SEBI CSCRF Clarifications: Tiered Cyber Rules for Intermediaries
Why in the news
SEBI clarified its cyber-safety rulebook, the CSCRF, in September 2025: obligations now scale with an intermediary’s size and risk.
Key facts
| Tier | Examples | Treatment |
|---|---|---|
| Large | Top brokers, clearing members, depositories | Stringent controls, strict timelines (systemic risk) |
| Mid-sized | Mid-level intermediaries | Moderate rules, some relaxations |
| Small | Small brokers, portfolio managers, RIAs | Simplified norms, longer timelines |
About the CSCRF
A SEBI framework that helps intermediaries resist, respond to and recover from cyberattacks. It protects investor data, keeps critical operations running and builds trust. The guiding idea is proportional regulation.
Exam angle
- Regulator: SEBI; framework: CSCRF.
- Principle: proportional regulation.