Skip to main content
Compliance · SEBI CSCRF

Four obligations under CSCRF, four separate cadences

VAPT, cyber audit, red teaming and threat hunting sit in three different tables of the master circular, with different applicability and different periodicity in each. Collapsing them into one annual exercise is the error this page is built to prevent. Every row below names the table it came from and the date that table was read.

The four, separated

Each cadence, and the table it is written in

Three tables, and the applicability column is not the same in any two of them. The activity you are being asked about decides which one you read.

ActivityApplicability, as the table writes itPeriodicity
VAPT Table 18 carries two rows. The first is REs which have been identified as “Protected systems” and/ or CII by NCIIPC. The second is the rest of the REs. Both rows are written against that NCIIPC designation, and the designation is what moves a firm between them. For the first row, at least twice: one VAPT activity completed — including report submission, closure and revalidation — in each half of the financial year, April to September and October to March. For the second row, at least once, with the activity commencing in the first quarter of the financial year.
Table 18, section 4.3.2, pages 48–49 of SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, Version 1.0. Read 2026-09-14. Section 4.3.2 also provides that REs shall plan their VAPT activity at the beginning of the financial year, and that no audit cycle shall be left unaudited due to a change in category — in such cases the unaudited period is included in the current audit cycle.
Cyber audit Table 21 carries three entity rows against two periodicity cells. MIIs and Qualified REs occupy the first row. Mid-size REs and Small-size REs who are providing IBT or Algo trading facility occupy the second. The first periodicity cell is merged across both of those rows. The rest of the REs occupy the third. At least twice in a year for the two rows under the merged cell. At least once in a year for the third row.
Table 21, section 4.4.1, page 51. Read 2026-09-14. The merged cell is the part that is easy to misread: it spans rows 1 and 2 rather than row 1 alone. Section 4.4 adds that cyber audit shall cover 100% of critical systems and 25% of non-critical systems, chosen on a sample basis.
Red teaming MIIs and Qualified REs. Standard DE.DP.S4 prints the applicability as MIIs and Qualified REs (Mandatory). Half-yearly. Guideline 1 provides that REs shall conduct red teaming exercises as part of their cybersecurity framework on a half-yearly basis, through use of red and blue teams.
Table 15 item 12, section 4.1, page 47, and standard DE.DP.S4 at page 121. Read 2026-09-14. Table 15 closes with a note that during cyber audit, auditors shall also validate adherence to the periodicities it sets.
Threat hunting MIIs and Qualified REs. Standard DE.DP.S5 prints the applicability as MIIs and Qualified REs (Mandatory). Quarterly. Guideline 2 sets threat hunting, drawing on threat intelligence, IOCs and IOAs, on a quarterly basis. Of the four activities on this page, quarterly is the cadence attached to this one.
Table 15 item 13, section 4.1, page 47, and standard DE.DP.S5 at page 122. Read 2026-09-14. Guideline 1 puts the activity as proactively searching for hidden and undetected cyber threats in the RE’s network.

VAPT

Applicability, as the table writes it
Table 18 carries two rows. The first is REs which have been identified as “Protected systems” and/ or CII by NCIIPC. The second is the rest of the REs. Both rows are written against that NCIIPC designation, and the designation is what moves a firm between them.
Periodicity
For the first row, at least twice: one VAPT activity completed — including report submission, closure and revalidation — in each half of the financial year, April to September and October to March. For the second row, at least once, with the activity commencing in the first quarter of the financial year.

Table 18, section 4.3.2, pages 48–49 of SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, Version 1.0. Read 2026-09-14. Section 4.3.2 also provides that REs shall plan their VAPT activity at the beginning of the financial year, and that no audit cycle shall be left unaudited due to a change in category — in such cases the unaudited period is included in the current audit cycle.

Cyber audit

Applicability, as the table writes it
Table 21 carries three entity rows against two periodicity cells. MIIs and Qualified REs occupy the first row. Mid-size REs and Small-size REs who are providing IBT or Algo trading facility occupy the second. The first periodicity cell is merged across both of those rows. The rest of the REs occupy the third.
Periodicity
At least twice in a year for the two rows under the merged cell. At least once in a year for the third row.

Table 21, section 4.4.1, page 51. Read 2026-09-14. The merged cell is the part that is easy to misread: it spans rows 1 and 2 rather than row 1 alone. Section 4.4 adds that cyber audit shall cover 100% of critical systems and 25% of non-critical systems, chosen on a sample basis.

Red teaming

Applicability, as the table writes it
MIIs and Qualified REs. Standard DE.DP.S4 prints the applicability as MIIs and Qualified REs (Mandatory).
Periodicity
Half-yearly. Guideline 1 provides that REs shall conduct red teaming exercises as part of their cybersecurity framework on a half-yearly basis, through use of red and blue teams.

Table 15 item 12, section 4.1, page 47, and standard DE.DP.S4 at page 121. Read 2026-09-14. Table 15 closes with a note that during cyber audit, auditors shall also validate adherence to the periodicities it sets.

Threat hunting

Applicability, as the table writes it
MIIs and Qualified REs. Standard DE.DP.S5 prints the applicability as MIIs and Qualified REs (Mandatory).
Periodicity
Quarterly. Guideline 2 sets threat hunting, drawing on threat intelligence, IOCs and IOAs, on a quarterly basis. Of the four activities on this page, quarterly is the cadence attached to this one.

Table 15 item 13, section 4.1, page 47, and standard DE.DP.S5 at page 122. Read 2026-09-14. Guideline 1 puts the activity as proactively searching for hidden and undetected cyber threats in the RE’s network.

The two clocks

VAPT and cyber audit each run their own timetable

Section 4.3 and section 4.4 have a submission and closure table apiece — Table 19 and Table 22. They run to the same three intervals and the deliverable at the end is named differently in each.

01 Within one month of completion

Submission

VAPT · Table 19
The VAPT report is submitted after approval from the respective IT Committee for REs, within one month of completion of the VAPT activity.
Cyber audit · Table 22
The final cyber audit report is submitted after approval from the respective IT Committee for REs, within one month of completion of the cyber audit.
The order it happens in
Both tables put the IT Committee approval before the submission as a condition of it. A plan that treats the approval as something running alongside the one-month window has the sequence wrong.
02 Within three months of submission

Closure of observations

VAPT · Table 19
Within 3 months of submission of the VAPT report, on a graded approach based on the criticality of the observations.
Cyber audit · Table 22
Within 3 months of cyber audit report submission, on the same graded approach based on criticality.
What section 4.3.4 adds
Any vulnerabilities still open after 3 months of the VAPT activity are to be approved by the IT Committee for REs and closed before the next VAPT exercise starts. REs are also expected to maintain a risk register, reviewed by that committee.
03 Within five months of completion

The return visit

VAPT · Table 19
Revalidation of VAPT shall be completed within 5 months of completion of the VAPT.
Cyber audit · Table 22
The follow-on audit shall be completed within 5 months of completion of the cyber audit.
Why the wording carries weight
A revalidation and a follow-on audit are two named deliverables in two tables. They run to the same five months, and a plan that books one where the other is owed has produced the wrong artefact.

Sourcing

What was read, and when

The circulars behind every row above As of 2026-09-14
  • The master circular is SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, Version 1.0. Tables 15, 17, 18, 19, 21 and 22, sections 4.1 and 4.3 to 4.4, and standards DE.DP.S4 and DE.DP.S5 were read at source on 14 September 2026.
  • The clarifications circular is SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025. Part-A clauses 5.1 to 5.3 with Table 2, and Part-B clause 6.7, were read at source on 14 September 2026.
  • Table 21 was read twice by different means. Plain text extraction of page 51 is ambiguous about which rows the first periodicity cell covers, so the page was rendered to an image and read directly, and that reading was confirmed against a second, table-aware extraction.
  • VAPT scope is set in three places read together: Annexure-L, Annexure-A at page 136, and DE.CM.S5 guideline 2 at page 120. Read 8 September 2026, and corroborated on 14 September 2026 by Part-A Table 1 of the clarifications circular, which cites the same three places.

Deliberately excluded

  • The reporting authority for Investment Advisers and Research Analysts is not stated on this page. Table 17 of the master circular names a body for Investment Advisers and a later circular is recorded as having moved it; that circular was not opened in this pass, so the row is left to your own check of the trail.
  • Two cyber-related SEBI circulars dated 24 August 2026 were identified in SEBI’s own circular listing and were not opened here — one on aligning the Cyber Incident Reporting Portal with the FIRE format, and one on an IT Resilience Index for Market Infrastructure Institutions. Nothing on this page rests on either.
  • No determination of your CSCRF entity category is made here. Each row reproduces the applicability its own table prints, and which row your firm falls in is settled with your own advisers.

How the output maps

What an engagement produces against each obligation

Testing evidence answers three of the four directly. The fourth is named in the boundary block, because a mapping that stretched to cover it would be the same conflation the rows above pull apart.

VAPT · section 4.3

The testing the section is about

Annexure-L, read with Annexure-A and DE.CM.S5 guideline 2, names mobile applications, infrastructure, applications, APIs, operating systems, databases and cloud inside VAPT scope. Those are coverage classes an engagement is scoped across and tested in one run.

Cyber audit · section 4.4

The testing evidence the audit draws on

Cyber audit pertains to the audit conducted for verifying compliance with CSCRF, across 100% of critical systems and 25% of non-critical systems chosen on a sample basis. An engagement produces the tested-and-proved evidence for the systems inside its scope; the verification against CSCRF standards is the separate exercise section 4.4 describes.

Red teaming · DE.DP.S4

A team independent of the function being tested

Guideline 3 provides that a red team may consist of the RE’s employees and/ or outside experts, and requires the team to be independent of the function being tested. In the human-led model a senior Security Brigade auditor runs the exercise with B-52 underneath, outside your own reporting line. Guideline 4 places the results before the IT Committee for REs and the Governing board.

Per finding

Grading a closure runs on the evidence

Table 19 and Table 22 both close observations on a graded approach based on criticality. Each finding carries a CVSS v4.0 vector rather than a bare score, the CWE, and the request and response that proved it — so the grading your IT Committee signs off has an input it can inspect.

Closure

Closure is dated to the retest

A finding closes on the retest, not on a fix being reported — and that dated retest is what the three-month closure window and the five-month return visit are measured against.

Scope

Where VAPT scope is written, and what moves it

Section 4.3 places VAPT scope, periodicity and compliance in standard DE.CM.S5 and its guidelines, and the scope itself is set across three places read together — Annexure-L, Annexure-A at page 136 and DE.CM.S5 guideline 2 at page 120. Annexure-L names mobile applications, infrastructure, applications, APIs, operating systems, databases and cloud. For an RE regulated by more than one regulator, Part-A of the 28 August 2025 clarifications adds two principles that bear on that scope. Under the Principle of Exclusivity the scope of CSCRF is limited to the systems, applications, infrastructure and processes exclusively used for SEBI regulated activities, with shared infrastructure, network, technology stack and security solutions drawn into SEBI’s audit or inspection scope unless the primary regulator’s own audit or inspection scope already covers them. Under the Principle of Equivalence, CSCRF controls having an equivalence in another regulator’s framework are deemed compliant provided the primary regulator’s framework is adhered to — and Table 2 lists red teaming under DE.DP.S4 with its guidelines 1 to 4 as one of its representative examples. Clause 5.1 requires the RE to demonstrate exclusivity or equivalence for the applicable controls at submission, and reserves SEBI’s right to seek the submissions made to the other regulator. Read 2026-09-14.

Which model

Whether the empanelled organisation was inside the engagement

All eleven coverage classes run in all three models and the depth is the same. What changes is whether a Security Brigade auditor stood inside the engagement while it happened.

Whether the empanelled organisation was inside the engagement
StateWhat it meansWhat follows
Autonomous, expert verified A senior Security Brigade auditor stands behind each finding, having verified it before the report is released, which is what puts the empanelled organisation inside the engagement rather than only on the invoice. Start here where the output goes into a CSCRF filing.
Human led A senior auditor owns the engagement end to end — scope, depth and the report itself — with B-52 running underneath. This is also the model that places a red team outside the function being tested, as DE.DP.S4 guideline 3 asks. Start here where the exercise is a red teaming exercise.
Fully autonomous Terminal Somebody authorises the scope and the targets, and the run proceeds without further human action. Nobody is inside the engagement to attest to what came out of it. Coverage between filings, on your own systems, for your own use.
Key
  • A Security Brigade auditor is inside the engagement
  • Scope authorisation only — nobody attests to the result
  • TerminalNo state follows this one

The footnotes

Where footnotes 16 and 17 attach

The VAPT footnote marker sits on the section heading itself — section 4.3 is printed with the marker on the word VAPT — and footnote 16 provides that, unless otherwise specified, all audits mentioned in CSCRF have to be conducted by a CERT-In empanelled information security auditing organisation. Section 4.4 carries its own, footnote 17, attached to the opening words of the section, and it is the wider of the two: it reads on all certifications and audits mentioned in CSCRF. Because the marker sits on the heading rather than on the report format, the condition falls on the engagement itself. Security Brigade has been CERT-In empanelled since 2008, and in the expert-verified and human-led models it is the organisation delivering the work. Red teaming under DE.DP.S4 is governed by guideline 3 instead, which sets independence from the function being tested as the requirement on the team. Both footnotes read 2026-09-14.

What you receive

What the report carries into a CSCRF filing

Per finding

The exploit artefact

The request and the response that proved it, retained as they went out and came back, with reproduction steps an engineer on your side can follow without anybody from here in the room.

Per finding

A severity your committee can recompute

CVSS v4.0 with the vector itself printed and not only the score, plus the CWE and the CSCRF standard the finding is reported under.

Per finding

The state it is in

Open, fixed, retested, closed. The closure record the three-month window is measured against is the retest that could not reproduce it.

Per engagement

Scope, authorisation and the dates it ran

The scope as signed, who authorised it, the dates the testing ran between, and what each of the three approval gates permitted or refused while it ran.

Per engagement

Who delivered it

Security Brigade, CERT-In empanelled since 2008, is the organisation delivering the work in the expert-verified and human-led models, and the report records that.

What is filed

The form the submission takes, and where it goes

Clause 6.7 of the 28 August 2025 clarifications sets the form, and it covers VAPT and cyber audit reports together. Table 17 of the master circular sets the reporting authority, and it is not the same for every entity type.

The artefactThe form it takesWhere it goes
VAPT report The summary, strictly as per the format mentioned in CSCRF — Annexure-A — submitted after approval from the respective IT Committee for REs. Section 4.3.1 requires the declaration from the MD or CEO given in Annexure-A to accompany it. Table 17 routes by entity type. Stock Brokers and Depository Participants report to Stock Exchanges and Depositories. MIIs and the rest of the REs report to SEBI.
Clause 6.7 of SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025; Table 17 and section 4.3.1 of the master circular. Read 2026-09-14. Table 17 carries a third route, for Investment Advisers, which a later circular is recorded as having changed — see the sourcing block above.
Cyber audit report The summary, in the format CSCRF names for it — Annexure-B — on the same clause. Clause 6.7 is headed for section 4.3 to 4.4 and names Annexure-A and Annexure-B together. Submitted after approval from the respective IT Committee for REs, within one month of completion of the cyber audit.
Clause 6.7; Table 22, section 4.4.2, page 51. Read 2026-09-14.
Explicit vulnerabilities Clause 6.7 reads: “It is clarified that at no point of time, REs shall submit the explicit vulnerabilities unless and otherwise asked for the details by SEBI.” Produced where SEBI asks for the details.
Read 2026-09-14. The detail behind the summary stays with you, which is why the per-finding artefact above is written for your engineers rather than for a regulator’s inbox.

VAPT report

The form it takes
The summary, strictly as per the format mentioned in CSCRF — Annexure-A — submitted after approval from the respective IT Committee for REs. Section 4.3.1 requires the declaration from the MD or CEO given in Annexure-A to accompany it.
Where it goes
Table 17 routes by entity type. Stock Brokers and Depository Participants report to Stock Exchanges and Depositories. MIIs and the rest of the REs report to SEBI.

Clause 6.7 of SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025; Table 17 and section 4.3.1 of the master circular. Read 2026-09-14. Table 17 carries a third route, for Investment Advisers, which a later circular is recorded as having changed — see the sourcing block above.

Cyber audit report

The form it takes
The summary, in the format CSCRF names for it — Annexure-B — on the same clause. Clause 6.7 is headed for section 4.3 to 4.4 and names Annexure-A and Annexure-B together.
Where it goes
Submitted after approval from the respective IT Committee for REs, within one month of completion of the cyber audit.

Clause 6.7; Table 22, section 4.4.2, page 51. Read 2026-09-14.

Explicit vulnerabilities

The form it takes
Clause 6.7 reads: “It is clarified that at no point of time, REs shall submit the explicit vulnerabilities unless and otherwise asked for the details by SEBI.”
Where it goes
Produced where SEBI asks for the details.

Read 2026-09-14. The detail behind the summary stays with you, which is why the per-finding artefact above is written for your engineers rather than for a regulator’s inbox.

The boundary

Three places this page is narrower than it could be

The VAPT cadence is stated against the NCIIPC designation, because that designation is what Table 18 writes its two rows against, and a page that recast them as entity tiers would be publishing a distinction it could not cite. The cyber audit cadence is stated against a periodicity cell that is merged across two entity rows, because that is what page 51 shows when it is rendered rather than extracted — and an earlier internal note of ours recorded that differently, so the circular was re-read at source on 14 September 2026 and the circular governs. Applicability for red teaming and threat hunting is reproduced as DE.DP.S4 and DE.DP.S5 print it, and nothing is inferred outward from it.

What is claimed

What this page claims, and on whose authority

Four lines this one holds.

The position
Mapping, never issuing Findings are mapped to the CSCRF standards they fall under. The certificate or attestation itself is the work of a certification body, or of an auditor appointed to that role, and an engagement here produces the tested evidence rather than that instrument.
Whose empanelment it is The CERT-In empanelment is Security Brigade’s, held since 2008, as the organisation that delivers the engagement. The B-52 platform holds no instrument of its own and this site claims none for it.
Threat hunting is your network, continuously DE.DP.S5 puts the activity as proactively searching for hidden and undetected cyber threats in the RE’s own network, quarterly, drawing on threat intelligence, IOCs and IOAs. What this page maps is testing output against the VAPT, cyber audit and red teaming obligations.
Your category is your determination Which CSCRF entity category your firm sits in, and which of the four obligations follow from it, is for you and your advisers to settle. What is stated here is what each table says and what each delivery model produces.

Mapping, never issuing

The position
Findings are mapped to the CSCRF standards they fall under. The certificate or attestation itself is the work of a certification body, or of an auditor appointed to that role, and an engagement here produces the tested evidence rather than that instrument.

Whose empanelment it is

The position
The CERT-In empanelment is Security Brigade’s, held since 2008, as the organisation that delivers the engagement. The B-52 platform holds no instrument of its own and this site claims none for it.

Threat hunting is your network, continuously

The position
DE.DP.S5 puts the activity as proactively searching for hidden and undetected cyber threats in the RE’s own network, quarterly, drawing on threat intelligence, IOCs and IOAs. What this page maps is testing output against the VAPT, cyber audit and red teaming obligations.

Your category is your determination

The position
Which CSCRF entity category your firm sits in, and which of the four obligations follow from it, is for you and your advisers to settle. What is stated here is what each table says and what each delivery model produces.

Scope the engagement against the cadence it is filed under

Which of the four you are producing decides the scope, the annexure format and who delivers it. Section 4.3.2 asks REs to plan the VAPT activity at the beginning of the financial year, so the scoping conversation is best had before that plan is fixed.