🛡️ SEBI CSCRF expects basic cyber-hygiene from every RA & IA  •  We harden the sites we build  •  🛡️ SEBI CSCRF expects basic cyber-hygiene from every RA & IA  •  We harden the sites we build  • 
Home / Blog / SEBI CSCRF Checklist

SEBI CSCRF for Research Analysts: A Plain-English Checklist

Published 25 September 2026 · By Arihant Intellect · SEBI compliance

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) reads like it was written for stock exchanges and clearing corporations — but it applies, in scaled form, to every SEBI Regulated Entity, including a one-person Research Analyst or Investment Adviser practice with a single website. Here's what it actually asks of a small practice, distilled into a checklist you can action this week.

What CSCRF is, in one paragraph

CSCRF asks every regulated entity to protect its IT systems, websites and client data, with the depth of controls scaled to the size of the entity — a stock exchange needs a security operations centre; a solo RA needs solid basic hygiene. It sits alongside SEBI's other RA/IA obligations, not instead of them. Our full website security guide for SEBI intermediaries covers the reasoning and threats in more depth; this article is the condensed checklist version.

The checklist

Website & server

Email & accounts

Availability

Data & recovery

If you only do three things: enforce HTTPS, turn on two-factor authentication everywhere it's offered, and put a CDN/WAF like Cloudflare in front of your site. That combination blocks the large majority of opportunistic attacks and costs little to nothing extra.

Common mistakes small RA/IA practices make

  1. Reusing one password across hosting, domain registrar, email and CMS — a single leaked password then compromises everything.
  2. Leaving old developer or ex-employee access active long after the relationship ended.
  3. No backups, or backups that have never actually been tested by restoring them.
  4. Treating this as a one-time task instead of an ongoing routine — patching, password rotation and access review need to happen on a schedule, not once.

How Arihant Intellect helps

Every website we build for a SEBI RA or IA ships hardened by default — HTTPS, security headers, CDN/WAF, and no exposed admin surface — following the same checklist above. If you already have a site and just want it checked, we offer a free website security check against this list.

Get your site checked against this list

A quick, honest read on where your current site stands.

Ask for a free check on WhatsApp

Frequently asked questions

What is SEBI's CSCRF?

SEBI's Cyber Security and Cyber Resilience Framework — it asks regulated entities, including RAs and IAs, to protect their IT systems, websites and client data, scaled to the size of the entity.

Does CSCRF apply to a solo Research Analyst?

Yes, in a scaled way — basic cyber-hygiene is still expected. Confirm the specific requirements for your category on sebi.gov.in.

What's the single highest-priority item?

HTTPS with a valid certificate, and two-factor authentication wherever it's available — these block most opportunistic attacks and cost nothing extra on most hosting.

This article is an informational summary by Arihant Intellect (a web & IT service provider, not a SEBI-registered intermediary), condensing general cyber-hygiene practice against SEBI's CSCRF, and is not legal or compliance advice. Always verify the current framework and applicability on the official SEBI website, sebi.gov.in, and consult your compliance officer. See also our full website security guide for SEBI intermediaries.