PITOWINGS — Secure Everywhere
All articles
Compliance2 June 2026·8 min read

SEBI CSCRF Compliance: A Practical Checklist for Regulated Entities

A clear checklist for regulated entities working through SEBI's Cybersecurity and Cyber Resilience Framework.

By PITOWINGS Team

CompliancePITOWINGS

If your business is regulated by SEBI, the Cybersecurity and Cyber Resilience Framework (CSCRF) is no longer something you can put off. It consolidates SEBI's cyber requirements into a single, stricter framework, and it applies across a wide range of regulated entities. This checklist breaks it down clearly, step by step.

Who needs to comply?

CSCRF applies to SEBI-regulated entities including:

  • Stock Brokers and Depository Participants
  • Portfolio Managers
  • Investment Advisers and Research Analysts
  • Mutual Funds, AMCs and other market intermediaries

Crucially, if you hold more than one SEBI registration, you must meet the strictest requirements that apply across all your categories — you cannot pick the easiest one.

The core building blocks

CSCRF is organised around a set of cyber-resilience goals: anticipate, withstand, contain, recover and evolve. In practice, becoming compliant means putting the following in place.

Your CSCRF checklist

  • Classify your entity — determine your category and size threshold (which decides how strict your obligations are).
  • Cybersecurity policy — a board-approved policy covering governance, roles and responsibilities.
  • Risk assessment — identify and rank your critical systems and data.
  • Access controls — least-privilege access, multi-factor authentication and strong identity management.
  • VAPT — regular vulnerability assessments and penetration testing of critical systems.
  • SOC / monitoring — continuous security monitoring, ideally through a Security Operations Centre.
  • Incident response plan — documented procedures, including the ability to report incidents to SEBI within the required timeframe.
  • Audit trails and logging — tamper-resistant logs retained for the required period.
  • Employee training — regular cyber-hygiene awareness for all staff.
  • Third-party / vendor risk — assess the security of your critical service providers.
The single most common gap we see is incident response: firms have firewalls, but no tested plan for the first six hours after a breach — exactly when SEBI expects to hear from you.

Getting audit-ready without disruption

Compliance projects fail when they try to do everything at once. A better approach is a gap assessment first — a clear picture of where you stand against each requirement — followed by a prioritised roadmap that fixes the highest-risk gaps first and schedules the rest so day-to-day operations are never disrupted.

How PITOWINGS helps

PITOWINGS provides end-to-end CSCRF support: threshold classification, policy drafting, VAPT, SOC monitoring, incident-response readiness, staff training and multi-registration unification — with certified professionals experienced in financial and market-infrastructure entities. We get you inspection-ready with zero business disruption.

P

PITOWINGS Team

Predictive cybersecurity experts — VAPT, SOC, forensics & J.I.M.M.Y.

Keep reading

Ready to make your business un-hackable?

Book a free, no-obligation consultation. We'll review your setup, explain your biggest risks in plain language, and show you exactly how to fix them.