What the SEBI CSCRF covers
The Cyber Security and Cyber Resilience Framework consolidates SEBI's cyber expectations into a single, structured baseline organised around the widely used functions of govern, identify, protect, detect, respond and recover. Its defining emphasis is cyber resilience — not just preventing incidents, but being able to keep critical operations running through one and recover within defined tolerances.
Govern
Policy & accountability
Identify
Assets & risk
Protect
Controls & hardening
Detect
Monitoring & alerts
Respond
Incident handling
Recover
Resilience & restore
Rather than a scattered set of circulars, CSCRF gives regulated entities one coherent structure. It formalises expectations that were previously spread across multiple documents — governance and board accountability, security operations and monitoring, incident detection and reporting, periodic audits and testing, and the management of third-party and outsourcing risk.
Who must comply — and the role of entity categories
CSCRF applies to SEBI-regulated entities across the securities market. SEBI has taken a proportionate, category-based approach: the depth of obligations scales with the size, interconnectedness and criticality of the entity. Larger market infrastructure institutions carry the most comprehensive requirements, while smaller entities have a lighter — but still meaningful — baseline to meet.
| Entity tier | Indicative expectation |
|---|---|
| Market Infrastructure Institutions (MIIs) | The most comprehensive obligations — full framework coverage with the deepest monitoring, testing and reporting expectations. |
| Qualified / larger regulated entities | Broad framework coverage, including structured security operations and regular independent assurance. |
| Mid-size regulated entities | Substantial coverage of the framework with proportionate monitoring and audit expectations. |
| Smaller / self-certification entities | A lighter, baseline set of obligations, typically evidenced through self-certification. |
Key requirements at a glance
The specifics vary by category, but most regulated entities will need to address the following areas:
- Governance: a board-approved cyber security and cyber resilience policy, defined roles, and a senior officer accountable for cyber security.
- Risk assessment: a maintained view of assets, data and the critical services they support, with periodic risk assessment.
- Protective controls: access control, strong authentication, secure configuration, patching and encryption of sensitive data.
- Security monitoring: the ability to continuously monitor, log and alert — with more comprehensive SOC expectations for larger entities.
- Incident detection and reporting: processes to detect, respond to and report incidents within regulatory timelines.
- Cyber resilience: business continuity, disaster recovery and defined recovery objectives for critical services.
- Assurance: periodic audits, vulnerability assessment and penetration testing (VAPT), and control testing.
- Third-party risk: oversight of vendors, service providers and outsourced arrangements.
How to approach CSCRF compliance
A practical route to CSCRF compliance — and, more importantly, to staying compliant — looks like this:
- 1Scope and categorise: confirm your entity category and the obligations that apply to you.
- 2Run a gap assessment against the CSCRF control set to see where you stand today.
- 3Prioritise and remediate the gaps, starting with the highest-risk critical services.
- 4Map every control to the evidence that proves it, in one place, so nothing lives in scattered drives.
- 5Stand up continuous monitoring and the reporting needed to meet regulatory timelines.
- 6Test and rehearse: run VAPT, audits and response-and-recovery exercises against your critical services.
Common pitfalls to avoid
- Treating CSCRF as a one-time project instead of an operating rhythm you sustain and report on.
- Leaving evidence in scattered folders and inboxes, so every audit becomes a multi-week scramble.
- Over-investing in preventative controls while under-investing in resilience, recovery and testing.
- Overlooking third-party and outsourced dependencies that sit outside your direct control.
- Rebuilding from scratch for each mandate instead of reusing overlapping controls from ISO 27001, PCI DSS and DPDPA.