India’s Securities and Exchange Board (SEBI) today issues the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-regulated entities.
Key points
- Standardised controls by entity category.
- A security operations centre requirement.
- Regular cyber audits.
- Incident reporting requirements.
- Phased compliance deadlines, later extended into 2025.
UK technology providers serving Indian stock exchanges, brokers and fund managers should expect CSCRF requirements to flow into contracts and audits. The framework consolidates earlier SEBI cyber security circulars and draws on international frameworks, including the NIST Cybersecurity Framework. Suppliers with ISO/IEC 27001 certification and mature logging and monitoring will find it easier to support their clients’ compliance.
Source: CSCRF circular (SEBI)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.