What the SEBI CSCRF covers
The Cyber Security and Cyber Resilience Framework consolidates SEBI's cyber expectations into a single, structured baseline organised around the widely used functions of govern, identify, protect, detect, respond and recover. Its defining emphasis is cyber resilience, not just preventing incidents, but being able to keep critical operations running through one and recover within defined tolerances.
Govern
Policy & accountability
Identify
Assets & risk
Protect
Controls & hardening
Detect
Monitoring & alerts
Respond
Incident handling
Recover
Resilience & restore
Rather than a scattered set of circulars, CSCRF gives regulated entities one coherent structure. It formalises expectations that were previously spread across multiple documents, governance and board accountability, security operations and monitoring, incident detection and reporting, periodic audits and testing, and the management of third-party and outsourcing risk.
Who must comply, and the role of entity categories
CSCRF applies to SEBI-regulated entities across the securities market. SEBI has taken a proportionate, category-based approach: the depth of obligations scales with the size, interconnectedness and criticality of the entity. Larger market infrastructure institutions carry the most comprehensive requirements, while smaller entities have a lighter (but still meaningful) baseline to meet.
| Entity tier | Indicative expectation |
|---|---|
| Market Infrastructure Institutions (MIIs) | The most comprehensive obligations, full framework coverage with the deepest monitoring, testing and reporting expectations. |
| Qualified / larger regulated entities | Broad framework coverage, including structured security operations and regular independent assurance. |
| Mid-size regulated entities | Substantial coverage of the framework with proportionate monitoring and audit expectations. |
| Smaller / self-certification entities | A lighter, baseline set of obligations, typically evidenced through self-certification. |
Key requirements at a glance
The specifics vary by category, but most regulated entities will need to address the following areas:
- Governance: a board-approved cyber security and cyber resilience policy, defined roles, and a senior officer accountable for cyber security.
- Risk assessment: a maintained view of assets, data and the critical services they support, with periodic risk assessment.
- Protective controls: access control, strong authentication, secure configuration, patching and encryption of sensitive data.
- Security monitoring: the ability to continuously monitor, log and alert, with more comprehensive SOC expectations for larger entities.
- Incident detection and reporting: processes to detect, respond to and report incidents within regulatory timelines.
- Cyber resilience: business continuity, disaster recovery and defined recovery objectives for critical services.
- Assurance: periodic audits, vulnerability assessment and penetration testing (VAPT), and control testing.
- Third-party risk: oversight of vendors, service providers and outsourced arrangements.
How to approach CSCRF compliance
A practical route to CSCRF compliance (and, more importantly, to staying compliant) looks like this:
- 1Scope and categorise: confirm your entity category and the obligations that apply to you.
- 2Run a gap assessment against the CSCRF control set to see where you stand today.
- 3Prioritise and remediate the gaps, starting with the highest-risk critical services.
- 4Map every control to the evidence that proves it, in one place, so nothing lives in scattered drives.
- 5Stand up continuous monitoring and the reporting needed to meet regulatory timelines.
- 6Test and rehearse: run VAPT, audits and response-and-recovery exercises against your critical services.
Common pitfalls to avoid
- Treating CSCRF as a one-time project instead of an operating rhythm you sustain and report on.
- Leaving evidence in scattered folders and inboxes, so every audit becomes a multi-week scramble.
- Over-investing in preventative controls while under-investing in resilience, recovery and testing.
- Overlooking third-party and outsourced dependencies that sit outside your direct control.
- Rebuilding from scratch for each mandate instead of reusing overlapping controls from ISO 27001, PCI DSS and DPDPA.