Infosek
INFOSEK

SEBI CSCRF Requirements by RE Category: MII, QRE and SRE Explained

Confused about which SEBI CSCRF requirements apply to your firm? This guide breaks down obligations by RE category — MII, Qualified RE, and Standard RE.

SEBI CSCRF Requirements by RE Category: MII, QRE and SRE Explained

Why the RE Category Matters

SEBI's CSCRF operates on a risk-proportionate model. Entities that are more systemically important, process higher volumes, or have greater exposure to retail investors face more stringent requirements. Before you build your compliance roadmap, you need to know with certainty which category your firm belongs to — and if you are near a threshold, you must plan for the possibility of reclassification.

Category 1: Market Infrastructure Institutions (MII)

MIIs are at the apex of India's securities market infrastructure. They include recognised stock exchanges (BSE, NSE, etc.), depositories (CDSL, NSDL), and clearing corporations. These entities operate the systems on which the entire market depends, so SEBI holds them to the highest cybersecurity standard.

Key MII Requirements

Category 2: Qualified Regulated Entities (QRE)

QREs are market intermediaries that exceed SEBI-specified thresholds of trading volume, client base, or operational scale. The majority of large stockbrokers and major depository participants fall into this category. If you are a stockbroker with significant retail client volume or a DP operating at scale, QRE classification is the most relevant category for you. For the complete list of controls QREs must implement, refer to our SEBI CSCRF Compliance Checklist.

Key QRE Requirements

Category 3: Standard Regulated Entities (SRE)

SREs are smaller market intermediaries — those below the QRE thresholds. This typically includes smaller sub-brokers, investment advisers with smaller AUM, and boutique intermediaries. While the compliance requirements are lighter relative to QREs, they are not trivial. SREs are still required to maintain basic cybersecurity hygiene.

Key SRE Requirements

The most common mistake we see is firms operating as QREs but treating themselves as SREs — often because no one has formally assessed which category applies. A reclassification audit finding is far more damaging than proactively preparing for the right tier.

Infosek Team

Key Differences Between Categories

Compliance Timelines

SEBI issued CSCRF in August 2024 and has provided a phased implementation timeline. MIIs were expected to comply immediately; QREs had a defined onboarding period; SREs have longer runway but must demonstrate progress. Industry experience shows that QREs that start their readiness programmes well in advance fare significantly better in audits than those who begin close to the deadline. For common failure modes, read our article on 5 Reasons Stockbrokers Fail Their SEBI Cyber Audit.

Common questions

What are the three SEBI CSCRF regulated entity categories?

Market Infrastructure Institutions, which include stock exchanges, clearing corporations and depositories; Qualified Regulated Entities, which are market intermediaries exceeding SEBI-specified thresholds; and Standard Regulated Entities, which covers the remainder.

What is a Qualified Regulated Entity under CSCRF?

A market intermediary that exceeds SEBI-specified thresholds of trading volume, client base or operational scale. Most large stockbrokers and major depository participants fall into this category.

Topics SEBI

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment