Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • English
    • English (US)
Contact Us
CyberNX Logo
  • English
    • English (US)
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • Contact

Data Localisation under SEBI CSCRF: Why the Mandate is Still in Abeyance

4 min read
9 Views
  • SEBI CSCRF

Where your data is stored is as important as how well it is protected. Across the world, regulators are introducing data localisation requirements to make sure sensitive information remains within national borders, improving oversight, resilience and data sovereignty. India’s financial sector is no exception in this case.

As part of its Cybersecurity and Cyber Resilience Framework (CSCRF), the Securities and Exchange Board of India (SEBI) introduced a data localisation requirement that would require regulated entities to host data relating to the Indian securities market within India. However, before the requirement became enforceable, SEBI issued a circular on 31 December 2024 placing the mandate in abeyance. In simple words, the requirement exists within the framework but is not currently mandatory.

That decision continues to shape compliance planning today. Firms must understand what the data localisation requirement originally intended, why SEBI paused it, which CSCRF obligations remain fully enforceable and how to prepare if the mandate is reinstated in the future.

This blog explains the current regulatory position, the practical implications for regulated entities and the steps BFSI compliance teams should take while the requirement remains on hold.

Table of Contents

What data localisation under SEBI CSCRF actually covers

SEBI introduced CSCRF through circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 Aug 2024. Inside the Protect function’s Data Security family, there is control PR.DS.S2, the Data Localisation standard. It was written to require regulated entities to host data connected to Indian securities market operations within India’s legal boundaries.

The scope was broad by design. It broadly applied to data relating to Indian securities market operations. Any regulated entity relying on overseas hosting arrangements would probably have needed architectural changes to satisfy localisation requirement.

Why the requirement moved into abeyance

Four months after the original circular, SEBI changed course. Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 which was dated 31 Dec 2024, extended certain compliance timelines and added a short but important note. Based on feedback received on the data localisation provisions, SEBI decided the standard needed further consultation and placed PR.DS.S2 in abeyance until further notification.

That pause has been held since. Subsequent CSCRF updates, including the technical clarification circular issued in Aug 2025, continued to list Data Localisation as in abeyance rather than reinstating it. No compliance deadline has been announced for PR.DS.S2, and no timeline for a decision has been published either.

What stays binding under SEBI CSCRF despite the pause

Abeyance applies narrowly to the geographic hosting requirement. Every other data-related control in CSCRF remains active and auditable. Regulated entities should still budget effort and evidence for:

SEBI CSCRF Data Controls Still Binding

  • Data classification: Sorting information into Public, Internal, Confidential and Restricted tiers remains a core CSCRF expectation.
  • Encryption at rest and in transit: The framework’s baseline encryption standard, PR.DS.S1, continues to apply to systems handling regulated data.
  • Data loss prevention monitoring: Continuous DLP coverage for critical systems is still required under the Detect function.
  • Log management and database activity monitoring: Centralised logging and database monitoring remain part of the audit evidence SEBI expects.
  • Secure data disposal: Retention and disposal practices must still align with SEBI’s record-keeping requirements.
  • Asset inventory and software bill of materials: Maintaining an accurate inventory of applications and their components stays mandatory for critical systems.

How this fits with the DPDP Act and CERT-In requirements

The Digital Personal Data Protection Act, 2023 (DPDP Act), takes a different route on cross-border data than the paused SEBI standard did. Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025, follow a blocklist approach. Personal data can move outside India by default, barring only transfers to countries the government specifically restricts, and no such list exists yet.

That lighter-touch model may be part of why SEBI wants more time before finalising its own position. Separately, CERT-In’s log retention rule asks regulated entities to keep certain logs within India for 180 days. That obligation sits outside CSCRF and is unaffected by the abeyance.

How BFSI compliance teams should plan while the mandate is paused

A few things that BFSI compliance teams should plan when the mandate is paused:

  • Do not list Data Localisation as binding in internal audit scopes or IT committee reports this cycle.
  • Do not exclude it from long-term architecture planning. Keep cloud contracts flexible enough to accommodate reactivation.
  • Document the abeyance in compliance records, citing circular 2024/184, so audit evidence reflects the current status.
  • Monitor SEBI’s circular page for a notification, since SEBI has not given long lead times for similar changes before.
  • Treat the binding data controls above as the real audit priority for this cycle.

Conclusion

Data Localisation under SEBI CSCRF is one of the most closely watched provisions in India, precisely because it is paused. The underlying control, its evidence requirements and its potential return all deserve a place in compliance planning, even while the mandate itself stays inactive. Every other CSCRF data control, from classification to encryption to asset inventory, continues to need audit-ready evidence today.

It’s important to build that evidence base and stay prepared for a possible reactivation of Data Localisation Under SEBI CSCRF. It needs a compliance programme that tracks every binding control alongside the paused one. CyberNX’s SEBI CSCRF framework consulting services help regulated entities run gap assessments, build a compliance roadmap and keep CSCRF evidence audit-ready, irrespective of if there’s abeyance or not. Connect with our experts to build a compliance architecture that is prepared for both outcomes.

Data Localisation Under SEBI CSCRF FAQs

What is PR.DS.S2 under SEBI CSCRF?

PR.DS.S2 is the CSCRF Data Security standard that would require regulated entities to host data related to Indian securities market operations within India. It sits in the framework’s Protect function.

Is data localisation currently mandatory under SEBI CSCRF?

No. SEBI placed the standard in abeyance through circular 2024/184 dated 31 Dec 2024, and subsequent CSCRF updates have not reinstated it.

Does the DPDP Act require data localisation?

No. The DPDP Act and its 2025 Rules allow personal data to move outside India by default, restricting only transfers to countries the government specifically notifies, and no such list exists yet.

What should regulated entities prioritise instead of localisation right now?

Data classification, encryption, DLP monitoring, log management, secure disposal and asset inventory remain binding and should form the current audit priority.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
SEBI CSCRF for KRAs and QRTAs: Key Changes You Must Know

SEBI CSCRF for KRAs & QRTAs: What Changed and What You Must Do Now

Every time an investor opens a demat account, a mutual fund folio or a trading account in India, their record

VAPT Requirements under SEBI CSCRF: A Quick Compliance Overview

VAPT Requirements under SEBI CSCRF: What Regulated Entities Must Know

VAPT is one of the most important parts of any cybersecurity program. It finds the weak spots in your cybersecurity

Incident Response under SEBI CSCRF: A Compliance Guide

Incident Response under SEBI CSCRF: A Practical Guide for Regulated Entities

CERT-In gives regulated entities six hours to report a cyber incident once it is detected. For SEBI-regulated firms, that clock

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
    • English (US)
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.