What SEBI CSCRF asks of an awareness programme
SEBI CSCRF puts the awareness obligation in two places: PR.AT sets the training programme and its cohorts, and GV.RM.S3 requires periodic assessment of the awareness level. What each asks, and which REs carry it.
An awareness programme run by a SEBI-regulated entity answers to two separate parts of the same circular. The Protect function carries the training obligation, at PR.AT on page 63. The Govern function carries an obligation to assess how aware the workforce actually is, and it is written twenty-four pages further on, under risk management. A programme calendar assembled from PR.AT alone will carry the first and not the second.
This piece sets out what each asks, at what cadence, and which regulated entities carry which. Every reference is to SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), Version 1.0, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024.
What PR.AT establishes
CSCRF §3.2, PR.AT: Awareness and Training, p. 63. The objective is stated for personnel and partners: that they "are provided cybersecurity awareness education, and are trained to perform their cybersecurity related duties".
Standard item 1 turns the objective into a requirement:
"Mandatory programs for building awareness … shall be established. Such programs shall be conducted on a periodic basis…"
Two words in that sentence set the shape of the programme. Mandatory governs establishment. Periodic governs frequency, and it is the word the rest of this piece has to reconcile.
Standard items 2 to 5 name the populations the programme reaches beyond general staff: privileged users, third parties, senior executives and the Board – with a "dedicated program … for Board members" – and physical and information security personnel.
That list has a practical consequence for how coverage is recorded. A single organisation-wide completion percentage cannot demonstrate that the Board received a programme designed for the Board, or that privileged users received something distinct from what general staff received. Coverage has to be held by cohort, because the Standard is written by cohort.
What the Guidelines expect the programme to address
CSCRF PR.AT Guidelines, pp. 103–104. Where the Standard sets the obligation, the Guidelines describe its content. Item 2:
"REs shall ensure that their employees are aware of potential risks including social engineering attacks, phishing, etc."
Item 3 raises the register:
"…thoughtfully designed security awareness campaigns that stress the avoidance of clicking on links and attachments in email, shall be established as an essential pillar of defence."
Item 4 extends the population outwards:
"REs shall conduct periodic training programs … Wherever possible, this shall be extended to outsourced staff, third-party service providers, etc."
Note the direction of travel in item 4. An RE that has scoped its awareness programme to payroll employees has scoped it more narrowly than the Guideline contemplates, and the extension to outsourced staff and third-party service providers is something a programme record should be able to show it considered.
Whether those same groups may be included in a test is a different question, governed by a different instrument. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, Version 1.0, 25 July 2025, §15.2.2(iii), pp. 55–56, limits social engineering and process testing to the group of employees explicitly included within the agreed audit scope, and requires specific written consent from the target organisation before external entities such as customers, business partners or vendors are involved. Training scope is defined by the CSCRF Guideline; testing scope is defined by the CERT-In Guidelines. Each is set in its own instrument, against its own consent requirement.
"Periodic" in the Standard, "Annually" in the table
Read PR.AT alone and the cadence is periodic. Read the circular's periodic-compliance table and the cadence is a figure. Row 9:
"9. Cybersecurity training program (PR.AT.S1) — All REs — Annually"
These are not two competing answers. They are the same obligation stated at two levels of the same circular, and each is doing a different job.
The Standard establishes the character of the obligation: a programme that is established once and then conducted repeatedly, rather than a project with an end date. That is what periodic is carrying.
The periodic-compliance table converts that character into a calendar: an interval, attached to a standard reference, applied across a stated population of REs. Annually, for All REs, against PR.AT.S1.
So the reconciliation is a division of labour rather than an ambiguity. A compliance calendar should cite the table row, because the table is where the interval is stated. A programme charter should cite PR.AT.S1, because the Standard is where the obligation and its cohorts are defined. A document that cites only one of the two is citing half the requirement, and two documents inside the same organisation, each citing a different half, will appear to disagree with one another when they do not.
The same discipline applies to summarising it publicly. Write periodic and name the Standard; write Annually and name the table row. The circular supports both words, and only in their own places.
The assessment obligation, and where it is written
CSCRF GV.RM Guidelines, "Risk Management", item 1(e), p. 87, standards column GV.RM.S3:
"REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc."
Applicability is taken from the row heading where this guideline block begins on p. 86: "All REs except small-size, self-certification REs (Mandatory)."
Three things sit in that one sentence.
- It is a "shall", and it is marked Mandatory for the REs it reaches.
- It attaches to the level of awareness in the employee population, which is a different object from the delivery of a training programme. PR.AT.S1 is discharged by conducting the programme. GV.RM.S3 is discharged by measuring the result.
- It names phishing test success rate, and it names it with the words "for e.g." in front. Those three words are part of the clause and have to survive any summary of it. The obligation the clause creates is the periodic assessment; phishing test success rate is the illustration the regulator chose of how one is done.
This clause is the one most often missed, and the reason is structural. A reader looking for the awareness requirement opens the Protect function, finds PR.AT, and stops there, because PR.AT is where a reasonable author would expect the whole subject to live. The measurement half was written into governance and risk management instead.
Which REs carry which
CSCRF applies across RE categories, and the three awareness-related obligations above do not reach the same set of entities. The carve-outs are stated in the circular, in three different places.
| Obligation | Where it is stated | Applies to | Stated cadence |
|---|---|---|---|
| Cybersecurity training programme (PR.AT.S1) | §3.2 PR.AT, p. 63; periodic-compliance table row 9 | All REs | Annually (table); periodic (Standard) |
| Periodic assessment of employee awareness level (GV.RM.S3) | GV.RM Guidelines item 1(e), p. 87; applicability heading p. 86 | "All REs except small-size, self-certification REs (Mandatory)" | Periodically |
| Security Training Measure [PR.AT.S1], scored | Annexure-K, Measure 3, p. 166 | MIIs and Qualified REs | Within the past one year |
The third row is the Cyber Capability Index measure, and it carries a precision that is easy to lose. Annexure-K, p. 166, Measure 3, "Security Training Measure [PR.AT.S1]", states the measure as the "Percentage (%) of information system security personnel that have received security training within the past one year", with a target of 100% and a weighting of 5%.
The denominator is information system security personnel, not the workforce. An RE that reports a workforce-wide completion figure against Measure 3 has reported against a denominator other than the one Measure 3 states, and the figure will read differently from the evidence the measure asks for. Per the GV.OV Guidelines, item 1, p. 85, the index is third-party assessed for MIIs and self-assessed for Qualified REs.
What a programme should be able to produce
Everything above resolves into three artefacts, and the third is the one most programmes have least of.
- A programme charter and calendar citing PR.AT.S1 for the obligation and periodic-compliance table row 9 for the annual interval, with the cycle dated.
- Coverage recorded by cohort – general staff, privileged users, third parties, senior executives, the Board's dedicated programme, and physical and information security personnel – plus the extension to outsourced staff and third-party service providers where Guideline item 4 was applied.
- An assessment series under GV.RM.S3: the awareness level measured periodically, with the method recorded and prior results retained, so that one cycle can be read against the next rather than standing alone.
Annexure-K states what evidence looks like for the scored measure, and it is the clearest statement in the circular of what an assessment will ask to see: "1. Details of the training/awareness sessions scheduled within the past 1 year. 2. Cyber audit observation against Standard 1 mentioned in 'Protect: Awareness and Training' header…"
The second item is the one to plan for. It puts PR.AT Standard 1 in front of a cyber auditor, which means the programme is assessed on the record it kept.
Where the awareness assessment under GV.RM.S3 is carried out by a CERT-In empanelled auditing organisation, the conduct of that assessment is governed by CISG-2025-02 §15.2.2(iii), pp. 55–56: the testing must use anonymised or statistical techniques, no individual is personally identified or penalised, and the stated purpose is to evaluate overall awareness and the effectiveness of security processes. The output is therefore a statement about a population – which is the same object GV.RM.S3 asks about when it says "level of employee cybersecurity awareness". The instrument that governs how the measurement is taken and the clause that requires it are describing the same thing, and the evidence reads back cleanly against both.
About the author
Parnika Kelkar
Head — People & Culture
Senior HR generalist partnering with leadership to drive talent acquisition, policy design, compliance, and an engaging workplace culture at Security Brigade.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.