SEBI CSCRF · India

SEBI asks you to measure
awareness, not just deliver it.

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF, 20 August 2024) makes employee awareness programmes mandatory, requires a dedicated programme for Board members, and asks most regulated entities to assess employee awareness periodically, for example through phishing test success rate.

Framework
CSCRF, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024, with clarifications in 2024 and 2025
Deadlines
Every category was due by 31 August 2025, the last extension
People
Mandatory awareness programmes, a Board programme, annual training and periodic phishing tests
Incidents
6 hours to SEBI and CERT-In, 24 hours on SEBI’s incident portal

What CSCRF says about people

Awareness is mandatory.
So is measuring it.

The framework is organised in standards and guidelines.

TopicWhat CSCRF saysReference
Employee awarenessMandatory programmes build awareness of cybersecurity, cyber resilience and system hygiene among employees, run periodically and updated for new threats.PR.AT Standard 1
Board membersA dedicated programme on cybersecurity, cyber resilience and system hygiene for Board members.PR.AT Standard 4
Phishing and outsourced staffStaff are made aware of social engineering and phishing, and training extends to outsourced staff and third-party providers.PR.AT.S1 and S2 guidelines
Measuring awarenessAssess employee awareness periodically, for example through phishing test success rate.GV.RM guideline (e), all REs except small-size and self-certification
IncidentsReport to SEBI and CERT-In within 6 hours, and on SEBI’s incident portal within 24 hours.RS.CO, Annexure-O

When a click becomes an incident

A clicked phishing email
is a reportable incident.

CSCRF’s incident table rates phishing emails that employees did not recognise and clicked as a Medium incident, and impersonation of SEBI officials by email as High. Since 24 August 2026, reports follow the FIRE format on SEBI’s portal.

Expectation to record

Training and awareness,
on the record.

TRAINING

Annual training for every employee.

LMS completions, assessments and certificates per person.

BOARD

A dedicated Board programme.

Completion records for Board and leadership sessions.

PHISHING TESTS

Awareness assessed periodically.

Simulation results by channel, team and campaign, over time.

REPORT LOGS

Who flags suspicious messages.

Phishing Reporter submissions with automated verdicts.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities20 August 2024 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 · in force
  2. Technical Clarifications to CSCRF28 August 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119
  3. Extension of the CSCRF deadline to 31 August 202530 June 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/96
  4. Clarifications to CSCRF (categories and thresholds)30 April 2025 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60
  5. Alignment of SEBI’s Cyber Incident Reporting Portal with FIRE format24 August 2026 · in force
  6. Caution to the public regarding impersonation of SEBI5 September 2025 · press release
  7. Validated UPI handles and SEBI Check go live1 October 2025 · press release

Questions buyers ask

Frequently asked questions.

Does SEBI CSCRF require phishing simulation?

The framework does not use the words “phishing simulation”. It asks regulated entities, other than small-size and self-certification ones, to assess employee awareness periodically, for example through phishing test success rate. Simulations produce exactly that measure.

What are the CSCRF deadlines?

SEBI extended them several times. The last extension set 31 August 2025 for all remaining regulated entities, so every category is now due.

How quickly must cyber incidents be reported?

Within 6 hours to SEBI and CERT-In, and on SEBI’s Cyber Incident Reporting Portal within 24 hours. Stockbrokers and depository participants also report to exchanges and depositories within 6 hours.

Does KeenSec make us compliant with SEBI CSCRF?

No tool makes you compliant on its own. KeenSec helps you run the awareness side of your programme and produce evidence; your auditor decides whether you meet the framework.

Let’s connect the dots

Measure awareness
the way SEBI asks.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo