Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI - 31st December 2024 - Securities and Exchange Board of India - Gazette Notification PDF
Executive Summary:
SEBI issued this circular to clarify its Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities (REs) following queries received. While the CSCRF was initially effective from January 1, 2025, regulatory forbearance is provided until March 31, 2025, for compliance requirements. Compliance deadlines have been extended for KYC Registration Agencies (KRAs) and Depository Participants (DPs) to April 1, 2025.
Key Points / Main Content:
Cybersecurity and Cyber Resilience Framework (CSCRF):
Issued by SEBI to ensure robust cybersecurity measures and data protection for regulated entities.
Aims to equip REs with adequate cyber resilience measures to withstand, respond to, and recover from cyber threats.
Regulatory Forbearance:
Provided until March 31, 2025, for compliance requirements initially effective from January 1, 2025.
No regulatory action will be taken for noncompliance during this period if REs demonstrate meaningful progress in implementing CSCRF.
REs will be given an opportunity to demonstrate progress before any regulatory action is considered.
Extension of Compliance Dates:
KYC Registration Agencies (KRAs): Compliance timeline extended to April 1, 2025.
Depository Participants (DPs): Compliance timeline extended to April 1, 2025.
Data Security Standard:
Guidelines and provisions regarding Data Localisation (Data Security standard PR.DS.S2) are kept in abeyance until further notification, pending further consultations.
Effective Date:
The provisions of this circular are effective immediately.
Impact Analysis:
Alternative Investment Funds (AIFs), Bankers to an Issue (BTI) and Self Certified Syndicate Banks (SCSBs), Clearing Corporations, Collective Investment Schemes (CIS), Credit Rating Agencies (CRAs), Custodians, Debenture Trustees (DTs), Depositories, Designated Depository Participants (DDPs), Depository Participants, Investment Advisors (IAs) Research Analysts (RAs), KYC Registration Agencies (KRAs), Merchant Bankers (MBs), Mutual Funds (MFs) Asset Management Companies (AMCs), Portfolio Managers, Registrar to an Issue and Share Transfer Agents (RTAs), Stock Brokers through Exchanges, Stock Exchanges, Venture Capital Funds (VCFs):
Impact: Need to understand the clarifications regarding the Cybersecurity and Cyber Resilience Framework (CSCRF).
Action Required: Ensure compliance with the CSCRF, considering the extended timelines for KRAs and DPs and the regulatory forbearance period. Monitor for further notifications regarding Data Localisation guidelines.
Key Entities Referenced
Securities and Exchange Board of India SEBI: The regulatory body that issued the circular concerning cybersecurity and cyber resilience.
Cybersecurity and Cyber Resilience Framework CSCRF: The framework issued by SEBI for regulated entities to maintain robust cybersecurity posture.
SEBI Regulated Entities REs: Entities regulated by SEBI that are subject to the Cybersecurity and Cyber Resilience Framework CSCRF.
KYC Registration Agencies KRAs: Agencies involved in KYC registration, for whom the CSCRF compliance timeline has been extended.
Depository Participants DPs: Participants in the depository system, for whom the CSCRF compliance timeline has been extended.
Securities and Exchange of India Act, 1992: The act under which the circular is issued to protect investors and regulate the securities market.
Data Localisation: A provision regarding data security standards within the CSCRF, which has been kept in abeyance for further consultation.
Alternative Investment Funds AIFs: One of the entities to whom the circular is addressed.
परिपत्र / CIRCULAR
SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/184 December 31, 2024
प्रति To,
सभी आनुकल्पिक तनवेश तनतिय ाँ (एआईफ) All Alternative Investment Funds (AIFs)
सभी तनर्गमन बैंकि औि स्व-प्रम तिि All Bankers to an Issue (BTI) and Self-
तसिंडीके ट बैंक
Certified Syndicate Banks (SCSBs)
सभी सम शोिन तनर्म (क्लीयरििंर्
All Clearing Corporations
क िपोिेशन)
All Collective Investment Schemes (CIS)
सभी स मूतिक तनवेश स्कीमें
All Credit Rating Agencies (CRAs)
सभी क्रे तडट िेतटिंर् एजेंतसय ाँ
सभी अतभिक्षक (कस्टोतडयन) All Custodians
सभी तडबेंचि न्य सी (टरस्टी) All Debenture Trustees (DTs)
सभी तनक्षेप र् ि (तडपॉतिटिी) All Depositories
सभी अतभतिि तनक्षेप र् ि सिभ र्ी All Designated Depository Participants
(डीडीपी)
(DDPs)
सभी तनक्षेप र् ि सिभ र्ी (तडपॉतिटिी All Depository Participants through
प तटगतसपेंट) [तनक्षेप र् िो िं (तडपॉतिटिी) के Depositories
जरिए]
सभी तनवेश सल िक ि / अनुसिंि न All Investment Advisors (IAs) / Research
तवश्लेषक Analysts (RAs)
सभी के व ईसी ितजस्टरीकिि एजेंतसय ाँ All KYC Registration Agencies (KRAs)
सभी मचेंट बैंकि All Merchant Bankers (MBs)
All Mutual Funds (MFs)/ Asset
सभी म्यूचुअल फिं ड / असेट मैनेजमेंट
किं पतनय ाँ Management Companies (AMCs)
All Portfolio Managers
सभी पोटगफोतलयो प्रबिंिक
All Registrar to an Issue and Share
सभी तनर्गम ितजस्टर ि औि शेयि अिंििि
Transfer Agents (RTAs)
अतभकि ग (आिटीए)
All Stock Brokers through Exchanges
सभी स्टॉक दल ल (ब्रोकि) [एक्सचेंजो िं के
जरिए]
All Stock Exchanges
सभी स्टॉक एक्सचेंज
All Venture Capital Funds (VCFs)
सभी जोल्पिम पूाँजी तनतिय ाँ
Page 1 of 3महोदय / महोदया, Dear Sir / Madam,
तवषय: सेबी से तवतनयतमि (िेग्यूलेटेड) Subject: Clarifications to
Cybersecurity and Cyber
एिंतटतटयो िं के तलए स इबि
Resilience Framework
सुिक्ष औि स इबि िमलो िं से
(CSCRF) for SEBI
तनपटने की क्षमि के ढ ाँचे
Regulated Entities (REs)
(सीएससीआिएफ) के सिंबिंि
में स्पष्टीकिि
1. Recognising the need for robust cybersecurity measures and protection of data
and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued
‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated
Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113
dated August 20, 2024. This framework is a necessary evolution to the changing
threat landscape and rapid technological advancements and designed to ensure
that SEBI REs maintain robust cybersecurity posture, remain equipped with
adequate cyber resiliency measures and can withstand, respond to, and recover
from cyber threats effectively.
2. Upon receipt of various queries from REs seeking clarifications on the
aforementioned circular, it has been decided to clarify as under:
2.1. Regulatory forbearance:
With regard to the compliance requirements, which are effective from January
01, 2025 under the CSCRF, regulatory forbearance is provided till March 31,
2025. For any non-compliance during this period that comes to the notice of
the regulator, no regulatory action shall be taken provided the REs are able to
demonstrate meaningful steps taken / progress made in implementation of
CSCRF. An opportunity shall be given to the REs to demonstrate the same
before any regulatory action is considered by SEBI.
Page 2 of 32.2. Extension of compliance dates for Regulated Entities (REs):
While the circular is effective from January 01, 2025, the date of compliance of
CSCRF for following REs has been extended based on the feedback received
on the rationalisation of categorisation of certain REs:
a. KYC Registration Agencies (KRAs): Compliance timeline is extended from
January 01, 2025 to April 01, 2025.
b. Depository Participants (DPs): Compliance timeline is extended from
January 01, 2025 to April 01, 2025.
2.3. Data Security Standard with regard to Data Localisation:
Based on the feedback received on the provisions of Data Localisation, a need
is felt for further consultations. Accordingly, the guidelines and provisions with
regard to Data Localisation [Data Security standard (PR.DS.S2)] has been
kept in abeyance until further notification.
3. The provisions of this Circular shall come into force with immediate effect.
4. This circular is being issued in exercise of powers conferred under Section 11 (1)
of the Securities and Exchange of India Act, 1992, to protect the interests of
investors in securities and to promote the development of, and to regulate the
securities market.
5. This circular is issued with the approval of Competent Authority.
6. This circular is available on SEBI website at www.sebi.gov.in under the category
“Legal” and drop “Circulars”.
भवदीय Yours faithfully,
श्वेि बनजी Shweta Banerjee
मि प्रबिंिक General Manager
दूिभ ष्/ Phone: 022-26449509
ईमेल / Email: shwetas@sebi.gov.in
Page 3 of 3