Key takeaways
- SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued on 20 August 2024, makes VAPT of critical systems mandatory, and the testing must be done by a CERT-In empanelled IS auditing organisation.1
- Most regulated entities must run VAPT at least once each financial year, starting in the first quarter. Entities whose systems NCIIPC has notified as protected systems or CII must finish a full cycle in each half-year.1
- Three clocks apply to every cycle: file the report within 1 month of finishing the test, close findings within 3 months of filing, and finish revalidation within 5 months of finishing the test.1
- SEBI's FAQs say high-severity findings caused by missing patches are judged against the 1-week patch timeline, and Qualified Stock Brokers test half-yearly whatever their CSCRF category.3
- Since the April 2025 clarification, a stock broker's category depends on its registered clients or yearly clientele trading volume, and the higher of the two decides.2
- For FY 2025-26, NSE and BSE asked most brokers to finish VAPT by 30 June 2026, file by 31 July 2026 and submit revalidation by 30 November 2026.78
A compliance head at a stock broker gets two emails in the same week. One is a VAPT report full of findings. The other is an exchange circular with three dates in it. The findings are the easy part. The hard part is the calendar: which clock has started, when it runs out, and whether the auditor, the scope and the approval trail will hold up in an inspection. SEBI's Cybersecurity and Cyber Resilience Framework turned VAPT from a yearly errand into a timed cycle with penalties at the end. This guide sets out that cycle for each category, clause by clause, and gives you a calendar to work out your own dates.
Last reviewed on 1 October 2026 against SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, the April and August 2025 clarifications, SEBI's CSCRF FAQs (June 2025) and the NSE and BSE VAPT circulars of 14 May 2026.
What is SEBI CSCRF?
SEBI CSCRF is the Cybersecurity and Cyber Resilience Framework that the Securities and Exchange Board of India issued on 20 August 2024 through circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113. It replaces a set of older cyber circulars with one rulebook, scaled by entity size, and makes VAPT, cyber audits and security monitoring mandatory.
CSCRF is written as a list of standards. Each one has a short code. The codes borrow the function names of the NIST Cybersecurity Framework, such as Govern (GV), Protect (PR), Detect (DE) and Recover (RC). VAPT sits under standard DE.CM.S5, which says VAPT "shall be done to detect vulnerabilities in the IT environment for all critical systems, infrastructure components and other IT systems as defined in the framework".1
- VAPT, in one line
- Vulnerability assessment and penetration testing. The assessment finds known weaknesses with scans. The penetration test tries to exploit them, the way an attacker would, to show what a weakness really exposes. Our guide on vulnerability assessment vs penetration testing explains the difference in detail.
The framework defines "critical systems" widely. The list includes any system whose compromise would hurt core business, systems that store or send regulated data, the network that connects them, internet-facing systems, client-facing systems, and the ancillary systems used to reach or maintain critical systems. It covers both on-premise and cloud.1 In practice, that means your trading front end, your back office, your admin jump servers and the cloud tenant behind your mobile app are all in scope.
Why SEBI cares about the timing
The timing rules exist because attackers now move faster than yearly checks. Verizon's 2026 Data Breach Investigations Report found that exploiting vulnerabilities was the top way into breached organisations, at 31% of cases, ahead of stolen credentials for the first time.12 IBM puts the average cost of a data breach in India at ₹25.5 crore in its 2026 report.13 A test that nobody fixes on time does little against that.
Not legal advice. This guide summarises SEBI and exchange texts as of 1 October 2026. SEBI and the exchanges update CSCRF through circulars, FAQs and notices. Always check the latest text and your own category annexure before you plan an audit.
Which regulated entities does CSCRF cover?
SEBI CSCRF covers almost every SEBI regulated entity (RE): stock exchanges, depositories and clearing corporations, plus stock brokers, depository participants, mutual funds, portfolio managers, KYC registration agencies, registrars, merchant bankers, investment advisers and more. Six entity types that already had SEBI cyber circulars were given the earliest deadline.
The applicability list in the circular runs from alternative investment funds, bankers to an issue, clearing corporations, collective investment schemes, credit rating agencies, custodians and debenture trustees to depositories and designated depository participants, among others.1 The categorisation tables and later clarifications add stock brokers, depository participants (DPs), mutual funds and asset management companies (AMCs), portfolio managers, KRAs, research analysts, investment advisers, registrars (RTAs) and merchant bankers.124
Who is left out, or partly out
- Very small stock brokers. Brokers with fewer than 1,000 registered clients and less than ₹1,000 crore of clientele trading volume in a year are exempt from CSCRF.2
- Inactive merchant bankers. The August 2025 technical clarification exempts them. Active merchant bankers are Small-size REs.4
- Tiny DPs and RTAs. DPs and RTAs with fewer than 100 clients do not have to take SOC services or join the Market SOC. They still have the other duties.2
If your firm is a bank or NBFC that is also a DP, you may be under both SEBI and RBI rules. Our guide to the RBI Cyber Security Directions 2026 and their VAPT rules covers the RBI side.
How are CSCRF categories decided?
CSCRF regulated entity categories are fixed at the start of each financial year using the previous year's data, and an entity stays in that category all year. SEBI uses a different yardstick for each entity type: registered clients and trading volume for stock brokers, assets under management for mutual funds and portfolio managers.
There are five categories, from heaviest to lightest duty:1
- Market Infrastructure Institutions (MIIs): stock exchanges, clearing corporations and depositories.
- Qualified REs: the largest intermediaries.
- Mid-size REs.
- Small-size REs.
- Self-certification REs: the smallest covered entities, which certify their own compliance for most controls.
SEBI's FAQs confirm the rule on timing: "Once the category of RE is decided, RE shall remain in the same category throughout the financial year."3 A broker that crosses a threshold in October keeps its old category until the next April.
Example 1: client-based stock brokers
The April 2025 clarification replaced the original "active clients" test with two measures. If a broker falls into two categories on the two measures, the higher category applies.2
| Category | Total registered clients | Clientele trading volume in a year |
|---|---|---|
| Qualified RE | More than 10 lakh | More than ₹10,00,000 crore |
| Mid-size RE | More than 1 lakh, up to 10 lakh | More than ₹1,00,000 crore, up to ₹10,00,000 crore |
| Small-size RE | More than 10,000, up to 1 lakh | More than ₹10,000 crore, up to ₹1,00,000 crore |
| Self-certification RE | More than 1,000, up to 10,000 | More than ₹1,000 crore, up to ₹10,000 crore |
| Exempt | Fewer than 1,000 | Less than ₹1,000 crore (both conditions) |
Proprietary brokers, which have no clients, are measured by the collateral or assets they hold with clearing corporations: more than ₹1,000 crore is Mid-size, more than ₹10 crore and less than ₹1,000 crore is Small-size, and ₹10 crore or below is Self-certification.3
Example 2: other entity types
- Mutual funds and AMCs (by AUM): under ₹10,000 crore is Small-size, ₹10,000 crore to under ₹1 lakh crore is Mid-size, and ₹1 lakh crore and above is Qualified.1
- Portfolio managers (by AUM, as revised in August 2025): ₹10,000 crore and above is Mid-size, more than ₹3,000 crore and under ₹10,000 crore is Small-size, and ₹3,000 crore and below is Self-certification. There is no Qualified tier.4
- KRAs: first placed at par with MIIs, then moved to the Qualified category in April 2025.12
- Non-individual investment advisers: Small-size REs.1
- Depository participants: SEBI's FAQ 5 lists banks, NBFCs, mutual funds, RTAs, financial institutions, custodians and clearing corporations that act as DPs as Qualified REs. For other DPs, check your category annexure.3
How often does each category need VAPT?
SEBI CSCRF VAPT requirements set two cadences. Entities whose systems NCIIPC has notified as protected systems or critical information infrastructure (CII) must complete a full VAPT cycle in each half of the financial year. Every other regulated entity must run VAPT at least once a year, starting in the first quarter (April to June).
Table 18 of the circular draws the line by protected-system status, not by category.1 For those entities, "one VAPT activity shall be completed (including report submission, closure, and revalidation) in each half of the financial year (April to September and October to March)". SEBI's FAQs add one more half-yearly group: Qualified Stock Brokers (QSBs), under a February 2023 SEBI circular, "irrespective of the category they fall in as per CSCRF".3
| Category | Minimum VAPT | Cyber audit | What else to note |
|---|---|---|---|
| MIIs | At least once a year, starting Q1. Twice if systems are protected / CII | At least twice a year | Half-yearly red teaming, half-yearly third-party CCI |
| Qualified REs | At least once a year, starting Q1. Twice if protected / CII | At least twice a year | Half-yearly red teaming, yearly CCI self-assessment |
| Qualified Stock Brokers | Half-yearly whatever the category | Half-yearly | Exchanges publish separate QSB due dates |
| Mid-size REs | At least once a year, starting Q1 | Twice a year if offering internet-based or algo trading, else once | Yearly cyber drill and SOC efficacy check |
| Small-size REs | At least once a year, starting Q1 | Twice a year if offering internet-based or algo trading, else once | Must join the Market SOC unless it has its own SOC |
| Self-certification REs | At least once a year, starting Q1 | None: VAPT is the only audit required | Must join the Market SOC unless it has its own SOC |
Sources for the table: CSCRF Tables 15, 18 and 21, the self-certification rule, the QSB FAQ and the August 2025 clarification on the Market SOC.134 One more rule matters for planning: SEBI's FAQ 20 says every periodicity in CSCRF runs on the financial year, not the calendar year.3
"At least once" is a floor. A yearly test shows your exposure on the days the auditor looked. The rest of the year is unobserved, a gap we measured in the 363-day blind spot of annual pentests.
Who can conduct VAPT under CSCRF?
VAPT under SEBI CSCRF must be carried out by an information security auditing organisation empanelled by CERT-In, India's national cyber security agency, unless SEBI says otherwise. The IT Committee must approve the report before it goes to the reporting authority: the exchange or depository for brokers and DPs, BASL for investment advisers, and SEBI for the rest.
The CSCRF footnote is short: "Unless otherwise specified, all audits mentioned in CSCRF have to be conducted by CERT-In empanelled IS auditing organization."1 CERT-In publishes its list of empanelled organisations on its website.10 For self-certification REs, the circular says they "shall be required to conduct only VAPT audit through CERT-In empanelled IS auditing organisation and no other audit is required".1 We explain how the empanelment scheme works in our guide to CERT-In guidelines on 6-hour reporting and VAPT audits.
Extra auditor rules for stock brokers
NSE's circular of 14 May 2026 adds conditions for trading members' auditors.7 The auditing organisation must be CERT-In empanelled and should preferably have at least 3 years of IT audit experience in banking and financial services. An auditor can audit the same member for at most three years in a row, followed by a two-year cooling-off period. It must not have done consulting work for the member in the previous two years, must use only licensed tools, must sign an NDA, and must keep data within India.
Checks before you sign the engagement letter
- The firm's name is on CERT-In's current empanelled list, not just a staff member's certificate.
- The scope names every critical system type in the CSCRF definition, including cloud and ancillary systems.
- The contract gives you the summary report in the CSCRF format and the full report with proof of concept (POC) separately.
- The auditor has not crossed the three-year rotation limit or consulted for you in the last two years.
- Retesting for revalidation is priced in. Our breakdown of VAPT cost in India shows how retests change the quote.
What is the timeline from test to closure?
The SEBI CSCRF VAPT timeline runs on three fixed clocks. File the IT Committee approved report within 1 month of finishing the test. Close findings within 3 months of filing the report, using a graded approach by severity. Complete revalidation, meaning a retest that proves the fixes work, within 5 months of finishing the test.
These timelines come from Table 19 of the circular.1 SEBI's FAQ 17 explains how closure is judged. High-severity findings caused by missing patches are checked against the patch management timeline of 1 week under standard PR.MA.S3. All other findings are checked against the 3-month closure window.3 FAQ 15 adds that the 3-month window applies even when the flaw sits in a third-party product you do not control.3
The cycle, step by step
- Scope. List every critical system as CSCRF defines it. NSE describes the scope as all critical assets, including network and security devices, servers, databases, applications, systems reachable over WAN, LAN or public IPs, and websites, as detailed in Annexure-L of CSCRF.7
- Test. A CERT-In empanelled auditor runs the vulnerability assessment and the penetration test. For once-a-year entities, the activity must start in Q1 of the financial year.1
- Approve and file. Your IT Committee approves the report, and you file it with your reporting authority within 1 month. Since August 2025, REs file a summary in the CSCRF format and must not send the detailed vulnerabilities unless SEBI asks for them.4
- Fix. Close findings within 3 months of filing, most severe first. Treat missing high-severity patches as a 1-week job.
- Revalidate. The auditor retests and confirms closure within 5 months of the test end. Brokers submit this as an action taken report (ATR) or revalidation report to the exchange.7
- Keep the evidence. Exchanges require members to keep the detailed VAPT report and proofs of concept for at least three years and to share them when asked.78
A VAPT report closes nothing. The day you file it, the 3-month clock starts.Arxiis Research
Protected systems get less room. If NCIIPC has notified your systems as protected systems or CII, the whole cycle, including filing, closure and revalidation, must fit inside the same half-year. A test that ends in August leaves only weeks, not months, to fix and retest before 30 September. Plan tests early in each half.
How the exchanges applied it for FY 2025-26
The NSE and BSE circulars of 14 May 2026 show the rules in action.78 For non-QSB brokers in every category, VAPT for the period April 2025 to March 2026 had to be done by 30 June 2026, the report filed by 31 July 2026, and the ATR or revalidation report filed by 30 November 2026. That is exactly 1 month and 5 months after the test deadline. For QSBs and protected systems, VAPT for the October 2025 to March 2026 half was due with its report by 30 June 2026, and the ATR by 30 September 2026. The submission link opened on 25 May 2026.
NSE's penalties are steep. Late filing costs ₹1,500 a day for the first week for non-Qualified members and ₹3,000 a day for Qualified ones, rising after that. After 21 days, new client registration is blocked, and after 28 days the member is disabled in all segments. Open findings attract charges per vulnerability, from ₹1,000 for a low-risk item at a self-certification broker to ₹50,000 for a critical or high item at a Qualified broker.7
Work out your next CSCRF VAPT dates
Pick your entity type and category, enter the day your last VAPT ended, and see every deadline that follows.
Indicative only. Dates assume you file the report on its last allowed day, and follow CSCRF Tables 17 to 21 and SEBI's FAQs. Exchanges and depositories can set their own due dates for members, so check the latest circular for your segment.
Test and retest before these datesWhat else does CSCRF require beyond VAPT?
Beyond VAPT, SEBI CSCRF compliance means cyber audits, security monitoring through a Security Operations Centre (SOC), scenario-based cyber drills and, for the largest entities, red teaming and a Cyber Capability Index score. MIIs and Qualified REs carry the heaviest load, with most of these checks due every half-year.
| Control | MIIs | Qualified REs | Other REs |
|---|---|---|---|
| Cyber audit | At least twice a year | At least twice a year | Once a year (twice for Mid and Small REs offering internet-based or algo trading). None for self-certification REs. |
| Red teaming (DE.DP.S4) | Half-yearly | Half-yearly | Not required |
| Scenario-based cyber drill (RC.RP.S3) | Half-yearly | Half-yearly | Yearly |
| SOC functional efficacy (DE.CM.S1) | Half-yearly | Half-yearly | Yearly, for REs using a third-party SOC or the Market SOC |
| Cyber Capability Index (GV.OV.S4) | Half-yearly, third-party assessment | Yearly self-assessment | Not applicable |
| ISO 27001 certification | Within 1 year of CSCRF | Within 1 year of CSCRF | Not mandated by CSCRF |
The cyber audit follows the same rhythm as VAPT: file the final report within 1 month of completion after IT Committee approval, and close findings within 3 months.1 SEBI's FAQ 22 adds that the cyber audit for a period starts only after that period ends. The audit for April 2025 to March 2026, for example, starts after March 2026.3 Since April 2025, a dedicated hardware security module (HSM) is also mandatory for MIIs and Qualified REs, while smaller REs may use an alternative based on their own risk assessment.2
Cyber Capability Index (CCI)
The Cyber Capability Index is a scored self-check of cyber maturity, applicable to MIIs and Qualified REs. MIIs get a third-party assessment every half-year. Qualified REs self-assess every year. Results go to SEBI within 15 days of completing the assessment.1 The circular maps scores to six bands: Exceptional (91 to 100), Optimal (81 to 90), Manageable (71 to 80), Developing (61 to 70), Bare Minimum (51 to 60) and Fail (50 or below).1 SEBI's FAQs allow partial scoring and scores up to two decimal places.3
SOC and the Market SOC (M-SOC)
CSCRF requires every RE to have security monitoring through a SOC. It can be the RE's own or group SOC, a third-party SOC, or the Market SOC, which NSE and BSE had to set up.1 The August 2025 clarification says Small-size and self-certification REs must join the Market SOC, though those with their own SOC may keep using it.4 SEBI's advisory of 5 May 2026 on AI-driven threats asked eligible REs to speed up Market SOC onboarding, run regular vulnerability assessments with AI-based tools where suitable, patch known vulnerabilities at once, and keep an up-to-date software bill of materials (SBOM) for critical applications.9
One evidence trail, many controls. The same asset inventory feeds VAPT scope, SOC coverage, the SBOM and the CCI. Build it once, keep it current, and every audit gets shorter.
CSCRF compliance deadlines
The CSCRF compliance timeline moved several times. The original circular set 1 January 2025 for six entity types that already had SEBI cyber circulars, and 1 April 2025 for the rest. SEBI then extended the date to 30 June 2025 and later to 31 August 2025 for most entities, but not for MIIs, KRAs and Qualified RTAs.
- CSCRF issued (circular 2024/113). Market SOC to be set up by 1 January 2025. MIIs and Qualified REs to get ISO 27001 within a year.1
- First set of clarifications (circular 2024/184).11
- Compliance date extended by three months to 30 June 2025 for all REs except MIIs, KRAs and Qualified RTAs (circular 2025/45).5
- Clarifications (circular 2025/60): new stock broker thresholds, KRAs moved to Qualified, HSM rules, and cyber audits from FY 2025-26 to follow CSCRF.2
- SEBI publishes CSCRF FAQs, including the QSB half-yearly rule and the 1-week patch check.3
- Deadline extended by two more months to 31 August 2025, with the same exceptions (circular 2025/96).6
- Technical clarifications (circular 2025/119): summary-only VAPT and audit reports, revised portfolio manager thresholds, Market SOC rules.4
- SEBI advisory on AI-driven cyber threats.9
- NSE and BSE circulars on FY 2025-26 VAPT: test by 30 June, report by 31 July, revalidation by 30 November 2026 (QSBs: ATR by 30 September 2026).78
For FY 2026-27, once-a-year entities follow the same rule: start VAPT in Q1 (April to June 2026). Watch your exchange or depository for the exact member due dates, which they publish by circular.
Common audit gaps
The SEBI cyber audit gaps that are easiest to avoid are process misses, not exotic hacks: a scope that leaves out internet-facing or ancillary systems, an auditor who is not CERT-In empanelled, a report filed without IT Committee approval, findings left open past three months, and revalidation that never happens.
Each item below maps to a written rule, so each one is a finding waiting to happen if you skip it.
- Narrow scope. Testing only the trading app while the CSCRF definition of critical systems also covers client-facing, internet-facing and ancillary systems, on-premise and in the cloud.1
- Wrong clock. Counting the 3-month closure window from the test date instead of the report date, or giving a missing high-severity patch 3 months instead of 1 week.3
- No revalidation. Fixing findings but never retesting within 5 months of the test end.1
- Missing approval. Filing the report before the IT Committee has approved it.1
- Oversharing. Sending full vulnerability details when SEBI asked for a summary in the CSCRF format.4
- Auditor rotation. Keeping the same auditor past three years in a row, which NSE does not allow for its members.7
- Lost evidence. Not keeping the detailed report and proofs of concept for three years.7
- Calendar mix-up. Planning on the calendar year when every CSCRF periodicity runs on the financial year.3
- Category drift. Changing controls mid-year when a threshold is crossed, instead of applying the new category from the next April.3
Frequently asked questions
Is VAPT mandatory under SEBI CSCRF?
Yes. Standard DE.CM.S5 of SEBI CSCRF requires VAPT of all critical systems, infrastructure components and other IT systems defined in the framework. It applies to every category, from MIIs to self-certification REs. For self-certification REs, VAPT through a CERT-In empanelled auditor is the only audit required. Entities exempt from CSCRF, such as brokers below the 1,000 client and ₹1,000 crore volume floor, fall outside it.
How often do stock brokers need VAPT under CSCRF?
Most stock brokers need VAPT at least once a financial year, starting in the first quarter (April to June). Qualified Stock Brokers must run VAPT and cyber audits half-yearly, whatever their CSCRF category, as SEBI's FAQ 14 confirms. Brokers whose systems NCIIPC has notified as protected systems or CII must complete a full cycle in each half-year. Exchanges publish the exact member due dates each year.
What is the deadline to close VAPT findings under CSCRF?
Findings must be closed within 3 months of submitting the VAPT report, using a graded approach that fixes the most critical issues first. SEBI's FAQ 17 adds that high-severity findings caused by missing patches are judged against the 1-week patch management timeline. The 3-month window also applies to flaws in third-party products. Revalidation must then be complete within 5 months of the test end.
Who can perform VAPT for SEBI regulated entities?
Unless SEBI specifies otherwise, all CSCRF audits, including VAPT, must be done by an information security auditing organisation empanelled by CERT-In. Stock exchanges add rules for their members. NSE caps an auditor at three consecutive years with a two-year cooling-off, bars consulting work in the prior two years, and requires licensed tools, an NDA and data kept in India.
What is revalidation in SEBI VAPT?
Revalidation is the retest that confirms the findings from a VAPT cycle have really been fixed. Under CSCRF Table 19, it must be complete within 5 months of the date the VAPT ended. Stock brokers submit the result to the exchange as an action taken report (ATR) or revalidation report. For FY 2025-26, NSE and BSE set the due date at 30 November 2026 for most brokers.
Do self-certification REs need a cyber audit under CSCRF?
No. SEBI CSCRF says self-certification REs only need to conduct a VAPT audit through a CERT-In empanelled IS auditing organisation, and no other audit is required. They still need VAPT at least once a financial year, starting in the first quarter. They must also join the Market SOC unless they run their own SOC, and those with their own SOC must file SOC efficacy reports.
What is the Cyber Capability Index in SEBI CSCRF?
The Cyber Capability Index (CCI) is a scored measure of cyber maturity for MIIs and Qualified REs. MIIs get a third-party CCI assessment every half-year, while Qualified REs assess themselves once a year. Scores fall into six bands, from Exceptional (91 to 100) down to Fail (50 or below), and results must be submitted within 15 days of completing the assessment.
Does CSCRF follow the calendar year or the financial year?
CSCRF follows the financial year, which runs from April to March. SEBI's FAQ 20 says all periodicities in the framework are based on the financial year. Categories are also fixed at the start of each financial year using the previous year's data, and an entity stays in that category for the whole year even if its numbers change during the year.
Meet the calendar. Then test between the dates.
CSCRF sets a floor: one or two audited VAPT cycles a year, fixed clocks for closure and a retest to prove it. The work that decides whether you pass is what happens in between. Findings need fixing before the 3-month clock runs out, and new releases need checking before the next audit finds them.
Arxiis is an autonomous AI red teaming platform that you run yourself, as often as you need. It does not replace the CERT-In empanelled audit that CSCRF requires. It helps your team find and fix issues between audits, and walk into each audit and revalidation with fewer surprises.
- Broad coverage: 26 security modules across 6 attack vectors, including web applications, Active Directory, cloud, containers, credentials and ransomware paths.
- An AI crew: agents for OSINT, exploitation, lateral movement and reporting work together like a red team.
- Audit-ready findings: CVSS scores, MITRE ATT&CK mapping and compliance overlays for 11 frameworks, including SEBI CSCRF, CERT-In and RBI.
- Data stays home: fully on-premise deployment with an MIT-licensed open-source core, and a pentest report in hours instead of weeks.
Sources
- SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113", 20 August 2024. https://www.sebi.gov.in/sebi_data/attachdocs/aug-2024/1724326790365.pdf
- SEBI, "Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60", 30 April 2025. https://www.sebi.gov.in/legal/circulars/apr-2025/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93734.html
- SEBI, "Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs", 11 June 2025. https://www.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
- SEBI, "Technical Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119", 28 August 2025. https://www.sebi.gov.in/legal/circulars/aug-2025/technical-clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_96329.html
- SEBI, "Extension towards Adoption and Implementation of CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45", 28 March 2025. https://www.sebi.gov.in/legal/circulars/mar-2025/extension-towards-adoption-and-implementation-of-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93146.html
- Taxmann, "SEBI Extends CSCRF Deadline for Regulated Entities to Aug 31, 2025 (on SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96 of 30 June 2025)", 2025. https://www.taxmann.com/post/blog/sebi-extends-cscrf-deadline-for-regulated-entities
- National Stock Exchange of India, "Submission of VAPT Report for the FY 2025-26, Inspection circular 24/2026", 14 May 2026. https://nsearchives.nseindia.com/content/circulars/INSP74185.pdf
- BSE, "Notice 20260514-27: Submission of VAPT Report for the FY 2025-26", 14 May 2026. https://www.bseindia.com/downloads/UploadDocs/Notices/20260514-27/20260514-27.pdf
- TaxGuru, "SEBI Issues AI Cybersecurity Advisory (SEBI advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026)", 5 May 2026. https://taxguru.in/sebi/sebi-issues-ai-cybersecurity-advisory-advanced-ai-tools-increase-vulnerability.html
- CERT-In, "Empanelled Information Security Auditing Organisations", current list. https://www.cert-in.org.in/PDF/Empanel_org.pdf
- SEBI, "Clarifications to CSCRF for SEBI Regulated Entities, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184", 31 December 2024. https://www.sebi.gov.in/legal/circulars/dec-2024/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_90401.html
- Verizon, "2026 Data Breach Investigations Report", 2026. https://www.verizon.com/business/resources/reports/dbir/
- IBM, "Cost of a Data Breach Report 2026", 2026. https://www.ibm.com/reports/data-breach