Skip to main content
CERT-In Empanelled Since 2008 — Mandatory for SEBI cyber audits and critical infrastructure assessments

SEBI CSCRF Compliance for Stock Brokers, AMCs, Mutual Funds, and Market Infrastructure Institutions

Security Brigade is the only CERT-In empanelled firm that delivers SEBI CSCRF compliance as a single bundled engagement covering VAPT, Attack Surface Management, Breach Attack Simulation, and compliance reporting for every category of SEBI regulated entity.

CSCRF
Compliance Framework
SEBI-Aligned
Methodology
370+
BFSI Engagements
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
HDFC
NPCI
PhonePe
Swiggy
Asian Paints
Mahindra
L&T
Aditya Birla
Pernod Ricard
Yes Bank
Tata Play
Voltas
DHL Express
Etihad Airways
Amazon Pay
Sephora
Groww
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
ICICI Bank
HDFC
NPCI
PhonePe
Swiggy
Asian Paints
Mahindra
L&T
Aditya Birla
Pernod Ricard
Yes Bank
Tata Play
Voltas
DHL Express
Etihad Airways
Amazon Pay
Sephora
Groww
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
STEP 01

Assess

Gap assessment against SEBI CSCRF controls mapped to your entity type. We evaluate your SOC/M-SOC readiness, vulnerability management, DC/DR posture, incident handling, governance reporting, and attack surface exposure using ShadowMap.

STEP 02

Remediate

Prioritized remediation roadmap with practical fixes your team can execute. Security Brigade provides VAPT, configuration hardening, policy development, and BAS testing. All findings tracked and retested via Lemon platform with verified closure evidence.

STEP 03

Certify

Final SEBI CSCRF compliance audit report with regulator-ready documentation, control evidence, and executive summary for your board and compliance team. CERT-In empanelled audit credibility for SEBI submission.

What Is SEBI CSCRF?

SEBI CSCRF is the Cyber Security and Cyber Resilience Framework issued by the Securities and Exchange Board of India, mandating comprehensive cybersecurity controls for all SEBI regulated entities including stock brokers, depository participants, asset management companies, mutual funds, and market infrastructure institutions.

SEBI CSCRF for Stock Brokers and Depository Participants

Full CSCRF applicability, annual audit cycle, and the most common SEBI regulated entity category

SOC / M-SOC Readiness

Assessment and implementation guidance for Security Operations Centre or Managed SOC as required by SEBI CSCRF for stock brokers and depository participants.

Vulnerability Management Program

Continuous vulnerability assessment and penetration testing aligned to SEBI CSCRF requirements for stock brokers and depository participants.

DC/DR Drills and BCP

Validation of disaster recovery and business continuity posture including failover testing for trading systems and depository connectivity.

Incident Handling and SEBI Reporting

Incident response procedures, CERT-In 6-hour notification management, and SEBI incident reporting for stock brokers and depository participants.

Annual CSCRF Cyber Audit

CERT-In empanelled audit delivering regulator-ready SEBI CSCRF compliance report for stock broker and depository participant annual submission.

Attack Surface Management

ShadowMap-powered continuous monitoring of internet-facing assets, leaked credentials, and shadow IT for stock brokers and depository participants.

Methodology

5 steps. Zero guesswork.

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Scoping and Entity Classification

Identify your SEBI CSCRF tier based on entity type, scale, and systemic importance. Map applicable controls for stock brokers, depository participants, AMCs, mutual funds, MIIs, or other regulated entities. Define audit scope, systems inventory, and timeline.

02

Gap Assessment and Risk Analysis

Evaluate current cybersecurity posture against all applicable SEBI CSCRF controls. Assess SOC/M-SOC readiness, vulnerability management maturity, DC/DR preparedness, incident handling capability, and governance reporting. ShadowMap scan identifies external attack surface exposure.

Testing
03

Technical Security Testing

Execute VAPT across applications, APIs, networks, and infrastructure. Conduct Breach Attack Simulation to validate SOC detection. Perform red team assessment for MII-tier entities. Run ShadowMap for continuous attack surface monitoring and dark web credential exposure checks.

Delivery
04

Remediation Support and Verified Closure

Deliver prioritized remediation roadmap with actionable guidance. Track all findings through Lemon with developer-friendly PoCs and specific remediation steps. Retest every fix with confirmed closure status, generating evidence that satisfies SEBI CSCRF audit requirements.

05

SEBI CSCRF Compliance Reporting

Produce regulator-ready SEBI CSCRF compliance audit report with control mapping, evidence references, executive summary, and board presentation pack. CERT-In empanelled auditor attestation. Governance documentation aligned to SEBI reporting requirements.

"Security Brigade's structured approach through Lemon gave us complete visibility into the testing process. The three-layer review caught issues that our previous vendor missed entirely. Their reports were the first our developers could actually act on without a follow-up call."
CISO, Leading Indian BFSI Enterprise
Top 5 Private Sector Bank · Engaged since 2019

Read more client stories →

The Platform

Powered by Lemon

Most firms rely on individual tester skill. We built a platform that makes quality structural — informed by 6,700+ previous assessments.

lemon.securitybrigade.com/project/PRJ-2847
D
C
F
R
T
PROJECT PRJ-2847
Coverage Validation — acmecorp.com
94% covered
Endpoints
247 / 263
Parameters
1,847
Auth Flows
12 / 12
JS Routes
38 / 41
AI flagged 3 undiscovered endpoints
/api/v2/admin/export, /api/v2/billing/webhook, /internal/healthcheck
L1 Complete
L2 In Review
L3 Pending

Lemon Audit Platform

All SEBI CSCRF findings, evidence, remediation tracking, and retesting managed through our proprietary audit platform. Every fix is verified with confirmed closure status generating regulator-ready evidence.

ShadowMap Attack Surface Management

Continuous monitoring of your internet-facing assets, leaked credentials, dark web exposure, shadow IT, and third-party risks. Satisfies SEBI CSCRF requirements for attack surface management and CART.

In-House Red Team and BAS

Red team assessments and breach attack simulation delivered by our own 150-plus security team. No third-party dependencies for SEBI CSCRF mandated adversary simulation testing.

Compliance-Ready

Audit-ready reporting for every framework

As a CERT-In empanelled firm, our reports are accepted by all major Indian and global regulators.

Vulnerability Assessment and Penetration Testing
Covered by Security Brigade VAPT service
Attack Surface Management and CART
Covered by ShadowMap platform providing
SOC and M-SOC Assessment
Security Brigade assesses SOC readiness,
Breach Attack Simulation
In-house BAS capability validates that s
Red Team Assessment
Adversary simulation by Security Brigade
Incident Handling and Response
Incident response planning, tabletop exe
DC/DR Drills and BCP
Assessment and validation of disaster re
Governance and Compliance Reporting
Board-ready governance documentation, SE
Dark Web and Credential Monitoring
ShadowMap monitors dark web marketplaces
Vendor Risk Assessment
Assessment of technology vendors, cloud

Industries

700+ clients across verticals

Every type of application architecture and business logic pattern — tested.

BFSIICICI Bank, HDFC, Yes Bank, UTI MF, Edelweiss
Fintech & PaymentsPhonePe, Amazon Pay, Groww, BillDesk
ManufacturingMahindra, Asian Paints, L&T, Hindalco
Retail & ConsumerSwiggy, Sephora, Pernod Ricard, Jubilant
Aviation & LogisticsEtihad Airways, DHL Express, Shadowfax
HealthcareCloudNine, Pharmeasy, Wave Health

Deliverables

What you get

Reports for two audiences — executives who need the risk picture, and developers who need to fix the issues. With code-level guidance, not vague advice.

SEBI CSCRF Compliance Audit Report

Regulator-ready report with scope, methodology, control mapping, evidence references, observations, compliance status, and auditor conclusions. CERT-In empanelled auditor attestation.

Gap Analysis Report

Detailed gap assessment with non-compliances, risk ratings, evidence gaps, and recommended remediation actions prioritized by severity and regulatory impact.

Remediation Roadmap

Prioritized remediation plan with owners, target dates, and implementation guidance. Tracked through Lemon with verified closure evidence for each finding.

VAPT and Security Testing Reports

Technical annexures covering web, mobile, API, network, and cloud VAPT findings with step-by-step proof-of-concepts and application-specific remediation guidance.

ShadowMap ASM Report

Attack surface assessment showing internet-facing assets, leaked credentials, shadow IT, dark web exposure, and third-party risk indicators.

BAS and Red Team Report

Breach attack simulation results and red team assessment findings including SOC Reconciliation Report documenting detection gaps with timestamps and IOCs.

Executive Summary and Board Pack

Management presentation summarizing SEBI CSCRF compliance status, key risks, remediation progress, and governance recommendations for board and audit committee.

Closure Validation Report

Final validated report confirming all critical and high-severity findings are remediated and retested. Provides the verified compliance evidence SEBI expects.

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

Common questions

Can't find what you're looking for? Talk to our team.

Contact us
What is SEBI CSCRF and who does it apply to?+
SEBI CSCRF is the Cyber Security and Cyber Resilience Framework issued by SEBI that mandates cybersecurity controls for all SEBI regulated entities. It applies to stock brokers, depository participants, asset management companies, mutual funds, market infrastructure institutions including stock exchanges, depositories, and clearing corporations, as well as registrars, transfer agents, investment advisers, research analysts, portfolio managers, and other SEBI registered intermediaries. The specific obligations vary by entity tier and systemic importance.
Is CERT-In empanelment mandatory for SEBI CSCRF audits?+
Yes, SEBI requires that cyber audits for regulated entities be conducted by CERT-In empanelled auditors. Security Brigade has been CERT-In empanelled since 2008, making us one of the longest-standing empanelled auditors in India. This empanelment is a statutory requirement, and audit reports from non-empanelled firms are not accepted by SEBI for compliance submissions.
How often do stock brokers need SEBI CSCRF audits?+
Stock brokers and depository participants are required to undergo annual SEBI CSCRF cyber audits. The annual audit cycle requires a comprehensive assessment of all applicable SEBI CSCRF controls including SOC/M-SOC readiness, vulnerability management, DC/DR drills, incident handling, and governance reporting. Additional audits may be triggered by significant system changes or cyber incidents.
What is the difference between SEBI CSCRF requirements for stock brokers and MIIs?+
Market Infrastructure Institutions face the highest-tier SEBI CSCRF obligations because they are systemically important to capital markets. MIIs must maintain dedicated 24x7 SOC operations, conduct red team assessments, implement breach attack simulation, and demonstrate advanced threat intelligence capabilities. Stock brokers and depository participants have full CSCRF applicability but at a proportionately lower tier. The core controls around vulnerability management, incident handling, and governance reporting apply to both categories.
Do AMCs and mutual funds have separate SEBI CSCRF requirements?+
Yes, AMCs and mutual funds operate under a separate SEBI CSCRF circular that accounts for the distinct technology and operational landscape of the mutual fund industry. AMCs and mutual funds must also comply with AMFI cybersecurity guidelines, which introduce additional expectations around investor data protection, fund transaction security, and distributor ecosystem controls. Security Brigade addresses both SEBI CSCRF and AMFI requirements in a single engagement.
What services are needed to become SEBI CSCRF compliant?+
Full SEBI CSCRF compliance typically requires VAPT, attack surface management, SOC or M-SOC assessment, breach attack simulation, DC/DR validation, incident handling readiness, dark web monitoring, governance reporting, and the formal compliance audit. Security Brigade is the only vendor that delivers almost all of these services in-house through a single bundled engagement. Competitors typically need three to four vendors to cover the same scope.
What are the penalties for SEBI CSCRF non-compliance?+
Non-compliance with SEBI CSCRF can result in SEBI enforcement actions including monetary penalties, directions, show-cause notices, restrictions on trading activities or new client onboarding, and in severe cases, suspension or cancellation of SEBI registration. The severity depends on the entity type, the nature of the non-compliance, and whether the entity has a history of cybersecurity violations. Beyond regulatory penalties, non-compliance increases the risk of a cyber incident that damages investor trust and market reputation.
How long does a SEBI CSCRF compliance engagement take?+
A typical SEBI CSCRF compliance engagement takes six to eight weeks from scoping through final report delivery. This includes entity classification and scope mapping, gap assessment, technical security testing including VAPT and BAS, remediation support with verified closure, and regulator-ready compliance reporting. Timeline may vary based on entity complexity, number of systems in scope, and remediation speed.
Does SEBI CSCRF require attack surface management?+
Yes, SEBI CSCRF mandates that regulated entities maintain visibility over their internet-facing attack surface and implement continuous monitoring. Security Brigade addresses this through ShadowMap, our proprietary attack surface management platform that provides continuous discovery of exposed assets, leaked credentials, dark web exposure, shadow IT, and third-party risk. ShadowMap also delivers Continuous Automated Red Teaming capabilities required under higher CSCRF tiers.
Can Security Brigade help with SEBI CSCRF compliance for investment advisers and research analysts?+
Yes, Security Brigade delivers SEBI CSCRF compliance for all categories of SEBI regulated entities including investment advisers, research analysts, portfolio managers, registrars and transfer agents, credit rating agencies, and merchant bankers. For smaller entities with lighter-tier obligations, we provide a right-sized engagement covering gap assessment, policy development, VAPT, and audit reporting proportionate to the entity's SEBI CSCRF tier.

Get SEBI CSCRF Compliant with India's Only Bundled Compliance Provider

CERT-In empanelled since 2008. VAPT, ASM, BAS, Red Team, Dark Web Monitoring, and compliance reporting from one team.

Typically responds within 1 business day · No commitment required

Request a Scoping Call