Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    Qvoyant

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
    • PQC Readiness
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    Qvoyant

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
    • PQC Readiness
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

How to Set up a Compliance Program for CSCRF in Your Organisation

4 min read
3 Views
  • SEBI CSCRF

In 2025, SEBI revised the CSCRF classification thresholds for stockbrokers, potentially moving firms with larger client bases or trading volumes into higher regulatory categories. For mid-size regulated entities, this can mean additional governance, cybersecurity, audit and incident-response requirements, including an IT Committee with an external cybersecurity expert, applicable VAPT and cyber audits, cybersecurity policies, and documented incident-response procedures.

For organisations with lean IT and compliance teams, meeting these requirements can be challenging. This blog explains how to set up a compliance program for CSCRF in your organisation, with a practical roadmap for building, implementing and maintaining CSCRF compliance.

Table of Contents

4 Steps to Build Compliance Program for CSCRF

Step one: confirm your tier and get it right

Everything in your compliance programme – scope, budget, audit frequency, governance structure – flows from your tier. Getting it wrong means either under-compliance or wasted investment.

Under the April 2025 clarification, stockbrokers are classified using a two-parameter rule. Your tier is determined by whichever of your two parameters – total registered clients or annual trading volume – places you in the higher category.

The current thresholds are:

  • Qualified RE (Qualified Stockbroker): more than 10 lakh clients OR more than Rs 10 lakh crore annual trading volume
  • Mid-size RE: more than 1 lakh clients OR more than Rs 1 lakh crore annual trading volume
  • Small size RE: more than 10,000 clients OR more than Rs 10,000 crore annual trading volume
  • Self-certification RE: more than 1,000 clients OR more than Rs 1,000 crore annual trading volume
  • Exempt: fewer than 1,000 clients AND less than Rs 1,000 crore annual trading volume – fully exempt from CSCRF

Your category is fixed at the start of each financial year using the previous year’s data and does not change mid-year. If you hold registrations in more than one SEBI-regulated capacity, the highest applicable tier governs your entire programme. Recheck your classification every April – CSCRF has been amended three times since August 2024 and thresholds have changed materially each time.

Step two: establish governance before touching technology

Most brokers reach for technology first – a new SIEM, an endpoint tool, a firewall upgrade. CSCRF starts with governance. Build the structure before the controls.

1. Designate a CISO or equivalent

Every regulated entity above self-certification must appoint a CISO or an equivalent role with documented responsibilities and a direct reporting line to the MD or CEO. For smaller brokers, a virtual CISO (vCISO) arrangement with a qualified external professional is a practical, CSCRF-compatible option.

2. Constitute an IT Committee

Mid-size and above entities must form an IT Committee with at least one external independent cybersecurity expert. This committee must meet quarterly with cybersecurity as a standing agenda item. Minutes from these meetings become audit evidence – auditors will ask for them.

3. Get board approval on a cybersecurity policy

CSCRF requires a written, board-approved cybersecurity policy covering asset classification, access controls, vendor risk, incident response and business continuity. For a stockbroker, this policy must address account takeover risks, order management system integrity and connectivity security to NSE and BSE. Review and reapprove it annually – document every review cycle.

Step three: map controls to your tier obligations

Do not build for MII-level compliance if you are a mid-size broker. Do not build below your tier. Map controls precisely to what your classification requires.

Self-certification brokers must:

  • Complete annual VAPT by a CERT-In empanelled auditor
  • Report incidents to SEBI and CERT-In within six hours of detection
  • Onboard to the Market-SOC (M-SOC) operated by NSE or BSE, unless operating their own SOC with periodic functional efficacy reports submitted to SEBI
  • Maintain a documented Cyber Crisis Management Plan (CCMP)

Small-size brokers carry the same obligations as self-certification, with a broader VAPT scope and more structured access control and endpoint security requirements across trading and back-office systems.

Mid-size brokers add:

  • IT Committee with external cybersecurity expert, meeting quarterly
  • Annual cyber audit covering all critical systems and a sample of non-critical systems, conducted by a CERT-In empanelled auditor
  • Documented vulnerability closure timelines – critical patches within 24 hours, all VAPT findings closed within three months
  • Annual cybersecurity awareness training for all staff
  • Third-party risk assessments for vendors with access to trading infrastructure

One point that applies across all tiers: M-SOC onboarding. SEBI’s May 2026 AI advisory directed all eligible non-onboarded entities to expedite this. For brokers without in-house SOC capability, M-SOC is both the compliance-efficient and cost-efficient path to meeting continuous monitoring requirements.

Step four: run compliance year-round

The most common failure mode for small and mid-size brokers is treating compliance as a pre-audit sprint. SEBI auditors are trained to spot it – quarterly IT Committee minutes with identical language, VAPT closure dates that cluster just before submission deadlines, incident logs with no entries throughout the year.

Build a calendar that runs continuously:

  • Monthly: open vulnerability tracking, access control review, SOC performance review
  • Quarterly: IT Committee meeting with documented minutes, third-party vendor review
  • Annually: full cyber audit, cybersecurity awareness training, policy review with board approval, CCMP testing

Book your CERT-In empanelled auditor well in advance. Demand spikes before SEBI submission deadlines. Late bookings risk missing your audit window.

Conclusion

A CSCRF compliance programme built correctly is a security discipline that satisfies your audit obligations as a by-product. For small and mid-size stockbrokers, the sequence is clear: confirm your tier accurately, build governance first, match controls to your actual obligations and maintain evidence year-round.

The audit does not create the compliance requirement. It reveals whether you have been meeting it all along.

CyberNX works with stockbrokers across all CSCRF tiers to build programmes that are operationally sound and audit ready. Connect with our SEBI CSCRF consulting team to assess where your current posture stands.

FAQs

What are the CSCRF tier thresholds for stockbrokers after the April 2025 revision?

Stockbrokers are classified using a two-parameter rule – whichever of total registered clients or annual trading volume places you in a higher tier determines your classification. Qualified RE: more than 10 lakh clients or Rs 10 lakh crore volume. Mid-size: more than 1 lakh clients or Rs 1 lakh crore volume. Small-size: more than 10,000 clients or Rs 10,000 crore volume. Self-certification: more than 1,000 clients or Rs 1,000 crore volume. Brokers below both thresholds are fully exempt. Your category is fixed for the full financial year and recalculated each April using the prior year’s data.

Does a small stockbroker need a full-time CISO?

No. CSCRF requires a designated CISO or equivalent with documented responsibilities and a direct reporting line to the MD or CEO – but does not mandate a full-time internal hire for smaller entities. A virtual CISO (vCISO) arrangement satisfies the framework’s governance requirement and is a practical option for brokers with lean IT teams.

What happens if a broker misses a CSCRF compliance deadline?

SEBI has a structured penalty framework for non-compliance – penalties escalate by entity size and number of lapses, and SEBI has the authority to restrict activities or suspend registration for persistent failures. Beyond penalties, a missed audit submission leaves the broker exposed in any subsequent SEBI inspection. The compliance deadlines for most entities passed on 31 August 2025 – the obligation now is the ongoing audit and reporting cycle.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Patch Management and Technical Controls under CSCRF

Patch Management and Technical Controls under CSCRF

CSCRF sets precise patching timelines, specific evidence requirements and defined technical controls across access, network, application and endpoint layers. It

AI, Cloud and Zero-Trust within CSCRF Compliance

The Role of Emerging Technologies (AI, Cloud, Zero-Trust) within CSCRF Compliance

Search through SEBI’s CSCRF circular and you will not find the words “Zero Trust”, “generative AI” or “cloud-first.” What you

Impact of CSCRF on investor confidence and market stability

Impact of CSCRF on Investor Confidence and Market Stability

In November 2022, a malware attack on a financial firm operating under depository services industry, disrupted the settlement process and

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

Qvoyant

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • PQC Readiness
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.