Compliance — SEBI CSCRF
SEBI CSCRF — 24x7 SOC and 6-hour cyber incident reporting for Indian capital markets
SEBI's Cyber Security and Cyber Resilience Framework requires registered intermediaries to maintain 24x7 SOC monitoring, 1-year India log retention, and 6-hour incident reporting. ManySignal automates all three in AWS Mumbai — satisfying both SEBI CSCRF and concurrent CERT-In requirements.
24x7
SOC monitoring required by SEBI CSCRF for all intermediaries
6 hours
Critical cyber incident reporting to SEBI (aligned with CERT-In)
1 year
Minimum log retention requirement within India
Annual
Penetration testing and VAPT requirements
SEBI CSCRF — common questions
Which SEBI-regulated entities must comply with CSCRF?
SEBI's Cyber Security and Cyber Resilience Framework applies to all registered intermediaries — stock brokers, depository participants, mutual funds, portfolio managers, investment advisers, Research Analysts, KYC Registration Agencies, and Market Infrastructure Institutions (stock exchanges, clearing corporations, depositories). Compliance requirements are graduated based on the intermediary category and transaction volume.
What are SEBI CSCRF's key operational requirements?
SEBI CSCRF requires: 24x7 SOC monitoring, minimum 1-year log retention within India, annual penetration testing, quarterly vulnerability assessments, and cyber incident reporting to SEBI within 6 hours (aligned with CERT-In) for critical incidents. ManySignal addresses the SOC, log retention, and incident reporting requirements.
How does ManySignal support SEBI CSCRF's cyber incident reporting requirement?
SEBI CSCRF requires reporting critical cyber incidents within 6 hours — aligned to CERT-In's reporting timeline. ManySignal's incident management module tracks the 6-hour window from detection, pre-populates the SEBI incident report format (SEBI Circular SEBI/HO/ITD/1/CIR/P/2023/135), and manages the concurrent CERT-In notification. Both notifications can be completed from the same ManySignal case record.
Does SEBI CSCRF require on-premises log storage in India?
SEBI CSCRF requires that all critical cyber data, including logs, be stored within India. ManySignal's India deployment (AWS Mumbai) stores all logs in-country — no data egress to non-Indian regions under default configuration. The 1-year minimum retention with extended retention options meets SEBI's log management requirements.
How does ManySignal address SEBI's requirement for business continuity and cyber resilience testing?
SEBI CSCRF requires annual Business Continuity Plan (BCP) and Disaster Recovery (DR) testing. ManySignal's incident management documents the DR test events, system restoration timelines, and RTO/RPO achievement — providing the cyber resilience testing evidence required for SEBI's annual compliance report submission.
Deploy SEBI-compliant monitoring in India
Speak with our India team about 24x7 SOC deployment, SEBI and CERT-In incident reporting automation, and AWS Mumbai data residency configuration.