Instrument 38 | F. SEBI - Securities / AI-ML / Cyber Resilience

FRAMEWORKBINDING SEBI FRAMEWORK

SEBI - Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities

SEBI2024Binding SEBI FrameworkSecurities

AI / PRIVACY / CYBER RELEVANCE

Applies to AI systems that are critical, cloud-hosted, client-facing or otherwise part of regulated entities’ information assets.

AI: HighPrivacy: HighCybersecurity: Very High

READ FIRST

  • Critical systems
  • data security
  • cloud / hosted services
  • incident response
  • cyber-resilience and audit provisions

PURVIEW

Creates SEBI’s consolidated Cybersecurity and Cyber Resilience Framework for SEBI-regulated entities, establishing a structured security, governance and resilience framework across covered market participants. AI systems deployed by regulated entities fall within this security environment because model infrastructure, applications, APIs, data stores and AI vendors form part of the technology estate that must be protected. For privacy, the CSCRF is particularly important where investor or market data is processed by automated systems, requiring security and resilience to be embedded in the wider technology-governance framework.

Classification and legal status. Binding sectoral regulatory framework for SEBI-regulated entities within scope.

Open document Download PDF Copyright remains with the publishing authority. For informational purposes only.

Read the official document

This browser cannot display the PDF in the page. Open the document or download the PDF.

Keywords

CSCRFcritical systemscyber resiliencecloudincident response

Source note

SEBI circular dated 20 Aug 2024 and CSCRF v1.0 reviewed.

Legal status indicates whether this resource is legislation, delegated regulation, regulatory direction, guidance, policy, research or technical material. Inclusion in this library does not by itself make a document legally binding.

This tool provides research navigation only and does not constitute legal advice or a determination of legal applicability.

Back to the framework library