Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • English
    • English (US)
Contact Us
CyberNX Logo
  • English
    • English (US)
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
    Data Sheets
  • Careers
  • Contact

SEBI CSCRF Reporting Requirements: A Complete Guide for Indian REs

4 min read
11 Views
  • SEBI CSCRF

Organisations across India’s securities market are quite relieved once their cybersecurity controls clear review and their compliance checklist is signed off. But are they really confident that this reporting would still hold up the moment a real incident happens?

This is important to address because SEBI’s CSCRF ties every control back to a specific report, format and deadline. A control that is technically compliant but reported the wrong way, in the wrong format, still counts as a gap. Stockbrokers, mutual funds, depositories and other regulated entities (REs) need to know exactly what SEBI CSCRF reporting requirements expect of them, and when.

This guide breaks down every reporting obligation under CSCRF, from incident timelines to audit formats to self-assessment scores. By the end, you will know exactly where SEBI CSCRF reporting requirements fit into your compliance calendar.

Table of Contents

What are SEBI CSCRF reporting requirements?

SEBI introduced the CSCRF in August 2024 to replace multiple older cybersecurity circulars with one unified structure. It groups REs into five categories, Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs and Self-certification REs, based on scale and systemic importance.

Each category carries its own set of SEBI CSCRF reporting requirements. A stock exchange faces a lot more frequent and detailed reporting than a small broker, but every RE has some obligation to document and submit evidence of its cybersecurity posture.

The framework is built around five resilience goals: anticipate, withstand, contain, recover and evolve. Reporting exists to prove that each of these goals is actually being met.

Types of reporting formats under SEBI CSCRF

CSCRF does not leave reporting formats open to interpretation. The framework specifies exact templates for each submission type. It’s better to understand these formats as early as possible.

5 SEBI CSCRF Reporting Formats

  • VAPT reporting: Vulnerability assessment and penetration testing results must be submitted in the standardised format, along with a declaration from the MD or CEO confirming compliance.
  • Cyber audit reporting: Annual cyber audits must cover all critical systems and a defined sample of non-critical systems, with findings reported through the existing SEBI audit submission channel.
  • Incident classification and reporting: Cybersecurity incidents must be classified by severity and reported using the format prescribed for incident handling.
  • Cyber Capability Index (CCI) reporting: This 23-parameter self-assessment score measures cyber maturity and must be submitted periodically, with supporting evidence made available on request.
  • Self-certification RE reporting: Smaller REs that qualify for self-certification use a simplified reporting format built for lower-complexity environments.

Incident reporting timelines you cannot miss

Cyber incident reporting sits at the centre of SEBI CSCRF reporting requirements, and it runs on two clocks at once.

  • CERT-In’s Directions of April 2022, issued under Section 70B of the IT Act, require reporting of listed cyber incident types within six hours of detection. This obligation applies regardless of sector.
  • On top of this, CSCRF requires REs to report incidents to SEBI or their respective exchange or depository, followed by a root-cause analysis once the incident is contained.

Treat these as two separate obligations since missing either clock leads to its own compliance gap.

How reporting frequency changes by entity tier

Not every RE reports on the same schedule. Frequency depends entirely on classification.

  • MIIs: Conduct third-party CCI assessment on a half-yearly basis and maintain continuous SOC-based monitoring evidence.
  • Qualified REs: Complete CCI self-assessment annually and submit evidence when SEBI requests it.
  • Mid-size REs: Run annual cyber audits covering all critical systems and a sample of non-critical systems, supported by an IT Committee that includes an external cybersecurity expert.
  • Small-size and Self-certification REs: Follow lighter, scaled-down reporting formats, though incident reporting timelines remain the same for everyone.

Knowing your category before you build a reporting calendar helps you prevent both under-reporting and unnecessary over-reporting.

Common reporting gaps in SEBI CSCRF compliance

Most reporting failures come from weak documentation habits.

  • Evidence collected after an incident instead of maintained continuously
  • Board reports written in technical language – instead of business terms
  • Generic templates that do not map cleanly to CSCRF annexures
  • No clear owner for the CERT-In six-hour clock during off-hours

Fixing these gaps usually takes less effort than the audit itself, once the reporting structure is set up correctly the first time.

Conclusion

SEBI CSCRF reporting requirements are not a single form to file once a year. They are a set of interlocking timelines, formats and evidence trails that differ by entity category and incident type. Getting ahead of them means building a reporting calendar before an auditor or a regulator asks for one.

CyberNX helps regulated entities map their evidence, close reporting gaps and stay ready for every SEBI CSCRF reporting requirement across the year. Connect with our experts to know more about our SEBI CSCRF framework consulting services and to build a compliance programme that holds up well under audit.

SEBI CSCRF Reporting Requirements FAQs

What is SEBI CSCRF reporting requirement?

It refers to the documentation, formats and timelines that SEBI-regulated entities must follow to prove compliance with the Cybersecurity and Cyber Resilience Framework, covering incidents, audits, VAPT and CCI scores.

How often should REs submit CCI reports

MIIs submit third-party CCI assessments every half year. Qualified REs complete a self-assessment annually. Both must keep supporting evidence ready for review.

What happens if an RE misses the CERT-In six-hour deadline?

Missing the window creates a separate compliance failure under CERT-In’s Directions, in addition to any gap under SEBI’s own incident reporting requirements.

Do self-certification REs have separate reporting formats?

Yes. CSCRF provides a scaled-down reporting format for self-certification REs that reflects their smaller operational footprint.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
SEBI CSCRF Cyber Crisis Drill: A Step-by-Step Guide for REs

How to Conduct a SEBI CSCRF Cyber Crisis Drill: A Step-by-Step Guide

In Feb 2021, a technical outage brought India’s largest stock exchange to a standstill for several hours. Trading froze and

Data Localisation under SEBI CSCRF: A Compliance Snapshot

Data Localisation under SEBI CSCRF: Why the Mandate is Still in Abeyance

Where your data is stored is as important as how well it is protected. Across the world, regulators are introducing

SEBI CSCRF for KRAs and QRTAs: Key Changes You Must Know

SEBI CSCRF for KRAs & QRTAs: What Changed and What You Must Do Now

Every time an investor opens a demat account, a mutual fund folio or a trading account in India, their record

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
    • English (US)
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.