Problem Threats Stories How it works Blogs Pricing
Compliance · Capital Markets

SEBI CSCRF VAPT requirements: a category-by-category guide for 2026

How often you must test, who can test, and the three clocks that start when the test ends. Checked against the SEBI circulars, FAQs and the 2026 exchange notices.

By Arxiis ResearchUpdated 25 min read

Key takeaways

  • SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued on 20 August 2024, makes VAPT of critical systems mandatory, and the testing must be done by a CERT-In empanelled IS auditing organisation.1
  • Most regulated entities must run VAPT at least once each financial year, starting in the first quarter. Entities whose systems NCIIPC has notified as protected systems or CII must finish a full cycle in each half-year.1
  • Three clocks apply to every cycle: file the report within 1 month of finishing the test, close findings within 3 months of filing, and finish revalidation within 5 months of finishing the test.1
  • SEBI's FAQs say high-severity findings caused by missing patches are judged against the 1-week patch timeline, and Qualified Stock Brokers test half-yearly whatever their CSCRF category.3
  • Since the April 2025 clarification, a stock broker's category depends on its registered clients or yearly clientele trading volume, and the higher of the two decides.2
  • For FY 2025-26, NSE and BSE asked most brokers to finish VAPT by 30 June 2026, file by 31 July 2026 and submit revalidation by 30 November 2026.78

A compliance head at a stock broker gets two emails in the same week. One is a VAPT report full of findings. The other is an exchange circular with three dates in it. The findings are the easy part. The hard part is the calendar: which clock has started, when it runs out, and whether the auditor, the scope and the approval trail will hold up in an inspection. SEBI's Cybersecurity and Cyber Resilience Framework turned VAPT from a yearly errand into a timed cycle with penalties at the end. This guide sets out that cycle for each category, clause by clause, and gives you a calendar to work out your own dates.

Last reviewed on 1 October 2026 against SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, the April and August 2025 clarifications, SEBI's CSCRF FAQs (June 2025) and the NSE and BSE VAPT circulars of 14 May 2026.

What is SEBI CSCRF?

SEBI CSCRF is the Cybersecurity and Cyber Resilience Framework that the Securities and Exchange Board of India issued on 20 August 2024 through circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. It replaces a set of older cyber circulars with one rulebook, scaled by entity size, and makes VAPT, cyber audits and security monitoring mandatory.

CSCRF is written as a list of standards. Each one has a short code. The codes borrow the function names of the NIST Cybersecurity Framework, such as Govern (GV), Protect (PR), Detect (DE) and Recover (RC). VAPT sits under standard DE.CM.S5, which says VAPT "shall be done to detect vulnerabilities in the IT environment for all critical systems, infrastructure components and other IT systems as defined in the framework".1

VAPT, in one line
Vulnerability assessment and penetration testing. The assessment finds known weaknesses with scans. The penetration test tries to exploit them, the way an attacker would, to show what a weakness really exposes. Our guide on vulnerability assessment vs penetration testing explains the difference in detail.

The framework defines "critical systems" widely. The list includes any system whose compromise would hurt core business, systems that store or send regulated data, the network that connects them, internet-facing systems, client-facing systems, and the ancillary systems used to reach or maintain critical systems. It covers both on-premise and cloud.1 In practice, that means your trading front end, your back office, your admin jump servers and the cloud tenant behind your mobile app are all in scope.

Why SEBI cares about the timing

The timing rules exist because attackers now move faster than yearly checks. Verizon's 2026 Data Breach Investigations Report found that exploiting vulnerabilities was the top way into breached organisations, at 31% of cases, ahead of stolen credentials for the first time.12 IBM puts the average cost of a data breach in India at ₹25.5 crore in its 2026 report.13 A test that nobody fixes on time does little against that.

Not legal advice. This guide summarises SEBI and exchange texts as of 1 October 2026. SEBI and the exchanges update CSCRF through circulars, FAQs and notices. Always check the latest text and your own category annexure before you plan an audit.

Which regulated entities does CSCRF cover?

SEBI CSCRF covers almost every SEBI regulated entity (RE): stock exchanges, depositories and clearing corporations, plus stock brokers, depository participants, mutual funds, portfolio managers, KYC registration agencies, registrars, merchant bankers, investment advisers and more. Six entity types that already had SEBI cyber circulars were given the earliest deadline.

The applicability list in the circular runs from alternative investment funds, bankers to an issue, clearing corporations, collective investment schemes, credit rating agencies, custodians and debenture trustees to depositories and designated depository participants, among others.1 The categorisation tables and later clarifications add stock brokers, depository participants (DPs), mutual funds and asset management companies (AMCs), portfolio managers, KRAs, research analysts, investment advisers, registrars (RTAs) and merchant bankers.124

Who is left out, or partly out

  • Very small stock brokers. Brokers with fewer than 1,000 registered clients and less than ₹1,000 crore of clientele trading volume in a year are exempt from CSCRF.2
  • Inactive merchant bankers. The August 2025 technical clarification exempts them. Active merchant bankers are Small-size REs.4
  • Tiny DPs and RTAs. DPs and RTAs with fewer than 100 clients do not have to take SOC services or join the Market SOC. They still have the other duties.2

If your firm is a bank or NBFC that is also a DP, you may be under both SEBI and RBI rules. Our guide to the RBI Cyber Security Directions 2026 and their VAPT rules covers the RBI side.

How are CSCRF categories decided?

CSCRF regulated entity categories are fixed at the start of each financial year using the previous year's data, and an entity stays in that category all year. SEBI uses a different yardstick for each entity type: registered clients and trading volume for stock brokers, assets under management for mutual funds and portfolio managers.

There are five categories, from heaviest to lightest duty:1

  1. Market Infrastructure Institutions (MIIs): stock exchanges, clearing corporations and depositories.
  2. Qualified REs: the largest intermediaries.
  3. Mid-size REs.
  4. Small-size REs.
  5. Self-certification REs: the smallest covered entities, which certify their own compliance for most controls.

SEBI's FAQs confirm the rule on timing: "Once the category of RE is decided, RE shall remain in the same category throughout the financial year."3 A broker that crosses a threshold in October keeps its old category until the next April.

Example 1: client-based stock brokers

The April 2025 clarification replaced the original "active clients" test with two measures. If a broker falls into two categories on the two measures, the higher category applies.2

SEBI CSCRF for stock brokers: category thresholds (circular 2025/60, 30 April 2025)
CategoryTotal registered clientsClientele trading volume in a year
Qualified REMore than 10 lakhMore than ₹10,00,000 crore
Mid-size REMore than 1 lakh, up to 10 lakhMore than ₹1,00,000 crore, up to ₹10,00,000 crore
Small-size REMore than 10,000, up to 1 lakhMore than ₹10,000 crore, up to ₹1,00,000 crore
Self-certification REMore than 1,000, up to 10,000More than ₹1,000 crore, up to ₹10,000 crore
ExemptFewer than 1,000Less than ₹1,000 crore (both conditions)

Proprietary brokers, which have no clients, are measured by the collateral or assets they hold with clearing corporations: more than ₹1,000 crore is Mid-size, more than ₹10 crore and less than ₹1,000 crore is Small-size, and ₹10 crore or below is Self-certification.3

Example 2: other entity types

  • Mutual funds and AMCs (by AUM): under ₹10,000 crore is Small-size, ₹10,000 crore to under ₹1 lakh crore is Mid-size, and ₹1 lakh crore and above is Qualified.1
  • Portfolio managers (by AUM, as revised in August 2025): ₹10,000 crore and above is Mid-size, more than ₹3,000 crore and under ₹10,000 crore is Small-size, and ₹3,000 crore and below is Self-certification. There is no Qualified tier.4
  • KRAs: first placed at par with MIIs, then moved to the Qualified category in April 2025.12
  • Non-individual investment advisers: Small-size REs.1
  • Depository participants: SEBI's FAQ 5 lists banks, NBFCs, mutual funds, RTAs, financial institutions, custodians and clearing corporations that act as DPs as Qualified REs. For other DPs, check your category annexure.3

How often does each category need VAPT?

SEBI CSCRF VAPT requirements set two cadences. Entities whose systems NCIIPC has notified as protected systems or critical information infrastructure (CII) must complete a full VAPT cycle in each half of the financial year. Every other regulated entity must run VAPT at least once a year, starting in the first quarter (April to June).

Table 18 of the circular draws the line by protected-system status, not by category.1 For those entities, "one VAPT activity shall be completed (including report submission, closure, and revalidation) in each half of the financial year (April to September and October to March)". SEBI's FAQs add one more half-yearly group: Qualified Stock Brokers (QSBs), under a February 2023 SEBI circular, "irrespective of the category they fall in as per CSCRF".3

SEBI VAPT guidelines under CSCRF: minimum frequency and related audits by category
CategoryMinimum VAPTCyber auditWhat else to note
MIIsAt least once a year, starting Q1. Twice if systems are protected / CIIAt least twice a yearHalf-yearly red teaming, half-yearly third-party CCI
Qualified REsAt least once a year, starting Q1. Twice if protected / CIIAt least twice a yearHalf-yearly red teaming, yearly CCI self-assessment
Qualified Stock BrokersHalf-yearly whatever the categoryHalf-yearlyExchanges publish separate QSB due dates
Mid-size REsAt least once a year, starting Q1Twice a year if offering internet-based or algo trading, else onceYearly cyber drill and SOC efficacy check
Small-size REsAt least once a year, starting Q1Twice a year if offering internet-based or algo trading, else onceMust join the Market SOC unless it has its own SOC
Self-certification REsAt least once a year, starting Q1None: VAPT is the only audit requiredMust join the Market SOC unless it has its own SOC

Sources for the table: CSCRF Tables 15, 18 and 21, the self-certification rule, the QSB FAQ and the August 2025 clarification on the Market SOC.134 One more rule matters for planning: SEBI's FAQ 20 says every periodicity in CSCRF runs on the financial year, not the calendar year.3

"At least once" is a floor. A yearly test shows your exposure on the days the auditor looked. The rest of the year is unobserved, a gap we measured in the 363-day blind spot of annual pentests.

Who can conduct VAPT under CSCRF?

VAPT under SEBI CSCRF must be carried out by an information security auditing organisation empanelled by CERT-In, India's national cyber security agency, unless SEBI says otherwise. The IT Committee must approve the report before it goes to the reporting authority: the exchange or depository for brokers and DPs, BASL for investment advisers, and SEBI for the rest.

The CSCRF footnote is short: "Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization."1 CERT-In publishes its list of empanelled organisations on its website.10 For self-certification REs, the circular says they "shall be required to conduct only VAPT audit through CERT-In empanelled IS auditing organisation and no other audit is required".1 We explain how the empanelment scheme works in our guide to CERT-In guidelines on 6-hour reporting and VAPT audits.

Extra auditor rules for stock brokers

NSE's circular of 14 May 2026 adds conditions for trading members' auditors.7 The auditing organisation must be CERT-In empanelled and should preferably have at least 3 years of IT audit experience in banking and financial services. An auditor can audit the same member for at most three years in a row, followed by a two-year cooling-off period. It must not have done consulting work for the member in the previous two years, must use only licensed tools, must sign an NDA, and must keep data within India.

Checks before you sign the engagement letter

  • The firm's name is on CERT-In's current empanelled list, not just a staff member's certificate.
  • The scope names every critical system type in the CSCRF definition, including cloud and ancillary systems.
  • The contract gives you the summary report in the CSCRF format and the full report with proof of concept (POC) separately.
  • The auditor has not crossed the three-year rotation limit or consulted for you in the last two years.
  • Retesting for revalidation is priced in. Our breakdown of VAPT cost in India shows how retests change the quote.

What is the timeline from test to closure?

The SEBI CSCRF VAPT timeline runs on three fixed clocks. File the IT Committee approved report within 1 month of finishing the test. Close findings within 3 months of filing the report, using a graded approach by severity. Complete revalidation, meaning a retest that proves the fixes work, within 5 months of finishing the test.

1 monthto file the approved VAPT report after the test endsCSCRF Table 19
3 monthsto close findings, counted from report submissionCSCRF Table 19
5 monthsto finish revalidation, counted from the test endCSCRF Table 19
1 weekfor high-severity findings caused by missing patchesSEBI FAQ 17

These timelines come from Table 19 of the circular.1 SEBI's FAQ 17 explains how closure is judged. High-severity findings caused by missing patches are checked against the patch management timeline of 1 week under standard PR.MA.S3. All other findings are checked against the 3-month closure window.3 FAQ 15 adds that the 3-month window applies even when the flaw sits in a third-party product you do not control.3

One CSCRF VAPT cycleTimeline · cadence by category
One CSCRF VAPT cycle, and how often each category repeats it One CSCRF VAPT cycle, and how often each category repeats it One CSCRF VAPT cycle. Scoping and testing come first. The IT Committee approved report is due within 1 month of the test ending. Findings must be closed within 3 months of submitting the report, and high-severity missing patches within 1 week under the patch standard. Revalidation must finish within 5 months of the test ending. Then the next cycle starts. Cadence by category across a financial year from April to March: entities with NCIIPC protected systems or CII complete one full cycle, including report, closure and revalidation, in each half year (April to September and October to March). Qualified Stock Brokers run VAPT half-yearly whatever their category. MIIs, Qualified, Mid-size and Small-size regulated entities run VAPT at least once a year, starting in the first quarter. Self-certification entities also run VAPT once a year and it is the only audit they need. MIIs and Qualified REs also run red teaming and cyber drills every half year. 1 · ONE CYCLE, IN MONTHS FROM THE END OF TESTING (T0) Scope Test Report Fix window · graded by severity Retest Next cycle → 1MONTH 3MONTHS AFTER REPORT 5MONTHS -2M -1M T0 +1M +2M +3M +4M +5M +6M +7M Revalidation must be complete within 5 months of T0 High-severity missing patch: 1 week Scope: critical + internet-facing Auditor: CERT-In empanelled 2 · CADENCE ACROSS ONE FINANCIAL YEAR APR MAY JUN JUL AUG SEP OCT NOV DEC JAN FEB MAR NCIIPC protected systems / CIIfull cycle inside each half H1: test → report → fix → retest H2: test → report → fix → retest Qualified Stock Brokers (QSBs)half-yearly, whatever the category VAPT + cyber audit VAPT + cyber audit MIIs · Qualified · Mid-size · Small-sizeat least once a year Start in Q1 Report Fix Retest Self-certification REsonce a year, and the only audit needed Start in Q1 Report Fix Retest MIIs and Qualified REs, beyond VAPTred teaming and cyber drills Red team + drill Red team + drill Shaded band: Q1 (April to June), when once-a-year VAPT must start. Dashed line: half-year split. One CSCRF VAPT cycle, and how often each category repeats it One CSCRF VAPT cycle, and how often each category repeats it One CSCRF VAPT cycle. Scoping and testing come first. The IT Committee approved report is due within 1 month of the test ending. Findings must be closed within 3 months of submitting the report, and high-severity missing patches within 1 week under the patch standard. Revalidation must finish within 5 months of the test ending. Then the next cycle starts. Cadence by category across a financial year from April to March: entities with NCIIPC protected systems or CII complete one full cycle, including report, closure and revalidation, in each half year (April to September and October to March). Qualified Stock Brokers run VAPT half-yearly whatever their category. MIIs, Qualified, Mid-size and Small-size regulated entities run VAPT at least once a year, starting in the first quarter. Self-certification entities also run VAPT once a year and it is the only audit they need. MIIs and Qualified REs also run red teaming and cyber drills every half year. 1 · ONE CYCLE 1 Scope critical + internet-facing systems 2 Test CERT-In empanelled auditor T0 3 Report IT Committee approved +1M 4 Fix window 3 months from report · patches 1 week +4M 5 Retest revalidation complete +5M 6 Next cycle Q1 next FY, or next half 2 · CADENCE PER FINANCIAL YEAR APR OCT MAR NCIIPC protected systems / CII full cycle inside each half H1 full cycle H2 full cycle Qualified Stock Brokers (QSBs) half-yearly, whatever the category VAPT + audit VAPT + audit MIIs · Qualified · Mid-size · Small-size at least once a year Q1 Fix Self-certification REs once a year, and the only audit needed Q1 Fix MIIs and Qualified REs, beyond VAPT red teaming and cyber drills Red team + drill Red team + drill
Source: SEBI CSCRF circular of 20 August 2024 (Tables 15, 18, 19, 21) and SEBI CSCRF FAQs, June 2025 (FAQ 14 and 17). Arxiis Research illustration.

The cycle, step by step

  1. Scope. List every critical system as CSCRF defines it. NSE describes the scope as all critical assets, including network and security devices, servers, databases, applications, systems reachable over WAN, LAN or public IPs, and websites, as detailed in Annexure-L of CSCRF.7
  2. Test. A CERT-In empanelled auditor runs the vulnerability assessment and the penetration test. For once-a-year entities, the activity must start in Q1 of the financial year.1
  3. Approve and file. Your IT Committee approves the report, and you file it with your reporting authority within 1 month. Since August 2025, REs file a summary in the CSCRF format and must not send the detailed vulnerabilities unless SEBI asks for them.4
  4. Fix. Close findings within 3 months of filing, most severe first. Treat missing high-severity patches as a 1-week job.
  5. Revalidate. The auditor retests and confirms closure within 5 months of the test end. Brokers submit this as an action taken report (ATR) or revalidation report to the exchange.7
  6. Keep the evidence. Exchanges require members to keep the detailed VAPT report and proofs of concept for at least three years and to share them when asked.78
A VAPT report closes nothing. The day you file it, the 3-month clock starts.Arxiis Research

Protected systems get less room. If NCIIPC has notified your systems as protected systems or CII, the whole cycle, including filing, closure and revalidation, must fit inside the same half-year. A test that ends in August leaves only weeks, not months, to fix and retest before 30 September. Plan tests early in each half.

How the exchanges applied it for FY 2025-26

The NSE and BSE circulars of 14 May 2026 show the rules in action.78 For non-QSB brokers in every category, VAPT for the period April 2025 to March 2026 had to be done by 30 June 2026, the report filed by 31 July 2026, and the ATR or revalidation report filed by 30 November 2026. That is exactly 1 month and 5 months after the test deadline. For QSBs and protected systems, VAPT for the October 2025 to March 2026 half was due with its report by 30 June 2026, and the ATR by 30 September 2026. The submission link opened on 25 May 2026.

NSE's penalties are steep. Late filing costs ₹1,500 a day for the first week for non-Qualified members and ₹3,000 a day for Qualified ones, rising after that. After 21 days, new client registration is blocked, and after 28 days the member is disabled in all segments. Open findings attract charges per vulnerability, from ₹1,000 for a low-risk item at a self-certification broker to ₹50,000 for a critical or high item at a Qualified broker.7

Interactive · CSCRF VAPT calendar

Work out your next CSCRF VAPT dates

Pick your entity type and category, enter the day your last VAPT ended, and see every deadline that follows.

Special cases
VAPT frequency
Once a year
Next VAPT

Report submission dueAfter IT Committee approval
Close findings by
Revalidation window
Auditor requirementCERT-In empanelled IS auditing organisation
File withCSCRF Table 17
Other audits

Indicative only. Dates assume you file the report on its last allowed day, and follow CSCRF Tables 17 to 21 and SEBI's FAQs. Exchanges and depositories can set their own due dates for members, so check the latest circular for your segment.

Test and retest before these dates

What else does CSCRF require beyond VAPT?

Beyond VAPT, SEBI CSCRF compliance means cyber audits, security monitoring through a Security Operations Centre (SOC), scenario-based cyber drills and, for the largest entities, red teaming and a Cyber Capability Index score. MIIs and Qualified REs carry the heaviest load, with most of these checks due every half-year.

CSCRF periodic controls beyond VAPT, by category (CSCRF Tables 15 and 21)
ControlMIIsQualified REsOther REs
Cyber auditAt least twice a yearAt least twice a yearOnce a year (twice for Mid and Small REs offering internet-based or algo trading). None for self-certification REs.
Red teaming (DE.DP.S4)Half-yearlyHalf-yearlyNot required
Scenario-based cyber drill (RC.RP.S3)Half-yearlyHalf-yearlyYearly
SOC functional efficacy (DE.CM.S1)Half-yearlyHalf-yearlyYearly, for REs using a third-party SOC or the Market SOC
Cyber Capability Index (GV.OV.S4)Half-yearly, third-party assessmentYearly self-assessmentNot applicable
ISO 27001 certificationWithin 1 year of CSCRFWithin 1 year of CSCRFNot mandated by CSCRF

The cyber audit follows the same rhythm as VAPT: file the final report within 1 month of completion after IT Committee approval, and close findings within 3 months.1 SEBI's FAQ 22 adds that the cyber audit for a period starts only after that period ends. The audit for April 2025 to March 2026, for example, starts after March 2026.3 Since April 2025, a dedicated hardware security module (HSM) is also mandatory for MIIs and Qualified REs, while smaller REs may use an alternative based on their own risk assessment.2

Cyber Capability Index (CCI)

The Cyber Capability Index is a scored self-check of cyber maturity, applicable to MIIs and Qualified REs. MIIs get a third-party assessment every half-year. Qualified REs self-assess every year. Results go to SEBI within 15 days of completing the assessment.1 The circular maps scores to six bands: Exceptional (91 to 100), Optimal (81 to 90), Manageable (71 to 80), Developing (61 to 70), Bare Minimum (51 to 60) and Fail (50 or below).1 SEBI's FAQs allow partial scoring and scores up to two decimal places.3

SOC and the Market SOC (M-SOC)

CSCRF requires every RE to have security monitoring through a SOC. It can be the RE's own or group SOC, a third-party SOC, or the Market SOC, which NSE and BSE had to set up.1 The August 2025 clarification says Small-size and self-certification REs must join the Market SOC, though those with their own SOC may keep using it.4 SEBI's advisory of 5 May 2026 on AI-driven threats asked eligible REs to speed up Market SOC onboarding, run regular vulnerability assessments with AI-based tools where suitable, patch known vulnerabilities at once, and keep an up-to-date software bill of materials (SBOM) for critical applications.9

One evidence trail, many controls. The same asset inventory feeds VAPT scope, SOC coverage, the SBOM and the CCI. Build it once, keep it current, and every audit gets shorter.

CSCRF compliance deadlines

The CSCRF compliance timeline moved several times. The original circular set 1 January 2025 for six entity types that already had SEBI cyber circulars, and 1 April 2025 for the rest. SEBI then extended the date to 30 June 2025 and later to 31 August 2025 for most entities, but not for MIIs, KRAs and Qualified RTAs.

  • CSCRF issued (circular 2024/113). Market SOC to be set up by 1 January 2025. MIIs and Qualified REs to get ISO 27001 within a year.1
  • First set of clarifications (circular 2024/184).11
  • Compliance date extended by three months to 30 June 2025 for all REs except MIIs, KRAs and Qualified RTAs (circular 2025/45).5
  • Clarifications (circular 2025/60): new stock broker thresholds, KRAs moved to Qualified, HSM rules, and cyber audits from FY 2025-26 to follow CSCRF.2
  • SEBI publishes CSCRF FAQs, including the QSB half-yearly rule and the 1-week patch check.3
  • Deadline extended by two more months to 31 August 2025, with the same exceptions (circular 2025/96).6
  • Technical clarifications (circular 2025/119): summary-only VAPT and audit reports, revised portfolio manager thresholds, Market SOC rules.4
  • SEBI advisory on AI-driven cyber threats.9
  • NSE and BSE circulars on FY 2025-26 VAPT: test by 30 June, report by 31 July, revalidation by 30 November 2026 (QSBs: ATR by 30 September 2026).78

For FY 2026-27, once-a-year entities follow the same rule: start VAPT in Q1 (April to June 2026). Watch your exchange or depository for the exact member due dates, which they publish by circular.

Common audit gaps

The SEBI cyber audit gaps that are easiest to avoid are process misses, not exotic hacks: a scope that leaves out internet-facing or ancillary systems, an auditor who is not CERT-In empanelled, a report filed without IT Committee approval, findings left open past three months, and revalidation that never happens.

Each item below maps to a written rule, so each one is a finding waiting to happen if you skip it.

  • Narrow scope. Testing only the trading app while the CSCRF definition of critical systems also covers client-facing, internet-facing and ancillary systems, on-premise and in the cloud.1
  • Wrong clock. Counting the 3-month closure window from the test date instead of the report date, or giving a missing high-severity patch 3 months instead of 1 week.3
  • No revalidation. Fixing findings but never retesting within 5 months of the test end.1
  • Missing approval. Filing the report before the IT Committee has approved it.1
  • Oversharing. Sending full vulnerability details when SEBI asked for a summary in the CSCRF format.4
  • Auditor rotation. Keeping the same auditor past three years in a row, which NSE does not allow for its members.7
  • Lost evidence. Not keeping the detailed report and proofs of concept for three years.7
  • Calendar mix-up. Planning on the calendar year when every CSCRF periodicity runs on the financial year.3
  • Category drift. Changing controls mid-year when a threshold is crossed, instead of applying the new category from the next April.3

Frequently asked questions

Is VAPT mandatory under SEBI CSCRF?

Yes. Standard DE.CM.S5 of SEBI CSCRF requires VAPT of all critical systems, infrastructure components and other IT systems defined in the framework. It applies to every category, from MIIs to self-certification REs. For self-certification REs, VAPT through a CERT-In empanelled auditor is the only audit required. Entities exempt from CSCRF, such as brokers below the 1,000 client and ₹1,000 crore volume floor, fall outside it.

How often do stock brokers need VAPT under CSCRF?

Most stock brokers need VAPT at least once a financial year, starting in the first quarter (April to June). Qualified Stock Brokers must run VAPT and cyber audits half-yearly, whatever their CSCRF category, as SEBI's FAQ 14 confirms. Brokers whose systems NCIIPC has notified as protected systems or CII must complete a full cycle in each half-year. Exchanges publish the exact member due dates each year.

What is the deadline to close VAPT findings under CSCRF?

Findings must be closed within 3 months of submitting the VAPT report, using a graded approach that fixes the most critical issues first. SEBI's FAQ 17 adds that high-severity findings caused by missing patches are judged against the 1-week patch management timeline. The 3-month window also applies to flaws in third-party products. Revalidation must then be complete within 5 months of the test end.

Who can perform VAPT for SEBI regulated entities?

Unless SEBI specifies otherwise, all CSCRF audits, including VAPT, must be done by an information security auditing organisation empanelled by CERT-In. Stock exchanges add rules for their members. NSE caps an auditor at three consecutive years with a two-year cooling-off, bars consulting work in the prior two years, and requires licensed tools, an NDA and data kept in India.

What is revalidation in SEBI VAPT?

Revalidation is the retest that confirms the findings from a VAPT cycle have really been fixed. Under CSCRF Table 19, it must be complete within 5 months of the date the VAPT ended. Stock brokers submit the result to the exchange as an action taken report (ATR) or revalidation report. For FY 2025-26, NSE and BSE set the due date at 30 November 2026 for most brokers.

Do self-certification REs need a cyber audit under CSCRF?

No. SEBI CSCRF says self-certification REs only need to conduct a VAPT audit through a CERT-In empanelled IS auditing organisation, and no other audit is required. They still need VAPT at least once a financial year, starting in the first quarter. They must also join the Market SOC unless they run their own SOC, and those with their own SOC must file SOC efficacy reports.

What is the Cyber Capability Index in SEBI CSCRF?

The Cyber Capability Index (CCI) is a scored measure of cyber maturity for MIIs and Qualified REs. MIIs get a third-party CCI assessment every half-year, while Qualified REs assess themselves once a year. Scores fall into six bands, from Exceptional (91 to 100) down to Fail (50 or below), and results must be submitted within 15 days of completing the assessment.

Does CSCRF follow the calendar year or the financial year?

CSCRF follows the financial year, which runs from April to March. SEBI's FAQ 20 says all periodicities in the framework are based on the financial year. Categories are also fixed at the start of each financial year using the previous year's data, and an entity stays in that category for the whole year even if its numbers change during the year.

Where Arxiis fits

Meet the calendar. Then test between the dates.

CSCRF sets a floor: one or two audited VAPT cycles a year, fixed clocks for closure and a retest to prove it. The work that decides whether you pass is what happens in between. Findings need fixing before the 3-month clock runs out, and new releases need checking before the next audit finds them.

Arxiis is an autonomous AI red teaming platform that you run yourself, as often as you need. It does not replace the CERT-In empanelled audit that CSCRF requires. It helps your team find and fix issues between audits, and walk into each audit and revalidation with fewer surprises.

  • Broad coverage: 26 security modules across 6 attack vectors, including web applications, Active Directory, cloud, containers, credentials and ransomware paths.
  • An AI crew: agents for OSINT, exploitation, lateral movement and reporting work together like a red team.
  • Audit-ready findings: CVSS scores, MITRE ATT&CK mapping and compliance overlays for 11 frameworks, including SEBI CSCRF, CERT-In and RBI.
  • Data stays home: fully on-premise deployment with an MIT-licensed open-source core, and a pentest report in hours instead of weeks.

Sources

  1. SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113", 20 August 2024. https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf
  2. SEBI, "Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60", 30 April 2025. https://www.sebi.gov.in/legal/circulars/apr-2025/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93734.html
  3. SEBI, "Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs", 11 June 2025. https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  4. SEBI, "Technical Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119", 28 August 2025. https://www.sebi.gov.in/legal/circulars/aug-2025/technical-clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_96329.html
  5. SEBI, "Extension towards Adoption and Implementation of CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45", 28 March 2025. https://www.sebi.gov.in/legal/circulars/mar-2025/extension-towards-adoption-and-implementation-of-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93146.html
  6. Taxmann, "SEBI Extends CSCRF Deadline for Regulated Entities to Aug 31, 2025 (on SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96 of 30 June 2025)", 2025. https://www.taxmann.com/post/blog/sebi-extends-cscrf-deadline-for-regulated-entities
  7. National Stock Exchange of India, "Submission of VAPT Report for the FY 2025-26, Inspection circular 24/2026", 14 May 2026. https://nsearchives.nseindia.com/content/circulars/INSP74185.pdf
  8. BSE, "Notice 20260514-27: Submission of VAPT Report for the FY 2025-26", 14 May 2026. https://www.bseindia.com/downloads/UploadDocs/Notices/20260514-27/20260514-27.pdf
  9. TaxGuru, "SEBI Issues AI Cybersecurity Advisory (SEBI advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026)", 5 May 2026. https://taxguru.in/sebi/sebi-issues-ai-cybersecurity-advisory-advanced-ai-tools-increase-vulnerability.html
  10. CERT-In, "Empanelled Information Security Auditing Organisations", current list. https://www.cert-in.org.in/PDF/Empanel_org.pdf
  11. SEBI, "Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184", 31 December 2024. https://www.sebi.gov.in/legal/circulars/dec-2024/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_90401.html
  12. Verizon, "2026 Data Breach Investigations Report", 2026. https://www.verizon.com/business/resources/reports/dbir/
  13. IBM, "Cost of a Data Breach Report 2026", 2026. https://www.ibm.com/reports/data-breach
Arxiis Research

Written by the Arxiis research team. Facts checked against primary sources on 1 October 2026. Not legal advice.