SEBI CSCRF Cyber Audit & VAPT for Regulated Entities
SEBI now expects every regulated entity — from stock exchanges to small brokers — to prove its cyber resilience under one consolidated framework, the CSCRF. As a CERT-In empaneled assessor, Intect conducts the mandated cyber audit and VAPT, and validates your controls the way an attacker would test them — so the compliance you submit to SEBI is evidenced, not just declared.
CERT-In Empaneled. Aligned to SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF). We test the controls we audit.
One framework, replacing a decade of scattered circulars
The Cybersecurity and Cyber Resilience Framework — CSCRF — is SEBI's single, consolidated rulebook for how its regulated entities must defend themselves against cyber attacks and recover from them.
For years, SEBI's cyber-security expectations were spread across separate circulars issued to different intermediaries: one for Market Infrastructure Institutions, others for brokers and depository participants, mutual funds, KRAs, portfolio managers and more. CSCRF brings them together. It is standards-based, graded by the size and role of each entity, and it requires something stronger than a policy on file — it requires evidence that controls actually work, reported to SEBI in standardized formats on a defined cadence.
The framework was issued on 20 August 2024 and supersedes SEBI's existing cyber-security circulars, guidelines, advisories and letters — the superseded list is set out in the framework itself. It is built on five cyber resilience goals — Anticipate, Withstand, Contain, Recover and Evolve — drawn from CERT-In's Cyber Crisis Management Plan, mapped across six cybersecurity functions: Governance, Identify, Protect, Detect, Respond and Recover. After two extensions, the implementation deadline for most regulated entities settled at 31 August 2025; MIIs, KYC Registration Agencies and Qualified RTAs were already in scope from 1 January 2025. The framework is now live — and the cyber audit and VAPT it mandates are how a regulated entity proves it complies.
"CSCRF turns cyber resilience from a policy you keep on file into a result you have to prove. A control you have written down is a claim. A control we have tested is compliance you can submit."
Five categories, one graded framework
CSCRF follows a graded approach: it classifies every SEBI Regulated Entity into one of five categories based on its span of operations and thresholds such as number of clients, trading volume and assets under management — and scales the obligations accordingly.
A stock exchange carries the full weight of the framework; a small intermediary self-certifies against a proportionate subset. We scope every engagement to the category that binds you, and to the standards and mandatory guidelines that apply at that tier.
CSCRF grades every SEBI Regulated Entity into one of five categories — obligations scale with size and role.
Market Infrastructure Institutions (MIIs) — Stock Exchanges · Clearing Corporations · Depositories.
Qualified REs — Largest intermediaries — e.g. Qualified Stock Brokers, large Depository Participants, KRAs, QRTAs, and others above the qualifying thresholds.
Mid-size REs — Mid-tier intermediaries by clients / trade volume / AUM.
Small-size REs — Smaller intermediaries below the mid-size thresholds.
Self-certification REs — Smallest entities — proportionate, self-certified compliance.
Built on five cyber resilience goals, across six functions
Adopted from CERT-In's Cyber Crisis Management Plan and aligned to the NIST Cybersecurity Framework.
Whatever your category, the framework examines the same families of control — governance, identification, protection, detection, response and recovery — calibrated to the obligations of your tier. The audit and VAPT scale with you; the underlying discipline does not change.
What CSCRF is built on
We anchor every engagement to the live SEBI text — so the audit you submit is current, defensible and mapped to the right standard.
The CSCRF circular (20 August 2024)
SEBI's consolidated Cybersecurity and Cyber Resilience Framework — issued 20 August 2024 — which supersedes SEBI's earlier cyber-security circulars, guidelines and advisories and folds them into one standards-based framework. It is organized in four parts: objectives and standards, guidelines, compliance formats, and annexures (including the VAPT scope and auditor guidelines). Subsequent SEBI clarifications and extensions (December 2024, April 2025, June 2025) refine categorisation thresholds and timelines.
Five cyber resilience goals, six functions
The framework is structured on five cyber resilience goals — Anticipate, Withstand, Contain, Recover, Evolve — adopted from CERT-In's Cyber Crisis Management Plan, and aligned to the NIST Cybersecurity Framework. These are delivered across six cybersecurity functions: Governance, Identify, Protect, Detect, Respond and Recover.
Mandated controls — VAPT, SOC/M-SOC, SBOM and more
CSCRF mandates concrete, testable controls: Vulnerability Assessment and Penetration Testing against a defined scope and cadence; a Security Operations Centre (own, group, third-party or Market-SOC) for continuous monitoring; data classification; a Software Bill of Materials (SBOM); ISO 27001 for MIIs and Qualified REs; and red-teaming exercises for MIIs and Qualified REs.
CERT-In empanelment
CSCRF specifies that, unless otherwise stated, all audits and certifications under the framework — including the cyber audit and VAPT — must be conducted by a CERT-In empanelled IS auditing organisation. Intect is CERT-In empaneled.
How a CSCRF audit runs
A disciplined, evidence-led path from category scoping to SEBI submission — built so your team always knows where the audit stands and what to act on next.
FIG. 02 — CSCRF audit lifecycle · 8 steps, scoping to SEBI submission · node 04 is the offensive edge (VAPT)
What an engagement includes
We scope to your CSCRF category and cover the work end to end — from establishing applicability to supporting your submission to SEBI.
Assess
- RE-category determination and CSCRF applicability mapping (standards + mandatory guidelines for your tier)
- Critical-system identification and scope definition
- Governance, policy and document review against CSCRF
Test
- Control testing across the six functions — Governance, Identify, Protect, Detect, Respond, Recover
- SOC arrangement and functional-efficacy review (own / group / third-party / Market-SOC)
- Data-classification, SBOM and recovery-readiness review
Validate (the offensive edge)
- VAPT against the CSCRF VAPT scope — critical systems, infrastructure and IT systems
- Red-teaming-style resilience testing where mandated (MIIs and Qualified REs)
- Remediation revalidation after fixes
Report
- Cyber audit report in SEBI's standardized format
- VAPT report in the prescribed format, with the MD/CEO declaration
- Gap analysis, severity-rated findings and a prioritized remediation roadmap
Sustain
- Open-observation categorisation and closure tracking through your IT Committee
- Support for submission to the correct reporting authority
- Ongoing cadence planning for the next audit cycle and continuous compliance
We don't just read your controls. We test them.
CSCRF doesn't ask you to declare that your controls work — it mandates that you prove it, through VAPT and, for the largest entities, red teaming. That is exactly what we do.
The document-only audit
A compliance-only audit reviews policies, interviews owners and samples evidence to confirm a control is documented and, on paper, operating. It is necessary work — and it is where many audits stop. But CSCRF was written precisely because a well-drafted policy and a control that withstands attack are not the same thing, and the difference is what an adversary exploits. The framework's own emphasis on VAPT, SOC efficacy and red teaming reflects that.
The technically validated audit
Intect comes from offensive security. So we treat the VAPT and resilience testing CSCRF mandates not as a checkbox but as the core of the assurance — vulnerability assessment, penetration testing and, where the framework requires it, red-teaming exercises that turn "we have controls" into demonstrated evidence of what an attacker can and cannot reach. You submit findings backed by proof of real exposure, and a compliance position your Board and SEBI can trust because it has been earned.
We are CERT-In empaneled, so the audit and VAPT are conducted by the assessor CSCRF requires — and we come from offensive security, so they are genuinely validated. CSCRF asks you to prove resilience; proving it is what we do.
See also: Web Application VAPT · Network VAPT · Red Team Assessment.
VAPT-BACKED EVIDENCEWhat you receive
Every engagement ends in the reports CSCRF requires you to submit — and the underlying evidence your Board, your IT Committee and SEBI can act on. Written for the engineers who will remediate and the leadership accountable for the risk.
CSCRF cyber audit report
A structured report in SEBI's standardized format, covering each cybersecurity function, with findings, severity and risk mapped to the applicable CSCRF standard and mandatory guideline.
VAPT report
Findings against the CSCRF VAPT scope in the prescribed format, with reproducible proof-of-concept, demonstrated impact and the MD/CEO declaration the framework requires.
RE-category & applicability assessment
A clear determination of your CSCRF category and the standards and guidelines that bind you at that tier.
Gap analysis & remediation roadmap
Prioritized, specific remediation guidance with clear ownership and sequencing — and support for categorising and closing open observations within CSCRF timelines.
Executive & Board/Partner summary
Cyber posture and the state of CSCRF compliance in plain language for senior management and the Board.
Submission support & revalidation
Help submitting the reports to the correct reporting authority, and revalidation of remediated controls so closure is evidenced.
Why regulated entities choose Intect
CERT-In Empaneled — The credential CSCRF requires for the cyber audit and VAPT — so the assurance behind your SEBI submission is accepted where it counts.
Offensive heritage — We come from penetration testing and red teaming. CSCRF mandates exactly that kind of testing; we treat it as the heart of the audit, not an afterthought.
Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the framework and the adversary — so findings are accurate, contextual and defensible.
Delhi-based, regulator-fluent — An India-based team that speaks the language of SEBI directions and the Indian securities-market landscape, available to your team through the engagement.
Related regulatory assurance
Financial-sector compliance spans several distinct regulators and audits. This page covers SEBI's CSCRF cyber audit and VAPT; for adjacent mandates, see the dedicated pages.
Frequently asked questions
Is a CSCRF cyber audit a certification?
No. CSCRF compliance is demonstrated through a cyber audit and VAPT, reported to SEBI in standardized formats — not through a certificate SEBI issues. The engagement produces a cyber audit report and a VAPT report that evidence how well your controls comply with the framework. (Separately, CSCRF makes ISO 27001 certification mandatory for MIIs and Qualified REs — but that certificate is issued by an accredited certification body, not by SEBI or by us.)
Who is allowed to conduct it?
CSCRF specifies that, unless otherwise stated, all audits and certifications under the framework — including the cyber audit and VAPT — must be conducted by a CERT-In empanelled IS auditing organisation. Intect is CERT-In empaneled, so we can conduct both the audit and the technical validation behind it.
Which CSCRF category are we in, and does it change what we have to do?
Yes — substantially. CSCRF grades entities into five categories: Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs, based on thresholds such as client numbers, trading volume and assets under management. The largest entities carry the full framework — CCI, red teaming, ISO 27001, Market-SOC efficacy reporting — while smaller entities meet a proportionate subset, down to self-certification. Establishing your category correctly is the first thing we do, because everything else follows from it.
When did CSCRF take effect?
CSCRF was issued on 20 August 2024. After two extensions, the implementation deadline for most regulated entities settled at 31 August 2025; MIIs, KYC Registration Agencies and Qualified RTAs were already in scope from 1 January 2025. The framework is live now, and the cyber audit and VAPT it mandates run on a defined periodic cadence thereafter.
What's the difference between the VAPT and the cyber audit?
They are complementary. The cyber audit verifies your compliance with the CSCRF standards and mandatory guidelines across the six functions. The VAPT independently tests your systems for exploitable vulnerabilities against the framework’s defined VAPT scope. CSCRF mandates both, in standardized report formats; we deliver them together so the audit’s findings and the technical evidence reinforce each other.
Do you help us fix the findings, or just report them?
Both. We deliver a prioritized remediation roadmap, support your team through the fixes, help you categorise and track open observations through your IT Committee within the framework’s closure timelines, and revalidate remediated controls so closure is evidenced — not just claimed.
Prove your resilience. Satisfy SEBI.
Tell us your entity type and CSCRF category, and we'll scope a cyber audit and VAPT that fits — or connect you directly with an assessor.