Open resource, CC BY 4.0
SEBI CSCRF tracker
The Cyber Security and Cyber Resilience Framework broken down by entity type, so you only read the parts that apply to you.
The table itself
This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.
Showing 17 of 17 rows
| Function | Requirement | Applies to | Frequency | Evidence |
|---|---|---|---|---|
| Governance | Board approved cyber security and resilience policy | All categories | Annual review | Board minutes and the approved policy |
| Governance | Designated senior official accountable for cyber security | All categories | Continuous | Appointment record and reporting line |
| Governance | Cyber capability index submitted | Qualified and above | Per the calendar | Submitted index with supporting evidence |
| Identify | Asset inventory including data classification | All categories | Continuous, reviewed periodically | Current inventory with owners |
| Identify | Risk assessment covering critical systems | All categories | Annual | Risk register and treatment decisions |
| Identify | Third party and vendor risk assessment | All categories | Annual and on change | Vendor assessments and contract terms |
| Protect | Access control with least privilege and periodic review | All categories | Quarterly review | Access review records with sign off |
| Protect | Network segmentation of critical systems | Qualified and above | Continuous | Architecture and segmentation test results |
| Protect | Data protection including encryption in transit and at rest | All categories | Continuous | Configuration evidence |
| Detect | Security operations centre coverage | Category dependent, shared SOC permitted for smaller entities | Continuous | SOC coverage records and escalation logs |
| Detect | Log retention aligned to CERT-In and SEBI | All categories | Continuous | Retention configuration and sample retrieval |
| Respond | Incident response plan with defined severities | All categories | Annual test | Plan and records of the last exercise |
| Respond | Incident reporting to SEBI within the timeline | All categories | Per incident | Copies of reports filed and their timestamps |
| Recover | Business continuity and disaster recovery plan | All categories | Annual test | Test results with RTO and RPO achieved |
| Recover | Recovery objectives defined per critical system | Qualified and above | Annual review | Documented RTO and RPO with drill evidence |
| Assurance | VAPT of critical systems | All categories | At least annual, plus on significant change | VAPT report and closure tracking |
| Assurance | System audit by an independent auditor | Category dependent | Per the calendar | Audit report submitted on schedule |
Obligations scale by entity category. Establish your category first, because scoping to the wrong one wastes a quarter in one direction or leaves you exposed in the other.
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- SEBI Cyber Security and Cyber Resilience Framework
- SEBI circulars amending the framework, cited by date
What people use it for
Tracking CSCRF obligations across a financial year without rereading the whole framework each quarter.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- India compliance registryEvery cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.Open it
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- DPDP compliance timelineWhat the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.Open it
What the CSCRF is asking of regulated entities
SEBI's cyber security and cyber resilience framework applies across market infrastructure institutions and intermediaries, with expectations scaled to the entity's size and criticality. The framing matters: it is a resilience framework, not only a security one, and the difference shows in what is examined.
Resilience means the questions extend past prevention into detection, response and recovery, with an emphasis on demonstrating that recovery works rather than that a plan exists.
As with RBI supervision, governance carries disproportionate weight. Board level ownership, defined accountability and evidence of review are examined ahead of technical control detail.
Where market entities typically have gaps
Recovery objectives that are asserted rather than measured. An RTO in a document is not evidence; a timed failover is.
Third party dependency mapping, particularly where multiple critical functions rest on one technology provider. The concentration question is the same one RBI supervision asks, and the answer is usually the same.
Access governance around privileged and market-facing systems. Standing administrative access is difficult to defend in any regulated context and particularly so where market integrity is involved.
Evidence of testing rather than of policy. The framework's expectations around periodic testing are specific, and a programme that documents intent without recording execution reads as incomplete.
How to use this tracker
Work it by owner rather than by section. The framework cuts across technology, operations, compliance and the board, and items with no named owner are the ones that will still be open at the next review.
Record the evidence artefact next to each item, not just the status. Status without an artefact is an assertion, and the reason programmes look complete and then fail examination is that the artefacts were never identified.
Track dates. Several expectations are periodic, and periodic obligations fail on the calendar rather than on capability.
Running it alongside your other obligations
Most SEBI regulated entities are also within scope of the CERT-In Directions and the DPDP Act, and a large share of the evidence overlaps: access reviews, logging and retention, incident detection, third party assessment and continuity testing.
Build each control once and evidence it once, then map the same artefact to each framework that requires it. Entities that run separate programmes per regulator produce the same evidence two or three times and still have gaps, because effort is spent on duplication rather than on coverage.
Where the frameworks genuinely differ is reporting: different recipients, different triggers, different timelines. Keep detection unified and reporting separate.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












