Skip to main content

Open resource, CC BY 4.0

SEBI CSCRF tracker

The Cyber Security and Cyber Resilience Framework broken down by entity type, so you only read the parts that apply to you.

The table itself

This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.

Showing 17 of 17 rows

FunctionRequirementApplies toFrequencyEvidence
GovernanceBoard approved cyber security and resilience policyAll categoriesAnnual reviewBoard minutes and the approved policy
GovernanceDesignated senior official accountable for cyber securityAll categoriesContinuousAppointment record and reporting line
GovernanceCyber capability index submittedQualified and abovePer the calendarSubmitted index with supporting evidence
IdentifyAsset inventory including data classificationAll categoriesContinuous, reviewed periodicallyCurrent inventory with owners
IdentifyRisk assessment covering critical systemsAll categoriesAnnualRisk register and treatment decisions
IdentifyThird party and vendor risk assessmentAll categoriesAnnual and on changeVendor assessments and contract terms
ProtectAccess control with least privilege and periodic reviewAll categoriesQuarterly reviewAccess review records with sign off
ProtectNetwork segmentation of critical systemsQualified and aboveContinuousArchitecture and segmentation test results
ProtectData protection including encryption in transit and at restAll categoriesContinuousConfiguration evidence
DetectSecurity operations centre coverageCategory dependent, shared SOC permitted for smaller entitiesContinuousSOC coverage records and escalation logs
DetectLog retention aligned to CERT-In and SEBIAll categoriesContinuousRetention configuration and sample retrieval
RespondIncident response plan with defined severitiesAll categoriesAnnual testPlan and records of the last exercise
RespondIncident reporting to SEBI within the timelineAll categoriesPer incidentCopies of reports filed and their timestamps
RecoverBusiness continuity and disaster recovery planAll categoriesAnnual testTest results with RTO and RPO achieved
RecoverRecovery objectives defined per critical systemQualified and aboveAnnual reviewDocumented RTO and RPO with drill evidence
AssuranceVAPT of critical systemsAll categoriesAt least annual, plus on significant changeVAPT report and closure tracking
AssuranceSystem audit by an independent auditorCategory dependentPer the calendarAudit report submitted on schedule

Obligations scale by entity category. Establish your category first, because scoping to the wrong one wastes a quarter in one direction or leaves you exposed in the other.

Where the facts come from

Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.

  • SEBI Cyber Security and Cyber Resilience Framework
  • SEBI circulars amending the framework, cited by date

What people use it for

Tracking CSCRF obligations across a financial year without rereading the whole framework each quarter.

Licence

Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.

What the CSCRF is asking of regulated entities

SEBI's cyber security and cyber resilience framework applies across market infrastructure institutions and intermediaries, with expectations scaled to the entity's size and criticality. The framing matters: it is a resilience framework, not only a security one, and the difference shows in what is examined.

Resilience means the questions extend past prevention into detection, response and recovery, with an emphasis on demonstrating that recovery works rather than that a plan exists.

As with RBI supervision, governance carries disproportionate weight. Board level ownership, defined accountability and evidence of review are examined ahead of technical control detail.

Where market entities typically have gaps

Recovery objectives that are asserted rather than measured. An RTO in a document is not evidence; a timed failover is.

Third party dependency mapping, particularly where multiple critical functions rest on one technology provider. The concentration question is the same one RBI supervision asks, and the answer is usually the same.

Access governance around privileged and market-facing systems. Standing administrative access is difficult to defend in any regulated context and particularly so where market integrity is involved.

Evidence of testing rather than of policy. The framework's expectations around periodic testing are specific, and a programme that documents intent without recording execution reads as incomplete.

How to use this tracker

Work it by owner rather than by section. The framework cuts across technology, operations, compliance and the board, and items with no named owner are the ones that will still be open at the next review.

Record the evidence artefact next to each item, not just the status. Status without an artefact is an assertion, and the reason programmes look complete and then fail examination is that the artefacts were never identified.

Track dates. Several expectations are periodic, and periodic obligations fail on the calendar rather than on capability.

Running it alongside your other obligations

Most SEBI regulated entities are also within scope of the CERT-In Directions and the DPDP Act, and a large share of the evidence overlaps: access reviews, logging and retention, incident detection, third party assessment and continuity testing.

Build each control once and evidence it once, then map the same artefact to each framework that requires it. Entities that run separate programmes per regulator produce the same evidence two or three times and still have gaps, because effort is spent on duplication rather than on coverage.

Where the frameworks genuinely differ is reporting: different recipients, different triggers, different timelines. Keep detection unified and reporting separate.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.