The Central Depository Services (India) Limited (CDSL) on December 10, 2025, issued a notification regarding the implementation of the SEBI CSCRF circular for Cyber Audit report submission.
The following has been stated: -
•SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) requires Depository Participants (DPs) to conduct half-yearly cyber audits covering all critical systems and sampled non-critical systems, ensuring no audit cycle remains unaudited.
•Specified RE categories (Qualified, Mid-size, Small-size providing IBT/Algo) must submit cyber audit reports by December 31, 2025, and ATR/revalidation by March 31, 2026.
•Other DPs must submit an auditor’s certificate confirming correct categorisation under the CSCRF, which must be board-approved and verified by auditors.
•REs must follow SEBI’s TOR requirements and CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines issued on July 25, 2025.
The detailed notification is given in the document below.
[Notification No.: CDSL/IS/DP/POLCY/2025/806]