A single Registrar and Transfer Agent can hold folio records for millions of investors for dozens of listed companies. That data is basically in one place, probably managed by a small back-office team, that might have limited built-in security oversight. A breach at this level would not just affect one company. It exposes shareholders across the entire market it serves.
SEBI CSCRF for RTAs solves this by setting clear, tiered security obligations based on how much data an RTA handles. Smaller RTAs get lighter requirements. Larger ones, especially the Qualified RTAs, follow a stricter audit and governance cycle.
This guide breaks down who SEBI CSCRF for RTAs applies to, what it requires and how to build compliance without disturbing day-to-day operations.
What is SEBI CSCRF for RTAs?
SEBI CSCRF for RTAs is the cybersecurity and cyber resilience framework the Securities and Exchange Board of India applies to Registrar and Transfer Agents. SEBI issued the master circular on Aug 20, 2024, replacing older cyber security guidelines for RTAs and other regulated entities.
The framework sets rules for governance, security controls, incident reporting and periodic audits. It applies alongside similar frameworks SEBI has built for stock brokers, depositories and mutual funds. For RTAs, the goal is simple: protect investor data and keep operations stable and resilient against cyberattacks.
Which RTAs must comply
Not every RTA falls under the same obligations. SEBI CSCRF compliance depends on the scale of operations.
- RTAs servicing fewer than 10,000 folios are excluded from the CSCRF requirements specified for higher-category entities, subject to SEBI’s applicability criteria.
- RTAs with more than 100 clients but below the QRTA threshold follow standard RE obligations, including onboarding to Market-SOC (M-SOC).
- RTAs with fewer than 100 clients are exempt from mandatory SOC services or M-SOC onboarding.
- RTAs become a Qualified RTA (QRTA) once combined physical and demat folios for listed companies cross 2 crores in any financial year.
Once an RTA crosses the QRTA threshold, it stays classified as a QRTA for the next three financial years, even if folio numbers later drop. The entity must inform SEBI within five working days of crossing the threshold and has 60 days to implement enhanced QRTA requirements.
Key requirements under the framework
QRTAs carry the heaviest compliance load. Standard RTAs above the exemption threshold still need baseline controls, but the intensity scales with classification. QRTA cyber audit obligations sit at the centre of this heavier compliance tier.
Here is what the framework expects, structured by activity:
- IT committee formation: Constitute a committee that includes at least one external cybersecurity expert to oversee governance decisions.
- Cyber audits: QRTAs must conduct comprehensive cyber audits twice a year. Audits must be carried out by CERT-In empanelled auditors.
- Management sign-off: The MD or CEO must submit a declaration confirming compliance alongside every cyber audit report.
- VAPT activity: Conduct vulnerability assessment and penetration testing at a cadence tied to entity category, with reports submitted within one month of completion.
- SOC monitoring: RTAs above the exemption thresholds must onboard to Market-SOC for continuous monitoring, unless specifically exempted.
- Data localisation: Sensitive investor data handled through SaaS-based solutions must stay within India’s legal boundaries, per SEBI’s advisory on SaaS adoption for financial sector organisations.
If an RTA holds multiple SEBI registrations, it must comply with the requirements of the highest applicable category. This layered structure is what makes SEBI CSCRF compliance tricky for RTAs operating across more than one registration type.
Compliance timelines and where things stand in 2026
SEBI extended CSCRF implementation deadlines twice through 2025, moving the effective date to Aug 31, 2025 for most regulated entities. MIIs, KRAs and QRTAs followed an earlier schedule and did not receive the same extension.
The framework now runs on a recurring audit cycle rather than a one-time deadline. RTAs that have not completed a first audit under this cycle carry direct exposure to regulatory action from SEBI and the exchanges.
Building a practical compliance approach
Meeting SEBI CSCRF for RTAs starts with confirming classification. An RTA needs to know its folio count, client count and whether it qualifies for exemption before deciding on control depth. A clear SEBI CSCRF for RTAs roadmap makes this sequencing far easier to defend during an audit.
From there, a phased approach works best:
- Map current controls against the CSCRF baseline to identify gaps.
- Prioritise IT committee formation and CERT-In empanelled audit scheduling, since both carry fixed timelines.
- Build a compliance calendar that tracks VAPT, cyber audits and CCI submissions against your specific entity tier.
- Review SaaS vendor contracts for data localisation clauses.
Getting this sequencing right prevents the common failure mode: scrambling to complete a first audit only after a deadline has already passed.
Conclusion
SEBI CSCRF for RTAs is not something that is done once and then forgotten. It is a repeating cycle of audits, VAPT, governance reviews and data protection controls that scales with how many folios and clients an RTA serves. Getting classification right and building a compliance calendar early keeps an RTA ahead of its obligations rather than reacting to them.
CyberNX helps RTAs and other SEBI regulated entities navigate this framework end to end, from gap assessment to audit readiness. Connect with our SEBI CSCRF framework consulting experts to build a compliance roadmap suited to your entity’s classification.
SEBI CSCRF for RTAs FAQs
What Is a Qualified RTA (QRTA)?
An RTA becomes a QRTA once combined physical and demat folios serviced for listed companies exceed 2 crores in a financial year. The classification holds for three financial years, regardless of any later drop in folio count.
Are All RTAs Required to Comply with SEBI CSCRF?
No. RTAs servicing fewer than 10,000 folios are excluded from CSCRF submission requirements. Compliance intensity for the remaining RTAs depends on client count and QRTA status.
How Often Must QRTAs Conduct Cyber Audits?
QRTAs must complete comprehensive cyber audits twice a year, using CERT-In empanelled auditors. The MD or CEO must sign a compliance declaration with each report.
What Happens if an RTA Misses Its Audit Deadline?
Entities that miss a scheduled audit cycle risk regulatory action from SEBI and the exchanges, along with reputational exposure among the listed companies and investors they serve.




