, direct)
  • SEBI → PMS / IA / RA (direct)

But incident reports go via the SEBI Incident Reporting portal + CERT-In in parallel, regardless of reporting chain [L4-C1]. This is the practitioner rule: CSCRF compliance follows the chain; incidents jump the chain.

Where your entity likely sits

Practitioner readers of this course are typically CISOs, DPOs, Heads of IT Risk or Heads of Cyber Compliance at:

  • NSE, BSE, NSDL, CDSL (MII CISOs) — expect ₹1.5-3.5 crore comp; Group CISO / Head-InfoSec title; direct MD/CEO reporting
  • KFin, CAMS (QRTA CISOs) — similar band
  • Angel One, Zerodha, Groww, HDFC Securities, ICICI Securities (Qualified RE brokers) — ₹80 lakh - ₹2 crore comp
  • Large mutual funds (SBI MF, HDFC MF, ICICI Prudential MF, Nippon India MF, Axis MF) — Qualified RE band
  • Mid-size PMS, RIA firms — Mid-size RE band; ₹35-70 lakh comp; often VP-InfoSec or SVP-InfoSec title rather than "CISO"

Why the ecosystem map matters for your programme

Three practical uses:

  1. Peer benchmarking. SEBI does not publish RE-level CCI scores, but auditor networks share peer bands informally. Knowing who your peers are lets you request peer benchmarks from your CERT-In empanelled auditor.
  2. Vendor negotiation. M-SOC vendors serve tiers of clients. Naming your peers signals your expected commercial band.
  3. Regulatory dialogue. When SEBI holds industry consultations on CSCRF revisions, participation happens through industry bodies (BSE-BOI, NSE-ICCL member forums, AMFI, APMI). Knowing your place in the ecosystem lets you engage the right forum.
Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of SEBI CSCRF Practitioner Certification?

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
SEBI CSCRF 2024, Incident Reporting (6-hour incident reporting to SEBI + CERT-In) L4-C1
Reportable cyber incidents must be reported to SEBI within 6 hours of detection, in alignment with the CERT-In Directions of 28 April 2022. Reporting is via the SEBI Incident Reporting portal. A parallel filing must be made to CERT-In under CERT-In's own format. Filing to one regulator does not satisfy the obligation to the other. Detection triggers the clock, not confirmation.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The CSCRF Framework and the 7-Instrument Document Stack
Module 2: The Cyber Capability Index (CCI) Deep Dive
  • What the CCI is and why SEBI cares
  • The 23 CCI parameters and their weightages
  • The submission workflow and the 15-day rule
  • How REs game CCI and what SEBI is doing about it
Module 3: Governance, the CISO Role, and Board Oversight
  • The CISO mandate under CSCRF
  • The Board Technology Committee cadence
  • Cyber Crisis Management Plan and drills
  • CISO career: salary bands, certifications, career map
Module 4: SOC, M-SOC, and Market SOC Architecture
  • The three approved SOC architectures
  • Cost economics: in-house vs M-SOC
  • M-SOC vendor selection and contract
  • SIEM stack selection
Module 5: Cyber Audit, VAPT, and CERT-In Empanelled Auditors
  • Cyber audit cadence and scope
  • VAPT scope and cost bands
  • Named CERT-In empanelled auditors and how to evaluate them
  • Managing findings to closure and the NSE Inspection ATR
Module 6: Incident Reporting, Cloud, Data Localisation, Business Continuity
  • The 6-hour dual clock: SEBI and CERT-In
  • Cloud, MeitY empanelment, and data residency
  • RTO 2 hours, RPO 15 minutes, and the interoperability framework
  • Real incident case studies at SEBI REs
Module 7: Cross-Regulator Crosswalk and Category-Specific Playbooks
  • The Principle of Exclusivity and the Principle of Equivalence
  • The single-view cross-regulator crosswalk
  • Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII
  • SBOM and the quarterly board deck template
Module 8: Final Exam and Certificate