Skip to content
Home India Securities and Exchange Board of India Notifications Clarifications to Cybersecurity and Cyber Resilien... (Official PDF)
Date: 31st December 2024 Jurisdiction: India, Central Government

Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI - 31st December 2024 - Securities and Exchange Board of India - Gazette Notification PDF

Issued by Securities and Exchange Board of India

Read or download the official PDF of this gazette notification issued by the Securities and Exchange Board of India on 31st December 2024.

Executive Summary & Key Takeaways

Executive Summary: SEBI issued this circular to clarify its Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities (REs) following queries received. While the CSCRF was initially effective from January 1, 2025, regulatory forbearance is provided until March 31, 2025, for compliance requirements. Compliance deadlines have been extended for KYC Registration Agencies (KRAs) and Depository Participants (DPs) to April 1, 2025.

Key Points / Main Content:

  • Cybersecurity and Cyber Resilience Framework (CSCRF):

    • Issued by SEBI to ensure robust cybersecurity measures and data protection for regulated entities.
    • Aims to equip REs with adequate cyber resilience measures to withstand, respond to, and recover from cyber threats.
  • Regulatory Forbearance:

    • Provided until March 31, 2025, for compliance requirements initially effective from January 1, 2025.
    • No regulatory action will be taken for noncompliance during this period if REs demonstrate meaningful progress in implementing CSCRF.
    • REs will be given an opportunity to demonstrate progress before any regulatory action is considered.
  • Extension of Compliance Dates:

    • KYC Registration Agencies (KRAs): Compliance timeline extended to April 1, 2025.
    • Depository Participants (DPs): Compliance timeline extended to April 1, 2025.
  • Data Security Standard:

    • Guidelines and provisions regarding Data Localisation (Data Security standard PR.DS.S2) are kept in abeyance until further notification, pending further consultations.
  • Effective Date:

    • The provisions of this circular are effective immediately.

Impact Analysis:

  • Alternative Investment Funds (AIFs), Bankers to an Issue (BTI) and Self Certified Syndicate Banks (SCSBs), Clearing Corporations, Collective Investment Schemes (CIS), Credit Rating Agencies (CRAs), Custodians, Debenture Trustees (DTs), Depositories, Designated Depository Participants (DDPs), Depository Participants, Investment Advisors (IAs) Research Analysts (RAs), KYC Registration Agencies (KRAs), Merchant Bankers (MBs), Mutual Funds (MFs) Asset Management Companies (AMCs), Portfolio Managers, Registrar to an Issue and Share Transfer Agents (RTAs), Stock Brokers through Exchanges, Stock Exchanges, Venture Capital Funds (VCFs):

    • Impact: Need to understand the clarifications regarding the Cybersecurity and Cyber Resilience Framework (CSCRF).
    • Action Required: Ensure compliance with the CSCRF, considering the extended timelines for KRAs and DPs and the regulatory forbearance period. Monitor for further notifications regarding Data Localisation guidelines.

Key Entities Referenced

Securities and Exchange Board of India SEBI: The regulatory body that issued the circular concerning cybersecurity and cyber resilience. Cybersecurity and Cyber Resilience Framework CSCRF: The framework issued by SEBI for regulated entities to maintain robust cybersecurity posture. SEBI Regulated Entities REs: Entities regulated by SEBI that are subject to the Cybersecurity and Cyber Resilience Framework CSCRF. KYC Registration Agencies KRAs: Agencies involved in KYC registration, for whom the CSCRF compliance timeline has been extended. Depository Participants DPs: Participants in the depository system, for whom the CSCRF compliance timeline has been extended. Securities and Exchange of India Act, 1992: The act under which the circular is issued to protect investors and regulate the securities market. Data Localisation: A provision regarding data security standards within the CSCRF, which has been kept in abeyance for further consultation. Alternative Investment Funds AIFs: One of the entities to whom the circular is addressed.
Official Gazette PDF Record Download Official PDF (Clarifications to Cybersecurity and Cyber...) →

Official Gazette Notification PDF Viewer

See Full Document Text & PDF Transcript
परिपत्र / CIRCULAR SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/184 December 31, 2024 प्रति To, सभी आनुकल्पिक तनवेश तनतिय ाँ (एआईफ) All Alternative Investment Funds (AIFs) सभी तनर्गमन बैंकि औि स्व-प्रम तिि All Bankers to an Issue (BTI) and Self- तसिंडीके ट बैंक Certified Syndicate Banks (SCSBs) सभी सम शोिन तनर्म (क्लीयरििंर् All Clearing Corporations क िपोिेशन) All Collective Investment Schemes (CIS) सभी स मूतिक तनवेश स्कीमें All Credit Rating Agencies (CRAs) सभी क्रे तडट िेतटिंर् एजेंतसय ाँ सभी अतभिक्षक (कस्टोतडयन) All Custodians सभी तडबेंचि न्य सी (टरस्टी) All Debenture Trustees (DTs) सभी तनक्षेप र् ि (तडपॉतिटिी) All Depositories सभी अतभतिि तनक्षेप र् ि सिभ र्ी All Designated Depository Participants (डीडीपी) (DDPs) सभी तनक्षेप र् ि सिभ र्ी (तडपॉतिटिी All Depository Participants through प तटगतसपेंट) [तनक्षेप र् िो िं (तडपॉतिटिी) के Depositories जरिए] सभी तनवेश सल िक ि / अनुसिंि न All Investment Advisors (IAs) / Research तवश्लेषक Analysts (RAs) सभी के व ईसी ितजस्टरीकिि एजेंतसय ाँ All KYC Registration Agencies (KRAs) सभी मचेंट बैंकि All Merchant Bankers (MBs) All Mutual Funds (MFs)/ Asset सभी म्यूचुअल फिं ड / असेट मैनेजमेंट किं पतनय ाँ Management Companies (AMCs) All Portfolio Managers सभी पोटगफोतलयो प्रबिंिक All Registrar to an Issue and Share सभी तनर्गम ितजस्टर ि औि शेयि अिंििि Transfer Agents (RTAs) अतभकि ग (आिटीए) All Stock Brokers through Exchanges सभी स्टॉक दल ल (ब्रोकि) [एक्सचेंजो िं के जरिए] All Stock Exchanges सभी स्टॉक एक्सचेंज All Venture Capital Funds (VCFs) सभी जोल्पिम पूाँजी तनतिय ाँ Page 1 of 3महोदय / महोदया, Dear Sir / Madam, तवषय: सेबी से तवतनयतमि (िेग्यूलेटेड) Subject: Clarifications to Cybersecurity and Cyber एिंतटतटयो िं के तलए स इबि Resilience Framework सुिक्ष औि स इबि िमलो िं से (CSCRF) for SEBI तनपटने की क्षमि के ढ ाँचे Regulated Entities (REs) (सीएससीआिएफ) के सिंबिंि में स्पष्टीकिि 1. Recognising the need for robust cybersecurity measures and protection of data and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued ‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. This framework is a necessary evolution to the changing threat landscape and rapid technological advancements and designed to ensure that SEBI REs maintain robust cybersecurity posture, remain equipped with adequate cyber resiliency measures and can withstand, respond to, and recover from cyber threats effectively. 2. Upon receipt of various queries from REs seeking clarifications on the aforementioned circular, it has been decided to clarify as under: 2.1. Regulatory forbearance: With regard to the compliance requirements, which are effective from January 01, 2025 under the CSCRF, regulatory forbearance is provided till March 31, 2025. For any non-compliance during this period that comes to the notice of the regulator, no regulatory action shall be taken provided the REs are able to demonstrate meaningful steps taken / progress made in implementation of CSCRF. An opportunity shall be given to the REs to demonstrate the same before any regulatory action is considered by SEBI. Page 2 of 32.2. Extension of compliance dates for Regulated Entities (REs): While the circular is effective from January 01, 2025, the date of compliance of CSCRF for following REs has been extended based on the feedback received on the rationalisation of categorisation of certain REs: a. KYC Registration Agencies (KRAs): Compliance timeline is extended from January 01, 2025 to April 01, 2025. b. Depository Participants (DPs): Compliance timeline is extended from January 01, 2025 to April 01, 2025. 2.3. Data Security Standard with regard to Data Localisation: Based on the feedback received on the provisions of Data Localisation, a need is felt for further consultations. Accordingly, the guidelines and provisions with regard to Data Localisation [Data Security standard (PR.DS.S2)] has been kept in abeyance until further notification. 3. The provisions of this Circular shall come into force with immediate effect. 4. This circular is being issued in exercise of powers conferred under Section 11 (1) of the Securities and Exchange of India Act, 1992, to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. 5. This circular is issued with the approval of Competent Authority. 6. This circular is available on SEBI website at www.sebi.gov.in under the category “Legal” and drop “Circulars”. भवदीय Yours faithfully, श्‍वेि बनजी Shweta Banerjee मि प्रबिंिक General Manager दूिभ ष्‍/ Phone: 022-26449509 ईमेल / Email: shwetas@sebi.gov.in Page 3 of 3

Continue your research