In 2025, SEBI revised the CSCRF classification thresholds for stockbrokers, potentially moving firms with larger client bases or trading volumes into higher regulatory categories. For mid-size regulated entities, this can mean additional governance, cybersecurity, audit and incident-response requirements, including an IT Committee with an external cybersecurity expert, applicable VAPT and cyber audits, cybersecurity policies, and documented incident-response procedures.
For organisations with lean IT and compliance teams, meeting these requirements can be challenging. This blog explains how to set up a compliance program for CSCRF in your organisation, with a practical roadmap for building, implementing and maintaining CSCRF compliance.
Step one: confirm your tier and get it right
Everything in your compliance programme – scope, budget, audit frequency, governance structure – flows from your tier. Getting it wrong means either under-compliance or wasted investment.
Under the April 2025 clarification, stockbrokers are classified using a two-parameter rule. Your tier is determined by whichever of your two parameters – total registered clients or annual trading volume – places you in the higher category.
The current thresholds are:
- Qualified RE (Qualified Stockbroker): more than 10 lakh clients OR more than Rs 10 lakh crore annual trading volume
- Mid-size RE: more than 1 lakh clients OR more than Rs 1 lakh crore annual trading volume
- Small size RE: more than 10,000 clients OR more than Rs 10,000 crore annual trading volume
- Self-certification RE: more than 1,000 clients OR more than Rs 1,000 crore annual trading volume
- Exempt: fewer than 1,000 clients AND less than Rs 1,000 crore annual trading volume – fully exempt from CSCRF
Your category is fixed at the start of each financial year using the previous year’s data and does not change mid-year. If you hold registrations in more than one SEBI-regulated capacity, the highest applicable tier governs your entire programme. Recheck your classification every April – CSCRF has been amended three times since August 2024 and thresholds have changed materially each time.
Step two: establish governance before touching technology
Most brokers reach for technology first – a new SIEM, an endpoint tool, a firewall upgrade. CSCRF starts with governance. Build the structure before the controls.
1. Designate a CISO or equivalent
Every regulated entity above self-certification must appoint a CISO or an equivalent role with documented responsibilities and a direct reporting line to the MD or CEO. For smaller brokers, a virtual CISO (vCISO) arrangement with a qualified external professional is a practical, CSCRF-compatible option.
2. Constitute an IT Committee
Mid-size and above entities must form an IT Committee with at least one external independent cybersecurity expert. This committee must meet quarterly with cybersecurity as a standing agenda item. Minutes from these meetings become audit evidence – auditors will ask for them.
3. Get board approval on a cybersecurity policy
CSCRF requires a written, board-approved cybersecurity policy covering asset classification, access controls, vendor risk, incident response and business continuity. For a stockbroker, this policy must address account takeover risks, order management system integrity and connectivity security to NSE and BSE. Review and reapprove it annually – document every review cycle.
Step three: map controls to your tier obligations
Do not build for MII-level compliance if you are a mid-size broker. Do not build below your tier. Map controls precisely to what your classification requires.
Self-certification brokers must:
- Complete annual VAPT by a CERT-In empanelled auditor
- Report incidents to SEBI and CERT-In within six hours of detection
- Onboard to the Market-SOC (M-SOC) operated by NSE or BSE, unless operating their own SOC with periodic functional efficacy reports submitted to SEBI
- Maintain a documented Cyber Crisis Management Plan (CCMP)
Small-size brokers carry the same obligations as self-certification, with a broader VAPT scope and more structured access control and endpoint security requirements across trading and back-office systems.
Mid-size brokers add:
- IT Committee with external cybersecurity expert, meeting quarterly
- Annual cyber audit covering all critical systems and a sample of non-critical systems, conducted by a CERT-In empanelled auditor
- Documented vulnerability closure timelines – critical patches within 24 hours, all VAPT findings closed within three months
- Annual cybersecurity awareness training for all staff
- Third-party risk assessments for vendors with access to trading infrastructure
One point that applies across all tiers: M-SOC onboarding. SEBI’s May 2026 AI advisory directed all eligible non-onboarded entities to expedite this. For brokers without in-house SOC capability, M-SOC is both the compliance-efficient and cost-efficient path to meeting continuous monitoring requirements.
Step four: run compliance year-round
The most common failure mode for small and mid-size brokers is treating compliance as a pre-audit sprint. SEBI auditors are trained to spot it – quarterly IT Committee minutes with identical language, VAPT closure dates that cluster just before submission deadlines, incident logs with no entries throughout the year.
Build a calendar that runs continuously:
- Monthly: open vulnerability tracking, access control review, SOC performance review
- Quarterly: IT Committee meeting with documented minutes, third-party vendor review
- Annually: full cyber audit, cybersecurity awareness training, policy review with board approval, CCMP testing
Book your CERT-In empanelled auditor well in advance. Demand spikes before SEBI submission deadlines. Late bookings risk missing your audit window.
Conclusion
A CSCRF compliance programme built correctly is a security discipline that satisfies your audit obligations as a by-product. For small and mid-size stockbrokers, the sequence is clear: confirm your tier accurately, build governance first, match controls to your actual obligations and maintain evidence year-round.
The audit does not create the compliance requirement. It reveals whether you have been meeting it all along.
CyberNX works with stockbrokers across all CSCRF tiers to build programmes that are operationally sound and audit ready. Connect with our SEBI CSCRF consulting team to assess where your current posture stands.
FAQs
What are the CSCRF tier thresholds for stockbrokers after the April 2025 revision?
Stockbrokers are classified using a two-parameter rule – whichever of total registered clients or annual trading volume places you in a higher tier determines your classification. Qualified RE: more than 10 lakh clients or Rs 10 lakh crore volume. Mid-size: more than 1 lakh clients or Rs 1 lakh crore volume. Small-size: more than 10,000 clients or Rs 10,000 crore volume. Self-certification: more than 1,000 clients or Rs 1,000 crore volume. Brokers below both thresholds are fully exempt. Your category is fixed for the full financial year and recalculated each April using the prior year’s data.
Does a small stockbroker need a full-time CISO?
No. CSCRF requires a designated CISO or equivalent with documented responsibilities and a direct reporting line to the MD or CEO – but does not mandate a full-time internal hire for smaller entities. A virtual CISO (vCISO) arrangement satisfies the framework’s governance requirement and is a practical option for brokers with lean IT teams.
What happens if a broker misses a CSCRF compliance deadline?
SEBI has a structured penalty framework for non-compliance – penalties escalate by entity size and number of lapses, and SEBI has the authority to restrict activities or suspend registration for persistent failures. Beyond penalties, a missed audit submission leaves the broker exposed in any subsequent SEBI inspection. The compliance deadlines for most entities passed on 31 August 2025 – the obligation now is the ongoing audit and reporting cycle.




