
Sebi Cybersecurity Framework: Sebi Grants Additional Two-Month Extension for Cybersecurity Compliance, ET CISO
The framework is designed to ensure that Sebi-regulated entities (REs) maintain a robust cybersecurity posture, remain equipped with adequate cyber resiliency measures and can withstand, respond to, and recover from cyber threats, effectively.
The move came after Sebi received multiple requests for extension of timelines to ensure ease of compliance for them.
"Therefore, it has been decided to extend the compliance timelines by two months, i.e., till August 31, 2025 to all REs, except Market Infrastructure Institutions (MIIs), KYC Registration Agencies (KRAs), and Qualified Registrars to an Issue and Share Transfer Agents (QRTAs)," Sebi said in a circular.
Advt
This marks the second extension granted by the regulator.Recognising the need for robust cybersecurity measures and protection of data and IT infrastructure, Sebi issued the Cybersecurity and Cyber Resilience Framework (CSCRF) for its regulated entities in August 2024.After receiving various queries from REs seeking clarification on the framework, the Securities and Exchange Board of India (Sebi) issued a clarification in December.The CSCRF is a significant step in adapting towards evolving cyber risks and technological advancements.The regulator emphasised that the framework aims to enhance the resilience of regulated entities, enabling them to withstand and recover from cyber incidents effectively.The regulator said the stock exchanges and depositories have been directed to inform their members and participants of the updated compliance deadline and disseminate the circular on their respective websites.
Join the community of 2M+ industry professionals. Subscribe to Newsletter to get latest insights & analysis in your inbox.
All about ETCISO industry right on your smartphone! Download the ETCISO App and get the Realtime updates and Save your favourite articles.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Time of India
an hour ago
- Time of India
Sebi permits joint inspections of stock brokers by Market Infrastructure Institutions
Mumbai: The Securities and Exchange Board of India (Sebi) on Thursday allowed market infrastructure institutions (MIIs) to carry out joint inspection of stock brokers . Now, annual inspections of stock brokers and depository participants are conducted by each MII including stock exchanges , depositories and clearing corporations separately. "Such an exercise unwarrantedly taxes the intermediaries due to frequent visits for inspections by different MIIs which result in disproportionate diversion of resources leading to disruption in the routine operations of the entities," Sebi said in a circular. Productivity Tool Zero to Hero in Microsoft Excel: Complete Excel guide By Metla Sudha Sekhar View Program Finance Introduction to Technical Analysis & Candlestick Theory By Dinesh Nagpal View Program Finance Financial Literacy i e Lets Crack the Billionaire Code By CA Rahul Gupta View Program Digital Marketing Digital Marketing Masterclass by Neil Patel By Neil Patel View Program Finance Technical Analysis Demystified- A Complete Guide to Trading By Kunal Patel View Program Productivity Tool Excel Essentials to Expert: Your Complete Guide By Study at home View Program Artificial Intelligence AI For Business Professionals Batch 2 By Ansh Mehra View Program The regulator said entities selected for annual inspections would be inspected for all segments jointly by all exchanges along with their depository participant operations and clearing activity. Further, MIIs have been asked to establish an information- sharing mechanism with one another for sharing of inspection observations of entities who hold multiple registrations with them.


Mint
9 hours ago
- Mint
Sebi proposes to allow graduates from any discipline to become investment advisers, analysts
Graduates from any discipline, including engineering and law, could become investment advisers and research analysts as India's capital market regulator unveiled sweeping proposals to slash red tape and widen entry for such professionals. The Securities and Exchange Board of India's consultation paper released on Thursday proposes to drop subject restrictions for new entrants. The only mandatory hurdle is clearing the relevant National Institute of Securities Markets (NISM) exams or an accredited equivalent. The paper seeks to overhaul compliance, registration, and data disclosure requirements for such investment advisers (IAs) or research analysts (RAs). It aims to 'facilitate ease of doing business and address practical challenges in the current framework', following persistent demands from the industry, it said. The paper is open for public comments until 28 August. 'Why should an engineering graduate not be any better than an economics graduate after having created the required examination for licence?' said Harsh Roongta, member of the Sebi Alternative Investment Policy Advisory Committee (AIPAC) and founder of Fee Only Investment Advisers LLP. Once an aspirant clears the key criteria of NISM Series X-A and X-B examination before getting a licence, all candidates should be treated equally, Roongta said. These examinations are mandatory qualification exams prescribed by Sebi for investment advisers in India. Sebi also intends to allow IAs and RAs to share past performance data with clients, a long-standing demand. However, this can only be done on a specific client's request and must be certified by a chartered accountant, company secretary, or cost accountant, rather than being disseminated publicly. Once Sebi's new Past Risk and Return Verification Agency (PaRRVA) is fully operational, only PaRRVA-certified performance metrics can be used for advertising or disclosure purposes. Another significant change would let IAs provide second opinions and charge fees for assets purchased via other distributors, provided the investor is fully informed and gives annual consent. The intent, according to Sebi, is to ensure investors are not deprived of independent advice simply due to prior distributor relationships. To streamline entry, Sebi proposes scrapping requirements for multiple address proofs and detailed infrastructure documentation, noting that most players now operate virtually. Applicants will now only need to declare infrastructure adequacy and provide basic contact details. The paper seeks to eliminate the requirement for submitting CIBIL credit scores, net worth, asset and liability statements, and income tax returns. Sebi explained: 'The requirement to submit the credit report/score from CIBIL is hence redundant for determining the eligibility of the applicant for registration and removal of this requirement shall reduce the compliance burden for applicants.' Sebi also proposes to give individual IAs a more flexible timeline to convert into corporate entities after crossing 300 clients or ₹ 3 crore in annual fees. Advisers will, for the first time, be able to onboard clients and collect fees during the process—minimizing business disruption. While these proposals mark significant progress, experts caution that more structural changes may be required to substantially grow the pool of registered advisers and analysts. 'There is a big need for a graded regulatory structure. The number otherwise is going to fall,' said an industry observer.


Hans India
9 hours ago
- Hans India
Sebi mulls introducing activity-based rules for RTAs, common definition
New Delhi: Sebi on Thursday proposed introducing activity-based regulation for Registrars and Transfer Agents (RTAs), whereby services provided to listed companies would fall within its regulatory ambit and those for unlisted firms would be overseen by the Ministry of Corporate Affairs (MCA). RTAs that cater to both listed and unlisted entities will be required to establish a Separate Business Unit (SBU) exclusively for unlisted services. These SBUs should be set up within 18 months from the date of implementation, Sebi said in its consultation paper. Also, RTAs are required to ensure complete operational separation between the listed and unlisted businesses. "While registrations shall continue to be granted by Sebi, services provided by RTAs to unlisted companies will be overseen by the MCA. The MCA will handle investor complaints pertaining to unlisted securities," the regulator said. Additionally, Sebi has also proposed merging the two existing categories -- Registrar to an Issue (RTI) and Share Transfer Agent (STA) -- into a single category called 'Registrar & Transfer Agent' with a common, updated definition. A uniform net worth requirement of Rs 50 lakh has been suggested for all RTAs. Currently, Category I RTAs perform both RTI and STA functions, while Category II handles either. This classification is now seen as outdated, given the near-complete phase-out of physical share transfers. To prevent frauds, Sebi has proposed an internal control and fraud prevention system within RTAs. This would include CEO/MD accountability, audit committee oversight, surveillance systems for fraud detection, a whistleblower policy with protection for complainants, and KYC-based monitoring of investor identity. Currently, there is no formal system within RTAs to detect or prevent fraud, and physical shareholding, though limited, still carries fraud risk. The regulator has also proposed to include securities premium in the net worth calculation for RTAs, aligning with net worth definitions in the Companies Act, 2013. Currently, only free reserves available for dividends are considered, while securities premium, though previously included under the Companies Act, 1956, is excluded under the existing rules. As per available data, Sebi-registered RTAs are currently providing services to around 35,000 unlisted companies, whereas they serve only about 4,000 listed companies. Moreover, Sebi's jurisdiction is limited to securities that are listed or proposed to be listed on a recognized stock exchange, it does not have the authority to oversee RTA activities related to unlisted companies. RTAs handle back-end operations for companies during IPOs and other share-related activities. Its role includes issuing allotment letters and certificates, managing investor records, and handling share transfers and redemptions. They act on behalf of companies-- that is, there exists a Principal-Agent relationship-- but companies remain responsible for compliance under the Companies Act, 2013. With dematerialization of shares becoming the norm, with less than 1 per cent of shares still in physical form, the RTA's role has notably shrunk, especially in the area of share transfers, Sebi noted. The Securities and Exchange Board of India (Sebi) has sought public comments till August 28 on the proposals.