SEBI issued clarifications to the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)

Jan 02, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe Securities and Exchange Board of India (SEBI) on December 31, 2024, issued clarifications to the Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs).

The SEBI has issued ‘Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs)’ vide circular SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. This framework is a necessary evolution to the changing threat landscape and rapid technological advancements and designed to ensure that SEBI REs maintain a robust cybersecurity posture, remain equipped with adequate cyber resiliency measures and can withstand, respond to, and recover from cyber threats effectively.

Upon receipt of various queries from REs seeking clarifications on the aforementioned circular, it has been decided to clarify as under:

• Regulatory forbearance:

With regard to the compliance requirements, which are effective from January 01, 2025 under the CSCRF, regulatory forbearance is provided till March 31, 2025. For any non-compliance during this period that comes to the notice of the regulator, no regulatory action shall be taken provided the REs are able to demonstrate meaningful steps taken / progress made in implementation of CSCRF. An opportunity shall be given to the REs to demonstrate the same before any regulatory action is considered by SEBI.

• Extension of compliance dates for Regulated Entities (REs):

While the circular is effective from January 01, 2025, the date of compliance of CSCRF for following REs has been extended based on the feedback received on the rationalisation of categorisation of certain REs:

o KYC Registration Agencies (KRAs): Compliance timeline is extended from January 01, 2025 to April 01, 2025.

o Depository Participants (DPs): Compliance timeline is extended from January 01, 2025 to April 01, 2025.

• Data Security Standard with regard to Data Localisation:

Based on the feedback received on the provisions of Data Localisation, a need is felt for further consultations. Accordingly, the guidelines and provisions with regard to Data Localisation [Data Security standard (PR.DS.S2)] has been kept in abeyance until further notification.

The provisions of this Circular shall come into force with immediate effect.

[Circular No. SEBI/HO/ ITD-1/ITD_CSC_EXT/P/CIR/2024/184]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT