Don’t do SECURITY. Do business SECURELY.

SEBI issues Cybersecurity and Cyber Resilience Framework

India’s securities regulator SEBI issues CSCRF, standardising cyber security controls across regulated entities.

India’s Securities and Exchange Board (SEBI) today issues the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-regulated entities.

Key points

  • Standardised controls by entity category.
  • A security operations centre requirement.
  • Regular cyber audits.
  • Incident reporting requirements.
  • Phased compliance deadlines, later extended into 2025.

UK technology providers serving Indian stock exchanges, brokers and fund managers should expect CSCRF requirements to flow into contracts and audits. The framework consolidates earlier SEBI cyber security circulars and draws on international frameworks, including the NIST Cybersecurity Framework. Suppliers with ISO/IEC 27001 certification and mature logging and monitoring will find it easier to support their clients’ compliance.

Source: CSCRF circular (SEBI)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights