Organisations across India’s securities market are quite relieved once their cybersecurity controls clear review and their compliance checklist is signed off. But are they really confident that this reporting would still hold up the moment a real incident happens?
This is important to address because SEBI’s CSCRF ties every control back to a specific report, format and deadline. A control that is technically compliant but reported the wrong way, in the wrong format, still counts as a gap. Stockbrokers, mutual funds, depositories and other regulated entities (REs) need to know exactly what SEBI CSCRF reporting requirements expect of them, and when.
This guide breaks down every reporting obligation under CSCRF, from incident timelines to audit formats to self-assessment scores. By the end, you will know exactly where SEBI CSCRF reporting requirements fit into your compliance calendar.
What are SEBI CSCRF reporting requirements?
SEBI introduced the CSCRF in August 2024 to replace multiple older cybersecurity circulars with one unified structure. It groups REs into five categories, Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs and Self-certification REs, based on scale and systemic importance.
Each category carries its own set of SEBI CSCRF reporting requirements. A stock exchange faces a lot more frequent and detailed reporting than a small broker, but every RE has some obligation to document and submit evidence of its cybersecurity posture.
The framework is built around five resilience goals: anticipate, withstand, contain, recover and evolve. Reporting exists to prove that each of these goals is actually being met.
Types of reporting formats under SEBI CSCRF
CSCRF does not leave reporting formats open to interpretation. The framework specifies exact templates for each submission type. It’s better to understand these formats as early as possible.
- VAPT reporting: Vulnerability assessment and penetration testing results must be submitted in the standardised format, along with a declaration from the MD or CEO confirming compliance.
- Cyber audit reporting: Annual cyber audits must cover all critical systems and a defined sample of non-critical systems, with findings reported through the existing SEBI audit submission channel.
- Incident classification and reporting: Cybersecurity incidents must be classified by severity and reported using the format prescribed for incident handling.
- Cyber Capability Index (CCI) reporting: This 23-parameter self-assessment score measures cyber maturity and must be submitted periodically, with supporting evidence made available on request.
- Self-certification RE reporting: Smaller REs that qualify for self-certification use a simplified reporting format built for lower-complexity environments.
Incident reporting timelines you cannot miss
Cyber incident reporting sits at the centre of SEBI CSCRF reporting requirements, and it runs on two clocks at once.
- CERT-In’s Directions of April 2022, issued under Section 70B of the IT Act, require reporting of listed cyber incident types within six hours of detection. This obligation applies regardless of sector.
- On top of this, CSCRF requires REs to report incidents to SEBI or their respective exchange or depository, followed by a root-cause analysis once the incident is contained.
Treat these as two separate obligations since missing either clock leads to its own compliance gap.
How reporting frequency changes by entity tier
Not every RE reports on the same schedule. Frequency depends entirely on classification.
- MIIs: Conduct third-party CCI assessment on a half-yearly basis and maintain continuous SOC-based monitoring evidence.
- Qualified REs: Complete CCI self-assessment annually and submit evidence when SEBI requests it.
- Mid-size REs: Run annual cyber audits covering all critical systems and a sample of non-critical systems, supported by an IT Committee that includes an external cybersecurity expert.
- Small-size and Self-certification REs: Follow lighter, scaled-down reporting formats, though incident reporting timelines remain the same for everyone.
Knowing your category before you build a reporting calendar helps you prevent both under-reporting and unnecessary over-reporting.
Common reporting gaps in SEBI CSCRF compliance
Most reporting failures come from weak documentation habits.
- Evidence collected after an incident instead of maintained continuously
- Board reports written in technical language – instead of business terms
- Generic templates that do not map cleanly to CSCRF annexures
- No clear owner for the CERT-In six-hour clock during off-hours
Fixing these gaps usually takes less effort than the audit itself, once the reporting structure is set up correctly the first time.
Conclusion
SEBI CSCRF reporting requirements are not a single form to file once a year. They are a set of interlocking timelines, formats and evidence trails that differ by entity category and incident type. Getting ahead of them means building a reporting calendar before an auditor or a regulator asks for one.
CyberNX helps regulated entities map their evidence, close reporting gaps and stay ready for every SEBI CSCRF reporting requirement across the year. Connect with our experts to know more about our SEBI CSCRF framework consulting services and to build a compliance programme that holds up well under audit.
SEBI CSCRF Reporting Requirements FAQs
What is SEBI CSCRF reporting requirement?
It refers to the documentation, formats and timelines that SEBI-regulated entities must follow to prove compliance with the Cybersecurity and Cyber Resilience Framework, covering incidents, audits, VAPT and CCI scores.
How often should REs submit CCI reports
MIIs submit third-party CCI assessments every half year. Qualified REs complete a self-assessment annually. Both must keep supporting evidence ready for review.
What happens if an RE misses the CERT-In six-hour deadline?
Missing the window creates a separate compliance failure under CERT-In’s Directions, in addition to any gap under SEBI’s own incident reporting requirements.
Do self-certification REs have separate reporting formats?
Yes. CSCRF provides a scaled-down reporting format for self-certification REs that reflects their smaller operational footprint.




