Sebi Clarifies Cybersecurity Framework

By By Rediff Money Desk, New Delhi
Aug 28, 2025 19:18
Sebi clarifies cybersecurity & cyber resilience framework (CSCRF) applicability, audits, & compliance for regulated entities.
Photograph: Kind courtesy pixabay.com
New Delhi, Aug 28 (PTI) Markets regulator Sebi on Thursday clarified that the cybersecurity and cyber resilience framework (CSCRF) applies only to systems used exclusively for its regulated activities.

Shared infrastructure will also be audited if not already covered by the RBI or another regulator.

Further, if regulated entities (REs) comply with RBI (or other regulator) cybersecurity rules that are equivalent to Sebi's, such compliance will be accepted by the markets watchdog.

In its circular, Sebi also elaborated on the definition of critical systems, stating that it includes all systems that affect core operations, store or transmit regulatory data, client-facing applications, internet-facing systems, and other systems on the same network.

REs have been asked to adopt zero-trust principles such as network segmentation, high availability, and avoiding single points of failure with approval from their IT Committees.

The regulator said that guidelines relating to mobile applications are recommendatory, not mandatory, while for cyber crisis response, entities must act as per their Cyber Crisis Management Plan instead of issuing press releases.

The regulator further clarified that deploying tools like threat simulations, vulnerability management, and decoy systems is encouraged but not compulsory.

Entities are also required to assess third-party/vendor risks in consultation with their IT Committees.

On audit-related matters, Sebi said, "While receiving and handling cyber audit reports submitted by their members, stock exchanges and depositories shall ensure that adequate safeguards are in place to maintain the confidentiality and integrity of such reports".

In terms of disaster recovery, REs must be capable of resuming critical operations within two hours (RTO), maintain a 15-minute Recovery Point Objective (RPO), and plan for scenarios where timelines are not met, Sebi said.

The regulator has also revised the thresholds and categorisation of regulated entities under the CSCRF. For Portfolio Managers, those with Assets Under Management (AUM) of Rs 10,000 crore and above will be categorised as Qualified REs, while those managing between Rs 3,000 crore and Rs 10,000 crore will fall under the Mid-size RE category.

Portfolio managers with AUM of Rs 3,000 crore or below will be treated as Small-size REs, and those below the minimum threshold may be classified as Self-certification REs with simplified compliance requirements.

For Merchant Bankers (MBs), all active MB-- those undertaking merchant banking activities during the relevant period--will be classified as Small-size REs for compliance purposes, while inactive MBs will be exempt from CSCRF provisions.
Source: PTI
Read More On:
sebicybersecuritycyber resilience frameworkcscrfregulated entities
DISCLAIMER - This article is from a syndicated feed. The original source is responsible for accuracy, views & content ownership. Views expressed may not reflect those of rediff.com India Limited.

You May Like To Read

MORE NEWS

Indian Bank Q4 Profit Up 5%, Dividend Declared

Indian Bank reports 5% rise in Q4 profit to Rs 3,103 cr, declares Rs 18.25/share...

Sensex, Nifty Rebound: FMCG, Auto Shares Lead

Sensex and Nifty rebound nearly 1% driven by FMCG, auto, and telecom stocks amid...

Vedanta Q4 Profit Zooms 89% on Metal Prices

Vedanta Ltd reports 89% jump in Q4 profit to Rs 9,352 cr, driven by higher metal prices...

Pinnacle Launches Global Centre in Bengaluru

Pinnacle Infotech launches Global Centre of Excellence in Bengaluru, signing MoUs with...

Maharashtra AI Policy: Rs 10,000 Cr Investment

Maharashtra approves AI Policy 2026, investing Rs 10,000 Cr, creating 1.5 lakh jobs,...

Skoda Auto India Partners with CSC Grameen eStore

Skoda Auto India partners with CSC Grameen eStore to expand reach in non-metro areas....

Rupee Falls to Near Record Low Amid Oil Price...

Rupee depreciates to 94.82 against USD amid rising crude oil prices, FII outflows, and...

Kissht IPO: Founders Invest Rs 40 Cr at Premium

Kissht founders invest Rs 40 crore at a premium ahead of IPO. IPO opens April 30....

Sterlite Technologies Posts Profit in Q4 FY26

Sterlite Technologies reports Rs 59 crore net profit in Q4 FY26, driven by order growth...

Vijay Anandh New MD of City Union Bank

Vijay Anandh appointed MD & CEO of City Union Bank (CUB) on May 1, succeeding Dr. N...

Read More »

Sectoral Indices Market Indicators Listed Companies Gainers Losers Mutual Funds Portfolio Watchlist
© 2026 Rediff.com