Most senior CISOs at SEBI Regulated Entities know the master CSCRF circular of 20 August 2024. Fewer can name all seven instruments in the stack. Not being able to name them is why compliance filings get made against superseded language and why board decks quote clauses that were softened months ago. This lesson fixes that.
The seven instruments, in order
| # | Date | Instrument | What it did |
|---|---|---|---|
| 1 | 20 Aug 2024 | Master CSCRF circular — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 [L1-C1] | 205-page baseline framework. Consolidates all prior SEBI cyber circulars. |
| 2 | Dec 2024 | PR.DS.S2 abeyance | Data-localisation control PR.DS.S2 suspended pending consultation. Still suspended today. |
| 3 | 28 Mar 2025 | First extension — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 [L1-C2] | Non-MII/KRA/QRTA deadline moved from 1 April 2025 to 30 June 2025. |
| 4 | 30 Apr 2025 | Clarifications — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 [L1-C3] | Broker exemption threshold (<1000 clients AND <₹1000cr trading volume). AIF and PMS re-categorisation. KRAs reclassified from MII to Qualified RE. |
| 5 | 11 Jun 2025 | FAQ document [L1-C4] | 76 questions across 17 sections. The practitioner reference for edge cases. |
| 6 | 30 Jun 2025 | Second extension | Non-MII/KRA/QRTA deadline moved to 31 August 2025. Final extension. |
| 7 | 28 Aug 2025 | Technical Clarifications — SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 [L1-C5] | Principle of Exclusivity + Principle of Equivalence. ISO 27001 becomes voluntary. RTO 2h / RPO 15min reaffirmed. M-SOC onboarding clarified. NCIIPC overlay acknowledged. |
What is in force today
Since 31 August 2025, CSCRF is fully in force for every category of SEBI Regulated Entity. MIIs, KRAs and QRTAs have been operating under CSCRF since 1 January 2025. There is no further extension.
The practitioner reading of "fully in force" is that a SEBI inspection or a CERT-In-empanelled auditor now examines: full compliance with the master circular; the operational implementations shaped by the April 2025 clarifications; the FAQ interpretations that resolve edge cases; and the Aug 2025 Technical Clarifications that introduce the Principle of Equivalence used to reduce duplicate audit burden.
Why the circular number matters
Every SEBI circular carries a unique number in the form SEBI/HO/[Department]/[Sub-code]/P/CIR/[Year]/[SeqNo]. Get the number wrong in your board paper or your regulatory filing and you signal amateurism. The right prefix for CSCRF is SEBI/HO/ITD-1/ITD_CSC_EXT. Some secondary sources cite ITD_CSC_POD1; that is incorrect. The correct middle segment is ITD_CSC_EXT.
Practical filing rule: every CSCRF-related document your team produces (board deck, audit report, incident report, CCI submission) should cite the specific circular number and date of every provision it relies on. This is the single most important habit to build inside the DPO or CISO team.
Which instrument to read for which question
- Framework structure and control catalogue: Master circular of 20 August 2024. Full 205 pages.
- Data localisation status: Master circular baseline + December 2024 PR.DS.S2 abeyance. Watch for reactivation.
- Your entity's categorisation and applicability: Master circular + 30 April 2025 clarifications (broker exemption + AIF/PMS + KRA reclassification).
- Edge-case operational questions: 11 June 2025 FAQ (76 questions, 17 sections). This is the document your CISO team should have printed and dog-eared.
- Multi-regulator overlap: 28 August 2025 Technical Clarifications, specifically the Principle of Exclusivity and Principle of Equivalence.
- Effective dates and any grace period: The extension circulars (28 March 2025 and 30 June 2025) plus the master circular. Since 31 August 2025 all grace periods are exhausted.
The trap secondary sources set
Vendor blogs and CSCRF guides published between August 2024 and April 2025 do not reflect the April 2025 clarifications or the August 2025 Technical Clarifications. They still describe ISO 27001 as mandatory, treat PR.DS.S2 as active, and use the pre-April 2025 categorisation. A CISO relying on a vendor blog dated December 2024 is nine months out of date on some material points.
The practitioner rule: for any material claim, cite the SEBI circular directly. Where a secondary source is used, note the source date and cross-check against the seven-instrument stack for any subsequent amendment.
The manual verification checklist inside this course
The primary CSCRF PDFs (master circular, Annexure K CCI template, June 2025 FAQ, April 2025 clarifications body) are not consistently machine-readable. Every lesson in this course is anchored to primary sources where feasible and to reputable practitioner sources where the primary is not accessible via automation. A 16-item manual verification checklist inside this course flags each item that requires human confirmation before the CISO acts on it. If your job is at stake on the accuracy of a specific number (a CCI parameter weight, an audit revalidation window, a broker exemption threshold), consult the primary SEBI PDF before you file.