SEBI CSCRF Compliance: A Practical Checklist for Regulated Entities
A clear checklist for regulated entities working through SEBI's Cybersecurity and Cyber Resilience Framework.
By PITOWINGS Team
If your business is regulated by SEBI, the Cybersecurity and Cyber Resilience Framework (CSCRF) is no longer something you can put off. It consolidates SEBI's cyber requirements into a single, stricter framework, and it applies across a wide range of regulated entities. This checklist breaks it down clearly, step by step.
Who needs to comply?
CSCRF applies to SEBI-regulated entities including:
- Stock Brokers and Depository Participants
- Portfolio Managers
- Investment Advisers and Research Analysts
- Mutual Funds, AMCs and other market intermediaries
Crucially, if you hold more than one SEBI registration, you must meet the strictest requirements that apply across all your categories — you cannot pick the easiest one.
The core building blocks
CSCRF is organised around a set of cyber-resilience goals: anticipate, withstand, contain, recover and evolve. In practice, becoming compliant means putting the following in place.
Your CSCRF checklist
- Classify your entity — determine your category and size threshold (which decides how strict your obligations are).
- Cybersecurity policy — a board-approved policy covering governance, roles and responsibilities.
- Risk assessment — identify and rank your critical systems and data.
- Access controls — least-privilege access, multi-factor authentication and strong identity management.
- VAPT — regular vulnerability assessments and penetration testing of critical systems.
- SOC / monitoring — continuous security monitoring, ideally through a Security Operations Centre.
- Incident response plan — documented procedures, including the ability to report incidents to SEBI within the required timeframe.
- Audit trails and logging — tamper-resistant logs retained for the required period.
- Employee training — regular cyber-hygiene awareness for all staff.
- Third-party / vendor risk — assess the security of your critical service providers.
The single most common gap we see is incident response: firms have firewalls, but no tested plan for the first six hours after a breach — exactly when SEBI expects to hear from you.
Getting audit-ready without disruption
Compliance projects fail when they try to do everything at once. A better approach is a gap assessment first — a clear picture of where you stand against each requirement — followed by a prioritised roadmap that fixes the highest-risk gaps first and schedules the rest so day-to-day operations are never disrupted.
How PITOWINGS helps
PITOWINGS provides end-to-end CSCRF support: threshold classification, policy drafting, VAPT, SOC monitoring, incident-response readiness, staff training and multi-registration unification — with certified professionals experienced in financial and market-infrastructure entities. We get you inspection-ready with zero business disruption.
PITOWINGS Team
Predictive cybersecurity experts — VAPT, SOC, forensics & J.I.M.M.Y.
Keep reading
What is VAPT? A Simple Guide for Indian Businesses (2026)
A simple, jargon-free guide to Vulnerability Assessment and Penetration Testing — what it is, when you need it, and what to expect.
Read more →In-House SOC vs Managed SOC: A Cost Comparison for Indian SMEs
Which model actually makes sense for Indian SMEs — and how to decide.
Read more →You've Been Hacked — The First 5 Steps to Take Right Now
A calm, practical survival guide for the first hour of a security incident.
Read more →