Skip to content
Back to Blog
·12 min read·Compliance

SEBI CSCRF Compliance Checklist for Stockbrokers India 2026 — Complete Guide

Complete SEBI CSCRF compliance checklist for Indian stockbrokers and regulated entities. June 30, 2026 deadline. 6-domain framework, evidence requirements, NSE/BSE submission guide, and penalties for non-compliance.

BS

Bachao.AI Security Team

Founder

Get Your Free VAPT Scan
SEBI CSCRF Compliance Checklist for Stockbrokers India 2026 — Complete Guide

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

What Is SEBI CSCRF and Why It Matters Now

The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) is a mandatory regulatory requirement for all SEBI-regulated entities in India. Introduced via SEBI circular SEBI/HO/ITD/ITD_VAPT/P/CIR/2023/168 (October 2023), it replaces the earlier 2019 cybersecurity circular and significantly raises the bar for all market intermediaries.

The June 30, 2026 deadline applies to:

    1. All Qualified Regulated Entities (QREs) — stockbrokers with more than 50,000 active clients
    2. All Mid-size Regulated Entities (MREs) — stockbrokers with 2,000–50,000 active clients
    3. Depository Participants
    4. Registrar and Transfer Agents (RTAs)
    5. KYC Registration Agencies (KRAs)
    6. Investment Advisors and Research Analysts with digital systems
Non-compliance risks: daily penalties of ₹1,500–₹5,000, suspension of trading operations, and adverse reporting to SEBI by NSE/BSE.


The 6-Domain SEBI CSCRF Framework — What Auditors Check

CSCRF is structured around six cybersecurity domains. Your audit report must address each domain with evidence.

Domain 1: Govern (Governance)

    1. Board-approved Cybersecurity Policy (reviewed annually)
    2. Designated CISO or equivalent with documented responsibilities
    3. Third-party vendor risk management policy
    4. Cybersecurity awareness training records (minimum annual)
    5. Cyber insurance policy (required for QREs)
Evidence required: Board resolution, policy document with version history, training attendance records, vendor risk register, CISO appointment letter.

Domain 2: Identify

    1. Comprehensive IT asset inventory (hardware, software, cloud resources)
    2. Network topology diagram (current)
    3. Data classification policy with data flow mapping
    4. Business impact analysis for critical systems
    5. Annual vulnerability assessment results
Evidence required: Asset register with last-updated date, network diagram, data flow diagram, BIA document, VA report.

Domain 3: Protect

    1. Multi-factor authentication (MFA) for all privileged access and remote access
    2. Patch management process (critical patches within 30 days, documented)
    3. Endpoint protection on all devices (EDR/antivirus with central management)
    4. Network segmentation between internet-facing and back-office systems
    5. Encryption of data at rest and in transit (TLS 1.2+ required)
    6. Privileged Access Management (PAM) for admin accounts
    7. Email security controls (SPF, DKIM, DMARC, anti-phishing)
    8. Web Application Firewall (WAF) for internet-facing applications
Evidence required: MFA policy and screenshots, patch management logs, AV dashboard, firewall rules, SSL certificate reports, PAM logs, DMARC records.

Domain 4: Detect

    1. SIEM or equivalent log aggregation (minimum 1-year log retention for QREs)
    2. Intrusion Detection System (IDS/IPS) on network perimeter
    3. File integrity monitoring on critical servers
    4. Vulnerability scanning — automated weekly or monthly
Evidence required: SIEM configuration screenshots, IDS alerts sample, FIM reports, scan reports with dates.

Domain 5: Respond

    1. Documented Incident Response Plan (IRP) with defined roles
    2. Cyber incident classification matrix (Critical / High / Medium / Low)
    3. CERT-In incident reporting process (6-hour notification requirement for critical incidents)
    4. Annual tabletop exercise or simulation (mandatory for QREs)
Evidence required: IRP document, incident log from last 12 months, tabletop exercise report, CERT-In reporting template.

Domain 6: Recover

    1. Business Continuity Plan (BCP) covering critical trading operations
    2. Disaster Recovery Plan (DRP) with documented RTO and RPO
    3. DR drill report — minimum annual (QREs: semi-annual)
    4. Data backup policy with off-site/cloud backup verification records
Evidence required: BCP/DRP document, DR drill report with screenshots, backup logs, RTO/RPO definitions.

SEBI CSCRF Compliance Checklist — Annex A (All Entities)

    1. [ ] Information Security Policy documented and board-approved
    2. [ ] Asset inventory maintained and updated quarterly
    3. [ ] MFA enabled for all privileged and remote access
    4. [ ] Patch management SOP with SLA (Critical: 30 days, High: 90 days)
    5. [ ] Antivirus/EDR deployed on all endpoints with central dashboard
    6. [ ] TLS 1.2+ enforced on all web-facing services
    7. [ ] Annual VAPT by CERT-In empanelled firm or equivalent
    8. [ ] Incident Response Plan documented
    9. [ ] CERT-In 6-hour reporting process defined
    10. [ ] Annual cybersecurity awareness training with records

Annex B — Additional Controls for QREs and MREs

    1. [ ] SIEM deployed with 1-year log retention
    2. [ ] IDS/IPS operational on network perimeter
    3. [ ] CISO appointed with board visibility
    4. [ ] Cyber insurance policy in place
    5. [ ] Vendor risk management with annual reviews
    6. [ ] Tabletop exercise conducted annually with report
    7. [ ] DR drill conducted semi-annually (QREs)

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Common Audit Failures — What Stockbrokers Get Wrong

1. Outdated asset inventory — Auditors require evidence the inventory was updated within the last quarter.

2. MFA not deployed on all privileged accounts — Firms often have MFA on email but not on trading systems or cloud consoles. CSCRF requires MFA everywhere privileged access exists.

3. Missing CERT-In 6-hour reporting SOP — The IT Amendment Rules 2022 require reporting certain cyber incidents to CERT-In within 6 hours. Almost no mid-size broker has this documented.

4. DR drill reports missing — Firms have DR sites but have not conducted or documented a drill in 2+ years.

5. No patch management logs — Firms patch systems but do not document it. CSCRF requires patch application evidence, not just a policy document.

6. Outdated network diagrams — Network topology submitted shows infrastructure from 2-3 years ago.

7. Vendor risk not assessed — Trading software vendors, payment gateways, and cloud providers not included in the vendor risk register.


NSE/BSE Submission Requirements

After completing the CSCRF audit, regulated entities must submit:

  1. Audit report in prescribed format with CISO sign-off and Board acknowledgement
  2. Executive summary (maximum 5 pages) with overall risk rating
  3. Control assessment matrix mapping each CSCRF control to compliance status
  4. Evidence index with SHA-256 hashes of key evidence documents
  5. Remediation plan for all gaps identified (with timelines)
Submission window: within 6 months of financial year end. For the June 30, 2026 deadline, this applies to entities that have not yet submitted their first report.

SEBI CSCRF Penalties for Non-Compliance

ViolationPenalty
Failure to submit audit report by deadline₹1,500–₹5,000 per day
Misrepresentation in audit reportSuspension of trading licence
Critical cyber incident not reported to CERT-In/SEBI₹1 crore+ per incident
Repeat non-complianceLicence cancellation proceedings

How to Get SEBI CSCRF Audit-Ready in 30 Days

Week 1 — Documentation Sprint:

    1. Collect and update: IT asset inventory, network diagram, all policies
    2. Identify gaps against Annex A and B checklists
Week 2 — Technical Controls:
    1. Enable MFA on all systems where missing
    2. Patch all critical vulnerabilities (CVSS 9.0+)
    3. Run automated VAPT to generate evidence
    4. Verify log retention configuration in SIEM
Week 3 — Evidence Collection:
    1. Run SIEM report for last 90 days
    2. Complete tabletop exercise and document the report
    3. Get CERT-In reporting SOP signed by CISO
Week 4 — Audit and Report:
    1. Engage certified auditor or automated audit service
    2. Review draft report against NSE/BSE format requirements
    3. Board acknowledgement sign-off and submit

Frequently Asked Questions

Is SEBI CSCRF mandatory or voluntary? Mandatory for all SEBI-regulated entities. Non-compliance results in daily penalties and potential licence action.

Do I need a CERT-In empanelled firm for SEBI CSCRF audit? SEBI does not explicitly mandate CERT-In empanelment for CSCRF audits. However, an external audit by a qualified cybersecurity firm with NSE/BSE-format report output is required.

What is the difference between VAPT and SEBI CSCRF audit? VAPT is one control under Domain 2 (Identify) of the CSCRF framework. A full CSCRF audit covers all six domains including governance, incident response, and BCP/DR — not just technical vulnerability scanning.

Is SEBI CSCRF the same as ISO 27001 or SOC 2? No. SEBI CSCRF is a SEBI-specific mandatory framework with India-specific requirements around NSE/BSE reporting formats and CERT-In incident reporting. ISO 27001 certification does not satisfy CSCRF audit requirements.


Last updated: April 2026. Reflects SEBI CSCRF requirements as of SEBI circular dated October 2023.

BS

Bachao.AI Security Team

Founder

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →