What Is the SEBI CSCRF Audit Requirement?
The Securities and Exchange Board of India’s Cybersecurity and Cyber Resilience Framework (CSCRF) requires regulated entities — stock brokers, depository participants, mutual funds, KRAs, RTAs, and other market intermediaries — to undergo periodic independent audits that check their cybersecurity posture and the health of their IT systems.
Here’s where a lot of confusion starts: this isn’t one audit. It’s two, and they’re not interchangeable.
- Cyber Audit — evaluates cybersecurity controls, threat readiness, and cyber resilience
- System Audit — evaluates IT systems, application controls, and operational integrity
We regularly hear compliance teams describe these as basically the same thing, or assume that clearing one takes care of the other. It doesn’t work that way, and getting this wrong is usually where the compliance gaps start.
Why Does SEBI Require Two Separate Audits?
SEBI splits these audits because, at their core, they’re trying to answer two very different questions:
Cyber Audit asks: Can this organization detect, withstand, and recover from a cyberattack?
System Audit asks: Are this organization’s IT systems, applications, and processes functioning correctly, securely, and as intended?
You can have a system that’s functionally rock-solid but cybersecurity-weak — an application that processes trades perfectly but has no real intrusion detection sitting behind it. Or the reverse: strong perimeter defenses paired with sloppy internal controls, poor change management, or access pathways nobody’s reviewed in years. After several sector-wide cyber incidents, SEBI made clear that functional correctness and cyber resilience needed to be judged on their own terms, not lumped into one generic “IT audit.”
It’s also worth noting this isn’t a uniquely Indian approach. Frameworks like NIST CSF and ISO 27001 draw a similar line between operational/system controls and dedicated cyber-risk controls, so CSCRF’s structure lines up with what regulators elsewhere have already settled on.
There’s a practical reason for the split too. India’s securities market moves enormous volumes of transactions and investor data every single day, which makes it a genuinely attractive target — for opportunistic attackers and well-funded ones alike. Run one combined audit a year and you’ll struggle to give either side the depth it needs: cyber threats shift week to week, sometimes day to day, while system and process controls tend to evolve on a slower cycle tied to software releases and governance updates. Splitting the audits lets each one go deep on its own schedule instead of getting watered down into a single, generic review.
How Do Cyber Audit and System Audit Differ?
If you just want the differences at a glance, here you go:
| Parameter | Cyber Audit | System Audit |
| Primary focus | Cybersecurity controls & resilience | IT systems & application integrity |
| Key question answered | Can we withstand and recover from a cyberattack? | Do our systems work correctly and securely? |
| Scope | Network security, VAPT, incident response, threat intelligence, SOC monitoring | Application controls, access management, change management, data integrity |
| Typical auditor expertise | Cybersecurity specialists, CERT-In empanelled auditors | Systems auditors, CISA-certified professionals |
| Regulatory reference | SEBI CSCRF cyber resilience clauses | SEBI system audit framework (SAF) provisions |
| Frequency | Generally annual (varies by entity category) | Generally annual, sometimes half-yearly for high-risk entities |
| Output | Cyber resilience report with vulnerability findings | System audit report with control gap findings |
| Common overlap area | Access controls, logging, monitoring | Access controls, logging, monitoring |
One thing worth flagging: both audits touch access controls and logging, but they’re looking at the same thing through different lenses. A cyber audit wants to know whether those controls actually stop unauthorized intrusion. A system audit wants to know whether they match the roles and business processes they’re supposed to enforce. Same territory, different question.
What Does a SEBI Cyber Audit Cover?
A SEBI Cyber Audit typically evaluates:
- Vulnerability Assessment and Penetration Testing (VAPT) across networks, applications, and infrastructure
- Security Operations Center (SOC) monitoring capability and incident detection speed
- Incident response readiness — documented playbooks, escalation matrices, and recovery time objectives
- Threat intelligence integration and how proactively the entity identifies emerging threats
- Data encryption practices for data at rest and in transit
- Cyber crisis management plan and business continuity provisions specific to cyber events
- Third-party and vendor risk — especially relevant given how many SEBI entities depend on external SaaS and cloud vendors
Findings generally get sorted by severity — critical, high, medium, low — and anything landing in the critical or high bucket comes with a time-bound remediation plan attached. This isn’t a report you file away and revisit next year.
What Does a SEBI System Audit Cover?
A SEBI System Audit typically evaluates:
- Application controls — input validation, transaction processing accuracy, and audit trails
- Access management — role-based access control, segregation of duties, and periodic access reviews
- Change management processes — how software updates, patches, and configuration changes are approved and tracked
- Data integrity and backup processes — ensuring records remain accurate, complete, and recoverable
- IT governance structure — policies, documented procedures, and management oversight
- Business continuity and disaster recovery (BCDR) planning from an operational (not purely cyber) standpoint
- Compliance with SEBI’s technical and operational circulars relevant to the entity’s category
Put simply: the cyber audit thinks like an attacker. The system audit checks whether things actually work the way they’re supposed to on paper.
How Often Must Each Audit Be Conducted?
How often you’re audited comes down to how SEBI has classified your entity — Market Infrastructure Institution, Qualified RE, Mid-size RE, or Small-size RE. As a rule, the bigger and more systemically important you are, the more often you’re audited.
Broadly, though:
- Cyber Audit: Usually annual, with some high-risk categories also required to run half-yearly VAPT cycles that feed into that annual audit
- System Audit: Usually annual too, typically aligned with the entity’s financial year or a SEBI-specified schedule
One caveat worth repeating: these timelines shift as SEBI issues new circulars, so don’t treat any of this as gospel. Check the latest circular that applies to your entity’s classification before you build a compliance calendar around it.
Who Needs to Comply?
CSCRF casts a wide net across the securities market ecosystem. That includes:
- Stock brokers and depository participants
- Asset Management Companies (AMCs) and Mutual Funds
- KYC Registration Agencies (KRAs) and Registrar & Transfer Agents (RTAs)
- Stock exchanges, clearing corporations, and depositories (Market Infrastructure Institutions)
- Investment advisers and portfolio managers, depending on classification thresholds
Where exactly you fall determines the audit scope and frequency you’re on the hook for — SEBI sorts entities by size, systemic importance, and risk profile, and that classification does a lot of the heavy lifting.
How to Prepare for Both Audits
A few things that separate teams who breeze through both audits from teams who dread them every year:
- Map your current compliance posture against both cyber and system audit requirements separately — don’t assume one audit’s readiness covers the other
- Conduct a pre-audit gap assessment to identify weak areas before the formal audit begins
- Engage empanelled or qualified auditors — SEBI often requires CERT-In empanelled auditors for cyber audits and CISA-certified professionals for system audits
- Document everything — policies, incident logs, access review records, and change management tickets are frequently requested as evidence
- Remediate known issues proactively rather than waiting for audit findings to force action
- Align both audits on a shared calendar so remediation from one audit doesn’t get missed by the time the next one begins
- Build continuous monitoring, not point-in-time compliance — CSCRF rewards entities that treat cyber resilience as an ongoing discipline rather than an annual checkbox
- Run a tabletop exercise before the audit window opens — simulating an incident response scenario surfaces gaps in your playbook long before an auditor points them out, and it gives management a chance to see how the team performs under pressure
- Assign clear internal ownership for each audit stream — a named owner for cyber audit readiness and a separate owner for system audit readiness keeps both workstreams moving in parallel instead of competing for the same people’s attention in the weeks before the deadline
Common Mistakes Regulated Entities Make
We see the same handful of mistakes come up again and again:
- Treating cyber audit findings as IT’s problem alone, without board or senior management involvement
- Delaying VAPT until close to the audit deadline, leaving no time for remediation
- Assuming ISO 27001 or SOC 2 certification automatically satisfies CSCRF requirements — these certifications help but don’t replace the mandated SEBI audits
- Underestimating third-party/vendor risk, which is increasingly a focus area in both audit types
- Not maintaining audit trail documentation year-round, forcing a scramble to reconstruct records before the audit
- Treating the two audits as a single combined event on paper, which often means neither report gets the specialist attention it needs, and gaps between the two get missed entirely
- Outsourcing compliance entirely to an external auditor without building any internal capability, which leaves the organization dependent on the auditor to catch issues rather than catching them itself between audit cycles
Conclusion
SEBI CSCRF’s Cyber Audit and System Audit exist to answer two different but equally important questions: can your organization withstand a cyberattack, and are your systems operating correctly and securely day to day. Treating them as one combined checkbox — or assuming strength in one area covers the other — is where most regulated entities run into avoidable audit findings.
The entities that navigate CSCRF smoothly are the ones that plan both audits on a shared calendar, assign clear ownership to each, and treat remediation as a continuous process rather than a once-a-year scramble. Getting this right isn’t just about avoiding penalties — it builds a genuinely more resilient organization, which is ultimately what the framework is designed to achieve.
If you’re unsure where your organization currently stands on either audit, a gap assessment is the fastest way to find out before SEBI does.
Navigating SEBI CSCRF’s dual-audit requirement can be complex, especially when cyber and system audit timelines overlap. Nishaj InfoSolutions supports regulated entities with end-to-end SEBI CSCRF compliance — from gap assessments and VAPT to full cyber and system audit readiness. Get in touch to discuss your audit calendar.