SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 · 28 Aug 2025
Official title
Technical Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)
Summary
Check the official recordSEBI has issued technical clarifications to its Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities. The circular introduces the 'Principle of Exclusivity' and 'Principle of Equivalence' to streamline compliance for entities regulated by multiple authorities. It provides technical guidance on critical system definitions, zero-trust models, mobile application security, and incident reporting. The circular also revises categorization thresholds for Portfolio Managers and Merchant Bankers, clarifies the applicability of NCIIPC guidelines, and provides guidance on Market-SOC onboarding. Additionally, it mandates adherence to CERT-In Cyber Security Audit Policy Guidelines. Stock exchanges, depositories, and BSE Limited are directed to update their byelaws and notify their members accordingly. These provisions are effective immediately.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
परिपत्र / CIRCULAR
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119
August 28, 2025
To,
All Alternative Investment Funds (AIFs) All Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs) All Clearing Corporations All Collective Investment Schemes (CIS) All Credit Rating Agencies (CRAs) All Custodians All Debenture Trustees (DTs) All Depositories All Designated Depository Participants (DDPs) All Depository Participants through Depositories All Investment Advisors (IAs) / Research Analysts (RAs) All KYC Registration Agencies (KRAs) All Merchant Bankers (MBs) All Mutual Funds (MFs)/ Asset Management Companies (AMCs) All Portfolio Managers Association of Portfolio Managers in India (APMI) All Registrar to an Issue and Share Transfer Agents (RTAs) All Stock Brokers through Exchanges All Stock Exchanges All Venture Capital Funds (VCFs) BSE Limited (Investment Adviser Administration and supervisory body- IAASB) BSE Limited (Research Analysts Administration and supervisory body- RAASB)
Sir / Madam,
Subject: Technical Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)
Recognising the need for robust cybersecurity measures and protection of data and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued ‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024.
Upon receipt of various queries from REs seeking extension and clarification on the aforementioned circular, SEBI has also issued following clarifications and Frequently Asked Questions (FAQs):
| S. No. | Circular Title | Circular Number | Date of Issuance |
|---|---|---|---|
| 1. | Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF)for SEBI Regulated Entities (REs) | SEBI/HO/ITD-1/ ITD_CSC_EXT/ P/CIR/2024/184 | December 31, 2024 |
| 2. | Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) | SEBI/HO/ITD-1/ ITD_CSC_EXT/ P/CIR/2025/45 | March 28, 2025 |
| 3. | Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) | SEBI/HO/ITD-1/ ITD_CSC_EXT/P/ CIR/2025/60 | April 30, 2025 |
| 4. | Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs and Framework for Adoption of Cloud Services by SEBI REs | FAQs | June 11, 2025 |
| 5. | Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) | SEBI/HO/ITD-1/ ITD_CSC_EXT/P/ CIR/2025/96 | June 30, 2025 |
3.1. Part-A: Principles for REs under multiple regulators’ purview 3.2. Part-B: Technical clarifications 3.3. Part-C: Re-categorisation of Portfolio Managers and Merchant Bankers 3.4. Part-D: Cyber Security Audit Policy Guidelines from CERT-In
There are several SEBI REs engaged in various business operations, and their activities are being regulated by multiple regulatory bodies within the Indian jurisdiction. For example: SEBI REs such as Custodians, Depository Participants (DPs) Merchant Bankers (MBs), etc. are also banks which are being primarily regulated by Reserve Bank of India (RBI).
Following clarifications are being issued for such REs w.r.t. CSCRF issued vide SEBI circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024:
5.1. There are various standards and corresponding guidelines mentioned in CSCRF which REs need to implement and comply with in a certain manner. For the ease of compliance and clarity of implementation, following Principle of Exclusivity and Principle of Equivalence have been formulated. During submission of CSCRF compliance, REs need to demonstrate that they follow the principle of equivalence and/ or exclusivity for the applicable controls. Further, SEBI reserves the right to seek the submissions made by the REs to other regulators to verify their compliances.
5.2. Principle of Exclusivity: The scope of CSCRF shall be limited to only those systems/ applications/ infrastructure/ processes which are exclusively used for SEBI regulated activities. Further, the shared infrastructure/ network/ technology stack, security solutions shall be included in the audit/ inspection scope by SEBI, if the same is not covered under audit/ inspection scope by primary regulator and their frameworks/ guidelines.
Following are representative examples of the standards and corresponding guidelines as mentioned in CSCRF:
Table 1: Representatives examples under Principle of Exclusivity
| S. No. | CSCRF Standard/ Guidelines | CSCRF Clause |
|---|---|---|
| 1. | Data Classification (Regulatory Data, and IT and Cybersecurity Data) and Data Localisation (currently in abeyance vide SEBI circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/184 dated December 31, 2024) | Box Item 9, Box Item 10, and PR.DS.S1-3 Guidelines (Page 107) |
| 2. | Definition and classification of Critical/ non-critical systems | Definitions (Page 26), ID.AM.S1 and ID.AM.S4 Guidelines (Page 90) |
| 3. | VAPT scope | Scope given in Annexure-A (Page 136), Annexure-L, and DE.CM.S5 Guideline 2 (Page 120) |
| 4. | Asset inventory updation timelines | ID.AM.S1 and ID.AM.S4 Guidelines 3 (Page 90) |
| 5. | Patch management timelines | PR.MA.S3 Guidelines 11 (Page 117-118) |
| 6. | SEBI Cloud circular compliance | Annexure-J |
| 7. | Supply chain risk management | GV.SC and corresponding guidelines |
| 8. | Requirements of log management and retention | PR.AA.S8-9 and corresponding Guideline (e) (Page 93) |
5.3. Principle of Equivalence: CSCRF controls which have an equivalence in other regulators’ cybersecurity frameworks/ guidelines shall be deemed compliant provided that the frameworks/ guidelines issued by primary regulator are adhered by such REs.
Following are representative examples of the standards and corresponding guidelines as mentioned in CSCRF:
Table 2: Representatives examples under Principle of Equivalence
| S. No. | CSCRF Standard/ Guidelines | CSCRF Clause |
|---|---|---|
| 1. | Cyber Capability Index (CCI) | GV.OV.S4, corresponding guidelines and Annexure-K |
| 2. | IT Committee constitution with an external independent cybersecurity expert or an independent director having IT and cybersecurity expertise, and various approval required from them | Clause 3.3-3.5 of Section 3 – IT Committee for REs (Page 44) |
| 3. | Patch Management policy | PR.MA.S3 Guidelines 8-10 (Page 117-118) |
| 4. | Cybersecurity policy | GV.PO.S1-4 (Page 54) and corresponding guidelines (Page 82-83) |
| 5. | Requirement of having Information Technology Service Management (ITSM) tool for managing asset inventory | ID.AM.S6 and corresponding guidelines (Page 91) |
| 6. | Red Teaming Exercise and requirement of placing report before IT committee | DE.DP.S4 and corresponding guidelines 1-4 |
| 7. | SOC efficacy | Annexure-N, DE.CM.S3 Guideline 2-3 (Page 118-119) |
6.1. Critical Systems definition (Page 26): Entities shall identify and classify their critical IT systems. Following systems shall be included in critical systems (both on premise and cloud): a. Any system, if compromised, that will have an adverse impact on core and critical business operations. b. Stores/ transmits data as per regulatory requirements. c. Devices/ network through which critical systems are connected (through trusted channels). d. Internet facing applications/ systems. e. Client facing application/ systems. f. All the ancillary systems used for accessing/ communicating with critical systems either for operations or for maintenance.”
Clarification: Above-mentioned para (f) shall now be read as under: Any other system which is on the same network segment where systems mentioned in para (a) to (e) are deployed.
6.2. Zero-trust security model (PR.AA.S4 and PR.AA.S5 guidelines – Page 97): “REs shall follow zero-trust security model in such a way that access (from within or outside REs’ network) to their critical systems is denied by default and allowed only after proper authentication and authorization.”