Live Founding Cohort open, limited seats remaining Back to main site →

The seven-instrument CSCRF document stack

CSCRF is not one circular. It is seven, issued over eighteen months. Read the wrong one and you are advising your board off out-of-date text. This lesson gives you the whole stack in one place, in the order the CISO reads it.

Free preview 10 min read Verified
Legal basis
SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.

Most senior CISOs at SEBI Regulated Entities know the master CSCRF circular of 20 August 2024. Fewer can name all seven instruments in the stack. Not being able to name them is why compliance filings get made against superseded language and why board decks quote clauses that were softened months ago. This lesson fixes that.

The seven instruments, in order

#DateInstrumentWhat it did
120 Aug 2024Master CSCRF circular — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 [L1-C1]205-page baseline framework. Consolidates all prior SEBI cyber circulars.
2Dec 2024PR.DS.S2 abeyanceData-localisation control PR.DS.S2 suspended pending consultation. Still suspended today.
328 Mar 2025First extension — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 [L1-C2]Non-MII/KRA/QRTA deadline moved from 1 April 2025 to 30 June 2025.
430 Apr 2025Clarifications — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 [L1-C3]Broker exemption threshold (<1000 clients AND <₹1000cr trading volume). AIF and PMS re-categorisation. KRAs reclassified from MII to Qualified RE.
511 Jun 2025FAQ document [L1-C4]76 questions across 17 sections. The practitioner reference for edge cases.
630 Jun 2025Second extensionNon-MII/KRA/QRTA deadline moved to 31 August 2025. Final extension.
728 Aug 2025Technical Clarifications — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 [L1-C5]Principle of Exclusivity + Principle of Equivalence. ISO 27001 becomes voluntary. RTO 2h / RPO 15min reaffirmed. M-SOC onboarding clarified. NCIIPC overlay acknowledged.

What is in force today

Since 31 August 2025, CSCRF is fully in force for every category of SEBI Regulated Entity. MIIs, KRAs and QRTAs have been operating under CSCRF since 1 January 2025. There is no further extension.

The practitioner reading of "fully in force" is that a SEBI inspection or a CERT-In-empanelled auditor now examines: full compliance with the master circular; the operational implementations shaped by the April 2025 clarifications; the FAQ interpretations that resolve edge cases; and the Aug 2025 Technical Clarifications that introduce the Principle of Equivalence used to reduce duplicate audit burden.

Why the circular number matters

Every SEBI circular carries a unique number in the form SEBI/HO/[Department]/[Sub-code]/P/CIR/[Year]/[SeqNo]. Get the number wrong in your board paper or your regulatory filing and you signal amateurism. The right prefix for CSCRF is SEBI/HO/ITD-1/ITD_CSC_EXT. Some secondary sources cite ITD_CSC_POD1; that is incorrect. The correct middle segment is ITD_CSC_EXT.

Practical filing rule: every CSCRF-related document your team produces (board deck, audit report, incident report, CCI submission) should cite the specific circular number and date of every provision it relies on. This is the single most important habit to build inside the DPO or CISO team.

Which instrument to read for which question

  • Framework structure and control catalogue: Master circular of 20 August 2024. Full 205 pages.
  • Data localisation status: Master circular baseline + December 2024 PR.DS.S2 abeyance. Watch for reactivation.
  • Your entity's categorisation and applicability: Master circular + 30 April 2025 clarifications (broker exemption + AIF/PMS + KRA reclassification).
  • Edge-case operational questions: 11 June 2025 FAQ (76 questions, 17 sections). This is the document your CISO team should have printed and dog-eared.
  • Multi-regulator overlap: 28 August 2025 Technical Clarifications, specifically the Principle of Exclusivity and Principle of Equivalence.
  • Effective dates and any grace period: The extension circulars (28 March 2025 and 30 June 2025) plus the master circular. Since 31 August 2025 all grace periods are exhausted.

The trap secondary sources set

Vendor blogs and CSCRF guides published between August 2024 and April 2025 do not reflect the April 2025 clarifications or the August 2025 Technical Clarifications. They still describe ISO 27001 as mandatory, treat PR.DS.S2 as active, and use the pre-April 2025 categorisation. A CISO relying on a vendor blog dated December 2024 is nine months out of date on some material points.

The practitioner rule: for any material claim, cite the SEBI circular directly. Where a secondary source is used, note the source date and cross-check against the seven-instrument stack for any subsequent amendment.

The manual verification checklist inside this course

The primary CSCRF PDFs (master circular, Annexure K CCI template, June 2025 FAQ, April 2025 clarifications body) are not consistently machine-readable. Every lesson in this course is anchored to primary sources where feasible and to reputable practitioner sources where the primary is not accessible via automation. A 16-item manual verification checklist inside this course flags each item that requires human confirmation before the CISO acts on it. If your job is at stake on the accuracy of a specific number (a CCI parameter weight, an audit revalidation window, a broker exemption threshold), consult the primary SEBI PDF before you file.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
SEBI CSCRF 2024, Master Circular 2024/113 (Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities) L1-C1
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. The 205-page master framework that supersedes all prior SEBI cyber circulars (2015 MIIs, 2016 depositories, 2018 stockbrokers/DPs, 2019 MFs/RTAs). Applies to all SEBI Regulated Entities across five categories: MIIs, Qualified REs, Mid-size REs, Small-size REs and Self-Certification REs. Structured around 5 cyber-resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) mapped to 6 NIST CSF 2.0 functions (Governance, Identify, Protect, Detect, Respond, Recover). Cross-references NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8, ISO 22301.
SEBI CSCRF Extension Mar 2025, Extension Circular 2025/45 (First extension: non-MII/KRA/QRTA deadline pushed to 30 June 2025) L1-C2
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 dated 28 March 2025. Extended the CSCRF implementation deadline for all REs except MIIs, KRAs and QRTAs (which continued on 1 January 2025) to 30 June 2025.
SEBI CSCRF Clarifications Apr 2025, Clarifications Circular 2025/60 (April 2025 clarifications: broker exemption + AIF categorisation) L1-C3
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 dated 30 April 2025. Introduced the dual-parameter broker exemption: brokers with fewer than 1,000 clients AND under ₹1,000 crore annual trading volume are exempt from CSCRF as Self-Certification REs. Also revised AIF and PMS categorisation criteria. Reclassified KRAs from MII to Qualified RE.
SEBI CSCRF FAQ Jun 2025, CSCRF FAQ Jun 2025 (SEBI CSCRF FAQ document (76 questions in 17 sections)) L1-C4
SEBI FAQ document on CSCRF and the Cloud Framework, published 11 June 2025. Contains 76 questions across 17 sections covering governance, audits, cloud, incident reporting, VAPT and applicability. Key clarifications include: MII/Qualified RE CISO independence; M-SOC contract minima; CSP MeitY empanelment; broker categorisation edge cases; VAPT scope for third-party integrations; DR testing evidence.
SEBI CSCRF Technical Clarifications Aug 2025, Technical Clarifications 2025/119 (Aug 2025 Technical Clarifications: Principles of Exclusivity + Equivalence, ISO 27001 voluntary) L1-C5
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025. Introduces the Principle of Exclusivity (an RE regulated by only one regulator complies with that regulator's framework) and the Principle of Equivalence (an RE regulated by multiple regulators complies with the stricter or equivalent regime, and may rely on one regulator's audit for the equivalent controls). Makes ISO 27001 certification voluntary rather than mandatory. Reaffirms Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes for critical operations. Clarifies M-SOC onboarding, NCIIPC applicability, and confidentiality safeguards for audit reports.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The CSCRF Framework and the 7-Instrument Document Stack
Module 2: The Cyber Capability Index (CCI) Deep Dive
  • What the CCI is and why SEBI cares
  • The 23 CCI parameters and their weightages
  • The submission workflow and the 15-day rule
  • How REs game CCI and what SEBI is doing about it
Module 3: Governance, the CISO Role, and Board Oversight
  • The CISO mandate under CSCRF
  • The Board Technology Committee cadence
  • Cyber Crisis Management Plan and drills
  • CISO career: salary bands, certifications, career map
Module 4: SOC, M-SOC, and Market SOC Architecture
  • The three approved SOC architectures
  • Cost economics: in-house vs M-SOC
  • M-SOC vendor selection and contract
  • SIEM stack selection
Module 5: Cyber Audit, VAPT, and CERT-In Empanelled Auditors
  • Cyber audit cadence and scope
  • VAPT scope and cost bands
  • Named CERT-In empanelled auditors and how to evaluate them
  • Managing findings to closure and the NSE Inspection ATR
Module 6: Incident Reporting, Cloud, Data Localisation, Business Continuity
  • The 6-hour dual clock: SEBI and CERT-In
  • Cloud, MeitY empanelment, and data residency
  • RTO 2 hours, RPO 15 minutes, and the interoperability framework
  • Real incident case studies at SEBI REs
Module 7: Cross-Regulator Crosswalk and Category-Specific Playbooks
  • The Principle of Exclusivity and the Principle of Equivalence
  • The single-view cross-regulator crosswalk
  • Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII
  • SBOM and the quarterly board deck template
Module 8: Final Exam and Certificate