Compliance · SEBI CSCRF SEBI CSCRF · 20 August 2024 · 5 RE categories

SEBI CSCRF Cyber Audit & VAPT for Regulated Entities

SEBI now expects every regulated entity — from stock exchanges to small brokers — to prove its cyber resilience under one consolidated framework, the CSCRF. As a CERT-In empaneled assessor, Intect conducts the mandated cyber audit and VAPT, and validates your controls the way an attacker would test them — so the compliance you submit to SEBI is evidenced, not just declared.

CERT-In Empaneled. Aligned to SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF). We test the controls we audit.

SEBI CSCRF 5 RE categories 6 cybersecurity functions CERT-In Empaneled
Framework
SEBI CSCRF — circular 20 August 2024
Structure
5 RE categories · 5 resilience goals · 6 functions
Role
CERT-In empaneled — cyber audit & VAPT conducted directly
Live now
Most REs by 31 Aug 2025 · MIIs/KRAs/QRTAs since 1 Jan 2025
02

One framework, replacing a decade of scattered circulars

The Cybersecurity and Cyber Resilience Framework — CSCRF — is SEBI's single, consolidated rulebook for how its regulated entities must defend themselves against cyber attacks and recover from them.

For years, SEBI's cyber-security expectations were spread across separate circulars issued to different intermediaries: one for Market Infrastructure Institutions, others for brokers and depository participants, mutual funds, KRAs, portfolio managers and more. CSCRF brings them together. It is standards-based, graded by the size and role of each entity, and it requires something stronger than a policy on file — it requires evidence that controls actually work, reported to SEBI in standardized formats on a defined cadence.

The framework was issued on 20 August 2024 and supersedes SEBI's existing cyber-security circulars, guidelines, advisories and letters — the superseded list is set out in the framework itself. It is built on five cyber resilience goals — Anticipate, Withstand, Contain, Recover and Evolve — drawn from CERT-In's Cyber Crisis Management Plan, mapped across six cybersecurity functions: Governance, Identify, Protect, Detect, Respond and Recover. After two extensions, the implementation deadline for most regulated entities settled at 31 August 2025; MIIs, KYC Registration Agencies and Qualified RTAs were already in scope from 1 January 2025. The framework is now live — and the cyber audit and VAPT it mandates are how a regulated entity proves it complies.

"CSCRF turns cyber resilience from a policy you keep on file into a result you have to prove. A control you have written down is a claim. A control we have tested is compliance you can submit."
03

Five categories, one graded framework

CSCRF follows a graded approach: it classifies every SEBI Regulated Entity into one of five categories based on its span of operations and thresholds such as number of clients, trading volume and assets under management — and scales the obligations accordingly.

A stock exchange carries the full weight of the framework; a small intermediary self-certifies against a proportionate subset. We scope every engagement to the category that binds you, and to the standards and mandatory guidelines that apply at that tier.

CSCRF grades every SEBI Regulated Entity into one of five categories — obligations scale with size and role.

Whatever your category, the framework examines the same families of control — governance, identification, protection, detection, response and recovery — calibrated to the obligations of your tier. The audit and VAPT scale with you; the underlying discipline does not change.

04

What CSCRF is built on

We anchor every engagement to the live SEBI text — so the audit you submit is current, defensible and mapped to the right standard.

01

The CSCRF circular (20 August 2024)

SEBI's consolidated Cybersecurity and Cyber Resilience Framework — issued 20 August 2024 — which supersedes SEBI's earlier cyber-security circulars, guidelines and advisories and folds them into one standards-based framework. It is organized in four parts: objectives and standards, guidelines, compliance formats, and annexures (including the VAPT scope and auditor guidelines). Subsequent SEBI clarifications and extensions (December 2024, April 2025, June 2025) refine categorisation thresholds and timelines.

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113
02

Five cyber resilience goals, six functions

The framework is structured on five cyber resilience goals — Anticipate, Withstand, Contain, Recover, Evolve — adopted from CERT-In's Cyber Crisis Management Plan, and aligned to the NIST Cybersecurity Framework. These are delivered across six cybersecurity functions: Governance, Identify, Protect, Detect, Respond and Recover.

03

Mandated controls — VAPT, SOC/M-SOC, SBOM and more

CSCRF mandates concrete, testable controls: Vulnerability Assessment and Penetration Testing against a defined scope and cadence; a Security Operations Centre (own, group, third-party or Market-SOC) for continuous monitoring; data classification; a Software Bill of Materials (SBOM); ISO 27001 for MIIs and Qualified REs; and red-teaming exercises for MIIs and Qualified REs.

04

CERT-In empanelment

CSCRF specifies that, unless otherwise stated, all audits and certifications under the framework — including the cyber audit and VAPT — must be conducted by a CERT-In empanelled IS auditing organisation. Intect is CERT-In empaneled.

CERT-IN EMPANELED
05

How a CSCRF audit runs

A disciplined, evidence-led path from category scoping to SEBI submission — built so your team always knows where the audit stands and what to act on next.

01
Scoping & RE-Category
Establish your CSCRF category — MII, Qualified, Mid-size, Small-size or Self-certification RE — and the standards and mandatory guidelines that bind you at that tier. Define which critical and non-critical systems, applications and locations are in scope.
02
Governance & Document Review
Examine the cyber-security and cyber-resilience policy, board/partner approvals, the cyber risk-management framework, incident-response and crisis-management plans, SOC arrangements and prior audit findings — establishing the design of your controls.
03
Control Testing (6 Functions)
Test controls in operation across Governance, Identify, Protect, Detect, Respond and Recover: access and authentication, network segmentation, encryption, logging and monitoring, SOC efficacy, data classification, SBOM and recovery readiness.
04 · VAPT
Technical Validation (VAPT)
Independently validate the controls by testing them — vulnerability assessment and penetration testing against the CSCRF VAPT scope, covering critical systems, infrastructure and IT systems on the cadence the framework expects — so exposure is proven, not assumed.
05
Gap Analysis vs CSCRF
Measure each finding against the applicable CSCRF standard and mandatory guideline, assign severity and risk, and separate true gaps from documentation issues.
06
Reporting
Deliver the cyber audit report and VAPT report in SEBI's standardized formats, written for both the engineers who will remediate and the Board/Partners who must approve — with evidence and concrete remediation guidance.
07
Remediation
Work alongside your team as findings are closed, support revalidation, and help you categorise and track any open observations through your IT Committee within the framework's closure timelines.
08 · TO SEBI
SEBI Compliance Submission
Support timely submission of the cyber audit and VAPT reports to the correct reporting authority — SEBI, the stock exchanges/depositories or BASL, depending on your entity type — with the MD/CEO declaration the framework requires.

FIG. 02 — CSCRF audit lifecycle · 8 steps, scoping to SEBI submission · node 04 is the offensive edge (VAPT)

06

What an engagement includes

We scope to your CSCRF category and cover the work end to end — from establishing applicability to supporting your submission to SEBI.

Assess 3 ITEMS
  • RE-category determination and CSCRF applicability mapping (standards + mandatory guidelines for your tier)
  • Critical-system identification and scope definition
  • Governance, policy and document review against CSCRF
Test 3 ITEMS
  • Control testing across the six functions — Governance, Identify, Protect, Detect, Respond, Recover
  • SOC arrangement and functional-efficacy review (own / group / third-party / Market-SOC)
  • Data-classification, SBOM and recovery-readiness review
Validate (the offensive edge) 3 ITEMS
  • VAPT against the CSCRF VAPT scope — critical systems, infrastructure and IT systems
  • Red-teaming-style resilience testing where mandated (MIIs and Qualified REs)
  • Remediation revalidation after fixes
Report 3 ITEMS
  • Cyber audit report in SEBI's standardized format
  • VAPT report in the prescribed format, with the MD/CEO declaration
  • Gap analysis, severity-rated findings and a prioritized remediation roadmap
Sustain 3 ITEMS
  • Open-observation categorisation and closure tracking through your IT Committee
  • Support for submission to the correct reporting authority
  • Ongoing cadence planning for the next audit cycle and continuous compliance
07

We don't just read your controls. We test them.

CSCRF doesn't ask you to declare that your controls work — it mandates that you prove it, through VAPT and, for the largest entities, red teaming. That is exactly what we do.

Confirms the claim

The document-only audit

A compliance-only audit reviews policies, interviews owners and samples evidence to confirm a control is documented and, on paper, operating. It is necessary work — and it is where many audits stop. But CSCRF was written precisely because a well-drafted policy and a control that withstands attack are not the same thing, and the difference is what an adversary exploits. The framework's own emphasis on VAPT, SOC efficacy and red teaming reflects that.

Proves the control

The technically validated audit

Intect comes from offensive security. So we treat the VAPT and resilience testing CSCRF mandates not as a checkbox but as the core of the assurance — vulnerability assessment, penetration testing and, where the framework requires it, red-teaming exercises that turn "we have controls" into demonstrated evidence of what an attacker can and cannot reach. You submit findings backed by proof of real exposure, and a compliance position your Board and SEBI can trust because it has been earned.

We are CERT-In empaneled, so the audit and VAPT are conducted by the assessor CSCRF requires — and we come from offensive security, so they are genuinely validated. CSCRF asks you to prove resilience; proving it is what we do.

See also: Web Application VAPT · Network VAPT · Red Team Assessment.

VAPT-BACKED EVIDENCE
08

What you receive

Every engagement ends in the reports CSCRF requires you to submit — and the underlying evidence your Board, your IT Committee and SEBI can act on. Written for the engineers who will remediate and the leadership accountable for the risk.

01

CSCRF cyber audit report

A structured report in SEBI's standardized format, covering each cybersecurity function, with findings, severity and risk mapped to the applicable CSCRF standard and mandatory guideline.

02

VAPT report

Findings against the CSCRF VAPT scope in the prescribed format, with reproducible proof-of-concept, demonstrated impact and the MD/CEO declaration the framework requires.

VAPT-BACKED
03

RE-category & applicability assessment

A clear determination of your CSCRF category and the standards and guidelines that bind you at that tier.

04

Gap analysis & remediation roadmap

Prioritized, specific remediation guidance with clear ownership and sequencing — and support for categorising and closing open observations within CSCRF timelines.

05

Executive & Board/Partner summary

Cyber posture and the state of CSCRF compliance in plain language for senior management and the Board.

06

Submission support & revalidation

Help submitting the reports to the correct reporting authority, and revalidation of remediated controls so closure is evidenced.

CERT-In Empaneled SEBI CSCRF 5 Cyber Resilience Goals 6 Cybersecurity Functions VAPT-backed validation
09

Why regulated entities choose Intect

CERT-In Empaneled Researcher-led · offensive heritage

CERT-In Empaneled — The credential CSCRF requires for the cyber audit and VAPT — so the assurance behind your SEBI submission is accepted where it counts.

Offensive heritage — We come from penetration testing and red teaming. CSCRF mandates exactly that kind of testing; we treat it as the heart of the audit, not an afterthought.

Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the framework and the adversary — so findings are accurate, contextual and defensible.

Delhi-based, regulator-fluent — An India-based team that speaks the language of SEBI directions and the Indian securities-market landscape, available to your team through the engagement.

10

Related regulatory assurance

Financial-sector compliance spans several distinct regulators and audits. This page covers SEBI's CSCRF cyber audit and VAPT; for adjacent mandates, see the dedicated pages.

11

Frequently asked questions

Is a CSCRF cyber audit a certification?

No. CSCRF compliance is demonstrated through a cyber audit and VAPT, reported to SEBI in standardized formats — not through a certificate SEBI issues. The engagement produces a cyber audit report and a VAPT report that evidence how well your controls comply with the framework. (Separately, CSCRF makes ISO 27001 certification mandatory for MIIs and Qualified REs — but that certificate is issued by an accredited certification body, not by SEBI or by us.)

Who is allowed to conduct it?

CSCRF specifies that, unless otherwise stated, all audits and certifications under the framework — including the cyber audit and VAPT — must be conducted by a CERT-In empanelled IS auditing organisation. Intect is CERT-In empaneled, so we can conduct both the audit and the technical validation behind it.

Which CSCRF category are we in, and does it change what we have to do?

Yes — substantially. CSCRF grades entities into five categories: Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs, based on thresholds such as client numbers, trading volume and assets under management. The largest entities carry the full framework — CCI, red teaming, ISO 27001, Market-SOC efficacy reporting — while smaller entities meet a proportionate subset, down to self-certification. Establishing your category correctly is the first thing we do, because everything else follows from it.

When did CSCRF take effect?

CSCRF was issued on 20 August 2024. After two extensions, the implementation deadline for most regulated entities settled at 31 August 2025; MIIs, KYC Registration Agencies and Qualified RTAs were already in scope from 1 January 2025. The framework is live now, and the cyber audit and VAPT it mandates run on a defined periodic cadence thereafter.

What's the difference between the VAPT and the cyber audit?

They are complementary. The cyber audit verifies your compliance with the CSCRF standards and mandatory guidelines across the six functions. The VAPT independently tests your systems for exploitable vulnerabilities against the framework’s defined VAPT scope. CSCRF mandates both, in standardized report formats; we deliver them together so the audit’s findings and the technical evidence reinforce each other.

Do you help us fix the findings, or just report them?

Both. We deliver a prioritized remediation roadmap, support your team through the fixes, help you categorise and track open observations through your IT Committee within the framework’s closure timelines, and revalidate remediated controls so closure is evidenced — not just claimed.

Scope a CSCRF audit

Prove your resilience. Satisfy SEBI.

Tell us your entity type and CSCRF category, and we'll scope a cyber audit and VAPT that fits — or connect you directly with an assessor.