If you are a SEBI-regulated entity, the Cyber Security and Cyber Resilience Framework (CSCRF) now requires you to run security testing and a cyber audit on a fixed schedule. This guide explains what a mid-size, small-size or self-certification RE actually has to do, how often, and who is allowed to do it.
Most non-top-tier REs must complete an annual VAPT and an annual cyber audit, report incidents to SEBI and CERT-In within 6 hours, and keep evidence for their auditor. Unlike the top tiers, a CERT-In empanelled auditor is not mandatory for these categories — but the testing still has to be real, manual and methodology-driven.
Who the CSCRF applies to
SEBI's CSCRF covers 22 categories of regulated entities (REs), grouped into five tiers by size and systemic importance. The obligations scale with the tier:
| Tier | Examples | VAPT | Cyber audit |
|---|---|---|---|
| MII | Stock exchanges, depositories, clearing corporations | Twice yearly | Twice yearly |
| Qualified RE | Large brokers, big AMCs, KRAs, custodians | Annual | Twice yearly |
| Mid-size RE | Mid-tier brokers, AMCs, PMS, AIFs | Annual | Annual |
| Small-size RE | Smaller brokers, merchant bankers, fund managers | Annual | Annual |
| Self-certification RE | CRAs, debenture trustees, smaller PMS, IAs / RAs | Annual | Annual |
Very small stock brokers — broadly, those below both a client-count and a trading-volume threshold — are excluded. If you are unsure which tier you fall in, that classification is the first thing to confirm, because it sets your entire testing calendar.
What a mid-size or small RE actually has to do
For the mid-size, small-size and self-certification tiers, the practical obligations are:
- Annual VAPT of internet-facing and critical internal systems — web applications, APIs, and supporting infrastructure.
- Annual cyber audit against the framework's controls, which are aligned to NIST CSF 2.0.
- Closure of findings with evidence, and a retest to confirm high and critical issues are actually fixed.
- Incident reporting to SEBI and CERT-In within 6 hours of detection.
- Governance artefacts — policies, a cyber-security committee or responsible officer, and audit trails your auditor can inspect.
Do you need a CERT-In empanelled auditor?
For MIIs and Qualified REs, SEBI expects vulnerability assessments to be carried out by CERT-In empanelled auditors. For the mid-size, small-size and self-certification tiers, this is not mandated — you can engage a competent independent security firm. What matters is that the testing is genuinely manual, follows a recognised methodology (PTES, OWASP, NIST), and produces defensible evidence.
This is worth understanding clearly, because it is often where smaller REs either overspend — assuming they must use a large empanelled firm — or underspend on a cheap scan that will not hold up.
How to plan your CSCRF cycle
- Confirm your tier. It sets your frequency and whether an empanelled auditor is required.
- Scope the assets. List internet-facing applications, APIs, admin panels and critical internal systems.
- Run the VAPT early in the year so you have time to remediate before the audit.
- Remediate and retest high and critical findings; keep the evidence.
- Complete the cyber audit and file what your tier requires.
- Keep the incident-response runbook current — the 6-hour clock is unforgiving.
Need your CSCRF VAPT and audit handled together?
XDepthSense runs the manual testing and the cyber audit under one roof — ISO 27001 Lead Auditor and OSCP/CRTE on the same team, with a clean attestation letter at the end. See exactly what you'd receive.
Frequently asked questions
How often does a mid-size RE need a VAPT under CSCRF?
Annually, along with an annual cyber audit. The top tiers (MII and Qualified RE) test more frequently.
Is a CERT-In empanelled auditor mandatory for a small broker?
No. Empanelment is required for MIIs and Qualified REs. Mid-size, small-size and self-certification REs may use a competent independent firm, provided the testing is manual and methodology-driven.
What happens if we only run an automated scan?
It is unlikely to satisfy the framework's intent and will not reliably surface authorisation or business-logic flaws — the issues that cause real breaches. Findings should be manually validated.
What is the incident-reporting timeline?
Cyber incidents must be reported to SEBI and CERT-In within 6 hours of detection.
This article is general information, not legal or compliance advice, and reflects our understanding of the framework at the time of writing. SEBI circulars are periodically amended — confirm the current requirements for your specific tier with SEBI's master circular and your compliance advisor before acting.