M-SOC
Also written Market SOC · Market-SOC · Market Security Operations Centre
A Security Operations Centre built for the cyber security needs of smaller market intermediaries — cheaper and more accessible than building a full SOC, and mandatory for portfolio managers except the smallest.
In plain language
A Security Operations Centre is the team and technology that watches an organisation's systems for attacks. Building one from scratch is expensive.
For a small portfolio manager with a handful of staff, that cost is out of proportion to the business. But the data is just as sensitive as a large firm's.
An M-SOC, or Market SOC, is the answer. It is a Security Operations Centre designed specifically for the cyber security needs of smaller registered entities in the financial market. The workbook's description is that it offers a more accessible and cost-effective solution than building a full-fledged SOC from scratch.
It is mandatory, with one narrow exemption. A portfolio manager in the self-certification category with fewer than 100 clients is exempted from the requirement.
Everyone else has to have one.
How it works
What it is (Chapter 11, section 11.7, footnote). M-SOC refers to a Security Operations Centre specifically designed to cater to the cyber security needs of smaller registered entities in the financial market, offering a more accessible and cost-effective solution than building a full-fledged SOC from scratch.
The exemption. Portfolio Managers who fall under the self-certification REs category and have less than 100 clients are exempted from the requirement of a mandatory Market-SOC.
Where the categories come from. Section 11.7 covers the Cyber Security and Cyber Resilience Framework (CSCRF) for portfolio managers. As part of operational risk management, portfolio managers need a robust cyber security and cyber resilience framework to protect data integrity and guard against breaches of privacy. All portfolio managers with assets under management as specified by SEBI must follow SEBI's cyber security guidelines, and the CSCRF follows a graded approach, classifying Regulated Entities into five broad categories:
- Market Infrastructure Institutions (MIIs)
- Qualified REs
- Mid-size REs
- Small-size REs
- Self-certification REs
How a portfolio manager is categorised. The workbook's entity-wise table for PMS players is drawn on AUM, and only two of the five categories carry a threshold for them:
| Category | AUM criterion for PMS players |
|---|---|
| Qualified REs | N.A. |
| Mid-size REs | Above Rs 3,000 crores |
| Small-size REs | N.A. |
| Self-certification REs | Rs 3,000 crores and below |
The timing rule. The category is decided at the beginning of the financial year on the previous financial year's data. Once decided, the RE remains in that category throughout the financial year, irrespective of any change in the parameters during the year. The respective reporting authority validates the category at the time of compliance submission, and the criteria and thresholds continue to be updated as and when required.
So the exemption has two conditions, and both must hold — the self-certification category, which for a PMS means AUM of Rs 3,000 crore and below, and fewer than 100 clients.
A worked example
Illustrative figures applying the workbook's thresholds. Four portfolio managers are categorised at the start of a financial year on the previous year's data.
| Portfolio manager | AUM last year | Clients | Category | M-SOC mandatory? |
|---|---|---|---|---|
| Arya Capital | Rs 240 crore | 68 | Self-certification | No — exempt |
| Bhairav Wealth | Rs 900 crore | 310 | Self-certification | Yes — 310 clients is not under 100 |
| Chandra PMS | Rs 4,100 crore | 84 | Mid-size | Yes — above Rs 3,000 crore, so not self-certification at all |
| Dwarka Asset | Rs 2,950 crore | 97 | Self-certification | No — exempt |
Arya Capital and Dwarka Asset clear both tests. Bhairav Wealth fails on client count despite modest AUM. Chandra PMS fails on AUM despite only 84 clients — the exemption is not available to a Mid-size RE at any client number.
Now watch the timing rule bite. Dwarka Asset wins a Rs 400 crore mandate in July, taking AUM to Rs 3,350 crore, and crosses 100 clients in September.
It does not move category mid-year. It stays a self-certification RE, and exempt, for the whole of that financial year — because the category is fixed at the beginning of the year on the previous year's data and holds irrespective of changes during the year.
At the start of the next financial year it is re-categorised on this year's data: Rs 3,350 crore is above Rs 3,000 crore, so it becomes a Mid-size RE and an M-SOC becomes mandatory. The lead time it gets is a consequence of the timing rule, not a concession.
Why NISM asks about it
Chapter 11, section 11.7 (Cyber Security and Cyber Resilience framework for Portfolio Managers), sets out the CSCRF's five RE categories, the AUM-based table for PMS players, the beginning-of-year categorisation rule, and the M-SOC exemption in its footnote.
Expect a question on the exemption's two conditions — self-certification category and fewer than 100 clients — on the Rs 3,000 crore AUM line that separates Mid-size from Self-certification for a PMS, and on when the category is decided and how long it holds. The five-category list is also asked directly.
Common exam traps
- The exemption needs both conditions. Self-certification category and fewer than 100 clients. Either one alone is not enough, and this is the whole point of the provision.
- Fewer than 100 clients, not 100 or fewer. A portfolio manager with exactly 100 clients is not exempt.
- Rs 3,000 crores and below is Self-certification; above Rs 3,000 crores is Mid-size. For PMS players the workbook's table marks the Qualified and Small-size rows as not applicable.
- The category is frozen for the financial year. Crossing a threshold in the middle of the year does not change the category until the next year's categorisation.
- M-SOC is a shared, scaled-down SOC, not a lighter set of rules. The saving is in how the centre is built and run, not in the obligation to monitor.
- CSCRF is the framework; M-SOC is one requirement inside it. Cyber Security Risk and cyber resilience pages cover the framework itself.
Check yourself
1.A portfolio manager had AUM of ₹2,800 crore and 85 clients at the end of last financial year. Its AUM crosses ₹3,200 crore in October this year. For this financial year it is:
- a)A Mid-size RE from October onwards
- b)A Self-certification RE for the whole year, exempt from mandatory M-SOC
- c)A Self-certification RE that must use M-SOC
- d)A Qualified RE
Show the answer
Answer: (b) A Self-certification RE for the whole year, exempt from mandatory M-SOC
Category is decided at the start of the financial year on the previous year's data and the entity remains in that category throughout the year regardless of changes. ₹2,800 crore → Self-certification RE. With fewer than 100 clients, it is exempt from mandatory M-SOC.
Option A re-categorises mid-year. Option C ignores the 100-client exemption. Qualified RE is N.A. for PMS.
Where this is taught
Free preparation for NISM Series XXI-BRelated terms
- Cyber resilienceAn organisation's ability to prepare for and respond to a cyber-attack, keep functioning during it and recover from it — the second half of SEBI's Cyber Security and Cyber Resilience Framework.
- Portfolio Management ServicesA tailored investment service where the client owns the securities directly in their own name, regulated under the SEBI (Portfolio Managers) Regulations, with a minimum investment of Rs 50 lakh.
- Operational riskThe risk of loss from fraud, inadequate documentation, improper execution or similar internal failures — one of the named risks of derivatives trading, distinct from market, credit, liquidity and legal risk.
- Cyber Security RiskThe risk that an AIF's or its service providers' systems are breached, corrupted or disrupted — governed by SEBI's Cyber Security and Cyber Resilience Framework, which all AIFs had to comply with by 31 August 2025.
- Risk frameworkThe risk structure a portfolio manager sets at the strategic level, in line with the investment objective — it names the risks, ranks them, decides how each will be treated, and is monitored and modified continuously.