Short answer
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) requires regulated entities to have cyber audits carried out by CERT-In empanelled auditing organisations. Market infrastructure institutions, qualified regulated entities and entities offering internet-based or algorithmic trading are audited half-yearly; other regulated entities annually. Findings must be tracked to closure through an action taken report.
Key takeaways
- Only CERT-In empanelled auditing organisations can perform CSCRF cyber audits.
- Half-yearly for MIIs, qualified REs and REs with IBT or algo trading; annual for others.
- Exchanges set submission dates for their members; check your exchange's circulars.
- The action taken report on findings matters as much as the audit report.
Who needs a CSCRF cyber audit
CSCRF applies to SEBI-regulated entities (REs), grouped by size and systemic importance. Every category needs a periodic cyber audit; what changes by category is how often and how much of the framework applies.
| Entity | Audit frequency |
|---|---|
| Market infrastructure institutions (MIIs) | Half-yearly |
| Qualified regulated entities | Half-yearly |
| REs offering internet-based trading or algorithmic trading | Half-yearly |
| Other regulated entities | Annual |
Who can audit you
Audits must be carried out by CERT-In empanelled information security auditing organisations. Check the current CERT-In empanelment list when you appoint an auditor, and keep the evidence of empanelment with your audit file.
What the audit looks at
- Governance: board-approved cyber security policy, roles and oversight.
- Identification and protection controls against the CSCRF standards that apply to your category.
- Detection and response: monitoring, SOC coverage and incident response.
- Recovery and resilience: backups, restoration testing and business continuity.
- Results of vulnerability assessment and penetration testing (VAPT).
Findings, deadlines and the action taken report
Exchanges and depositories set submission dates for their members. For example, NSE set 30 June 2026 for preliminary audit reports and 30 September 2026 for action taken reports for its trading members. An action taken report that shows each finding, its owner, the fix and the evidence of closure is what the next audit starts from.
Checklist
Preparing for your CSCRF cyber audit
0 of 7 done
CSCRF has been amended since it was issued in 2024. Check the latest SEBI circulars and your exchange's instructions for the requirements that apply to your category.
Frequently asked questions
Who can conduct a SEBI CSCRF cyber audit?
Only CERT-In empanelled information security auditing organisations.
How often is a SEBI CSCRF cyber audit required?
Half-yearly for market infrastructure institutions, qualified regulated entities and regulated entities offering internet-based or algorithmic trading; annually for other regulated entities.