Compliance Frameworks

SEBI CSCRF Compliance Guide 2026 | FourCore ATTACK

SEBI CSCRF (Cybersecurity and Cyber Resilience Framework) is the Securities and Exchange Board of India's unified cybersecurity framework for regulated market entities, mandating governance, baseline controls, periodic audits, VAPT, breach and attack simulation (BAS), continuous automated red teaming (CART), and a Cyber Capability Index (CCI) score to measure security maturity. Deadlines run through 2025–2026 by entity category, and non-compliance penalties can reach ₹25 lakh plus daily fines for continuing violations.

What Is SEBI CSCRF?

The Cybersecurity and Cyber Resilience Framework (CSCRF) sets baseline and role-specific cybersecurity requirements for entities in the Indian securities market. It is intended to improve governance, detection, response, resilience, and reporting for institutions that support critical market operations and investor trust.

CSCRF consolidates SEBI's earlier cyber circulars into a single framework and applies to stock brokers, mutual funds, AMCs, depositories and depository participants, Alternative Investment Funds (AIFs), portfolio managers, and Market Infrastructure Institutions (MIIs) such as exchanges, clearing corporations, and depositories.

What the Framework Emphasizes

  1. Governance and Accountability: Clear ownership of cybersecurity responsibilities, including a designated CISO and reporting to the Board or risk committee.
  2. Security Controls: Documented requirements for identity, access, network, endpoint, data, and application protection and monitoring.
  3. Resilience and Recovery: Readiness for disruption, including backup, disaster recovery drills, and incident response.
  4. Continuous Improvement: Ongoing review, testing, and control strengthening, with periodic audits and VAPT.
  5. Continuous Validation: For higher-tier entities, breach and attack simulation (BAS) and continuous automated red teaming (CART) to prove that controls work, not only that they exist.

Cyber Capability Index (CCI)

The Cyber Capability Index (CCI) is SEBI's maturity score for regulated entities under CSCRF. It is calculated from control coverage, testing depth, incident response readiness, and audit outcomes. A higher CCI reduces regulatory scrutiny and signals stronger cyber posture to investors and counterparties.

CSCRF Penalties for Non-Compliance

Penalties depend on the entity category and the nature of the violation. For most regulated entities, SEBI can levy monetary penalties, daily fines for continuing non-compliance, restrictions on new product launches, and supervisory action against the entity's compliance officers. The penalty ceiling for serious cyber governance failures can reach ₹25 lakh per violation, with additional daily fines for ongoing lapses.

CSCRF Compliance Checklist (2026)

CSCRF groups controls into governance, identity and access, network and endpoint security, data protection, secure development, third-party risk, incident response, and testing. For MIIs and Qualified REs, the framework also requires scenario-based cyber resilience testing at least twice per financial year (guideline RC.RP.S2), live trading from the DR site for two consecutive days every six months, and submission of lessons learned to SEBI within three months of each exercise.

How FourCore ATTACK Helps with CSCRF Compliance

FourCore ATTACK supports CSCRF compliance by continuously validating the security controls CSCRF mandates, mapping every test to MITRE ATT&CK, and producing audit-ready evidence of what was tested, what was blocked, what was detected, and what was missed.

CSCRF RequirementHow FourCore ATTACK Helps
Periodic VAPTContinuous validation that goes beyond point-in-time pen tests
BAS / CART for Qualified REsAlways-on breach and attack simulation mapped to ATT&CK
Cyber Capability Index (CCI)Empirical evidence of control effectiveness that lifts the maturity score
Scenario-based resilience testing (RC.RP.S2)Replayable, MITRE-mapped attack scenarios for resilience exercises
Audit and evidenceAuto-generated, auditor-ready reports of every test, detection, and gap

Frequently Asked Questions About SEBI CSCRF

What is the SEBI CSCRF compliance deadline?

The CSCRF rollout is phased by entity category. Most regulated entities (MIIs, Qualified REs, and large intermediaries) were required to be compliant by 2025, with smaller and self-certified entities phased in through 2026. SEBI's June 2026 consultation paper proposes further consolidation of MII cyber provisions under CSCRF, with comments open through July 13, 2026.

What is the SEBI CSCRF checklist?

The CSCRF checklist covers governance (CISO designation, board reporting, policy), identity and access management, network and endpoint security, data protection and encryption, secure SDLC, third-party risk, incident response, periodic VAPT, and for Qualified REs continuous validation (BAS and CART), Cyber Capability Index reporting, and scenario-based cyber resilience testing at least twice per financial year.

What is the penalty for SEBI CSCRF non-compliance?

Penalties for non-compliance can reach ₹25 lakh per violation, with additional daily fines for continuing lapses. SEBI may also impose restrictions on new product launches, heightened reporting, and supervisory action against compliance officers and the entity's board.

What is BAS under SEBI CSCRF?

Under CSCRF, Breach and Attack Simulation (BAS) is the continuous, automated emulation of real-world adversary techniques against an entity's live defenses to prove that controls actually prevent, detect, and alert as expected. For Qualified REs and MIIs, BAS satisfies the framework's continuous-validation requirement that periodic VAPT alone does not.

What is the Cyber Capability Index (CCI) under SEBI CSCRF?

The Cyber Capability Index (CCI) is SEBI's maturity score for regulated entities under CSCRF. It aggregates control coverage, testing depth, detection engineering maturity, incident response readiness, and audit outcomes into a single score that entities report to SEBI and that influences the regulator's supervisory posture.

How does ISO 27001 and SEBI CSCRF work together?

ISO 27001 provides the information security management system (ISMS) that CSCRF expects as the governance backbone. Most entities operating under CSCRF also maintain an ISO 27001 ISMS and extend it with CSCRF-specific controls for the Indian securities market, periodic SEBI reporting, and CCI evidence.

Why CSCRF Matters

For regulated organizations, compliance is not only a legal and audit issue. It also reflects operational resilience and the ability to prove that security controls are working under realistic conditions. CSCRF's shift toward continuous validation, BAS, and CCI reporting means entities that can produce empirical evidence of control effectiveness carry a clear advantage in both regulatory reviews and live incidents.

How FourCore ATTACK Relates

FourCore ATTACK helps regulated teams continuously validate important controls, detection workflows, and attack-path resilience in support of broader SEBI CSCRF security assurance efforts.

Related Terms

Related Reading