SEBI MII Cybersecurity Framework Audit
MII-grade cyber audit — 99.99% availability, capacity-tested, cross-MII coordinated.
Cybersecurity and cyber-resilience audit for Market Infrastructure Institutions — Stock Exchanges, Clearing Corporations and Depositories. Covers the SEBI MII cyber framework, the CSCRF MII tier, capacity planning, cyber-resilience drills and cross-MII coordination obligations.
- SEBI Cybersecurity & Cyber Resilience Framework (CSCRF) — MII tier (SEBI/HO/MIRSD/CRADT/CIR/P/2024/113 dated 20-Aug-2024 and successors)
- SEBI Cybersecurity & Cyber Resilience Framework for MIIs (SEBI/HO/MIRSD/CIR/P/2018/147)
- SEBI Business Continuity Plan & Disaster Recovery for MIIs
- SEBI Outsourcing by Stock Exchanges, Clearing Corporations & Depositories
- IOSCO Principles for Financial Market Infrastructures (PFMI)
- ISO 27001:2022 + ISO 22301 (BCP)
- NIST CSF 2.0 (cross-mapped)
- CERT-In incident-reporting obligations
What is SEBI MII compliance?
SEBI Market Infrastructure Institutions — stock exchanges, depositories, and clearing corporations — face the highest tier of cyber obligations: a dedicated SOC, frequent VAPT, and system audits. Macksofy delivers CSCRF-aligned audits, VAPT, and SOC support for MIIs and qualified regulated entities.
SEBI MII is leverage, not paperwork.
MIIs sit at the apex of India's capital-market plumbing — a single outage propagates across every broker, AMC and investor. SEBI's MII cyber framework (originating with SEBI/HO/MIRSD/CIR/P/2018/147 and consolidated under CSCRF in 2024-25) mandates 99.99% availability, periodic capacity testing, red-team exercises, cross-MII cyber drills and quarterly SEBI reporting. Non-MII brokers run against the CSCRF Qualified / Mid-size / Small RE tiers — but MIIs face the strictest bar, with SEBI inspections, SOP-2 access reviews and ETP reporting layered on top. Macksofy's MII audit produces the cyber-resilience, capacity and cross-MII evidence pack SEBI's IT department reviews quarterly.
- Stock Exchanges (BSE, NSE, MSE, MCX, NCDEX, etc.)
- Clearing Corporations (NSCCL, ICCL, MCCIL, NCCL, etc.)
- Depositories (NSDL, CDSL)
- MII subsidiaries running critical capital-market services
- MII-style entities seeking IOSCO-aligned attestation
- MII technology providers (where SEBI access extends)
Aligned to the regulations that matter.
How we run a SEBI MII engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
- Phase 01
1 · MII tier scoping
- Critical-system inventory (matching, clearing, settlement, depository)
- RTO / RPO + 99.99% availability commitment baseline
- Cross-MII dependency mapping
- SEBI / IT-Committee + IOSCO PFMI alignment
01Station 0101Phase 011 · MII tier scoping
- Critical-system inventory (matching, clearing, settlement, depository)
- RTO / RPO + 99.99% availability commitment baseline
- Cross-MII dependency mapping
- SEBI / IT-Committee + IOSCO PFMI alignment
- Phase 02
2 · Cybersecurity controls
- CSCRF MII-tier control assessment
- Identity, access, privileged-access, MFA evidence
- Network segmentation + microsegmentation
- Cryptographic-control + HSM lifecycle
02Station 0202Phase 022 · Cybersecurity controls
- CSCRF MII-tier control assessment
- Identity, access, privileged-access, MFA evidence
- Network segmentation + microsegmentation
- Cryptographic-control + HSM lifecycle
- Phase 03
3 · Cyber resilience & capacity
- Capacity-planning + stress-testing evidence
- Cyber-resilience drill (matching engine failover)
- Active-active / hot-DR validation
- Recovery-time + recovery-point empirical evidence
03Station 0303Phase 033 · Cyber resilience & capacity
- Capacity-planning + stress-testing evidence
- Cyber-resilience drill (matching engine failover)
- Active-active / hot-DR validation
- Recovery-time + recovery-point empirical evidence
- Phase 04
4 · Threat operations
- 24×7 SOC capability + use-case coverage
- Threat-intel ingestion + TTP coverage (ATT&CK)
- Red-team + purple-team exercise evidence
- Vulnerability + patch SLA per criticality
04Station 0404Phase 044 · Threat operations
- 24×7 SOC capability + use-case coverage
- Threat-intel ingestion + TTP coverage (ATT&CK)
- Red-team + purple-team exercise evidence
- Vulnerability + patch SLA per criticality
- Phase 05
5 · Cross-MII & ecosystem
- Cross-MII cyber-drill participation evidence
- Member / broker connectivity security audit
- Outsourcing + third-party risk per SEBI outsourcing circular
- Incident-reporting to SEBI + CERT-In (6h)
05Station 0505Phase 055 · Cross-MII & ecosystem
- Cross-MII cyber-drill participation evidence
- Member / broker connectivity security audit
- Outsourcing + third-party risk per SEBI outsourcing circular
- Incident-reporting to SEBI + CERT-In (6h)
- Phase 06
6 · Reporting & SEBI pack
- Quarterly SEBI cyber-report format
- CSCRF System Audit Report draft
- IT-Committee + Board cybersecurity dashboard
- Remediation tracker + 30-day retest
06Station 0606Phase 066 · Reporting & SEBI pack
- Quarterly SEBI cyber-report format
- CSCRF System Audit Report draft
- IT-Committee + Board cybersecurity dashboard
- Remediation tracker + 30-day retest
What your SEBI MII engagement puts on the table.
- CSCRF MII-tier compliance attestation
- Capacity + cyber-resilience drill evidence pack
- Red-team + purple-team executive report
- Cross-MII coordination evidence file
- Quarterly SEBI cyber-report template + first submission
- IT-Committee + Board cybersecurity dashboard
- Member-connectivity security audit pack
- Free retest within 30 days + closure letter
CSCRF MII-tier audit + cross-MII drill facilitation
Outcome: Cross-MII drill cleared end-to-end; 99.99% availability empirically evidenced; SEBI quarterly report cycle reduced from 14 to 5 working days
Capacity test + cyber-resilience drill
Outcome: Matching-engine failover validated under simulated DDoS + insider scenarios; recovery-time empirical evidence accepted by SEBI without queries
The shape of a SEBI MII engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- MII availability & capacity3 pts
- Cyber resilience drills3 pts
- MII-tier security controls3 pts
- Threat operations & red-team3 pts
- Ecosystem & cross-MII3 pts
- SEBI reporting & governance3 pts
99.99% is not a marketing target — SEBI tests it quarter on quarter.
- Capacity-planning + stress-test evidence
- Active-active / hot-DR validation
- Latency + jitter monitoring at matching layer
Tested failover under cyber-incident scenarios, not just hardware faults.
- Annual cyber-resilience drill participation
- Cross-MII coordinated drill evidence
- Recovery-time empirical proof per critical system
CSCRF MII tier — the strictest control baseline in the SEBI universe.
- Privileged-access + MFA + JIT controls
- Network segmentation + microsegmentation
- Crypto + HSM lifecycle management
Continuous threat detection plus periodic adversary-emulation testing.
- 24×7 SOC use-case + ATT&CK coverage
- Threat-intel ingestion + sharing
- Red-team + purple-team annual exercise
The MII is only as resilient as the brokers, clearing members and inter-MII links it touches.
- Member-connectivity security audit
- Cross-MII drill + information sharing
- Outsourcing + third-party risk evidence
What the IT Committee, Board and SEBI see — in the cadence SEBI sets.
- Quarterly SEBI cyber report
- IT-Committee + Board cyber dashboard
- Incident reporting (SEBI + CERT-In 6h)
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a SEBI MII engagement. Click any station for detail in the methodology section above.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
SEBI MII — what compliance leads ask before signing.
RBI Cyber Security Framework Audit
End-to-end RBI CSF audit — control assessment, SAR drafting, inspector defence.
Learn moreSEBI CSCRF Audit
CSCRF audit for stock brokers, depository participants, AMCs.
Learn moreSEBI System Audit Report (SAR)
The half-yearly / annual SAR your stock broker or DP can submit on the first read.
Learn moreSEBI MII evidence starts with hands-on testing.
A clean SEBI MII report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
