Infosek
INFOSEK

SEBI CSCRF Compliance Checklist for Stockbrokers & DPs [2025]

A practical SEBI CSCRF compliance checklist for stockbrokers and depository participants. Know exactly what controls, policies, and audits you need — and when.

SEBI CSCRF Compliance Checklist for Stockbrokers & DPs [2025]

What Is SEBI CSCRF?

The Cybersecurity & Cyber Resilience Framework (CSCRF) is SEBI's comprehensive directive that consolidates and strengthens cybersecurity requirements for all Regulated Entities (REs). Issued in August 2024 as a master framework, CSCRF replaces and supersedes prior SEBI circulars on cybersecurity and integrates international standards like NIST CSF, ISO 27001, and CERT-In guidelines into a single coherent structure. Every stockbroker, depository participant, investment adviser, and other market intermediary registered with SEBI must comply.

Who Must Comply: The Three RE Categories

SEBI CSCRF classifies all Regulated Entities into three tiers based on their systemic importance and transaction volumes. Understanding which category your firm falls into determines the depth of compliance required. For a detailed breakdown of each category's obligations, see our guide on SEBI CSCRF Requirements by RE Category: MII, QRE and SRE Explained.

The SEBI CSCRF Compliance Checklist

The following controls are mandatory across all RE categories (with enhanced requirements for QREs and MIIs). Use this as your working checklist before your next SEBI cyber audit.

1. Governance & Policy

2. Access Control

3. Vulnerability Assessment & Penetration Testing (VAPT)

4. Patch Management

5. Incident Response

6. Log Management & Monitoring

7. Business Continuity & Disaster Recovery

The CSCRF is not a one-time checklist exercise. SEBI auditors are increasingly looking for evidence of an ongoing programme — not a document binder assembled two weeks before the audit.

Infosek Team

The Annual Audit Timeline

SEBI requires annual IS audits for QREs and MIIs by a CERT-In empanelled auditor. The audit report must be submitted to SEBI within 30 days of completion. Most firms find that meaningful preparation needs to start at least 4–6 months before the audit date to address gaps identified in VAPT, policy reviews, and access control exercises. For common reasons firms fail at this stage, read our article on 5 Reasons Stockbrokers Fail Their SEBI Cyber Audit.

Key Takeaway

CSCRF compliance is not simply about having the right documents — auditors verify evidence of implementation and ongoing operation. Access control reviews need records. Patch management needs approved change logs. Incident response needs test reports. Start building your evidence trail well in advance of your audit date.

Common questions

Who must comply with SEBI CSCRF?

SEBI classifies regulated entities into three categories: Market Infrastructure Institutions such as stock exchanges and depositories, Qualified Regulated Entities which are market intermediaries exceeding SEBI-specified thresholds of trading volume, client base or operational scale, and Standard Regulated Entities. The controls required increase with the category.

Who can carry out the SEBI CSCRF information systems audit?

SEBI's CSCRF requires the IS audit to be carried out by a CERT-In empanelled auditor. A SOC 2 report from an external accounting firm does not satisfy this requirement.

Topics SEBI

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment