Skip to content

SEBI CSCRF Clarifications: Tiered Cyber Rules for Intermediaries

1 September 20251 min read
BANKING & FINANCESEBI CSCRFClarifications:Tiered Cyber Rulesfor Intermediaries1 September 2025safalsetu.com

Why in the news

SEBI clarified its cyber-safety rulebook, the CSCRF, in September 2025: obligations now scale with an intermediary’s size and risk.

Key facts

TierExamplesTreatment
LargeTop brokers, clearing members, depositoriesStringent controls, strict timelines (systemic risk)
Mid-sizedMid-level intermediariesModerate rules, some relaxations
SmallSmall brokers, portfolio managers, RIAsSimplified norms, longer timelines

About the CSCRF

A SEBI framework that helps intermediaries resist, respond to and recover from cyberattacks. It protects investor data, keeps critical operations running and builds trust. The guiding idea is proportional regulation.

Exam angle

  • Regulator: SEBI; framework: CSCRF.
  • Principle: proportional regulation.

Test yourself

1. Which regulator issued clarifications on the Cybersecurity and Cyber Resilience Framework (CSCRF) with graded compliance in September 2025?

SEBI is the regulator that framed and clarified the CSCRF.

2. Under SEBI's CSCRF clarifications, which group receives simplified norms and extended timelines?

Small entities get lighter norms; large ones face strict controls.

3. Why do large entities such as depositories face the strictest CSCRF controls?

Higher systemic risk justifies stricter rules and timelines.