Compliance · SEBI CSCRF
SEBI CSCRF security awareness training requirements
SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) makes periodic cybersecurity awareness programmes mandatory for every regulated entity, and most entities must also assess how aware their employees are.
Here is what the clauses say, why phishing simulation helps you show them, and the evidence SecurityRing gives you for them.
Last reviewed 10 October 2026 against the official texts. Not legal advice.
The short answer
SEBI CSCRF in three lines
Who it applies to
SEBI regulated entities (REs), in five tiers: market infrastructure institutions, Qualified, Mid-size, Small-size and Self-certification REs.
What it asks on awareness training
Mandatory, periodic awareness programmes updated for new threats, a dedicated programme for Board members, and employees aware of phishing and social engineering (PR.AT).
Where phishing simulation fits
It helps you show training and resilience. The CSCRF does not mandate simulations by name, but “phishing test success rate” is SEBI’s own example of how to assess awareness (GV.RM).
Who it applies to
Who has to follow SEBI CSCRF
The CSCRF was issued on 20 August 2024 (circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113) to SEBI regulated entities. SEBI’s 2025 clarification circular is addressed to, for example, stock exchanges, clearing corporations, depositories, depository participants, stock brokers, mutual funds and AMCs, portfolio managers, investment advisers, research analysts, AIFs, KYC registration agencies, registrars and transfer agents, credit rating agencies and merchant bankers.
The framework is graded. It sorts entities into five categories by span of operations and thresholds such as number of clients, trade volume and assets under management, and the category decides which guidelines apply to you. SEBI re-categorised some entities (for example portfolio managers and merchant bankers) in 2025, so confirm yours against its current circulars.
- Market Infrastructure Institutions (MIIs)
- Qualified REs
- Mid-size REs
- Small-size REs
- Self-certification REs
What it asks for
What SEBI CSCRF asks for on awareness training
The clauses that matter, with their numbers. “Official wording” is quoted exactly; “Our paraphrase” is our summary in plain words.
PR.AT standard 1 (CSCRF section 3.2, p. 63)Official wording
Mandatory programs for building awareness of cybersecurity, cyber resilience, and system hygiene among employees shall be established. Such programs shall be conducted on a periodic basis, and shall be updated as per emergence of new threats, state-of-the-art technologies and industry trends.
PR.AT standard 4 (p. 63)Official wording
… a dedicated program on cybersecurity, cyber resilience, and system hygiene shall be made for Board members.
PR.AT guidelines 1–2 (p. 103, all REs, mandatory)Our paraphrase
Build awareness of cybersecurity, cyber resilience and system hygiene among employees, with a focus on those from non-technical disciplines, and make sure employees are “aware of potential risks including social engineering attacks, phishing”.
PR.AT guideline 3 (p. 104)Our paraphrase
Because most infections arrive through phishing emails, malicious adverts and third-party apps, awareness campaigns that stress avoiding clicking links and attachments in email are to be established as “an essential pillar of defence”.
PR.AT guidelines 4–5 (p. 104)Our paraphrase
Run periodic training on IT and cybersecurity policy and standards that includes up-to-date threats, extended where possible to outsourced staff and third-party providers, and review and update the programmes so the content stays current.
GV.RM guideline 1(e) (p. 87, all REs except small-size and self-certification REs, mandatory)Official wording
REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc.
Phishing simulation
Why phishing simulation helps
Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.
Test
A realistic simulated attack
SecurityRing sends a realistic simulated attack to your employees.
Teach
A short lesson after the click
A short lesson opens straight after the click, designed to take under two minutes.
Evidence
A report a reviewer can read
Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.
Campaign results
Evidence for SEBI CSCRF review
- People tested
- Opened
- Clicked
- Completed the lesson
In the report
- Completion records
- Trend report
- Audit trail
Export as
- PPT
- CSV
Show training and resilience
Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.
Faster, with less chasing
A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.
A short lesson at the right moment
When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.
Reports a reviewer can read
The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.
For all REs except small-size and self-certification REs, GV.RM asks for a periodic assessment of employee awareness and gives “phishing test success rate” as its example. A simulation produces that result for every campaign and by department, and the executive trend report shows it over time. The mandatory PR.AT programmes cover phishing and social engineering; the lesson after a click and the completion records show that the people who clicked were taught the attack they met.
What SEBI CSCRF says
The CSCRF cites phishing test success rate as an example. It does not mandate simulations by name.
The CSCRF does not say “run phishing simulations”. It requires mandatory, periodic awareness programmes that cover phishing and social engineering, and, for all REs except small-size and self-certification REs, a periodic assessment of employee awareness.
For that assessment SEBI gives “phishing test success rate” as its example. The wording is “for e.g.”, so other methods are not excluded; a simulation is the method the text itself points to, and it gives you a number you can track over time.
Evidence from SecurityRing
Evidence for SEBI CSCRF from SecurityRing
SecurityRing gives evidence for the employee-awareness parts of PR.AT and GV.RM. This is how its outputs line up with the clauses above.
| What SEBI CSCRF asks | Evidence from SecurityRing |
|---|---|
| Periodic programme, updated for new threats (PR.AT standard 1, guideline 5) | Campaigns you schedule, each with a dated campaign report. Recommendations refresh from current public advisories such as CERT-In, so each campaign can be shown to reflect new threats. |
| Employees aware of phishing and social engineering (PR.AT guidelines 2–3) | A short lesson on the exact attack an employee just fell for, and per-person completion records showing which of the people who clicked finished it. |
| Periodically assess employee awareness, e.g. phishing test success rate (GV.RM 1(e)) | Campaign reports with click and behaviour outcomes per campaign and by department; the executive trend report shows the change over time. |
| Programmes reviewed and kept current (PR.AT guideline 5) | Dated campaign reports and the interaction audit trail show what ran, when, and how people responded. Export as PPT, PDF or CSV. |
| Board awareness (PR.AT standard 4) | The executive trend report (PPT export) gives the Board a view of exposure and where to focus first. It is not a Board training programme; you would still deliver that yourself. |
What SecurityRing produces
- Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
- Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
- Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
- Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
- PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.
What it does not do
- SecurityRing does not deliver the dedicated Board programme that PR.AT asks for.
- SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
- SecurityRing’s reports are not mapped to CSCRF clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
- CSCRF covers far more than awareness (governance, SOC, audits, resilience). SecurityRing is not a CSCRF audit and does not cover those areas.
This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.
How does phishing simulation help with SEBI CSCRF, and is it required?
It helps you show both training and resilience: employees are tested with realistic attacks, and the reports give evidence of the result. The CSCRF requires mandatory, periodic awareness programmes that cover phishing and social engineering. All REs except small-size and self-certification REs must also periodically assess employee awareness, and SEBI gives “phishing test success rate” as an example method. A simulation fits that text, but the CSCRF does not mandate one by name.
Which regulated entities have to assess employee awareness under CSCRF?
The assessment guideline (GV.RM, “periodically assess level of employee cybersecurity awareness”) applies to all REs except small-size and self-certification REs. The mandatory awareness programmes under PR.AT apply to all REs. Check your category against SEBI’s current circulars, because some categories were revised in 2025.
What CSCRF evidence can SecurityRing give an auditor?
Dated campaign reports with click and behaviour outcomes, per-person completion records, an executive trend report showing exposure over time, and a dated interaction audit trail, exported as PPT, PDF or CSV. They give evidence for the awareness clauses; they are not mapped to CSCRF clause numbers, and your auditor decides what is enough.
Does using SecurityRing make us CSCRF compliant?
No. SecurityRing helps you demonstrate the awareness-training part of CSCRF. The framework covers much more than training, no regulator endorses SecurityRing, and SEBI or your auditor decides whether you comply. It also does not deliver the dedicated Board programme that PR.AT asks for.
Sources and how we checked
Last reviewed 10 October 2026. Quoted text and page numbers are from the CSCRF PDF attached to the 20 August 2024 circular. The 28 August 2025 clarification circular was read for changes to awareness requirements and found none; it does revise entity categories.
- SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 Aug 2024): CSCRF for SEBI regulated entities
- CSCRF document (PDF attached to the 2024 circular): PR.AT section 3.2 and guidelines; GV.RM guidelines
- SEBI circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 Aug 2025): technical clarifications to the CSCRF
See the evidence your SEBI CSCRF reviewer will read
Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with SEBI CSCRF.