MCX issued a notification regarding Cyber Security and Cyber Resilience Framework (CSCRF)

Nov 11, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Multi-Commodity Exchange (MCX) on November 10, 2025, issued a notification regarding Cyber Security and Cyber Resilience Framework (CSCRF).

The following has been stated:

As per the Cybersecurity and Cyber Resilience Framework (CSCRF), all SEBI-regulated entities (REs) must conduct half-yearly cyber audits, covering 100% of critical systems and 25% of non-critical systems on a sample basis, with justification for the sample size.

For Qualified REs and Mid-size/Small-size REs providing IBT or Algo Trading, the audit for the period ending September 30, 2025, must be carried out by a CERT-In empaneled auditor and submitted by December 31, 2025, with the Action Taken Report (ATR) or Revalidation Report due by March 31, 2026. Entities with multiple SEBI registrations (like PMS, AIF, RA/IA, Merchant Banker, etc.) must self-categorize as per CSCRF guidelines, with annual approval from the Board or designated authority. Auditors must verify this categorization during the audit process. 

The audit report must include management comments and mark each Term of Reference (TOR) item as Compliant, Non-Compliant, or Not Applicable, with justifications. All audits must follow CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines (July 25, 2025) to maintain uniformity and security. Updated formats for reports and declarations are provided in Annexure C, while penalties for non-compliance are detailed in Annexure D of Circular MCX/INSP/525/2025 dated October 10, 2025. Trading members must ensure timely submission and strict adherence to SEBI’s CSCRF requirements.

Please refer to the document attached below for Annexures and more details.

[Circular No.: MCX/TECH/580/2025]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT