SEBI door. CSCRF + LODR. Listed India.

SEBI compliance for listed India.

CSCRF for cybersecurity resilience, LODR for quarterly disclosures, subsidiary and shareholding pattern tracking. Every SEBI filing on time, with the audit trail underneath. dcomply automates compliance with SEBI's Cyber Security and Cyber Resilience Framework across all 5 functions (Identify, Protect, Detect, Respond, Recover), plus the LODR quarterly disclosure calendar, Reg 24 subsidiary tracking, and PIT insider list management.

IDENTIFY    ████████░░ 82%
PROTECT    ███████░░░ 74%
DETECT     ██████░░░░ 61%
RESPOND    ████████░░ 80%
RECOVER    ███████░░░ 75%
SEBI CSCRF maturity score by function
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

Your quarterly LODR filings are done in the last 48 hours before deadline, every quarter.

Your CSCRF gap assessment is a document that circulates between Legal, IT, and the CS office and nobody owns.

Subsidiary tracking under Reg 24 is a spreadsheet that goes stale in one week.

Your shareholding pattern reconciliation is manual.

If you are a fintech listed on the exchange, the Fintech door covers RBI + CSCRF together.

Your regulator stack

Here's what sits above the foundation.

SEBI-regulated listed India lives under multiple SEBI regulations plus overlapping non-SEBI obligations. dcomply ships modules for each layer.

DPDP Act 2023 (investor data)
Consent capture at KYC, DSR portal for shareholders, breach for retail investor data.
MCA (parallel to SEBI for listed)
Companies Act filings, board resolutions, SBO tracker, DIR-3 KYC scheduler.
SEBI (PIT) Prohibition of Insider Trading
Designated persons list, trading window, pre-clearance workflow.
SEBI LODR
Quarterly disclosure calendar, filing archive, board approval workflow, Reg 24 subsidiary tracker.
SEBI CSCRF
The cybersecurity foundation. Control library, VAPT scheduling, incident register, 6-hour reporting.
The Problem

SEBI CSCRF Compliance Is Not Optional

SEBI mandates quarterly and annual cyber security assessments for all regulated entities, non-compliance triggers regulatory action.

Quarterly Reporting

SEBI requires quarterly cyber security compliance reports, manually compiling evidence is error-prone

Multi-Framework Overlap

CSCRF overlaps with ISO 27001, NIST CSF, and DPDP, organizations struggle to avoid duplication

Entity Classification

Different CSCRF requirements apply to Market Infrastructure Institutions vs. qualified entities, easy to misapply

Capabilities

Full SEBI CSCRF Automation

5-Function Framework Mapping

All SEBI CSCRF controls mapped across Identify, Protect, Detect, Respond, and Recover with implementation guidance and evidence templates.

Maturity Score & Gap Analysis

Automated CSCRF maturity assessment with function-wise scoring, gap identification, and prioritized remediation roadmap.

Quarterly Report Generation

One-click generation of SEBI CSCRF quarterly compliance reports in the prescribed format with evidence annexures.

Cross-Framework Integration

Map CSCRF controls to ISO 27001, NIST CSF, and DPDP simultaneously, single evidence set satisfies multiple frameworks.

Incident Reporting Workflows

Structured workflows for cyber incident reporting to SEBI with timeline tracking and communication templates.

SOC & CISO Dashboards

Real-time visibility for security teams with control status, evidence gaps, and pending actions across all CSCRF domains.

What's Included

Complete CSCRF Coverage

Covers all SEBI CSCRF requirements for stock brokers, depositories, mutual funds, investment advisors, and other market intermediaries.

Entity classification and scoping

Determine applicable CSCRF tier (MII, Qualified, or Mid-size) and customise the compliance scope accordingly.

Control library with 100+ CSCRF controls

Pre-mapped control catalogue with implementation guidance, evidence requirements, and testing procedures.

Annual CSCRF audit readiness pack

Pre-built evidence folders and report templates aligned to SEBI's prescribed audit methodology.

Third-party SOC monitoring

Track CSCRF obligations for critical third parties and technology service providers.

SEBI compliance FAQs

Questions Company Secretaries and CROs actually ask.

SEBI's Cybersecurity and Cyber Resilience Framework, a mandatory cybersecurity requirement issued in August 2024 (effective 1 January 2025) for all SEBI-registered intermediaries: stock exchanges, depositories, brokers, mutual funds, portfolio managers, alternative investment funds, custodians, credit rating agencies, and market infrastructure institutions.

Every SEBI-registered intermediary, regardless of size. Tiered by category (MII / QRTA / Broker etc.) with proportionate requirements. Even the smallest sub-broker under a QRTA has baseline obligations.

A cybersecurity policy approved by the board, a Chief Information Security Officer (CISO) reporting to the CEO/MD, quarterly VAPT, annual comprehensive audit, cybersecurity incident reporting to SEBI within 6 hours, cyber-insurance for MIIs, and a Security Operations Centre for larger entities.

CSCRF-specific module covering: policy templates aligned to SEBI's prescribed structure, CISO appointment tracking, VAPT scheduling and evidence, incident reporting to SEBI (6-hour clock parallel to CERT-In 6-hour), audit prep with evidence collection, and quarterly board-report generation.

SEBI can impose penalties under the SEBI Act (up to ₹1 crore per instance), suspend or cancel the intermediary registration, and issue individual accountability orders against directors. CSCRF non-compliance is treated seriously. Recent enforcement has been active.

CSCRF's 6-hour incident report is parallel to CERT-In's 6-hour rule. The same event triggers both. Additionally, if personal data was affected, DPDP's 72-hour DPB notification applies. dcomply's breach module tracks all three clocks in parallel from a single incident record.

SEBI CSCRF applies to regulated entities and market intermediaries: stock brokers, mutual funds, portfolio managers, KRAs, RTAs, and more. The applicability module tells you whether you're in scope and to which extent.

No. Filings go through the exchange's own submission portal. dcomply prepares the disclosure, routes it for board sign-off, and archives the audit trail.

Your RTA continues to handle the transfer agent function. dcomply handles the compliance record-keeping and evidence.

Yes. The insider trading module maintains the designated persons list, trading window, and the pre-clearance workflow.

The module maps every CSCRF control to evidence you upload, flags gaps, and produces the pre-assessment report your auditor expects.
Real teams, real programmes

"The workflow enforces the board approval."

"LODR quarter-end used to be a fire. Now the calendar drives it, the workflow enforces the board approval, and the evidence lives in the same place as the CSCRF audit trail."
Company Secretary, a listed mid-cap manufacturing company on the NSE.

Achieve SEBI CSCRF Compliance Faster

Automate quarterly reporting and evidence collection for all CSCRF controls

View All Features