SEBI CSCRF · India
SEBI asks you to measure
awareness, not just deliver it.
SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF, 20 August 2024) makes employee awareness programmes mandatory, requires a dedicated programme for Board members, and asks most regulated entities to assess employee awareness periodically, for example through phishing test success rate.
- Framework
- CSCRF, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024, with clarifications in 2024 and 2025
- Deadlines
- Every category was due by 31 August 2025, the last extension
- People
- Mandatory awareness programmes, a Board programme, annual training and periodic phishing tests
- Incidents
- 6 hours to SEBI and CERT-In, 24 hours on SEBI’s incident portal
What CSCRF says about people
Awareness is mandatory.
So is measuring it.
The framework is organised in standards and guidelines.
| Topic | What CSCRF says | Reference |
|---|---|---|
| Employee awareness | Mandatory programmes build awareness of cybersecurity, cyber resilience and system hygiene among employees, run periodically and updated for new threats. | PR.AT Standard 1 |
| Board members | A dedicated programme on cybersecurity, cyber resilience and system hygiene for Board members. | PR.AT Standard 4 |
| Phishing and outsourced staff | Staff are made aware of social engineering and phishing, and training extends to outsourced staff and third-party providers. | PR.AT.S1 and S2 guidelines |
| Measuring awareness | Assess employee awareness periodically, for example through phishing test success rate. | GV.RM guideline (e), all REs except small-size and self-certification |
| Incidents | Report to SEBI and CERT-In within 6 hours, and on SEBI’s incident portal within 24 hours. | RS.CO, Annexure-O |
When a click becomes an incident
A clicked phishing email
is a reportable incident.
CSCRF’s incident table rates phishing emails that employees did not recognise and clicked as a Medium incident, and impersonation of SEBI officials by email as High. Since 24 August 2026, reports follow the FIRE format on SEBI’s portal.
SEBI Enforcement Cell <notice@sebi-gov-in.example>
Show-cause notice: respond within 24 hours
A complaint has been registered against your firm. Download the notice and submit your reply today to avoid penalty proceedings.
Download notice- Not an @sebi.gov.in address
- 24-hour deadline and penalty threat
- Attachment from an unknown sender
Expectation to record
Training and awareness,
on the record.
Annual training for every employee.
LMS completions, assessments and certificates per person.
A dedicated Board programme.
Completion records for Board and leadership sessions.
Awareness assessed periodically.
Simulation results by channel, team and campaign, over time.
Who flags suspicious messages.
Phishing Reporter submissions with automated verdicts.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities20 August 2024 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 · in force
- Technical Clarifications to CSCRF28 August 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119
- Extension of the CSCRF deadline to 31 August 202530 June 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96
- Clarifications to CSCRF (categories and thresholds)30 April 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60
- Alignment of SEBI’s Cyber Incident Reporting Portal with FIRE format24 August 2026 · in force
- Caution to the public regarding impersonation of SEBI5 September 2025 · press release
- Validated UPI handles and SEBI Check go live1 October 2025 · press release
Questions buyers ask
Frequently asked questions.
Does SEBI CSCRF require phishing simulation?
The framework does not use the words “phishing simulation”. It asks regulated entities, other than small-size and self-certification ones, to assess employee awareness periodically, for example through phishing test success rate. Simulations produce exactly that measure.
What are the CSCRF deadlines?
SEBI extended them several times. The last extension set 31 August 2025 for all remaining regulated entities, so every category is now due.
How quickly must cyber incidents be reported?
Within 6 hours to SEBI and CERT-In, and on SEBI’s Cyber Incident Reporting Portal within 24 hours. Stockbrokers and depository participants also report to exchanges and depositories within 6 hours.
Does KeenSec make us compliant with SEBI CSCRF?
No tool makes you compliant on its own. KeenSec helps you run the awareness side of your programme and produce evidence; your auditor decides whether you meet the framework.
Let’s connect the dots
Measure awareness
the way SEBI asks.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo