Skip to main content
SEBI CSCRF · RBI · India

Walk into your next regulatory audit with VAPT evidence you can defend.

SEBI and the RBI expect regulated Indian firms to show tested cyber controls, regular VAPT and board oversight. Summit prepares you with gap analysis, penetration testing evidence and a board-ready report that holds up.

Human-led VAPT · NDA first · report in 48h

20 Aug 2024
date SEBI issued the consolidated CSCRF circular
4
entity categories in the CSCRF: self-certification, small-size, mid-size and qualified regulated entities
5
cyber resiliency goals in the CSCRF: anticipate, withstand, contain, recover and evolve
6
hours, the CERT-In window for reporting certain cyber incidents (2022 directions)
Board and leadership view

Why SEBI and RBI cyber rules matter to your board

The work is technical. The consequences of getting SEBI CSCRF and RBI wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Licence and market access

Regulators can raise cyber failures in inspections and audits. Weak controls put your standing and business activity at risk.

Regulatory exposure and liability

Senior management and the board are expected to oversee cyber risk. Documented, tested controls are your best record of having done so.

Reputation with clients and investors

A cyber incident at a financial firm becomes public quickly. Clients expect proof that controls were tested.

Deadlines and ownership

Testing and submission calendars are set by the regulators. Someone senior needs to own the dates and the evidence.

Fit

Who usually needs this

Brokers, depository participants and asset managers

SEBI regulated entities that must follow the CSCRF for their category.

Exchanges, depositories and clearing bodies

Market infrastructure faces the most demanding controls and testing expectations.

Banks and NBFCs

RBI expects board-level IT oversight, tested controls and managed third-party risk.

Fintech and technology vendors

Regulated customers pass requirements to you through contracts and vendor reviews.

Scope of work

What Summit delivers for SEBI CSCRF and RBI

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your controls mapped against SEBI and RBI expectations for your category, with a prioritised plan.

Penetration testing

Manual testing across critical assets, including applications, networks, servers and databases.

Control validation

We check that governance, logging and response controls work in practice.

Evidence pack

Dated test reports, remediation logs and control evidence organised for your audit.

Remediation support and retest

Guidance while your team fixes findings, then a retest and action taken report.

Board-ready report

A plain-English summary for the board and IT committee, with technical detail behind it.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A realistic preparation roadmap

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Confirm which rules apply

    Week 1

    Identify your entity category and the SEBI and RBI texts, dates and submission formats that apply to you.

  2. 2

    Run a gap analysis and fix gaps

    Weeks 2 to 12

    Compare current controls and testing with the requirements, then close policy, governance and technical gaps with evidence captured continuously.

  3. 3

    Run VAPT

    Month 2 to 3

    Manual penetration testing across critical assets, written up for both regulators and technical teams.

  4. 4

    Remediate and retest

    Month 3 to 4

    Fix findings, retest, and prepare the action taken report within your deadlines.

  5. 5

    Prepare for audit

    Ahead of submission

    Assemble the evidence pack and brief the board so management responses are consistent.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Which rules apply to our entity type?

    Confirm your category and the current circular dates.

  • Do we know our critical assets?

    VAPT scope starts with an accurate inventory.

  • Who signs off on risk acceptance?

    Decisions on unfixed findings need a named owner.

  • Is our board seeing real cyber metrics?

    Reports should show findings, closure rates and incident readiness.

  • Which vendors hold critical data?

    Third-party exposure lands on your side of the table.

The detail

What the SEBI and RBI expectations actually are

On 20 August 2024 SEBI issued the Cybersecurity and Cyber Resilience Framework (CSCRF), a consolidated circular that supersedes earlier cyber circulars and guidelines for SEBI regulated entities such as stock exchanges, depositories, brokers, depository participants, asset managers and others. Requirements are graded by entity category and organised around cyber resiliency goals, with expectations on governance, risk assessment, VAPT, cyber audits, monitoring and recovery.

Implementation dates were extended more than once after the original start dates, and later circulars set VAPT and audit submission timelines for particular categories of entity. Check the latest SEBI circulars for the dates and formats that apply to your entity type.

For banks and NBFCs, the RBI sets expectations through its master directions and circulars, including its Master Direction on IT governance, risk, controls and assurance practices, its IT outsourcing directions and earlier cyber security framework circulars. They cover board oversight, IT and information security governance, vulnerability assessment and penetration testing, incident reporting and third-party risk. Which rules apply depends on your regulatory category and scale, so confirm against the current texts.

Key terms in plain English

CSCRF
SEBI's framework of cybersecurity and cyber resilience controls for its regulated entities, graded by entity category.
VAPT
Vulnerability assessment and penetration testing: scanning plus manual testing to find and prove exploitable weaknesses.
Action Taken Report
A report showing how identified vulnerabilities and audit findings were addressed, submitted within the timelines SEBI specifies.
Regulated entity
A firm that falls under SEBI or RBI rules, such as a broker, depository participant, bank or NBFC.
Requirements

What regulators expect, area by area

This is a plain-English summary, not legal advice. Confirm exact obligations in the current SEBI and RBI texts for your entity type.

1

Governance and board oversight

Both regulators expect cyber risk to be owned at senior level. The CSCRF asks for an IT committee and a named responsible officer, and for external cybersecurity expertise on the committee. RBI directions set out board and senior management responsibilities for IT governance.

What it looks like in practice

  • A cyber policy approved by the board
  • Regular board and committee reporting on cyber risk
  • A named, accountable security lead
  • Documented decisions on risk acceptance
2

Vulnerability assessment and penetration testing

SEBI expects VAPT across critical assets such as networks, security devices, servers, databases and applications, to recognised standards, with frequency and submission dates set by entity category. RBI expects regular testing and tracking of findings.

What it looks like in practice

  • A complete asset inventory with critical assets flagged
  • Testing against recognised methods such as NIST SP 800-115 and OWASP
  • Findings tracked to closure with an action taken report
  • Retesting after fixes
3

Cyber audit

SEBI requires periodic cyber audits for specified entities. The audit is conducted by an auditor on CERT-In's approved list who declares no conflict of interest. Your side of it is evidence, not just policy.

What it looks like in practice

  • Evidence mapped to each framework control
  • Prior findings closed and documented
  • Management responses to every observation
4

Monitoring, detection and incident response

Regulated entities need to detect and respond quickly. The CSCRF refers to security operations capability, and CERT-In directions require reporting of specified cyber incidents within six hours.

What it looks like in practice

  • Centralised logging and alerting
  • A tested incident response plan with reporting steps
  • Exercises that include the board or senior team
5

Third-party and outsourcing risk

Regulators hold the regulated entity accountable for vendors. RBI has specific directions for outsourcing IT services, and SEBI expects vendor risk to be managed.

What it looks like in practice

  • An inventory of critical vendors
  • Security clauses and audit rights in contracts
  • Evidence of vendor testing or assurance
Where testing fits

How penetration testing supports SEBI CSCRF and RBI

SEBI sets out VAPT expectations for critical assets, and RBI expects regular testing of IT systems. A manual test with clear severity ratings, a remediation log and a retest gives your auditor and your board a record they can rely on.

CSCRF

VAPT scope

Testing across networks, security devices, servers, databases and applications, aligned to recognised standards.

CSCRF

Action taken report

A remediation log that shows each finding, owner, fix date and retest result.

RBI

IT governance and assurance

Testing evidence supports board and audit committee oversight of IT risk.

Incident readiness

Attack path validation

Testing shows which weaknesses attackers could chain together, which informs detection and response plans.

Avoid these

Common SEBI CSCRF and RBI mistakes, and how to avoid them

!

Assuming dates are fixed

Implementation and submission dates have moved before. Track current circulars and plan with margin.

!

Scoping VAPT too narrowly

Regulators refer to all critical assets. A test that only covers a website leaves the rest unproven.

!

Leaving the board out

Cyber oversight is a board matter. Reports that only technical teams understand do not meet the intent.

!

No closure evidence

Findings without owners, dates and retest results are hard to defend in an audit.

FAQ

SEBI CSCRF and RBI questions, answered

What is the SEBI CSCRF?

It is SEBI's Cybersecurity and Cyber Resilience Framework, issued on 20 August 2024. It consolidates earlier cyber circulars for SEBI regulated entities and grades requirements by entity category.

Who has to follow it?

SEBI regulated entities such as stock exchanges, depositories, brokers, depository participants, asset managers and others, with requirements varying by category. Check the circular for your entity type.

What are the VAPT expectations?

VAPT is expected across critical assets, to recognised standards, at a frequency and with submission timelines set by entity category. Findings must be closed and reported through an action taken report.

Who can carry out the cyber audit?

Where SEBI requires a cyber audit, it must be carried out by an auditor on CERT-In's approved list, who declares no conflict of interest.

What does the RBI expect from banks and NBFCs?

The RBI expects board oversight of IT, a defined IT and information security governance structure, regular testing, incident reporting and controls over IT outsourcing. The details are in its master directions, which depend on your category.

Have the dates changed?

Yes. SEBI extended implementation dates more than once after the original start dates. Always check the latest circulars before planning.

Does SEBI or RBI name penetration testing?

Both expect vulnerability assessment and penetration testing as part of a regular cyber testing programme. The exact scope and frequency depend on your entity category.

Ready to get SEBI CSCRF and RBI sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →