SEBI CSCRF Compliance
& Cyber Audit Services
We help SEBI-regulated entities meet the Cybersecurity and Cyber Resilience Framework: gap assessment, control engineering and remediation, and cyber-audit readiness, so the statutory audit is a formality.
SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) is a consolidated set of cybersecurity obligations that applies to nearly all SEBI-regulated entities — market infrastructure institutions, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, AIFs, investment and research advisers, KRAs and RTAs — under a five-tier, graded model. It requires periodic vulnerability assessment and penetration testing (VAPT), a security operations capability (SOC or Market-SOC), cyber audits in SEBI’s prescribed formats, a software bill of materials (SBOM), data classification, incident reporting, and data-centre / disaster-recovery drills. It is now in force and the audit and VAPT obligations recur on an ongoing cycle.
CSCRF applies across the SEBI-regulated universe
Obligations are graded across a five-tier model, so the depth of what you need depends on your entity type and scale. Almost every regulated entity is in scope for some part of the framework.
- Market Infrastructure Institutions (stock exchanges, clearing corporations, depositories)
- Stock brokers and depository participants
- Mutual funds and asset management companies (AMCs)
- Portfolio managers and Alternative Investment Funds (AIFs)
- Investment advisers and research analysts
- KYC Registration Agencies (KRAs) and Registrar & Transfer Agents (RTAs / QRTAs)
What CSCRF requires
The framework consolidates the controls a regulated entity is expected to have. These are the areas most programmes need to build or strengthen.
VAPT
Periodic vulnerability assessment and penetration testing of critical systems and internet-facing assets, with tracked remediation.
SOC / Market-SOC
A security operations capability for continuous monitoring — either your own SOC or participation in a Market-SOC, depending on your tier.
Cyber audit
Cyber and network-security audits documented in SEBI’s prescribed formats, on the required reporting cadence.
SBOM
A software bill of materials for critical applications so third-party and open-source components are inventoried and tracked.
Data classification & protection
Classifying data by sensitivity and applying access, encryption and retention controls aligned to the framework.
Incident reporting
Processes and tooling to detect, log and report cyber incidents within the required timelines.
DC-DR resilience
Data-centre and disaster-recovery architecture with periodic drills to prove recovery objectives are met.
Governance & ISO 27001
Cybersecurity governance, policies and, for higher tiers such as MIIs and Qualified REs, an ISO 27001-aligned management system.
From gap assessment to audit-ready
Gap assessment
We map your current controls against the CSCRF requirements for your tier and produce a prioritized remediation plan.
VAPT, engineering & remediation
We run our own vulnerability assessment and penetration testing to surface issues, then build and fix what the framework needs: access controls, logging and SIEM, encryption, secure SDLC, network segmentation and SBOM tooling.
Monitoring & SOC readiness
We design and build the logging, alerting and incident-response plumbing, and integrate it with your SOC or Market-SOC provider.
Audit readiness
We assemble the evidence, documentation and reporting in SEBI’s formats so your cyber audit is a formality, not a scramble.
A repeatable CSCRF programme
Discovery & scoping
We confirm your RE tier and inventory the systems and data in scope.
Gap assessment
A control-by-control review against CSCRF, with a prioritized remediation roadmap.
Remediation & build
Engineering the missing controls, tooling and processes in reviewable sprints.
Audit & ongoing cycle
Evidence assembly for the cyber audit, plus a plan for the recurring VAPT and audit cadence.
Compliance-aware engineering, not just a checklist
We have spent years building software for fintech, banking and other regulated industries where audits, data protection and resilience are non-negotiable. CSCRF work sits naturally alongside our cybersecurity, cloud and compliance-automation practice, so remediation is engineered properly rather than papered over for an audit.
Frequently asked questions
What is SEBI CSCRF?
CSCRF is SEBI’s Cybersecurity and Cyber Resilience Framework — a consolidated set of cybersecurity and resilience obligations that applies to SEBI-regulated entities under a five-tier, graded model. It brings VAPT, security monitoring, cyber audits, SBOM, data classification, incident reporting and DR resilience under one framework.
Who has to comply with CSCRF?
Nearly all SEBI-regulated entities, including market infrastructure institutions, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, AIFs, investment advisers, research analysts, KRAs and RTAs. The specific obligations depend on the tier your entity falls into.
Is CSCRF still active?
Yes. The framework is in force and the VAPT and cyber-audit obligations recur on an ongoing cycle rather than being a one-time exercise. Regulated entities need a repeatable programme, not a single audit.
What does a CSCRF engagement with Levitation involve?
We start with a gap assessment against the CSCRF requirements for your tier, then remediate the missing controls, help stand up or integrate a SOC, and assemble the evidence and documentation your cyber audit needs. We focus on the engineering and audit-readiness rather than issuing the statutory audit itself.
Does CSCRF require a CERT-In empanelled auditor?
CSCRF requires certain assessments to be carried out in line with SEBI’s requirements, which reference CERT-In empanelled auditors for the statutory testing. Levitation is not a CERT-In empanelled auditor, so we do not issue that statutory certification. What we do: run our own VAPT to find and fix issues, engineer and remediate the controls the framework needs, and prepare your documentation and evidence, so the statutory VAPT and audit your entity commissions from an empanelled auditor go smoothly.
Get a CSCRF gap assessment
Tell us your entity type and systems, and we will map exactly what CSCRF needs from you and what it takes to get audit-ready.
Talk to our team