SEBI - Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities
AI / PRIVACY / CYBER RELEVANCE
Applies to AI systems that are critical, cloud-hosted, client-facing or otherwise part of regulated entities’ information assets.
AI: HighPrivacy: HighCybersecurity: Very High
READ FIRST
- Critical systems
- data security
- cloud / hosted services
- incident response
- cyber-resilience and audit provisions
PURVIEW
Creates SEBI’s consolidated Cybersecurity and Cyber Resilience Framework for SEBI-regulated entities, establishing a structured security, governance and resilience framework across covered market participants. AI systems deployed by regulated entities fall within this security environment because model infrastructure, applications, APIs, data stores and AI vendors form part of the technology estate that must be protected. For privacy, the CSCRF is particularly important where investor or market data is processed by automated systems, requiring security and resilience to be embedded in the wider technology-governance framework.
Classification and legal status. Binding sectoral regulatory framework for SEBI-regulated entities within scope.