SEBI CSCRF + AI Vulnerability Detection Advisory
Recurring deadline:
30 Jun 2026
Applies to: All SEBI regulated entities, tiered across five categories
A 205-page master framework replacing SEBI's 2015/2018 cyber guidelines, built on five resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) and a five-tier model from Market Infrastructure Institutions down to self-certification entities. Obligations scale by tier: SOC onboarding (own, group, market or third-party), VAPT after every major release, SBOM maintenance, API and endpoint security with rate limiting, data classification and localisation, and a post-quantum-cryptography asset inventory. Cyber audits must use CERT-In empanelled auditors; incident reporting is 6 hours to SEBI and CERT-In. The August 2025 technical clarifications added substantial detail: a principle of equivalence (compliance with an equivalent RBI or other-regulator framework is accepted) and exclusivity for multiply-regulated entities; disaster-recovery targets of a 2-hour RTO and 15-minute RPO; zero-trust principles including network segmentation and elimination of single points of failure with IT-Committee approval; encryption-key management kept within India; and revised RE categorisation thresholds for Portfolio Managers and Merchant Bankers. The 5 May 2026 AI advisory adds 10 directives requiring AI vulnerability-assessment tooling in the VAPT programme and AI-augmented attacker scenarios in the risk register.
Why it matters
CSCRF is the most demanding cyber regime any Indian financial regulator has issued, and it is no longer hypothetical — the implementation deadline has passed and the recurring cyber audit is the live obligation, with SEBI supervisory teams reviewing submissions. For a dual-regulated entity (e.g. an NBFC-cum-broker) the equivalence principle is the single most useful clause: map your RBI compliance to CSCRF controls once and avoid duplicate audits. The PQC inventory requirement is the forward signal — SEBI is the first Indian regulator to put quantum migration on the clock, and a cryptographic asset register is the no-regrets first step.