Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications); SEBI Circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 (5 May 2026 AI Vulnerability Detection Advisory, advisory not mandatory; supplements the M-SOC, VAPT, SBOM and Cyber Capability Index teaching with AI-assisted detection guidance). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.

How this SEBI CSCRF Practitioner Certification register is built

This trust page is the citation register for the SEBI CSCRF Practitioner Certification course. It cites 25 authorities across 14 statutory instruments, drawn from the legal basis snapshot above (SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications); SEBI Circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 (5 May 2026 AI Vulnerability Detection Advisory, advisory not mandatory; supplements the M-SOC, VAPT, SBOM and Cyber Capability Index teaching with AI-assisted detection guidance). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.).

Primary sources: SEBI CSCRF 2024 (11 entries), SEBI CSCRF Technical Clarifications Aug 2025 (2 entries), Angel One AWS Breach Feb 2025 (1 entry).

Every claim in every SEBI CSCRF Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
8
modules
28
lessons
25
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

Feb 2025 AWS Breach , Angel One AWS breach — Feb 2025 28 Feb 2025
Plain summary: On 27 February 2025 Angel One was alerted by a dark-web-monitoring partner to unauthorised access to its AWS resources. Approximately 8 million users' data was exposed. Angel One rotated all AWS credentials and engaged external forensics. Angel One publicly clarified that funds, securities and login credentials were not impacted. The stock dropped approximately 11 percent in two sessions, hitting a 52-week low on 3 March 2025. The case is treated in industry commentary as the reference example for why cloud IAM hygiene and continuous credential-exposure monitoring are now table-stakes CSCRF operational expectations.
Angel One Limited disclosed on 28 February 2025 that on 27 February 2025 it was alerted by an external monitoring partner to unauthorised access of its Amazon Web Services resources. Approximately 8 million users\' data was affected. The company rotated all AWS credentials, engaged external forensics, and clarified that client funds, securities and login credentials were not impacted. The stock dropped approximately 11 percent in the two trading sessions following disclosure, hitting a 52-week low on 3 March 2025.

Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Plain summary: CERT-In Directions of 28 April 2022, Direction (ii): any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing. Runs in parallel with SEBI CSCRF 6-hour clock. Filing to one regulator does not satisfy the obligation to the other.
Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.

Protected System designation , NCIIPC Protected System status for MIIs
Plain summary: National Critical Information Infrastructure Protection Centre (NCIIPC) designates specific systems as "Protected Systems" under Section 70 of the IT Act 2000. Typical MII trading, clearing and depository systems fall in this category. Protected System status brings additional NCIIPC audit obligations that layer on top of CSCRF. The 28 August 2025 Technical Clarifications explicitly acknowledge this overlay via the Principle of Equivalence.
NCIIPC (National Critical Information Infrastructure Protection Centre) designates specific systems as Protected Systems under Section 70 of the Information Technology Act 2000. Protected System status brings additional NCIIPC-specific audit obligations, evidence-sharing requirements and threat-intelligence integration that layer on top of the CSCRF baseline. Under the Principle of Equivalence (SEBI Technical Clarifications, 28 August 2025), audits performed to NCIIPC specifications may satisfy equivalent CSCRF controls where the two regimes overlap.

NSE 2021 Settlement 2023 , NSE Feb 2021 outage — ₹72.64 crore SEBI settlement (2023) 28 Jun 2023
Plain summary: On 24 February 2021, NSE experienced an approximately 4-hour trading halt due to a telecom link failure hitting NSE Clearing's online risk system. SEBI investigated. In 2023, NSE, NCL and three executives settled the case for a combined ₹72.64 crore, plus community-service undertakings. The case is the reference precedent for SEBI treating trading availability as a systemic-risk item and pursuing personal-liability enforcement.
On 24 February 2021, National Stock Exchange of India Limited (NSE) experienced a trading halt of approximately four hours due to a telecom link failure impacting the online risk management system of NSE Clearing Limited (NCL). SEBI investigated the incident. In 2023, NSE, NCL and three members of the Crisis Management Team settled the case with SEBI for a combined amount of ₹72.64 crore, along with community-service undertakings.

RBI PDS Direction 2018 , RBI Payment Data Storage direction (April 2018) 06 Apr 2018
Plain summary: RBI directive requiring all payment-related data of payment system operators to be stored only in India. Applies to MIIs and clearing corporations that are also payment-system operators. Stricter than SEBI's abeyance-mode data localisation and continues to bind those entities regardless of the SEBI abeyance.
RBI Notification DPSS.CO.OD No.2785/06.08.005/2017-2018 dated 6 April 2018. All system providers shall ensure that the entire data relating to payment systems operated by them is stored only in India. This data shall include the full end-to-end transaction details, and information collected, carried or processed as part of the message or payment instruction. For the foreign leg of the transaction, if any, the data can also be stored in the foreign country, if required.

Section 15HB , Penalty for non-compliance with SEBI directions
Plain summary: Section 15HB of the SEBI Act 1992: any person who fails to comply with any provision of the Act, its rules or regulations, or any direction of SEBI, is liable to a penalty which may extend to one crore rupees per violation. This is the primary penalty channel for CCI shortfall or other CSCRF non-compliance.
SEBI Act 1992, Section 15HB. Penalty for contravention where no separate penalty has been provided. Whoever fails to comply with any provision of this Act, the rules or the regulations made or directions issued by the Board thereunder for which no separate penalty has been provided, shall be liable to a penalty which shall not be less than one lakh rupees but which may extend to one crore rupees.

SEBI AI Vulnerability Detection Advisory (5-May-2026) , SEBI advisory on AI-assisted vulnerability detection, M-SOC onboarding, and SBOM upkeep 05 May 2026
Plain summary: SEBI Circular reference HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (published at sebi.gov.in in the May 2026 circulars index). An advisory (not a mandatory instrument) that nudges SEBI Regulated Entities toward AI-assisted vulnerability detection inside their VAPT and SOC operations (calling out AI tools such as Claude Mythos as example vectors), faster M-SOC onboarding for entities still on the sidelines, and disciplined upkeep of the SBOM and asset inventory that CSCRF already requires. Also constitutes a task force branded cyber-suraksha.ai to examine AI-related cybersecurity risks, devise mitigation strategies, facilitate threat-intelligence sharing, and review the cybersecurity posture of third-party application service providers. The advisory does not amend the master CSCRF circular or the 28 August 2025 Technical Clarifications. It signals SEBI's supervisory direction for FY 2026-27 audit cycles: expect inspectors to probe how the RE is treating the advisory even though compliance is not compulsory.
SEBI Circular reference HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026. Subject: Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection. Addressed to nearly every category of SEBI-regulated securities market participant (AIFs, clearing corporations, credit-rating agencies, custodians, depositories, investment advisers, research analysts, KYC registration agencies, merchant bankers, mutual funds and AMCs, portfolio managers, stock brokers, stock exchanges, venture capital funds and others). The advisory recommends: (a) integration of AI-assisted or machine-learning-based vulnerability detection into existing VAPT and continuous scanning workflows, alongside traditional signature-based tooling; (b) acceleration of Managed SOC (M-SOC) onboarding for eligible REs that have not yet completed onboarding to a CERT-In empanelled M-SOC or to the Market SOC operated by MIIs; (c) reinforced upkeep of the Software Bill of Materials and asset inventory obligations already carried in the CSCRF baseline, including refresh cadence and coverage of customer-facing and trading-adjacent applications; (d) engagement with third-party vendors for security reviews and development of long-term AI-based detection and mitigation plans. SEBI has constituted a task force branded cyber-suraksha.ai to examine AI-related cybersecurity risks, devise mitigation strategies, facilitate sharing of threat intelligence, and review the cybersecurity posture of third-party application service providers. This is an advisory. It does not amend the master CSCRF circular or the Technical Clarifications of 28 August 2025.

Cloud Framework 2023 , SEBI Framework for Adoption of Cloud Services 06 Mar 2023
Plain summary: Issued March 2023, folded into CSCRF Protect and Identify domains. Requires: MeitY-empanelled CSP; STQC-audited data centre; data must reside and be processed inside India; RE retains full ownership of data, logs, encryption keys; data encrypted at rest, in transit, in use; requirement flows down to sub-contractors.
SEBI Framework for Adoption of Cloud Services by SEBI Regulated Entities. Cloud Service Providers used by REs must be empanelled by the Ministry of Electronics and Information Technology (MeitY). The underlying data centre must hold a valid Standardisation Testing and Quality Certification (STQC) audit. Data must reside and be processed within India. The RE retains full ownership of data, logs and encryption keys. Data shall be encrypted at rest, in transit and in use. The requirement to comply with these terms flows down to all sub-contractors in the CSP chain.

Annexure K , Cyber Capability Index (CCI) template 20 Aug 2024
Plain summary: Annexure K of the master CSCRF circular sets out the Cyber Capability Index (CCI). CCI is a quantitative maturity score built from 23 parameters, each with a defined weightage, producing a weighted-average score on a 0-100 scale. Six maturity bands: Exceptional (91-100), Optimal (81-90), Manageable (71-80), Developing (61-70), Bare Minimum (51-60), Fail (≤50). MIIs and critical MIIs must achieve at least Manageable (≥71). Qualified REs must achieve at least Developing (≥61). Mid-size, Small-size and Self-Certification REs are not required to submit CCI.
Annexure K — Cyber Capability Index (CCI). The CCI is a weighted score across 23 parameters covering asset inventory, access management, encryption coverage, VAPT closure rate, SOC alert triage MTTR, patch cycle time, backup RTO/RPO, awareness training coverage, third-party risk, incident response drill outcomes and similar operational metrics. Maturity bands: Exceptional 91-100, Optimal 81-90, Manageable 71-80, Developing 61-70, Bare Minimum 51-60, Fail below 51. Mandatory minimum for MIIs and critical MIIs: Manageable (71). Mandatory minimum for Qualified REs: Developing (61).
BCP RTO/RPO , Business continuity RTO 2 hours, RPO 15 minutes 20 Aug 2024
Plain summary: For critical operations, the Recovery Time Objective is 2 hours and the Recovery Point Objective is 15 minutes. Reaffirmed in the 28 August 2025 Technical Clarifications circular. Cyber Crisis Management Plan (CCMP) is board-signed, refreshed annually, and tested through at least one full tabletop and one technical drill per year. CCMP must map to the CERT-In National Cyber Crisis Management Plan.
Business Continuity: For critical operations of Regulated Entities, the Recovery Time Objective (RTO) shall be two hours and the Recovery Point Objective (RPO) shall be fifteen minutes. Cyber Crisis Management Plan (CCMP): shall be Board-approved, reviewed and updated at least annually, and tested through at least one full-scale tabletop exercise and one technical drill per year. The CCMP shall be aligned to the CERT-In National Cyber Crisis Management Plan.
CCI Submission Cadence , CCI assessment cadence and submission rule 20 Aug 2024
Plain summary: MIIs must have a third-party assessment of CCI by a CERT-In empanelled auditor every six months and submit evidence to SEBI within 15 days of assessment completion. Qualified REs run an annual self-assessment, also submitted within 15 days. Mid-size, Small-size and Self-Certification REs are exempt from CCI submission.
CCI Submission Cadence: (a) MIIs — half-yearly third-party assessment by a CERT-In empanelled auditor; submission to SEBI within 15 days of assessment completion. (b) Qualified REs — annual self-assessment; submission to SEBI within 15 days of self-assessment completion.
CISO Mandate , CISO role, reporting line, independence 20 Aug 2024
Plain summary: For MIIs and Qualified REs, the CISO must be full-time, equivalent in rank to CTO/CIO, report directly to MD/CEO, and have unfettered board access. Mid-size REs may use a fractional or virtual CISO (vCISO). Small and Self-Cert REs must document a cyber-security officer who may be part-time. The CISO cannot report to the CTO or IT Head under CSCRF. Board Technology Committee must have cybersecurity as a standing agenda item and meet at least quarterly for MIIs and Qualified REs.
Chief Information Security Officer (CISO): For Market Infrastructure Institutions and Qualified Regulated Entities, the CISO shall be a full-time officer of at least equivalent rank to the Chief Technology Officer or Chief Information Officer, shall report directly to the Managing Director or Chief Executive Officer, and shall have unfettered access to the Board of Directors. The CISO shall not report through the CTO or IT Head. For Mid-size REs a virtual or fractional CISO arrangement is permitted. For Small-size and Self-Certification REs, a documented cyber-security officer must be identified. Board Technology Committee cadence for MIIs and Qualified REs: at least quarterly, with cybersecurity as a standing agenda item.
Cyber Audit , Cyber audit cadence and scope 20 Aug 2024
Plain summary: MIIs, Qualified REs, and Mid/Small REs with Internet-Based Trading (IBT) or Algo trading: at least twice a year. Other Mid-size / Small REs: at least once a year. Self-Certification REs: exempt from periodic audit; VAPT-only + self-certification. Audit scope must cover 100% of critical systems and at least 25% of non-critical systems on a sample basis. All audits must be performed by CERT-In empanelled Information Security auditing organisations. Auditors need at least 3 years of BFSI IT-audit experience and hold CISA/CISM/CISSP.
Cyber Audit Frequency: (a) MIIs, Qualified REs, and Mid/Small REs with IBT or Algo — at least twice a year. (b) Other Mid-size and Small-size REs — at least once a year. (c) Self-Certification REs — exempt from periodic cyber audit; must undertake VAPT and self-certify. Audit Scope: 100 percent of critical systems and 25 percent of non-critical systems on a sample basis. Auditor Empanelment: CERT-In empanelled Information Security auditing organisations only; auditors must have minimum 3 years BFSI IT audit experience and CISA/CISM/CISSP.
Incident Reporting , 6-hour incident reporting to SEBI + CERT-In 20 Aug 2024
Plain summary: Reportable cyber incidents must be reported to SEBI within 6 hours of detection, in alignment with the CERT-In Directions of 28 April 2022. Reporting is via the SEBI Incident Reporting portal. A parallel filing must be made to CERT-In under CERT-In's own format. Filing to one regulator does not satisfy the obligation to the other. Detection triggers the clock, not confirmation.
Cyber Incident Reporting: All SEBI Regulated Entities shall report cyber security incidents to SEBI within six hours of detection, aligned with the reporting timeline under the CERT-In Directions dated 28 April 2022. Reporting shall be via the SEBI Incident Reporting portal. A separate report shall be filed with CERT-In in the format prescribed by CERT-In. Detection of an incident, not confirmation, starts the six-hour clock.
Master Circular 2024/113 , Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities 20 Aug 2024
Plain summary: SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. The 205-page master framework that supersedes all prior SEBI cyber circulars (2015 MIIs, 2016 depositories, 2018 stockbrokers/DPs, 2019 MFs/RTAs). Applies to all SEBI Regulated Entities across five categories: MIIs, Qualified REs, Mid-size REs, Small-size REs and Self-Certification REs. Structured around 5 cyber-resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) mapped to 6 NIST CSF 2.0 functions (Governance, Identify, Protect, Detect, Respond, Recover). Cross-references NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8, ISO 22301.
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. Subject: Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs). This framework is applicable to all SEBI Regulated Entities and consolidates all prior cybersecurity guidelines. The framework is structured around five cyber-resilience goals: Anticipate, Withstand, Contain, Recover and Evolve. These goals are implemented through six functional domains aligned to NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond and Recover.
RE Categorisation , Five-tier Regulated Entity categorisation 20 Aug 2024
Plain summary: CSCRF categorises SEBI REs into five tiers: (1) Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations, depositories. (2) Qualified REs — QRTAs, KRAs (moved from MII in Apr 2025), large brokers, large mutual funds, large DPs, large custodians. (3) Mid-size REs — AIFs, PMS, merchant bankers, debenture trustees, credit rating agencies, RTAs, IAs and RAs above threshold. (4) Small-size REs — below mid threshold. (5) Self-Certification REs — brokers below 1,000 clients AND below ₹1,000 crore trading volume (per Apr 2025 clarifications). Category placement is fixed annually at start of the financial year using prior-year data.
The framework categorises SEBI Regulated Entities into five tiers based on scale and systemic importance: Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs, and Self-Certification REs. Category placement is determined annually at the start of the financial year based on prior-year operational data (client base, AUM, trading volume, and similar metrics as applicable to the RE class).
SOC Architecture , SOC / M-SOC / Market SOC architecture 20 Aug 2024
Plain summary: MIIs must operate a dedicated in-house 24×7 SOC. Qualified REs and Mid-size REs may run in-house SOC or a CERT-In empanelled Managed SOC (M-SOC). Small-size REs may onboard the Market SOC (M-SOC) operated by BSE (via empanelled MSSP Blue Sapphire Cyber Systems) and NSE (via Aujas Cybersecurity). Self-Certification REs may have M-SOC obligation waived if below the size threshold (e.g., PMS with under 100 clients). SIEM must cover all critical systems. Log retention at least 180 days online plus 2 years archived (UNVERIFIED — verify against Detect annexure).
SOC Architecture by RE Category: (a) MIIs — dedicated in-house 24×7 SOC. (b) Qualified REs and Mid-size REs — in-house SOC or CERT-In empanelled Managed SOC (M-SOC) provider. (c) Small-size REs — Market SOC service operated by MIIs (Bombay Stock Exchange and National Stock Exchange). (d) Self-Certification REs — M-SOC obligation may be waived for entities below the size threshold. SIEM shall cover all critical systems. Log retention minimum: 180 days online and 2 years archived.
VAPT , VAPT scope, cadence, remediation SLA 20 Aug 2024
Plain summary: VAPT required at least annually and additionally after every major application or software release. Real-time DAST scanning against OWASP Top 10 and SANS Top 25. Findings closed within 3 months of the report. High-severity vulnerabilities where a patch is already available: 1 week. Revalidation within 6 months of initial audit completion; open items beyond 6 months need IT Committee sign-off. Only CERT-In empanelled auditors qualify.
Vulnerability Assessment and Penetration Testing (VAPT): required at least once every twelve months, and additionally after every major application release. Testing shall include real-time DAST against OWASP Top 10 and SANS Top 25. Remediation timelines: high-severity vulnerabilities with patch available shall be closed within one week; all other findings shall be closed within three months of the report date. Revalidation shall be completed within six months of the initial audit; observations open beyond six months require IT Committee sign-off. VAPT shall be performed only by CERT-In empanelled Information Security auditing organisations.
PR.DS.S2 Abeyance Dec 2024 , Data localisation control PR.DS.S2 placed in abeyance 01 Dec 2024
Plain summary: In December 2024, SEBI placed Control PR.DS.S2 of the CSCRF Protect Domain in abeyance pending industry consultation. PR.DS.S2 originally required that all data generated or stored within India remain within India. The control remains suspended as of August 2026. Cloud data still must reside in a MeitY-empanelled CSP's Indian data centre in practice. UNVERIFIED — the specific SEBI circular that put PR.DS.S2 in abeyance could not be identified against source; consistently cited as December 2024.
Control PR.DS.S2 — All data generated or stored by REs within India shall remain within India — placed in abeyance in December 2024 pending industry consultation. The abeyance continues as of August 2026. The general cloud residency expectation via MeitY empanelled CSPs with Indian data centres continues.

Clarifications Circular 2025/60 , April 2025 clarifications: broker exemption + AIF categorisation 30 Apr 2025
Plain summary: SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 dated 30 April 2025. Introduced the dual-parameter broker exemption: brokers with fewer than 1,000 clients AND under ₹1,000 crore annual trading volume are exempt from CSCRF as Self-Certification REs. Also revised AIF and PMS categorisation criteria. Reclassified KRAs from MII to Qualified RE.
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 dated 30 April 2025. Subject: Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities. Stock brokers with fewer than 1,000 active clients AND annual trading volume below ₹1,000 crore are placed in the Self-Certification category. Alternative Investment Funds and Portfolio Management Services are re-categorised per revised thresholds appended. KYC Registration Agencies are moved from Market Infrastructure Institution status to Qualified Regulated Entity status.

Extension Circular 2025/45 , First extension: non-MII/KRA/QRTA deadline pushed to 30 June 2025 28 Mar 2025
Plain summary: SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 dated 28 March 2025. Extended the CSCRF implementation deadline for all REs except MIIs, KRAs and QRTAs (which continued on 1 January 2025) to 30 June 2025.
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 dated 28 March 2025. Subject: Extension towards adoption and implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities. The implementation date for all REs except Market Infrastructure Institutions, KYC Registration Agencies, and Qualified Registrar and Share Transfer Agents is extended from 1 April 2025 to 30 June 2025. MIIs, KRAs and QRTAs remain on the original 1 January 2025 effective date.

CSCRF FAQ Jun 2025 , SEBI CSCRF FAQ document (76 questions in 17 sections) 11 Jun 2025
Plain summary: SEBI FAQ document on CSCRF and the Cloud Framework, published 11 June 2025. Contains 76 questions across 17 sections covering governance, audits, cloud, incident reporting, VAPT and applicability. Key clarifications include: MII/Qualified RE CISO independence; M-SOC contract minima; CSP MeitY empanelment; broker categorisation edge cases; VAPT scope for third-party integrations; DR testing evidence.
SEBI CSCRF Frequently Asked Questions (FAQ) document dated 11 June 2025. 76 questions across 17 sections. Sections cover: framework applicability, RE categorisation, governance and CISO independence, information security committee, policy and procedures, asset management, access management, VAPT, cyber audit, incident reporting, cloud services and MeitY empanelment, business continuity and disaster recovery, SOC and M-SOC, third-party and vendor risk, awareness and training, board reporting, and CCI submission. This is the practitioner reference for edge cases in day-to-day CSCRF operations.

SBOM Requirement , Software Bill of Materials (SBOM) mandatory since Aug 2025 28 Aug 2025
Plain summary: SBOM obligation formalised in the Aug 2025 Technical Clarifications. Required fields: supplier, licence, transitive dependencies, cryptographic hashes, update cadence. Applies to customer-facing and trading-adjacent applications. Legacy in-house code needs a collection strategy.
Software Bill of Materials (SBOM): Regulated Entities shall maintain a Software Bill of Materials for all customer-facing and trading-adjacent applications. The SBOM shall include: (a) supplier name, (b) licence terms, (c) transitive dependencies, (d) cryptographic hashes of components, and (e) update cadence. Legacy in-house code shall be inventoried through a documented collection strategy.
Technical Clarifications 2025/119 , Aug 2025 Technical Clarifications: Principles of Exclusivity + Equivalence, ISO 27001 voluntary 28 Aug 2025
Plain summary: SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025. Introduces the Principle of Exclusivity (an RE regulated by only one regulator complies with that regulator's framework) and the Principle of Equivalence (an RE regulated by multiple regulators complies with the stricter or equivalent regime, and may rely on one regulator's audit for the equivalent controls). Makes ISO 27001 certification voluntary rather than mandatory. Reaffirms Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes for critical operations. Clarifies M-SOC onboarding, NCIIPC applicability, and confidentiality safeguards for audit reports.
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025. Subject: Technical Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities. Principle of Exclusivity: A Regulated Entity that is regulated by only one financial-sector regulator shall comply with that regulator\'s cybersecurity framework. Principle of Equivalence: A Regulated Entity that is regulated by multiple financial-sector regulators shall comply with the stricter or equivalent regime for each control domain, and may rely on one regulator\'s audit report where the other regulator recognises it for equivalent controls. ISO 27001 certification is voluntary rather than mandatory. Recovery Time Objective for critical operations remains two hours; Recovery Point Objective remains fifteen minutes.

MII Interoperability Framework , MII interoperability framework (live 1 April 2025) 28 Nov 2024
Plain summary: SEBI Interoperability Framework notified November 2024, effective 1 April 2025. MIIs must invoke alternative trading venues on outage. Exchange must intimate SEBI within 75 minutes of outage. Alternate venue must be invoked within 15 minutes of SEBI intimation. Regular updates at 45-minute intervals until service is restored.
SEBI Framework for Interoperability of Market Infrastructure Institutions for Business Continuity, effective 1 April 2025. On material outage at any exchange, the affected exchange shall intimate SEBI within 75 minutes of outage. Alternate trading venue shall be invoked within 15 minutes of SEBI intimation. Status updates shall be provided to SEBI at 45-minute intervals until normal service is restored.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.