Technical Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)
X X X X Extracts X X X X
X X X X Extracts X X X X
....upervisory body- IAASB) BSE Limited (Research Analysts Administration and supervisory body- RAASB) Sir / Madam, Subject: Technical Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) 1. Recognising the need for robust cybersecurity measures and protection of data and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued 'Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)' vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. 2. Upon receipt of various queries from REs seeking extension and clarification on the aforementioned circular, SEBI has also issued following clarifications and Frequently Asked Questions (FAQs): S. No. Circular Title Circular Number Date of Issuance 1. Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF)for SEBI Regulated Entities (REs) SEBI/HO/ITD-1/ ITD_CSC_EXT/ P/CIR/2024/184 December 31, 2024 2. Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) SEBI/HO/ITD-1/ ITD_CSC_EXT/ ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... for SEBI regulated activities. Further, the shared infrastructure/ network/ technology stack, security solutions shall be included in the audit/ inspection scope by SEBI, if the same is not covered under audit/ inspection scope by primary regulator and their frameworks/ guidelines. Following are representative examples of the standards and corresponding guidelines as mentioned in CSCRF: Table 1: Representatives examples under Principle of Exclusivity S. No. CSCRF Standard/ Guidelines CSCRF Clause 1. Data Classification (Regulatory Data, and IT and Cybersecurity Data) and Data Localisation (currently in abeyance vide SEBI circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/184 dated December 31, 2024) Box Item 9, Box Item 10, and PR.DS.S1-3 Guidelines (Page 107) 2. Definition and classification of Critical/ non-critical systems Definitions (Page 26), ID.AM.S1 and ID.AM.S4 Guidelines (Page 90) 3. VAPT scope Scope given in Annexure-A (Page 136), Annexure-L, and DE.CM.S5 Guideline 2 (Page 120) 4. Asset inventory updation timelines ID.AM.S1 and ID.AM.S4 Guidelines 3 (Page 90) 5. Patch management timelines PR.MA.S3 Guidelines 11 (Pa....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ritical systems either for operations or for maintenance." Clarification: Above-mentioned para (f) shall now be read as under: Any other system which is on the same network segment where systems mentioned in para (a) to (e) are deployed. 6.2. Zero-trust security model (PR.AA.S4 and PR.AA.S5 guidelines - Page 97): "REs shall follow zero-trust security model in such a way that access (from within or outside REs' network) to their critical systems is denied by default and allowed only after proper authentication and authorization." Clarification: Above-mentioned guidelines shall now be read as under: REs shall implement suggested strategies/ methodologies such as Zero-trust networks, segmentation, no single point of failure, high availability, etc. Further, the same shall be approved by IT committee for REs. 6.3. Mobile Application Security guidelines (PR.AA.S16 and corresponding guidelines - Page 102-103) Clarification: Above-mentioned guidelines are recommendatory (not mandatory) in nature. 6.4. RS.CO.S2 guidelines (Page 124-125): "If the cyber-attack is of high impact and has a broad reach, the RE shall give a press release which shall include (but not limited to)....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... 118) and (Clause 2.2, 2.6, 2.7 and 3 of SEBI circular vide SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2025/60 dated April 30, 2025) have been mandated to be on boarded on Market-SOC. Please refer Q. 60 of CSCRF FAQs [Refer https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf] issued vide dated June 11, 2025: Question: In a scenario where an RE falling under small-size or self-certification REs category has its own SOC, is it necessary for such REs to get onboarded to Market-SOC? Answer: It is imperative that setting up own SOC is a costly proposition. Hence, SEBI has mandated NSE and BSE to setup Market-SOC (M-SOC) where small-size REs and self-certification REs can get onboarded and take the benefit to stay cyber secure and resilient. However, REs who have their own SOC and falling under the category of small-size REs or self-certification REs by virtue of their regulatory activity may leverage their existing SOC. Further, such REs shall be required to submit the SOC efficacy report periodically as mandated in CSCRF 6.10. RC.RP.S2 guideline (Page 128-129): "In the event of disruption of any one or more of the critical systems, the RE shall, within 30 minutes of th....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ore than Rs. 3000 Crores and less than Rs. 10,000 Crores Rs. 3000 Crores and below 7.2. Merchant Bankers (MBs) Table 2: Criteria and thresholds for MBs categorization S. No. Criteria Merchant Bankers (MBs) categorisation for CSCRF 1. All active Merchant Bankers (i.e., who have undertaken any merchant banking activity during the relevant period) Small-size REs 2. All inactive Merchant Bankers (i.e., those have not undertaken any merchant banking activities in the relevant review period. Exempt from CSCRF Part - D: Cyber Security Audit Policy Guidelines from CERT-In 8. CERT-In has issued comprehensive Cyber Security Audit Policy Guidelines [ https://www.cert-in.org.in/PDF/Comprehensive_Cyber_Security_Audit_Policy_Guidelines.pdf]. These guidelines are intended to serve as a reference both CERT-In empanelled auditing organisations and auditee organisations. REs shall follow these guidelines to ensure a consistent, effective and secure approach to cyber security audits. 9. Stock Exchanges/ Depositories are directed to: 9.1. Make necessary amendments to the relevant byelaws, rules and regulations for the implementation of the above directio....
TaxTMI