SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs

  • Home
  • SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs
SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs
SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs
SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs
SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs

SEBI CSCRF · ISO/IEC 27001:2022

SEBI CSCRFWe implement and operate the controls. We do not audit them — and that separation is deliberate.

Compliance work for brokers, AMCs, RTAs, depository participants and other SEBI-regulated entities divides into two halves that should not sit with the same firm. One half is assurance: an independent audit against SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF), issued in August 2024 and clarified through subsequent circulars. The other is implementation — designing the controls, running them, and producing evidence that they actually operated. We do the second.

Gap assessment · control implementation · security operations · evidence

The division

Where we fit

Diagram separating implementation work from assurance work: P J Networks builds and operates controls and produces evidence, while an independent auditor performs the assurance.Two boxes side by side. The left, highlighted, is labelled Implementation – controls, operations and evidence, done by P J Networks. The right is labelled Assurance – independent audit, done by somebody else. A dashed line separates them and a caption notes that one firm on both sides defeats the purpose.IMPLEMENTATIONcontrols, operations,evidence — P J NetworksASSURANCEindependent audit— somebody elseOne firm on both sides defeats the purpose of each.

The separation is the point, not a limitation.

The work Who should do it What we provide
Independent audit or assurance An independent auditor Nothing — engaging your implementer as your auditor defeats the purpose of both
Gap assessment Either A control-by-control read of where you stand
Control implementation Us with your team Network, identity, endpoint, logging and recovery controls
Security operations Us or in-house SOC and NOC capability, and the records they generate
Evidence Us with your team Repeatable proof that a control operated, not just that it exists

Scroll the table sideways on a narrow screen.

If a provider offers to both implement your controls and audit them, that is the first thing to question.

Control domains

The controls we actually implement

Regulatory frameworks differ in wording and overlap almost entirely in substance. The control domains below are what the work reduces to in practice.

01

Identity and access

Joiner-mover-leaver process, privileged access separation, multi-factor authentication on administrative paths, and access reviews that produce a dated record with a named approver rather than an assertion.

02

Network segmentation

Separating what must not reach what, and being able to demonstrate the separation from the running configuration rather than from a diagram. See firewall audit.

03

Logging and retention

Logs that leave the device, are retained where they can be queried, and cover the systems the policy claims they cover. See SIEM services.

04

Monitoring and response

Somebody watching, with a defined escalation path and a record of what was seen and what was done about it.

05

Backup and recovery

Tested recovery with a documented result. An untested backup is a claim, and auditors have become good at asking when it was last proven. See backup and DR.

06

Third-party risk

Knowing which suppliers reach your data and what they are contractually obliged to do about it — increasingly the domain where findings are raised.

The real difficulty

Why evidence is the hard part

Regulated entities rarely fail on the absence of controls. They struggle to demonstrate that a control operated consistently over the period under review — that access was reviewed and by whom, that changes went through approval, that monitoring actually covered the systems it claimed to, that recovery was tested rather than assumed.

That is an operations problem rather than a documentation problem, which is why organisations running a real SOC and NOC find audits substantially less painful: the evidence is a by-product of the operation rather than something assembled retrospectively each year.

On regulatory specifics — deadlines, thresholds, submission windows — we do not restate them on this page. They are amended, and a confidently wrong figure on a vendor’s website is worse than no figure. We will check the current text with you against your own category.

Related

Related work

These sit alongside this engagement more often than not:

SEE ALSO

Compliance services

The wider compliance practice, across frameworks and sectors.

SEE ALSO

SOC as a Service

Subscription security operations without building the team yourself.

SEE ALSO

Managed security services

Day-to-day security operations run on your behalf, which is what leadership and compliance work both depend on.

SEE ALSO

Industry solutions

Sector-specific security programmes.

Questions

SEBI CSCRF Compliance Services for Brokers, AMCs and RTAs, answered

What is the CSCRF?

SEBI’s Cybersecurity and Cyber Resilience Framework, issued in August 2024 for SEBI-regulated entities, consolidating earlier cybersecurity circulars into a single framework covering governance, security operations, incident response and resilience testing.

What are the current deadlines?

SEBI has issued several clarifications and extensions since the original circular, and dates differ by entity category. We deliberately do not publish a date here, because a stale compliance deadline on a vendor page is worse than none — check the current position on SEBI’s own site or ask us and we will look it up with you.

The framework expects a SOC. Does that have to be our own?

The framework contemplates access to security operations capability and measuring its effectiveness. Whether that is built in-house, shared, or taken as a service is an operational choice. See SOC as a Service and managed SOC services.

Are you CERT-In empanelled?

No, and we will not imply otherwise. Where an engagement requires an empanelled auditor, that work goes to an empanelled firm and we support the implementation and remediation around it.

Do you hold a security certification yourselves?

P J Networks holds ISO/IEC 27001:2022. We have been operating since 2002 and run our own NOC and SOC from New Delhi.

Can you help if we have already failed an audit?

Yes, and it is a common starting point. A findings list is in practice a well-specified scope of work — we take the observations, agree remediation with owners and dates, implement, and produce the evidence for the follow-up review.

Next step

Talk to someone who has done this before

Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.