Trading & Broking · Compliance

SEBI CSCRF: what it requires of your trading app.

SEBI's Cybersecurity and Cyber Resilience Framework sets a mobile app security baseline under Standard 16 of PR.AA — Identity Management, Authentication, and Access Control. Issued 20 August 2024, binding on all regulated entities by 31 August 2025.

The Objection We Hear

"CSCRF Isn't Mandatory For Us."

It usually is. CSCRF applies to virtually every category of SEBI-regulated intermediary — stock brokers, depository participants, mutual funds, RTAs, investment advisers, research analysts, and more. What changes by size isn't whether the framework binds you; it's which specific controls and audit obligations apply to your category.

CategoryThreshold (Stock Brokers)What Scales With Category
Qualified REs More than ₹1,000 crore in collateral/assets with Clearing Corporations Automated tools (BAS, CART), CISO reporting directly to MD/CEO, own SOC expected
Mid-size REs ₹10 crore to ₹1,000 crore Full baseline controls, lighter audit cadence than Qualified REs
Small-size REs ₹10 crore and below Can onboard to Market-SOC (M-SOC) via NSE/BSE instead of building their own SOC
Self-certification REs Smallest scale, per SEBI's published criteria Reduced audit burden, but still required to submit a SOC efficacy report periodically

Thresholds per SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025), clarifying the original CSCRF circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Category is fixed for the financial year based on the prior year's data. Not legal advice; confirm your category and obligations with your compliance counsel.

The Mobile App Baseline

Standard 16: Identity, Authentication, Access Control.

SEBI's own FAQ names the baseline mobile application security requirements at Standard 16, under the PR.AA control family — Identity Management, Authentication, and Access Control.

RequirementWhat It Means in the AppWhat Satisfies It in NonaShield
Identity management The app must reliably identify the device and the person placing an order, not just the logged-in session. Hardware-bound device identity, tied to the enrolled customer, that can't be cloned or replayed.
Authentication A dynamic factor unique to the transaction, not a static password or a single OTP that can be phished. A key created in secure hardware signs each transaction — a factor that never leaves the device.
Access control An order placed from a hijacked session, a rooted device, or a remote-access tool shouldn't reach the exchange as genuine. RASP detects root, tampering, hooking and remote-access tools before the order is placed.
Evidence for audit Cyber audits under CSCRF need proof the controls actually ran on a given session, not a policy on paper. A signed, tamper-evident evidence record for every session, generated at the moment it happened.

Instrument: SEBI CSCRF, Standard 16 (PR.AA), as published in SEBI's FAQ on Cybersecurity and Cyber Resilience Framework. Not legal advice; confirm current requirements with your compliance counsel.

The Deadline

31 August 2025. Already Behind You.

31 Aug 2025

The compliance date for most regulated entities under CSCRF, binding across categories. Entities already covered by prior cybersecurity guidelines had an earlier date of 1 January 2025. Dates are compliance dates, not issue dates, as published by SEBI.

Common Mistake

Unauthorised Orders Pass Every Password Check.

What teams treat as "done"

  • Confirming their category and filing the self-assessment.
  • A password and OTP for login, treated as sufficient authentication.
  • Assuming a hijacked but logged-in session looks the same as a genuine one.

What Standard 16 is actually asking for

  • A dynamic, device-bound factor on the order itself, not just at login.
  • Detecting the device is rooted, tampered with, or running a remote-access tool before the order is placed.
  • A signed record showing what the app actually checked, for cyber audit and CAG review.

An order placed from a compromised session authenticates cleanly — the login was real. The gap Standard 16 is closing sits after login, on the device, at the moment the order is placed. See how this fits the rest of NonaShield's compliance mapping.

The Full Picture

One Platform, Twelve Controls, Every Sector.

SEBI CSCRF is one of seven compliance instruments NonaShield maps to on day one — alongside the RBI Digital Payment Security Controls, RBI Authentication Directions, RBI Digital Lending Directions, NPCI's UPI MASF, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →

Questions People Ask

SEBI CSCRF, Answered.

What does SEBI's CSCRF require of a mobile trading app?

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) sets baseline mobile application security requirements under Standard 16 of PR.AA (Identity Management, Authentication, and Access Control). It was issued 20 August 2024, with a compliance date of 31 August 2025 for most regulated entities.

Is SEBI CSCRF mandatory for my firm, or only for large brokers?

CSCRF is binding on virtually all SEBI-regulated entities, not only large ones. SEBI groups REs into five categories — Qualified, Mid-size, Small-size, Self-certification, and MIIs — based on scale. The category changes which specific controls and audit tools apply, not whether the framework applies at all.

How is my firm's SEBI CSCRF category decided?

For stock brokers, category is based on the value of collateral or assets held with Clearing Corporations: Qualified REs hold more than ₹1,000 crore, Mid-size REs between ₹10 crore and ₹1,000 crore, and Small-size REs ₹10 crore and below. The category is fixed for the full financial year based on the prior year's data.

How does NonaShield map to SEBI CSCRF's mobile app security baseline?

NonaShield's RASP layer, hardware-bound identity and behavioural signals map directly to Standard 16's identity, authentication and access-control requirements, with a signed evidence record for every session — control-mapped on day one, not a compliance roadmap.

Ask Us for the Coverage Report.

Twelve controls, mapped to SEBI CSCRF Standard 16, for your category.