SEBI CSCRF Consultant — Getting a Regulated Entity Audit-Ready
The framework that changed the conversation for every SEBI-regulated entity
Since SEBI issued the Cyber Security and Cyber Resilience Framework on 20 August 2024, my phone has rung differently. It used to be brokers and fund managers asking for a firewall or a pen-test before a routine inspection. Now it is compliance heads asking a harder question: are we audit-ready under CSCRF, or do we just think we are?
I have spent three decades securing networks across BFSI, and this framework is not a repackaging of old advice. CSCRF consolidates a long trail of SEBI circulars and advisories into a single, graded, enforceable structure. It tells you which category your entity falls into, what controls that category demands, whether you may outsource your security operations, and when an auditor will come asking for evidence. There is very little ambiguity left — which is why so many regulated entities are uncomfortable.

This post is what I tell clients in the first working session: what the framework demands, where entities fail, and how I run a CSCRF readiness engagement. If you want a SEBI CSCRF consultant rather than a slide deck, read on.
What CSCRF actually demands of regulated entities
A graded classification — your obligations depend on your category
CSCRF does not treat a stock exchange and a boutique portfolio manager the same way, and that is one of its strengths. Entities are sorted into five categories: Market Infrastructure Institutions (exchanges, clearing corporations, depositories), Qualified REs, Mid-size REs, Small-size REs, and Self-certification REs. Thresholds — client counts, trading volumes, assets under management — decide where you land, and the control set scales accordingly. The first thing I do in any engagement is confirm your classification; I have seen entities prepare for the wrong tier entirely.
The SOC mandate — three permitted models
This is the requirement that causes the most anxiety. CSCRF requires security monitoring through a Security Operations Centre, and permits exactly three models:
- Your own SOC or a group SOC, if you are large enough to staff and run one credibly;
- The Market SOC — the shared facility operated through the exchanges and depositories, onto which small-size and self-certification entities are directed;
- A third-party managed SOC, which SEBI explicitly recognises as a sanctioned model, not a workaround.
Notice what that means: outsourcing your SOC is legitimate under the framework. What is not legitimate is a SOC that exists only on paper.
ISO 27001 — read the August 2025 clarification carefully
The base circular created real confusion here, and SEBI has since clarified it twice — through its June 2025 FAQ and the technical clarifications dated 28 August 2025. The position as it now stands: ISO/IEC 27001:2022 certification is mandatory for MIIs. For Qualified REs it has been moved from mandatory to encouraged and recommended — a deliberate downgrade, not an oversight. For Mid-size, Small-size and Self-certification REs it is voluntary. If a vendor tells you certification is compulsory for your category without knowing this clarification, be careful what else they are selling you.
VAPT, cyber audit and reporting timelines
CSCRF sets a vulnerability assessment and penetration testing cadence that scales with your category — twice-yearly at the top end, at least annually below — and an annual cyber audit by a CERT-In empanelled auditor, with defined submission timelines. Incident reporting obligations flow down from the CERT-In directions as well. These are calendar events with evidence attached. The auditor does not want to hear that you ran a scan; they want the report, the remediation tracker, and proof the findings were closed.
Where regulated entities actually fail
I have sat on both sides of audits long enough to know the failure patterns. They are rarely exotic:
- A SOC that is a dashboard nobody watches. A screen in a server room with a SIEM on it is not a SOC. When I ask who triages alerts at 2 a.m. on a Sunday, the silence tells me everything.
- Logs not retained, or retained but unusable. Clock skew across devices, logs rotated out in days, critical systems never onboarded at all. The audit asks for six months of evidence and the entity can produce six weeks.
- Governance documentation written after the audit letter arrives. A policy dated two weeks before the inspection, a board that has never reviewed a risk register, a CISO role filled by whoever was free. Auditors see through this because the document trail has no history.
- VAPT treated as a certificate exercise. The same medium-severity findings reappearing audit after audit because remediation was never tracked to closure.
- Wrong SOC model chosen by default. A mid-size broker running an in-house SOC with two engineers and a licence it cannot afford to use properly, when a managed model would have been cheaper and defensible.
None of these are technology failures. They are governance and operating-model failures, which is why another tool never fixes them.
The Market SOC versus private SOC decision
For smaller REs this is the real strategic question. The Market SOC is affordable, SEBI-sanctioned, and for small-size and self-certification entities it is effectively the directed path. Its limitation is coverage: it watches the market-facing perimeter well, but your internal estate — endpoints, lateral movement, your own log quality — remains your responsibility, and the audit will still ask about it.
A private or managed SOC costs more but covers your whole estate, keeps log evidence audit-ready continuously, and gives you someone to call during an incident who knows your environment. For Qualified and Mid-size REs with anything beyond a trivial footprint, I generally recommend a third-party managed SOC over an in-house build — you get 24/7 coverage without hiring a shift team you cannot retain. Decide on your risk surface and audit obligations, not the licence price alone.
How I run a CSCRF readiness engagement
My engagements follow the same arc whether the client is a depository participant or an asset manager. I work hands-on with your engineers and compliance team, not from a report written at arm’s length.
Assess — gap analysis against the framework
I confirm your RE category, then map every applicable CSCRF control against what you actually have: monitoring coverage, log retention, VAPT history, incident reporting, governance artefacts, third-party dependencies. The output is a gap register ranked by audit risk, not by what is fashionable to fix.
Architect — the SOC model decision
Together we decide between your own or group SOC, the Market SOC, and a third-party managed SOC. I model the true cost of each — staffing, tooling, 24/7 coverage, evidence production — because the wrong choice is the most expensive mistake in the programme. Where a managed model wins, my team at PJ Networks runs exactly this for regulated entities through our SEBI CSCRF compliance services and SOC-as-a-Service for BFSI. PJ Networks is ISO/IEC 27001:2022 certified with its SOC in scope, which matters when an auditor asks who is watching your watchers.
Deploy — close the gaps and build the evidence pack
Remediation is sequenced so audit-visible items close first: log retention fixed, VAPT findings tracked to closure, policies and committee minutes built with genuine history behind them. The evidence pack is assembled as we go, not reconstructed the week before the audit.
Operate — mock audit, then continuous readiness
Before the real audit, I run a mock audit against the same expectations a CERT-In empanelled auditor will bring. Whatever survives that survives the real thing. Afterwards, readiness becomes an operating rhythm — quarterly evidence reviews, VAPT scheduling, incident reporting drills — so next year’s audit is a non-event. You can read more about how I work on my about page.
Frequently asked questions
Which SEBI-regulated entities does CSCRF apply to?
Effectively all of them: Market Infrastructure Institutions (exchanges, clearing corporations, depositories), stock brokers, depository participants, asset management companies and mutual funds, portfolio managers, investment advisers, research analysts, custodians, KYC registration agencies, alternative investment funds and others. What varies is the category you are placed in — MII, Qualified, Mid-size, Small-size or Self-certification — and the control set that follows from it.
Is ISO 27001 certification mandatory for us?
It depends on your category, and the answer changed in 2025. Following SEBI’s June 2025 FAQ and the technical clarifications dated 28 August 2025, ISO/IEC 27001:2022 certification is mandatory for Market Infrastructure Institutions. For Qualified REs it is now encouraged and recommended rather than mandatory — SEBI deliberately downgraded it. For Mid-size, Small-size and Self-certification REs it remains voluntary, though certification often makes the cyber audit materially easier.
Do we have to use the Market SOC?
Small-size and Self-certification REs are directed onto the Market SOC. For everyone else, CSCRF permits three models: your own or a group SOC, the Market SOC, or a third-party managed SOC. Outsourcing to a managed SOC provider is an explicitly sanctioned option, and for most Qualified and Mid-size entities it is the most cost-effective way to get genuine 24/7 monitoring and audit-ready log evidence.
What does the SEBI cyber audit actually cover?
The annual audit, conducted by a CERT-In empanelled auditor, tests your controls against the CSCRF requirements for your category: SOC operations and alert handling, log retention and integrity, VAPT reports and remediation closure, incident reporting history, access management, and governance artefacts such as policies, risk registers and committee minutes. Auditors ask for evidence with dates and history, which is why documentation written after the audit letter arrives fails.
How long does CSCRF readiness take?
For a typical broker or portfolio manager starting from a reasonable baseline, three to six months to reach audit-ready state: a few weeks for the gap analysis and SOC model decision, then remediation and evidence-pack build-out. Entities starting with no log retention, no monitored SOC or no governance documentation should budget towards the longer end, because some evidence — committee minutes, incident drills, retained logs — can only accumulate with time.
What does a consultant cost versus getting it wrong?
A readiness engagement costs a fraction of what a failed audit costs. The direct consequences of poor audit findings include SEBI observations, follow-up inspections, remediation under deadline pressure, and in serious cases monetary penalties and restrictions on onboarding clients. The indirect cost — a security incident at an entity the regulator has already flagged — is worse. Paying for an honest gap analysis early is the cheapest insurance in this framework.
Get audit-ready before the letter arrives
If CSCRF applies to you, the audit is not a question of if but when. The entities that pass calmly treated readiness as a programme, not a fire drill. If you want senior eyes on your gap register, your SOC model decision, or your evidence pack, book a working session with me and we will start with where you actually stand.
Based in Delhi, working with enterprises across India.