Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • English (US)
    • English
Contact Us
CyberNX Logo
  • English (US)
    • English
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • Contact

SEBI CSCRF for KRAs & QRTAs: What Changed and What You Must Do Now

4 min read
8 Views
  • SEBI CSCRF

Every time an investor opens a demat account, a mutual fund folio or a trading account in India, their record gets checked against a single centralised database. That database sits with a KYC Registration Agency (KRA). It’s the reason SEBI treats KRAs – as well as Qualified Registrars to an Issue and Share Transfer Agents (QRTAs) – as high-value entities under its Cybersecurity and Cyber Resilience Framework (CSCRF).

In April 2025, SEBI reclassified KRAs from MII category to Qualified RE category. QRTAs remained MIIs. The obligations your organisation carries today may look different from what applied in 2024. This guide breaks down SEBI CSCRF for KRAs & QRTAs: what changed, what stayed the same and what to do next.

Table of Contents

What is SEBI CSCRF for KRAs and QRTAs?

SEBI’s Cybersecurity and Cyber Resilience Framework brings every SEBI-regulated entity under one unified cybersecurity structure. It replaced a set of older, scattered circulars with a single rulebook covering governance, network security, data protection and incident response.

Entities are grouped into tiers based on risk. KRAs and QRTAs sit at the top because both handle sensitive investor data at a large scale:

  • KRAs hold the centralised KYC records used across the market
  • QRTAs service the largest folio bases among Registrar and Transfer Agents

Because of this footprint, both entity types were both subjected to MII-level obligations, the heaviest tier in the framework.

How the April 2025 reclassification changed KRA obligations

Under SEBI’s original CSCRF circular of August 2024, KRAs sat at MII tier alongside Stock Exchanges, Depositories and Clearing Corporations. That meant half-yearly VAPT, mandatory ISO 27001, a Market SOC obligation and third-party Cyber Capability Index (CCI) assessments every six months.

SEBI’s amendment circular, CIR/2025/60, moved KRAs from MII tier to Qualified RE (QRE) tier. Several obligations eased and many others stayed exactly where they were.

What changed for KRAs under SEBI CSCRF

The table below sums up the shift. Some obligations reduced in frequency or became optional. Others remained fixed at the MII standard, since the underlying data risk has not changed.

What Changed for KRAs under SEBI CSCRF

  • VAPT frequency eased: Half-yearly VAPT moved to annual, unless the KRA is designated a Critical Information Infrastructure (CII) or Protected System, in which case half-yearly VAPT still applies.
  • CCI assessment simplified: The Cyber Capability Index assessment moved from a mandatory third-party review every six months to an annual self-assessment.
  • ISO 27001 became voluntary: KRAs that already hold the certification can retain it. New certification is no longer mandatory for this tier.
  • Market SOC onboarding became optional: KRAs are now eligible to onboard to the Market SOC run by NSE or BSE, rather than required to operate one.
  • Cyber audit, red teaming and threat hunting stayed unchanged: Half-yearly cyber audits, half-yearly red teaming and quarterly threat hunting remain at the same cadence as MII tier.
  • CISO reporting line stayed unchanged: The CISO must still report directly to the MD or CEO, with a grade equivalent to CTO or CIO.
  • RTO/RPO targets stayed unchanged: Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes still apply.

Why QRTAs still carry the full MII burden

QRTAs did not move. Registrar and Transfer Agents servicing 2 crore folios or more remain classified at MII tier, with no change from the April 2025 amendment. The threshold is a hard line: an RTA on 1.9 crore folios sits at Mid-size RE, while one at 2.0 crore folios sits at MII tier.

For QRTAs, this means the complete MII compliance set applies without exception:

  • Half-yearly VAPT for CII and Protected Systems
  • Half-yearly cyber audit and red teaming
  • Quarterly threat hunting
  • Mandatory ISO 27001 certification
  • Third-party CCI assessment every six months
  • Market SOC operation through NSE or BSE
  • Quarterly IT Committee meetings with an external cyber expert

Folio count is checked at the start of each financial year using the prior year’s data. A QRTA that drops below 2 crore folios only reclassifies from the start of the following financial year, not mid-year.

Practical steps for KRAs and QRTAs

Getting the tier right is only the first step. Both entity types need to translate the classification into an updated programme:

  • For KRAs: Update documentation to reflect Qualified RE tier. Decide whether to retain ISO 27001 if already certified. Keep the half-yearly cyber audit and red teaming calendar unchanged.
  • For QRTAs: Reconfirm folio count every financial year. Prepare the half-yearly audit and Board reporting cycle MII tier demands.
  • For both: Map current controls against the CSCRF’s five domains, governance, network security, application security, data protection and incident management, and close gaps before the next audit.

The stakes are real. Already, the average cost of a data breach in India was at an all-time high in 2025, with phishing and third-party vendor compromise among the top causes. For entities holding centralised KYC and investor data, that exposure is what CSCRF is designed to reduce.

Conclusion

The 2025 amendment changed how KRAs are classified under SEBI CSCRF, easing some obligations while leaving the heaviest ones, cyber audit, red teaming and CISO reporting, exactly where they were. QRTAs saw no change and continue to carry the complete MII burden.

CyberNX provides SEBI CSCRF consulting services that help KRAs and QRTAs map their current controls, close gaps and stay audit-ready under SEBI CSCRF for KRAs & QRTAs, from VAPT and red teaming to CCI assessments and IT Committee support. We help you understand SEBI CSCRF needs, develop a compliance roadmap and do periodic assessments as well as measure effectiveness. Connect with our experts to review where your company stands today.

SEBI CSCRF for KRAs & QRTAs FAQs

What is SEBI CSCRF for KRAs and QRTAs?

It is the set of cybersecurity obligations SEBI applies to KYC Registration Agencies and Qualified Registrars to an Issue and Share Transfer Agents under its Cybersecurity and Cyber Resilience Framework, based on each entity’s classification tier.

Why were KRAs moved from MII to Qualified RE tier?

SEBI’s amendment circular CIR/2025/60 re-categorised KRAs from the MII category to the Qualified RE category. The circular does not specify the rationale for this change.

Do QRTAs need to do anything differently after the April 2025 amendment?

No. QRTAs servicing 2 crore folios or more remain at MII tier. The amendment applied only to KRA classification, so QRTAs continue to follow the full MII compliance calendar.

What happens if a KRA also holds another SEBI registration?

The multi-category rule under CSCRF applies. If a KRA also holds a registration that qualifies for MII tier, such as a Depository licence, the higher MII classification governs across all its operations.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Data Localisation under SEBI CSCRF: A Compliance Snapshot

Data Localisation under SEBI CSCRF: Why the Mandate is Still in Abeyance

Where your data is stored is as important as how well it is protected. Across the world, regulators are introducing

VAPT Requirements under SEBI CSCRF: A Quick Compliance Overview

VAPT Requirements under SEBI CSCRF: What Regulated Entities Must Know

VAPT is one of the most important parts of any cybersecurity program. It finds the weak spots in your cybersecurity

Incident Response under SEBI CSCRF: A Compliance Guide

Incident Response under SEBI CSCRF: A Practical Guide for Regulated Entities

CERT-In gives regulated entities six hours to report a cyber incident once it is detected. For SEBI-regulated firms, that clock

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English (US)
    • English
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.