Six Domains. One Intelligent Foundation.

SEBI's Cybersecurity and Cyber Resilience Framework supersedes all of SEBI's earlier cybersecurity circulars, replacing a patchwork of sector-specific advisories with a single standard for every regulated entity in the Indian securities market. Entities already covered by earlier cybersecurity guidelines had to comply from 1 January 2025; entities adopting CSCRF for the first time had until 1 April 2025. 

The framework is broader than a typical audit checklist. It draws on ISO 27001, NIST 800-53, and CIS v8, and folds in governance, supply-chain risk, data classification and localisation, API security, and SOC monitoring under one structure. It also asks REs to plan now for "harvest now, decrypt later" risk from quantum computing, a detail worth noting since it's one of the few compliance frameworks that names quantum threat modelling directly. 

TeamSync doesn't file your cyber audit for you. But the underlying controls CSCRF is built around- access control, encryption, audit logging, retention, and quantum-resistant security at the storage layer, are the same things the platform already handles.

What CSCRF Requires

Requirement

What it actually says

Governance

Board-level ownership of cybersecurity posture; standardised reporting formats for audits

ISO 27001 certification

Mandatory for Market Infrastructure Institutions (MIIs) and Qualified REs 

VAPT

Regular Vulnerability Assessment and Penetration Testing 

Incident reporting

All cybersecurity incidents reported immediately via the dedicated SEBI portal 

Cyber Capability Index (CCI)

MIIs and Qualified REs must use CCI to periodically monitor and assess cyber resilience 

Red teaming

Required for MIIs and Qualified REs 

SOC monitoring

All REs must establish a Security Operations Centre for security monitoring 

Disaster recovery

Critical operations must meet a 2-hour Recovery Time Objective and 15-minute Recovery Point Objective 

Data classification & localisation

Data classified by sensitivity, with localisation requirements for critical systems

Log retention

SOC/Market-SOC providers must meet defined log retention periods and monitoring expectations 

Multi-regulator entities

Entities also governed by RBI can apply the Principle of Equivalence to reduce duplicated compliance effort 

Who Counts As A "Qualified RE"

CSCRF applies different depths of obligation depending on entity type and scale. It covers a wide range of SEBI-regulated entities, stock exchanges, depositories, clearing corporations, stock brokers, depository participants, AMCs, RTAs, and KRAs among them. MIIs (exchanges, depositories, clearing corporations) and entities designated "Qualified REs" carry the heaviest requirements: ISO 27001, CCI reporting, and red teaming. Smaller REs still need the governance, VAPT, and SOC baseline, just without the top tier of obligations. 

Penalty Exposure

SEBI doesn't have a single CSCRF-specific penalty clause; non-compliance is enforced through the general penalty provisions of the SEBI Act, 1992, so the exposure depends on which regulation or direction the failure sits under.

Type of contravention

Statutory exposure

Residual/general non-compliance with SEBI directions

Up to ₹1 crore under Section 15HB 

Failure by an asset management company to comply with restrictions

₹1 lakh per day of continuing failure, up to ₹1 crore 

Fraudulent or unfair trade practices

Up to ₹25 crore or three times the profit made, whichever is higher

Non-monetary action

Suspension or cancellation of registration, market-access prohibition, disgorgement of profits 

Beyond monetary penalties, non-compliance can trigger other regulatory action — which in practice includes operational restrictions and increased supervisory scrutiny, independent of any fine. 

Flag for legal: this table intentionally shows a range across different SEBI Act sections rather than one CSCRF-specific figure, worth confirming with your compliance reviewer which provision is most relevant to lead with for your audience (MIIs vs. brokers vs. AMCs will map to different sections).

Compliance Deadlines

Milestone

Date

CSCRF formulated

20 August 2024 

Entities under prior cybersecurity guidelines

Comply from 1 January 2025 

First-time CSCRF adopters

Comply from 1 April 2025 

Ongoing

Cyber audit reports submitted in structured formats per CSCRF timelines

What Else Runs On The Same Platform

Capability

What it does inside the CSCRF perimeter

RBAC

Access-control layer supporting the governance and audit requirements

Compliance Audit Trail

Cryptographic audit chain, supports log retention and cyber audit evidence

Security and Deployment

Air-gapped, quantum-secure encryption, a direct answer to CSCRF's quantum-risk guidance

Risk Radar

Flags documents or data patterns that need closer security review

Agentic Workflow

Automates incident logging and escalation steps ahead of SEBI portal reporting

Intelligent Repository

Central store with retention and classification rules applied at the platform level

DocuTalk

Permission-aware AI search, never surfaces data a user isn't entitled to see

What A Cyber Audit Looks Like

Audit request

What you'd need to produce

"Show us your VAPT reports for this cycle"

Structured VAPT report in CSCRF format

"Show us your access logs for this system"

Audit trail with cryptographic chain of custody

"Show us your incident reporting timeline"

Timestamped incident log

"Show us your data classification and localisation controls"

Classification rules and storage-location evidence

"Show us your CCI score" (Qualified REs / MIIs)

Generated CCI assessment artifact

What Changes For Compliance And Security Teams

Activity

Before

With TeamSync

Cyber audit evidence assembly

Manual document pull across systems

Generated artifact from the audit chain

Access control documentation

Policy PDF

Live RBAC configuration + audit trail

Data classification for localisation

Manual tagging

AI-assisted metadata and tagging

Incident log retrieval

Ad hoc

Timestamped, queryable log

Quantum-readiness question in an audit

Open engineering question

Architectural answer

How TeamSync Compares

  • Legacy GRC platforms: Strong policy and audit-workflow tooling, but the documents and data CSCRF is protecting still need to be found and secured in a separate repository

  • Point VAPT/SOC vendors: Strong on the security-testing and monitoring layer, narrower on where the underlying data actually lives

  • In-house SOC + spreadsheets: Most flexible on paper, but CCI tracking, log retention, and audit evidence assembly are left entirely to the team