Compliance & Regulation

SEBI Cybersecurity Framework: What Broking and Wealth Apps Need

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for brokers, advisers and other regulated entities: categories, controls, testing, incident reporting and what it means for app development.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Monitoring dashboards on multiple screens

In August 2024 SEBI replaced its separate cybersecurity circulars with one framework for every regulated entity: the Cybersecurity and Cyber Resilience Framework, or CSCRF. If you are building a trading app, a wealth platform or a back office for a broker, adviser, asset manager or depository participant, this framework sets your security requirements.

01

Who it covers and how entities are graded

CSCRF applies to SEBI-regulated entities including stock brokers, depository participants, mutual funds and asset managers, portfolio managers, investment advisers, research analysts, registrars and market infrastructure institutions. Obligations scale with size. Entities are placed in categories by criteria such as client numbers, trading volume or assets under management, and SEBI has revised these thresholds through later clarifications, so confirm your category against the current circular.

Market infrastructure institutionsExchanges, clearing corporations, depositories: the strictest tier
Qualified REsLarge entities such as qualified stock brokers
Mid-size REsFuller controls with some relaxations
Small-size REsA reduced set of controls
Self-certification REsThe smallest entities, with basic requirements
02

The structure of the framework

CSCRF is organised around five cyber resilience goals, Anticipate, Withstand, Contain, Recover and Evolve, mapped to six functions: Governance, Identify, Protect, Detect, Respond and Recover. Each function has standards and guidelines, some mandatory for all and some only for larger categories.

GovernanceIdentifyProtectDetectRespondRecover
03

Controls that affect how software is built

Several requirements land directly on product and engineering teams.

Auditors will ask for the component list of your app. Generate it in the build, not in a spreadsheet.

Asset inventory and classificationEvery system, application and data store identified, with critical systems marked
Access controlLeast privilege, multi-factor authentication for critical systems and privileged access management
EncryptionData protected in transit and at rest
Secure developmentSecurity in the software development life cycle, code review and testing before release
Software bill of materialsA list of components in critical applications, so vulnerable libraries can be found quickly
API securityAuthentication, rate limiting and monitoring of APIs exposed to partners and clients
Logging and monitoringSecurity operations centre coverage, own or through a market SOC for smaller entities
Vulnerability assessment and penetration testingPeriodic testing by qualified auditors with time-bound closure of findings
04

Incidents, recovery and audits

Entities need an incident response plan, classification of incidents and reporting to SEBI within short timelines, in addition to CERT-In's reporting requirement. Recovery objectives must be defined and tested through drills. Compliance is checked through periodic cyber audits by CERT-In empanelled auditors, with reports submitted in the formats and timelines set for each category.

05

Data and cloud

The framework expects regulated data to be classified and protected, and addresses where it is stored. SEBI's cloud framework for regulated entities also applies: the entity stays accountable, cloud providers should be empanelled by MeitY with data centres in India, and contracts must allow audit and exit. Treat data residency in India as the default for investor data.

06

For app teams: a working checklist

Beyond CSCRF itself, trading and investment apps should plan for two-factor login, session controls, transaction alerts and accessibility requirements SEBI has set for regulated entities' digital platforms.

Two-factor authenticationDevice bindingSession timeoutCertificate pinningRoot and tamper detectionSBOM in CISecrets managementPen test before releaseAudit trail for ordersDR drill evidence
5 goals
Anticipate, Withstand, Contain, Recover, Evolve
By category
Controls scale with entity size
CERT-In
Empanelled auditors for cyber audits
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact