The Bombay Stock Exchange (BSE) on November 10, 2025, issued a circular regarding Cyber Security and Cyber Resilience Audit of Trading Members.
The following has been stated: -
•The notice outlines the implementation timelines and compliance requirements for conducting and submitting Cybersecurity and Cyber Resilience Framework (CSCRF) audits by SEBI-regulated entities (REs) as per SEBI Circular dated August 20, 2024, and subsequent updates.
•Cyber audits must cover 100% of critical and 25% of non-critical systems, with reports for the half-year ending September 30, 2025, due by December 31, 2025, and ATR by March 31, 2026.
•REs must self-categorize as per SEBI’s criteria, obtain board approval, and auditors must validate this categorization and compliance for each TOR item.
•Audits must follow CERT-In’s July 25, 2025, Comprehensive Cyber Security Audit Policy Guidelines, with penalties for non-compliance as detailed in Annexure D.
The detailed circular is given in the document below.
[Circular No. : 20251110-19]