India compliance

SEBI CSCRF cyber audit: what the audit covers and how often

Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.

Short answer

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) requires regulated entities to have cyber audits carried out by CERT-In empanelled auditing organisations. Market infrastructure institutions, qualified regulated entities and entities offering internet-based or algorithmic trading are audited half-yearly; other regulated entities annually. Findings must be tracked to closure through an action taken report.

Key takeaways

  • Only CERT-In empanelled auditing organisations can perform CSCRF cyber audits.
  • Half-yearly for MIIs, qualified REs and REs with IBT or algo trading; annual for others.
  • Exchanges set submission dates for their members; check your exchange's circulars.
  • The action taken report on findings matters as much as the audit report.

Who needs a CSCRF cyber audit

CSCRF applies to SEBI-regulated entities (REs), grouped by size and systemic importance. Every category needs a periodic cyber audit; what changes by category is how often and how much of the framework applies.

EntityAudit frequency
Market infrastructure institutions (MIIs)Half-yearly
Qualified regulated entitiesHalf-yearly
REs offering internet-based trading or algorithmic tradingHalf-yearly
Other regulated entitiesAnnual

Who can audit you

Audits must be carried out by CERT-In empanelled information security auditing organisations. Check the current CERT-In empanelment list when you appoint an auditor, and keep the evidence of empanelment with your audit file.

What the audit looks at

  • Governance: board-approved cyber security policy, roles and oversight.
  • Identification and protection controls against the CSCRF standards that apply to your category.
  • Detection and response: monitoring, SOC coverage and incident response.
  • Recovery and resilience: backups, restoration testing and business continuity.
  • Results of vulnerability assessment and penetration testing (VAPT).

Findings, deadlines and the action taken report

Exchanges and depositories set submission dates for their members. For example, NSE set 30 June 2026 for preliminary audit reports and 30 September 2026 for action taken reports for its trading members. An action taken report that shows each finding, its owner, the fix and the evidence of closure is what the next audit starts from.

Checklist

Preparing for your CSCRF cyber audit

0 of 7 done

CSCRF has been amended since it was issued in 2024. Check the latest SEBI circulars and your exchange's instructions for the requirements that apply to your category.

Frequently asked questions

Who can conduct a SEBI CSCRF cyber audit?

Only CERT-In empanelled information security auditing organisations.

How often is a SEBI CSCRF cyber audit required?

Half-yearly for market infrastructure institutions, qualified regulated entities and regulated entities offering internet-based or algorithmic trading; annually for other regulated entities.

Sources

  1. Cyber audit under SEBI CSCRF: compliance guide for regulated entities, CyberNX
  2. NSE mandates cyber audits for trading members, GovPing
  3. SEBI CSCRF in 2026: a complete compliance guide, Security Brigade