SEBI Cybersecurity Framework: What Broking and Wealth Apps Need
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for brokers, advisers and other regulated entities: categories, controls, testing, incident reporting and what it means for app development.

In August 2024 SEBI replaced its separate cybersecurity circulars with one framework for every regulated entity: the Cybersecurity and Cyber Resilience Framework, or CSCRF. If you are building a trading app, a wealth platform or a back office for a broker, adviser, asset manager or depository participant, this framework sets your security requirements.
Who it covers and how entities are graded
CSCRF applies to SEBI-regulated entities including stock brokers, depository participants, mutual funds and asset managers, portfolio managers, investment advisers, research analysts, registrars and market infrastructure institutions. Obligations scale with size. Entities are placed in categories by criteria such as client numbers, trading volume or assets under management, and SEBI has revised these thresholds through later clarifications, so confirm your category against the current circular.
The structure of the framework
CSCRF is organised around five cyber resilience goals, Anticipate, Withstand, Contain, Recover and Evolve, mapped to six functions: Governance, Identify, Protect, Detect, Respond and Recover. Each function has standards and guidelines, some mandatory for all and some only for larger categories.
Controls that affect how software is built
Several requirements land directly on product and engineering teams.
Auditors will ask for the component list of your app. Generate it in the build, not in a spreadsheet.
Incidents, recovery and audits
Entities need an incident response plan, classification of incidents and reporting to SEBI within short timelines, in addition to CERT-In's reporting requirement. Recovery objectives must be defined and tested through drills. Compliance is checked through periodic cyber audits by CERT-In empanelled auditors, with reports submitted in the formats and timelines set for each category.
Data and cloud
The framework expects regulated data to be classified and protected, and addresses where it is stored. SEBI's cloud framework for regulated entities also applies: the entity stays accountable, cloud providers should be empanelled by MeitY with data centres in India, and contracts must allow audit and exit. Treat data residency in India as the default for investor data.
For app teams: a working checklist
Beyond CSCRF itself, trading and investment apps should plan for two-factor login, session controls, transaction alerts and accessibility requirements SEBI has set for regulated entities' digital platforms.
- SEBI circular: Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, 20 August 2024
- SEBI: circulars
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





