Home India Securities and Exchange Board of India Extension towards Adoption and Implementation of Cybersecuri...
Date: 2025-06-30 Category: Not Applicable State: Union Government Country: India

Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)

Issued by Securities and Exchange Board of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Summary:** This circular, reference number SEBI/HO/ITD1/ITD/CSC/EXT/P/CIR/2025/96, issued by the Securities and Exchange Board of India (SEBI) on June 30, 2025, announces an extension to the compliance timelines for the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs). This extension, granted in response to multiple requests from REs, pushes the compliance deadline by two months, from the original date specified in circular SEBI/HO/ITD1/ITD/CSC/EXT/P/CIR/2024/113 dated August 20, 2024, to August 31, 2025. The extension applies to all REs with the exception of Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs). Stock Exchanges and Depositories are directed to inform their members and participants about this circular and disseminate it on their websites. The circular takes effect immediately and is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992. The full circular is available on the SEBI website (www.sebi.gov.in) under the "Legal" and "Circulars" categories. For further information, contact Mridusmita Goswami, General Manager, at 022-26449504 or mridusmitag@sebi.gov.in.

Key Entities Referenced

Securities and Exchange Board of India SEBI: The regulatory body issuing the circular related to cybersecurity and cyber resilience. Cybersecurity and Cyber Resilience Framework CSCRF: A framework issued by SEBI to enhance cybersecurity measures for regulated entities. SEBI Regulated Entities REs: Entities regulated by SEBI and subject to the CSCRF guidelines. Market Infrastructure Institutions MIIs: Entities that form the basic infrastructure of the securities market, such as stock exchanges and clearing corporations. KYC Registration Agencies KRAs: Agencies registered with SEBI that maintain KYC Know Your Client records of investors. Qualified Registrars to an Issue and Share Transfer Agents QRTAs: Registrars and share transfer agents that meet specific qualification criteria set by SEBI. Securities and Exchange of India Act, 1992: The legal framework under which SEBI operates and derives its powers. Association of Portfolio Managers in India APMI: Association of Portfolio Managers in India
Official Source Record View Original Source →
See Full Document Text
परिपत्र / CIRCULAR SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2025/96 June 30, 2025 To, All Alternative Investment Funds (AIFs) All Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs) All Clearing Corporations All Collective Investment Schemes (CIS) All Credit Rating Agencies (CRAs) All Custodians All Debenture Trustees (DTs) All Depositories All Designated Depository Participants (DDPs) All Depository Participants through Depositories All Investment Advisors (IAs) / Research Analysts (RAs) All KYC Registration Agencies (KRAs) All Merchant Bankers (MBs) All Mutual Funds (MFs)/ Asset Management Companies (AMCs) All Portfolio Managers Association of Portfolio Managers in India (APMI) All Registrar to an Issue and Share Transfer Agents (RTAs) All Stock Brokers through Exchanges All Stock Exchanges All Venture Capital Funds (VCFs) Page 1 of 2Dear Sir / Madam, Subject: Extension towards Adoption and Implementation of Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs) 1. Recognising the need for robust cybersecurity measures and protection of data and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued ‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. 2. SEBI has received multiple requests for CSCRF compliance timelines extension to ensure ease of compliance for them. Therefore, it has been decided to extend the compliance timelines by two (2) months, i.e., till August 31, 2025 to all REs, except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs). 3. Stock Exchanges/ Depositories are directed to: 3.1. Bring the provisions of this circulars to the notice of their members/ participants and also disseminate the same on their websites. 4. The provisions of this Circular shall come into force with immediate effect. 5. This circular is being issued in exercise of powers conferred under Section 11 (1) of the Securities and Exchange of India Act, 1992, to protect the interests of investors in securities and to promote the development of, and to regulate the securities market. 6. This circular is issued with the approval of Competent Authority. 7. This circular is available on SEBI website at www.sebi.gov.in under the category “Legal” and drop “Circulars”. भवदीय Yours faithfully, मृदुस्मिता गोस्वामी Mridusmita Goswami महाप्रबंधक General Manager दूिभाष / Phone: 022-26449504 ईमेल / Email: mridusmitag@sebi.gov.in Page 2 of 2

Continue your research