SEBI Extends CSCRF Deadline for Regulated Entities to Aug 31, 2025

  • Blog|News|Company Law|
  • 2 Min Read
  • By Chetan Kulasri
  • |
  • Last Updated on 3 July, 2025

SEBI Cybersecurity Framework Deadline

Circular No. SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2025/96; Dated: 30.06.2025

1. Background – SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF)

The Cybersecurity and Cyber Resilience Framework (CSCRF) introduced by the Securities and Exchange Board of India (SEBI) mandates regulated entities to implement robust measures to safeguard their IT systems, ensure data security, and maintain operational continuity in the face of cyber threats. The framework plays a crucial role in maintaining the integrity and resilience of India’s capital markets.

2. Requests for Extension of Compliance Timeline

In response to the original compliance deadline, SEBI received multiple representations from various Regulated Entities (REs) requesting an extension. These entities cited the need for more time to:

  • Upgrade or modify internal systems
  • Align with specific CSCRF technical and procedural requirements
  • Ensure a smoother, more effective implementation process

3. Timeline Extended for Regulated Entities (REs)

Considering the challenges highlighted and to promote ease of compliance, SEBI has extended the deadline for CSCRF compliance by two months, setting the new deadline at August 31, 2025. This extension provides REs additional time to effectively implement the required cybersecurity and cyber resilience measures.

4. Entities Excluded from the Extension

It is important to note that the extension does not apply to certain critical market participants. Specifically, the following entities must adhere to the original compliance timeline:

  • Market Infrastructure Institutions (MIIs) – including exchanges, clearing corporations, and depositories
  • KYC Registration Agencies (KRAs)
  • Qualified Registrars to an Issue and Share Transfer Agents (QRTAs)

These entities are considered systemically important, and therefore, SEBI expects timely implementation of cybersecurity measures without any relaxation in deadlines.

5. Conclusion

With this two-month extension, SEBI aims to balance regulatory rigour with practical compliance feasibility for Regulated Entities. While flexibility has been granted to the broader segment of REs, system-critical institutions must remain on track to meet the original compliance date, reinforcing the overall cyber resilience of India’s securities market ecosystem.

Click Here To Read The Full Circular

Disclaimer: The content/information published on the website is only for general information of the user and shall not be construed as legal advice. While the Taxmann has exercised reasonable efforts to ensure the veracity of information/content published, Taxmann shall be under no liability in any manner whatsoever for incorrect information, if any.

Leave a Reply

Your email address will not be published. Required fields are marked *

Everything on Tax and Corporate Laws of India

To subscribe to our weekly newsletter please log in/register on Taxmann.com