business@xdepthsense.com
+91 97695 13095  |  +91 98335 86361  |  +91 96197 39550
COMPLIANCE · SEBI CSCRF

SEBI CSCRF: What a Mid-Size RE Actually Needs

Compliance guide · ~7 min read · XDepthSense

If you are a SEBI-regulated entity, the Cyber Security and Cyber Resilience Framework (CSCRF) now requires you to run security testing and a cyber audit on a fixed schedule. This guide explains what a mid-size, small-size or self-certification RE actually has to do, how often, and who is allowed to do it.

In short

Most non-top-tier REs must complete an annual VAPT and an annual cyber audit, report incidents to SEBI and CERT-In within 6 hours, and keep evidence for their auditor. Unlike the top tiers, a CERT-In empanelled auditor is not mandatory for these categories — but the testing still has to be real, manual and methodology-driven.

Who the CSCRF applies to

SEBI's CSCRF covers 22 categories of regulated entities (REs), grouped into five tiers by size and systemic importance. The obligations scale with the tier:

TierExamplesVAPTCyber audit
MIIStock exchanges, depositories, clearing corporationsTwice yearlyTwice yearly
Qualified RELarge brokers, big AMCs, KRAs, custodiansAnnualTwice yearly
Mid-size REMid-tier brokers, AMCs, PMS, AIFsAnnualAnnual
Small-size RESmaller brokers, merchant bankers, fund managersAnnualAnnual
Self-certification RECRAs, debenture trustees, smaller PMS, IAs / RAsAnnualAnnual

Very small stock brokers — broadly, those below both a client-count and a trading-volume threshold — are excluded. If you are unsure which tier you fall in, that classification is the first thing to confirm, because it sets your entire testing calendar.

What a mid-size or small RE actually has to do

For the mid-size, small-size and self-certification tiers, the practical obligations are:

  • Annual VAPT of internet-facing and critical internal systems — web applications, APIs, and supporting infrastructure.
  • Annual cyber audit against the framework's controls, which are aligned to NIST CSF 2.0.
  • Closure of findings with evidence, and a retest to confirm high and critical issues are actually fixed.
  • Incident reporting to SEBI and CERT-In within 6 hours of detection.
  • Governance artefacts — policies, a cyber-security committee or responsible officer, and audit trails your auditor can inspect.
The point most REs miss: a raw automated-scanner report does not satisfy the intent of a VAPT. The framework expects findings to be validated and prioritised by real exploitability. A clean-looking scan with no manual verification is exactly what an auditor — or an attacker — will see through.

Do you need a CERT-In empanelled auditor?

For MIIs and Qualified REs, SEBI expects vulnerability assessments to be carried out by CERT-In empanelled auditors. For the mid-size, small-size and self-certification tiers, this is not mandated — you can engage a competent independent security firm. What matters is that the testing is genuinely manual, follows a recognised methodology (PTES, OWASP, NIST), and produces defensible evidence.

This is worth understanding clearly, because it is often where smaller REs either overspend — assuming they must use a large empanelled firm — or underspend on a cheap scan that will not hold up.

How to plan your CSCRF cycle

  1. Confirm your tier. It sets your frequency and whether an empanelled auditor is required.
  2. Scope the assets. List internet-facing applications, APIs, admin panels and critical internal systems.
  3. Run the VAPT early in the year so you have time to remediate before the audit.
  4. Remediate and retest high and critical findings; keep the evidence.
  5. Complete the cyber audit and file what your tier requires.
  6. Keep the incident-response runbook current — the 6-hour clock is unforgiving.

Need your CSCRF VAPT and audit handled together?

XDepthSense runs the manual testing and the cyber audit under one roof — ISO 27001 Lead Auditor and OSCP/CRTE on the same team, with a clean attestation letter at the end. See exactly what you'd receive.

Frequently asked questions

How often does a mid-size RE need a VAPT under CSCRF?

Annually, along with an annual cyber audit. The top tiers (MII and Qualified RE) test more frequently.

Is a CERT-In empanelled auditor mandatory for a small broker?

No. Empanelment is required for MIIs and Qualified REs. Mid-size, small-size and self-certification REs may use a competent independent firm, provided the testing is manual and methodology-driven.

What happens if we only run an automated scan?

It is unlikely to satisfy the framework's intent and will not reliably surface authorisation or business-logic flaws — the issues that cause real breaches. Findings should be manually validated.

What is the incident-reporting timeline?

Cyber incidents must be reported to SEBI and CERT-In within 6 hours of detection.

This article is general information, not legal or compliance advice, and reflects our understanding of the framework at the time of writing. SEBI circulars are periodically amended — confirm the current requirements for your specific tier with SEBI's master circular and your compliance advisor before acting.