Every time an investor opens a demat account, a mutual fund folio or a trading account in India, their record gets checked against a single centralised database. That database sits with a KYC Registration Agency (KRA). It’s the reason SEBI treats KRAs – as well as Qualified Registrars to an Issue and Share Transfer Agents (QRTAs) – as high-value entities under its Cybersecurity and Cyber Resilience Framework (CSCRF).
In April 2025, SEBI reclassified KRAs from MII category to Qualified RE category. QRTAs remained MIIs. The obligations your organisation carries today may look different from what applied in 2024. This guide breaks down SEBI CSCRF for KRAs & QRTAs: what changed, what stayed the same and what to do next.
What is SEBI CSCRF for KRAs and QRTAs?
SEBI’s Cybersecurity and Cyber Resilience Framework brings every SEBI-regulated entity under one unified cybersecurity structure. It replaced a set of older, scattered circulars with a single rulebook covering governance, network security, data protection and incident response.
Entities are grouped into tiers based on risk. KRAs and QRTAs sit at the top because both handle sensitive investor data at a large scale:
- KRAs hold the centralised KYC records used across the market
- QRTAs service the largest folio bases among Registrar and Transfer Agents
Because of this footprint, both entity types were both subjected to MII-level obligations, the heaviest tier in the framework.
How the April 2025 reclassification changed KRA obligations
Under SEBI’s original CSCRF circular of August 2024, KRAs sat at MII tier alongside Stock Exchanges, Depositories and Clearing Corporations. That meant half-yearly VAPT, mandatory ISO 27001, a Market SOC obligation and third-party Cyber Capability Index (CCI) assessments every six months.
SEBI’s amendment circular, CIR/2025/60, moved KRAs from MII tier to Qualified RE (QRE) tier. Several obligations eased and many others stayed exactly where they were.
What changed for KRAs under SEBI CSCRF
The table below sums up the shift. Some obligations reduced in frequency or became optional. Others remained fixed at the MII standard, since the underlying data risk has not changed.
- VAPT frequency eased: Half-yearly VAPT moved to annual, unless the KRA is designated a Critical Information Infrastructure (CII) or Protected System, in which case half-yearly VAPT still applies.
- CCI assessment simplified: The Cyber Capability Index assessment moved from a mandatory third-party review every six months to an annual self-assessment.
- ISO 27001 became voluntary: KRAs that already hold the certification can retain it. New certification is no longer mandatory for this tier.
- Market SOC onboarding became optional: KRAs are now eligible to onboard to the Market SOC run by NSE or BSE, rather than required to operate one.
- Cyber audit, red teaming and threat hunting stayed unchanged: Half-yearly cyber audits, half-yearly red teaming and quarterly threat hunting remain at the same cadence as MII tier.
- CISO reporting line stayed unchanged: The CISO must still report directly to the MD or CEO, with a grade equivalent to CTO or CIO.
- RTO/RPO targets stayed unchanged: Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes still apply.
Why QRTAs still carry the full MII burden
QRTAs did not move. Registrar and Transfer Agents servicing 2 crore folios or more remain classified at MII tier, with no change from the April 2025 amendment. The threshold is a hard line: an RTA on 1.9 crore folios sits at Mid-size RE, while one at 2.0 crore folios sits at MII tier.
For QRTAs, this means the complete MII compliance set applies without exception:
- Half-yearly VAPT for CII and Protected Systems
- Half-yearly cyber audit and red teaming
- Quarterly threat hunting
- Mandatory ISO 27001 certification
- Third-party CCI assessment every six months
- Market SOC operation through NSE or BSE
- Quarterly IT Committee meetings with an external cyber expert
Folio count is checked at the start of each financial year using the prior year’s data. A QRTA that drops below 2 crore folios only reclassifies from the start of the following financial year, not mid-year.
Practical steps for KRAs and QRTAs
Getting the tier right is only the first step. Both entity types need to translate the classification into an updated programme:
- For KRAs: Update documentation to reflect Qualified RE tier. Decide whether to retain ISO 27001 if already certified. Keep the half-yearly cyber audit and red teaming calendar unchanged.
- For QRTAs: Reconfirm folio count every financial year. Prepare the half-yearly audit and Board reporting cycle MII tier demands.
- For both: Map current controls against the CSCRF’s five domains, governance, network security, application security, data protection and incident management, and close gaps before the next audit.
The stakes are real. Already, the average cost of a data breach in India was at an all-time high in 2025, with phishing and third-party vendor compromise among the top causes. For entities holding centralised KYC and investor data, that exposure is what CSCRF is designed to reduce.
Conclusion
The 2025 amendment changed how KRAs are classified under SEBI CSCRF, easing some obligations while leaving the heaviest ones, cyber audit, red teaming and CISO reporting, exactly where they were. QRTAs saw no change and continue to carry the complete MII burden.
CyberNX provides SEBI CSCRF consulting services that help KRAs and QRTAs map their current controls, close gaps and stay audit-ready under SEBI CSCRF for KRAs & QRTAs, from VAPT and red teaming to CCI assessments and IT Committee support. We help you understand SEBI CSCRF needs, develop a compliance roadmap and do periodic assessments as well as measure effectiveness. Connect with our experts to review where your company stands today.
SEBI CSCRF for KRAs & QRTAs FAQs
What is SEBI CSCRF for KRAs and QRTAs?
It is the set of cybersecurity obligations SEBI applies to KYC Registration Agencies and Qualified Registrars to an Issue and Share Transfer Agents under its Cybersecurity and Cyber Resilience Framework, based on each entity’s classification tier.
Why were KRAs moved from MII to Qualified RE tier?
SEBI’s amendment circular CIR/2025/60 re-categorised KRAs from the MII category to the Qualified RE category. The circular does not specify the rationale for this change.
Do QRTAs need to do anything differently after the April 2025 amendment?
No. QRTAs servicing 2 crore folios or more remain at MII tier. The amendment applied only to KRA classification, so QRTAs continue to follow the full MII compliance calendar.
What happens if a KRA also holds another SEBI registration?
The multi-category rule under CSCRF applies. If a KRA also holds a registration that qualifies for MII tier, such as a Depository licence, the higher MII classification governs across all its operations.




