A stock broker’s trading platform runs on client trust. One breach can freeze that platform, expose client accounts and trigger a regulatory review within hours. Cyberattacks on India’s financial sector have grown sharper and faster, and a single weak link in a broker’s systems can ripple across the exchange it connects to.
SEBI built the Cybersecurity and Cyber Resilience Framework to close that gap. CSCRF gives every registered stock broker a clear set of controls to follow: how to classify risk, monitor systems and report incidents on time. This guide breaks down what SEBI CSCRF for stock brokers actually requires, how classification works and where brokers most often fall short.
What SEBI CSCRF means for stock brokers
SEBI CSCRF for stock brokers builds on the NIST Cybersecurity Framework, organised around six goals: Govern, Identify, Protect, Detect, Respond and Recover. It supersedes every earlier SEBI cybersecurity circular for brokers, depositories and other regulated entities into a single rulebook.
Every broker registered with a stock exchange falls under it, regardless of size. What changes is the depth of obligation, which depends on your classification tier.
How SEBI CSCRF classification works
SEBI groups regulated entities into five tiers: Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. Stock brokers are classified according to the thresholds prescribed by SEBI, based mainly on the number of registered clients and annual clientele trading volume. SEBI has also issued detailed clarification on how trading volume should be calculated for client-based brokers.
Core SEBI CSCRF requirements for stock brokers
Once classified, most brokers above the smallest tier need to demonstrate the following controls, with evidence, not just policy documents.
- Governance and board oversight: A designated CISO and board-level visibility into cyber risk, not just an IT sign-off.
- Asset classification and risk assessment: Every critical system inventoried and ranked by exposure.
- Access control and network security: MFA, network segmentation and least-privilege access across trading and back-office systems.
- Continuous monitoring: A SOC or managed SOC watching trading platforms and client-facing systems around the clock.
- VAPT and cyber audits: Periodic vulnerability assessment and penetration testing, plus periodic cybersecurity audits by auditors meeting SEBI’s prescribed eligibility requirements.
- Incident reporting: Cyber incidents must be reported to CERT-In within the timelines prescribed under CERT-In Directions and to the relevant stock exchange/reporting authority in accordance with SEBI CSCRF requirements.
Higher tiers add obligations like threat hunting, red teaming and a formal Cyber Capability Index assessment.
Where stock brokers commonly fall short
Two gaps show up repeatedly during audits.
- The first is an inflated self-assessed Cyber Capability Index score that the broker cannot back up with actual evidence when an auditor asks for it.
- The second is incomplete documentation and evidence for cloud deployments, third-party environments and critical systems, making it difficult to demonstrate compliance during assessments..
Third-party risk is the other recurring issue. Brokers lean on vendors for trading platforms, cloud hosting and KYC processing. Each vendor is a potential entry point, and CSCRF expects you to extend your controls to them, not just your own systems.
Conclusion
SEBI CSCRF for stock brokers is not just a one-time filing anymore. It is an ongoing programme that includes governance, continuous monitoring, audits and incident response, with your obligations changing directly with your tier. Getting classification right and keeping evidence audit-ready is what separates a smooth annual review from a scramble.
CyberNX can help you achieve compliance with their SEBI CSCRF consulting services. We address your key challenges like understanding your SEBI CSCRF needs, developing a compliance roadmap, keeping up with control implementations, periodic assessments and measuring your effectiveness. If you’re unsure where your brokerage stands, connect with our experts for a structured path to SEBI CSCRF compliance.
SEBI CSCRF for stock brokers FAQs
What is SEBI CSCRF for stock brokers?
It is SEBI’s unified cybersecurity and cyber resilience framework, issued in August 2024, that sets governance, monitoring, audit and incident reporting requirements for every SEBI-registered stock broker.
How does stock broker classification work under CSCRF?
SEBI classifies stock brokers using thresholds based mainly on the number of registered clients and annual clientele trading volume, placing them into one of five tiers that determine applicable cybersecurity obligations and audit requirements.
What do you need to submit during a CSCRF audit?
Auditors expect documented policies, asset inventories, VAPT reports, incident logs and evidence supporting your Cyber Capability Index score, not just a completed checklist.
Why Cyber Capability Index matters for stock brokers
The Cyber Capability Index (CCI) measures cybersecurity maturity across multiple test parameters that are defined by SEBI. Higher-category entities must demonstrate and evidence the required maturity levels during assessments.




