**Summary:**
This circular, reference number SEBI/HO/ITD1/ITD/CSC/EXT/P/CIR/2025/96, issued by the Securities and Exchange Board of India (SEBI) on June 30, 2025, announces an extension to the compliance timelines for the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs). This extension, granted in response to multiple requests from REs, pushes the compliance deadline by two months, from the original date specified in circular SEBI/HO/ITD1/ITD/CSC/EXT/P/CIR/2024/113 dated August 20, 2024, to August 31, 2025. The extension applies to all REs with the exception of Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs). Stock Exchanges and Depositories are directed to inform their members and participants about this circular and disseminate it on their websites. The circular takes effect immediately and is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992. The full circular is available on the SEBI website (www.sebi.gov.in) under the "Legal" and "Circulars" categories. For further information, contact Mridusmita Goswami, General Manager, at 022-26449504 or mridusmitag@sebi.gov.in.
Key Entities Referenced
Securities and Exchange Board of India SEBI: The regulatory body issuing the circular related to cybersecurity and cyber resilience.
Cybersecurity and Cyber Resilience Framework CSCRF: A framework issued by SEBI to enhance cybersecurity measures for regulated entities.
SEBI Regulated Entities REs: Entities regulated by SEBI and subject to the CSCRF guidelines.
Market Infrastructure Institutions MIIs: Entities that form the basic infrastructure of the securities market, such as stock exchanges and clearing corporations.
KYC Registration Agencies KRAs: Agencies registered with SEBI that maintain KYC Know Your Client records of investors.
Qualified Registrars to an Issue and Share Transfer Agents QRTAs: Registrars and share transfer agents that meet specific qualification criteria set by SEBI.
Securities and Exchange of India Act, 1992: The legal framework under which SEBI operates and derives its powers.
Association of Portfolio Managers in India APMI: Association of Portfolio Managers in India
परिपत्र / CIRCULAR
SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2025/96 June 30, 2025
To,
All Alternative Investment Funds (AIFs)
All Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs)
All Clearing Corporations
All Collective Investment Schemes (CIS)
All Credit Rating Agencies (CRAs)
All Custodians
All Debenture Trustees (DTs)
All Depositories
All Designated Depository Participants (DDPs)
All Depository Participants through Depositories
All Investment Advisors (IAs) / Research Analysts (RAs)
All KYC Registration Agencies (KRAs)
All Merchant Bankers (MBs)
All Mutual Funds (MFs)/ Asset Management Companies (AMCs)
All Portfolio Managers
Association of Portfolio Managers in India (APMI)
All Registrar to an Issue and Share Transfer Agents (RTAs)
All Stock Brokers through Exchanges
All Stock Exchanges
All Venture Capital Funds (VCFs)
Page 1 of 2Dear Sir / Madam,
Subject: Extension towards Adoption and Implementation of Cybersecurity
and Cyber Resilience Framework (CSCRF) for SEBI Regulated
Entities (REs)
1. Recognising the need for robust cybersecurity measures and protection of data
and IT infrastructure, Securities and Exchange Board of India (SEBI) has issued
‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated
Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113
dated August 20, 2024.
2. SEBI has received multiple requests for CSCRF compliance timelines extension to
ensure ease of compliance for them. Therefore, it has been decided to extend the
compliance timelines by two (2) months, i.e., till August 31, 2025 to all REs, except
Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and
Qualified Registrars to an Issue and Share Transfer Agents (QRTAs).
3. Stock Exchanges/ Depositories are directed to:
3.1. Bring the provisions of this circulars to the notice of their members/ participants
and also disseminate the same on their websites.
4. The provisions of this Circular shall come into force with immediate effect.
5. This circular is being issued in exercise of powers conferred under Section 11 (1)
of the Securities and Exchange of India Act, 1992, to protect the interests of
investors in securities and to promote the development of, and to regulate the
securities market.
6. This circular is issued with the approval of Competent Authority.
7. This circular is available on SEBI website at www.sebi.gov.in under the category
“Legal” and drop “Circulars”.
भवदीय Yours faithfully,
मृदुस्मिता गोस्वामी Mridusmita Goswami
महाप्रबंधक General Manager
दूिभाष / Phone: 022-26449504
ईमेल / Email: mridusmitag@sebi.gov.in
Page 2 of 2