Introduction
The clock is ticking for SEBI-regulated entities as the June 30, 2026, deadline for cybersecurity audit submissions fast approaches. For compliance officers, IT heads, and CISOs across India's financial sector, understanding the full scope of the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) audit is no longer optional—it's critical for business continuity.
The landscape has shifted dramatically. What was once a guidelines-driven approach has evolved into a rigorous, evidence-based audit model where every control and response must be validated through documented proof. Adding to the urgency, SEBI's recent advisory has emphasized the need for continuous, AI-driven vulnerability assessments, fundamentally changing the tempo of security expectations.
This guide cuts through the complexity, offering a comprehensive roadmap to achieve full compliance with the SEBI CSCRF cyber audit for 2026.

What Is the SEBI CSCRF Audit and Why Does It Matter So Much?
The SEBI CSCRF audit is a regulatory mandate designed to evaluate whether SEBI-regulated entities—including stock brokers, portfolio managers, exchanges, depositories, and other market participants—comply with the unified Cybersecurity and Cyber Resilience Framework. It covers governance, risk management, SOC operations, and incident response across all critical systems.
Why 2026 is Different
The framework has moved from a "checklist-based" exercise to a "live, evidence-based" operational mandate. Cyber resilience is now a board-level and management-level responsibility, not just an IT function. This shift is driven by a massive surge in cyber threats; for instance, Indian organizations encountered nearly 1.2 billion attacks in Q3 2024 alone, a staggering 92% increase from the previous year.
Key Takeaway: The old annual VAPT cycle is dead. The 2026 mandate focuses on "continuous" security.
The Complete Compliance Checklist: What Needs to Be in Place
To be ready for the audit, entities must implement a comprehensive cybersecurity program. Based on the updated CSCRF requirements, the checklist is extensive and covers the following critical areas:
1. Governance and Oversight
- Board-Approved Policies: Formal, board-approved cybersecurity policies covering access control, incident response, and vulnerability management.
- Defined Roles: Clear accountability structures, including the mandatory appointment of a CISO and an IT committee.
2. Asset and Data Management
- Critical System Identification: Identification and classification of 100% of critical systems. Auditors will cover 100% of critical systems and 25% of non-critical systems (on a sample basis).
3. Network and Technical Controls
- Infrastructure Protection: Implementation of firewalls, network segmentation, and secure configurations.
- Access Control: Enforcement of least privilege access and periodic reviews.
- API Security: Continuous inventory and testing of all APIs, especially given the rise in API-based breaches (e.g., the 2024 lending app data exposure).
4. Vulnerability Assessment and Penetration Testing (VAPT)
This is arguably the most critical operational component of the 2026 audit:
- Continuous VAPT: "Regular" is now interpreted as "continuous." Organizations must move beyond annual tests.
- AI-Based Tools: The May 2026 SEBI advisory explicitly endorses the use of "suitable AI-based vulnerability assessment tools" to keep pace with attackers.
- Full Coverage: Testing must cover internal/external infrastructure, web and mobile apps, APIs, and cloud deployments.
5. Security Operations Center (SOC)
- Continuous Monitoring: SOC must provide 24/7 monitoring, centralized log collection, and threat detection.
- Incident Response: Defined workflows to detect, contain, and remediate incidents within prescribed timelines.
Audit Process and Strict Deadlines for 2026
The 2026 audit cycle operates on a strict calendar based on the entity's categorization. As per CDSL, BSE, and NCDEX circulars, here are the critical dates you cannot miss.
For Most Entities (Self-Certified, Small, Mid-Size, Qualified REs)
- Audit Period: Financial Year 2025-26 (April 2025 - March 2026).
- Conduct VAPT: Must be completed by June 30, 2026.
- Submit Report: The report (approved by the IT Committee) must be submitted by July 31, 2026.
- Action Taken Report (ATR): Submit closure status by November 30, 2026.
For Systemically Important Entities (QSBs & Protected REs)
These entities face half-yearly scrutiny:
- Period (Oct 2025 - Mar 2026): VAPT must be conducted by June 30, 2026, with ATRs due by September 30, 2026.
Critical Rule: No audit cycle shall be left unaudited. If an entity changes categorization, the unaudited period must be included in the current cycle.
Essential Documents for the Audit
Being documentation-ready is half the battle. You need to prepare the following:
- VAPT Audit Report: As per the format prescribed in Annexure-2 of the CSCRF circular.
- Vulnerability Closure Log (ATR): Proof of remediation/closure of vulnerabilities.
- Minutes of Meeting (MoM): Approval of the VAPT report by the IT Committee.
- Auditor Declaration: Declaration from the CERT-In empanelled auditor regarding conflict of interest and scope.
- Categorization Rationale: Documented justification for the entity's categorization under CSCRF.
- Retention Records: Detailed VAPT reports and POCs must be retained for a minimum of three years.
The New Shift: Continuous VAPT and SOC Integration
The most significant change is the death of the "periodic" approach.
- From Periodic to Continuous: A quarterly audit that clears you in January tells you nothing about a vulnerability introduced in February. Continuous VAPT catches these changes in near-real time.
- The Angel One Incident: In 2024, attackers accessed a publicly exposed AWS storage bucket, exposing ~7.9 million users' data—a basic misconfiguration that continuous cloud posture assessment would have flagged.
- SOC Integration: VAPT findings can no longer sit in a PDF. They must be directly fed into your SOC and the Market SOC (M-SOC) run by exchanges. All SOC alerts, including low-priority ones, must be investigated.
Auditor Selection: Who Can Conduct the Audit?
You cannot pick just any auditor. SEBI mandates strict criteria:
- CERT-In Empanelment: The auditing organization must be empanelled with CERT-In.
- Experience: The auditor should have a minimum of 3 years of experience in IT audit, specifically in the securities market.
- Certifications: Relevant credentials like CISA, CISM, CISSP, or GSNA are recommended.
- Independence: The auditor must have no conflict of interest (e.g., no consulting engagement with the entity in the last two years).
