SEBI CSCRF Audit
CSCRF audit for stock brokers, depository participants, AMCs.
SEBI's CSCRF (effective 2025) consolidates earlier circulars into a single framework graded by entity type and size. Macksofy delivers full CSCRF audit + cyber resilience assessment + System Audit submission for SEBI-regulated entities.
- SEBI CSCRF (Cybersecurity & Cyber Resilience Framework, 2024)
- SEBI Cybersecurity Circular 2015 (legacy controls retained)
- CERT-In Information Security Audit
- ISO 27001:2022 (mapped to CSCRF)
- NIST Cybersecurity Framework 2.0
What is SEBI CSCRF compliance?
SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) sets graded obligations for regulated entities and market infrastructure — VAPT, SOC, SBOM, and a Cyber Capability Index. Macksofy delivers CSCRF gap assessments, audits, and the ISO 27001 plus VAPT control stack SEBI requires.
SEBI CSCRF is leverage, not paperwork.
CSCRF replaces SEBI's 2015–2022 cybersecurity circulars with a unified, graded framework. Every regulated entity now sits in one of five categories — Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small REs, Self-certification REs — with controls calibrated to scale. Non-compliance attracts SEBI penalties under Sections 11/15HA. Macksofy's CSCRF audit ships in a format SEBI's IT department reads in days, not weeks.
- Stock Exchanges, Clearing Corporations, Depositories (MIIs)
- Stock Brokers + Depository Participants (Qualified / Mid-size / Small)
- Asset Management Companies + Mutual Fund RTAs
- Custodians, Portfolio Managers, RIAs
- Investment Bankers, Merchant Bankers
- Alternative Investment Funds (AIFs)
Aligned to the regulations that matter.
How we run a SEBI CSCRF engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
- Phase 01
1 · Categorisation + scoping
- Determine RE category (MII / Qualified / Mid-size / Small / SC)
- Scoped controls from CSCRF Annexure
- Cyber resilience baseline assessment
01Station 0101Phase 011 · Categorisation + scoping
- Determine RE category (MII / Qualified / Mid-size / Small / SC)
- Scoped controls from CSCRF Annexure
- Cyber resilience baseline assessment
- Phase 02
2 · Control assessment
- Identify · Protect · Detect · Respond · Recover (NIST CSF aligned)
- Cyber Capability Index (CCI) computation
- Cyber Resilience Maturity Model (CRMM) scoring
02Station 0202Phase 022 · Control assessment
- Identify · Protect · Detect · Respond · Recover (NIST CSF aligned)
- Cyber Capability Index (CCI) computation
- Cyber Resilience Maturity Model (CRMM) scoring
- Phase 03
3 · Technical testing
- VAPT covering trading + back-office systems
- DR drill validation + recovery time evidence
- Cloud + colocation environment testing
- API gateway + customer-facing surface
03Station 0303Phase 033 · Technical testing
- VAPT covering trading + back-office systems
- DR drill validation + recovery time evidence
- Cloud + colocation environment testing
- API gateway + customer-facing surface
- Phase 04
4 · Reporting
- SEBI System Audit Report (CSCRF format)
- CCI score + CRMM tier report
- Quarterly compliance certificate
04Station 0404Phase 044 · Reporting
- SEBI System Audit Report (CSCRF format)
- CCI score + CRMM tier report
- Quarterly compliance certificate
- Phase 05
5 · Submission + advisory
- Submission to SEBI / MII as applicable
- Board / Audit Committee briefing
- Annual surveillance + change-event re-audit
05Station 0505Phase 055 · Submission + advisory
- Submission to SEBI / MII as applicable
- Board / Audit Committee briefing
- Annual surveillance + change-event re-audit
What your SEBI CSCRF engagement puts on the table.
- CSCRF Annexure-mapped findings register
- Cyber Capability Index (CCI) score sheet
- Cyber Resilience Maturity Model (CRMM) tier report
- SEBI-format System Audit Report
- Quarterly compliance certificate template
- Free retest within 30 days · SEBI inspector support
First CSCRF audit + transition from 2015 circular
Outcome: Submitted in CSCRF format ahead of go-live; CCI score 78 / 100; zero penalty
Annual CSCRF + DR drill validation
Outcome: DR RTO reduced from 6h to 90 min; CRMM tier moved from Bronze to Silver
The shape of a SEBI CSCRF engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- Governance & cyber-risk management3 pts
- Identify & inventory3 pts
- Protect & detect3 pts
- Respond & recover3 pts
- Outsourcing & third-party3 pts
- Reporting & assurance3 pts
Board, MD/CEO and CISO accountability lined up to SEBI CSCRF clauses.
- Cyber-security & cyber-resilience policy review
- CSC / CRC committee minutes evidence
- Annual self-assessment + board-approved risk register
What SEBI auditors check first — completeness of the protected asset list.
- Critical-systems inventory keyed to business processes
- Data classification + ownership matrix
- Third-party / vendor / DP / RTA dependency map
The technical-control evidence that CSCRF inspections actually consume.
- Network segmentation + DMZ posture
- EDR / SIEM coverage on critical systems
- VAPT + secure-SDLC artefacts
Cyber-incident & recovery capabilities mapped to the SEBI CSCRF lifecycle.
- Cyber-IR playbook + escalation matrix
- DR / BCP drill evidence (RTO/RPO recorded)
- Major-incident communication to SEBI
Where most CSCRF gaps actually surface — cloud, MII, RTA, custodian linkages.
- Vendor-risk classification (critical / non-critical)
- Cloud + DR-site security audits
- MII / Depository / Exchange interface review
What you submit, when, and in which format — preserved for inspectors.
- Quarterly SAR + cyber-resilience reports
- Half-yearly compliance status to board
- Annual third-party CSCRF audit pack
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a SEBI CSCRF engagement. Click any station for detail in the methodology section above.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
SEBI CSCRF — what compliance leads ask before signing.
RBI Cyber Security Framework Audit
End-to-end RBI CSF audit — control assessment, SAR drafting, inspector defence.
Learn moreSEBI System Audit Report (SAR)
The half-yearly / annual SAR your stock broker or DP can submit on the first read.
Learn moreIRDAI Information Security Audit
IRDAI compliance for insurers, brokers, web aggregators, TPAs.
Learn moreSEBI CSCRF evidence starts with hands-on testing.
A clean SEBI CSCRF report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceField notes from SEBI CSCRF engagements.
RBI CSF vs SEBI CSCRF in 2026 — Which Framework Applies to You?
RBI Cyber Security Framework vs SEBI CSCRF — clause-by-clause 2026 guide for Indian BFSI, including dual-regulated broker-dealers, NBFCs and bank-owned AMCs.
Read article ComplianceSEBI CSCRF — A 2026 Compliance Readiness Guide for Regulated Entities
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is now in force across all Regulated Entities after a phased 2025 rollout. A practical readiness guide to the graded model, the Cyber Capability Index, the SOC mandate, VAPT/SBOM and audit evidence — for MIIs, brokers, AMCs and other REs.
Read articleMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
