SEBI's Cybersecurity and Cyber Resilience Framework sets a mobile app security baseline under Standard 16 of PR.AA — Identity Management, Authentication, and Access Control. Issued 20 August 2024, binding on all regulated entities by 31 August 2025.
It usually is. CSCRF applies to virtually every category of SEBI-regulated intermediary — stock brokers, depository participants, mutual funds, RTAs, investment advisers, research analysts, and more. What changes by size isn't whether the framework binds you; it's which specific controls and audit obligations apply to your category.
| Category | Threshold (Stock Brokers) | What Scales With Category |
|---|---|---|
| Qualified REs | More than ₹1,000 crore in collateral/assets with Clearing Corporations | Automated tools (BAS, CART), CISO reporting directly to MD/CEO, own SOC expected |
| Mid-size REs | ₹10 crore to ₹1,000 crore | Full baseline controls, lighter audit cadence than Qualified REs |
| Small-size REs | ₹10 crore and below | Can onboard to Market-SOC (M-SOC) via NSE/BSE instead of building their own SOC |
| Self-certification REs | Smallest scale, per SEBI's published criteria | Reduced audit burden, but still required to submit a SOC efficacy report periodically |
Thresholds per SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025), clarifying the original CSCRF circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Category is fixed for the financial year based on the prior year's data. Not legal advice; confirm your category and obligations with your compliance counsel.
SEBI's own FAQ names the baseline mobile application security requirements at Standard 16, under the PR.AA control family — Identity Management, Authentication, and Access Control.
| Requirement | What It Means in the App | What Satisfies It in NonaShield |
|---|---|---|
| Identity management | The app must reliably identify the device and the person placing an order, not just the logged-in session. | Hardware-bound device identity, tied to the enrolled customer, that can't be cloned or replayed. |
| Authentication | A dynamic factor unique to the transaction, not a static password or a single OTP that can be phished. | A key created in secure hardware signs each transaction — a factor that never leaves the device. |
| Access control | An order placed from a hijacked session, a rooted device, or a remote-access tool shouldn't reach the exchange as genuine. | RASP detects root, tampering, hooking and remote-access tools before the order is placed. |
| Evidence for audit | Cyber audits under CSCRF need proof the controls actually ran on a given session, not a policy on paper. | A signed, tamper-evident evidence record for every session, generated at the moment it happened. |
Instrument: SEBI CSCRF, Standard 16 (PR.AA), as published in SEBI's FAQ on Cybersecurity and Cyber Resilience Framework. Not legal advice; confirm current requirements with your compliance counsel.
The compliance date for most regulated entities under CSCRF, binding across categories. Entities already covered by prior cybersecurity guidelines had an earlier date of 1 January 2025. Dates are compliance dates, not issue dates, as published by SEBI.
An order placed from a compromised session authenticates cleanly — the login was real. The gap Standard 16 is closing sits after login, on the device, at the moment the order is placed. See how this fits the rest of NonaShield's compliance mapping.
SEBI CSCRF is one of seven compliance instruments NonaShield maps to on day one — alongside the RBI Digital Payment Security Controls, RBI Authentication Directions, RBI Digital Lending Directions, NPCI's UPI MASF, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) sets baseline mobile application security requirements under Standard 16 of PR.AA (Identity Management, Authentication, and Access Control). It was issued 20 August 2024, with a compliance date of 31 August 2025 for most regulated entities.
CSCRF is binding on virtually all SEBI-regulated entities, not only large ones. SEBI groups REs into five categories — Qualified, Mid-size, Small-size, Self-certification, and MIIs — based on scale. The category changes which specific controls and audit tools apply, not whether the framework applies at all.
For stock brokers, category is based on the value of collateral or assets held with Clearing Corporations: Qualified REs hold more than ₹1,000 crore, Mid-size REs between ₹10 crore and ₹1,000 crore, and Small-size REs ₹10 crore and below. The category is fixed for the full financial year based on the prior year's data.
NonaShield's RASP layer, hardware-bound identity and behavioural signals map directly to Standard 16's identity, authentication and access-control requirements, with a signed evidence record for every session — control-mapped on day one, not a compliance roadmap.
Twelve controls, mapped to SEBI CSCRF Standard 16, for your category.