Cyber Security & Risk Advisory

SEBI CSCRF Compliance

Meet the Cyber Security and Cyber Resilience Framework, without the guesswork.

What This Is

Built for how SEBI actually categorises you

SEBI's Cyber Security and Cyber Resilience Framework doesn't apply the same way to every regulated entity — the depth of compliance expected scales with the category you fall into. We start by confirming exactly where you sit, then scope the engagement to match.

From policy documentation through to technical controls and board-level reporting, we build a compliance program that holds up under SEBI's actual audit expectations, not a generic checklist.

Confirm Your CSCRF Category
Regulated Entity Categories

CSCRF applies differently depending on which category your entity falls into.

Market Infrastructure
Qualified RE
Mid-size RE
Small-size RE
Self-Certification RE
Coverage

What we cover

A complete compliance program, not just a one-time policy document.

policy.sh

Policy Documentation

Cyber security and cyber resilience policy drafted to match your RE category's requirements.

vapt_coord.sh

VAPT & Audit Coordination

Vulnerability assessment and audit cycles scheduled and coordinated to meet CSCRF timelines.

incident_plan.sh

Incident Response Planning

A response plan that meets CSCRF's incident reporting and escalation requirements.

vendor_risk.sh

Third-Party Risk Management

Vendor and outsourcing risk assessed and documented as CSCRF requires.

backup_dr.sh

Data Localisation & Backup

Backup, retention and data localisation practices reviewed against the framework.

board_report.sh

Board-Level Reporting

Reporting structured for board and designated officer sign-off, as CSCRF expects.

What You'll Receive

What a compliance gap looks like

Every gap in your assessment is rated, mapped to the specific CSCRF requirement it relates to, and paired with a remediation step.

Below is an illustrative example of how a single gap is presented in your assessment report.

Incident Response Plan Not Formally Documented High
CSCRF Alignment
Gap: 70%
Description

The organisation has informal breach response practices, but no board-approved incident response plan meeting CSCRF's documentation and reporting timelines.

Illustrative example only — for demonstration of report format, not an actual finding from a client engagement.

How We Work

Our compliance methodology

The same structured path, scoped to your specific RE category.

01

Gap Assessment

Review current practices against CSCRF requirements for your category.

02

Policy & Documentation

Draft or update the policies CSCRF specifically requires.

03

Technical Controls

Implement or verify the technical safeguards the framework expects.

04

Testing & Validation

VAPT and control testing scheduled to meet CSCRF timelines.

05

Certification & Reporting

Compile the reporting and sign-off your category requires.

Compliance Mapping

Frameworks we align with

CSCRF compliance often overlaps with these — we account for all of them where relevant.

SEBI CSCRF ISO 27001 NIST CSF CERT-In Guidelines RBI Cyber Security Framework
Common Questions

Frequently asked questions

Which category do we fall under?

It depends on your size, business type and the systems you operate — we'll assess this with you as the first step, since it determines the scope of everything that follows.

How often does CSCRF require testing?

Frequency varies by category — larger, more critical entities face more frequent requirements. We'll confirm your specific cycle.

Do smaller entities really need to comply?

Yes — even self-certification REs have baseline requirements under CSCRF, though the depth expected is lower than for market infrastructure institutions.

Can you help if we've already had a SEBI inspection finding?

Yes — this is a common trigger for engagement, and we scope the work around closing the specific findings raised.

Is VAPT included in CSCRF compliance?

VAPT is often a required component — we coordinate it as part of the broader compliance program, not as a separate disconnected exercise.

Not sure which CSCRF requirements apply to you?

Tell us your entity type and we'll confirm your category and next steps.

Get in Touch
← Back to

Cyber Security & Risk Advisory

See all offerings — VAPT, information system audit, risk advisory and forensic audit.