SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) does not rely on self-assertion. It builds in independent assurance, so that your compliance is tested rather than assumed. That assurance comes in three forms: Vulnerability Assessment and Penetration Testing (VAPT), a periodic cyber audit, and, for larger and more critical entities, a Cyber Capability Index (CCI) that measures cyber resilience maturity. This guide explains what each involves, how often it applies, who is allowed to perform it, and how to walk into these assessments ready rather than exposed. For the full control picture these assessments test against, see the SEBI CSCRF compliance checklist.
VAPT under SEBI CSCRF
VAPT is the technical test of whether your defences hold. Under CSCRF it is not a one-off: it recurs at a cadence set by your category, and its value is only realised when findings are actually closed.
- Scope across internet-facing and critical internal systems, applications, networks and infrastructure.
- A frequency set for your category, with higher categories testing more often and more deeply.
- Testing by suitably qualified, independent testers (CERT-In empanelled providers are commonly used).
- Findings tracked to closure with retesting, not just reported and shelved.
- Evidence of the whole cycle: scope, findings, remediation and closure, ready for inspection.
The CSCRF cyber audit
Where VAPT tests the technology, the cyber audit assesses the whole program: governance, controls, processes and evidence. It is an independent, periodic examination against the CSCRF requirements applicable to your category.
- Conducted by independent, suitably qualified auditors, separate from the teams running the audited systems.
- Scoped to the CSCRF functions and controls that apply to your category.
- Reported to your board or audit committee, and to SEBI where required.
- Findings tracked to remediation and closure, with the trail retained as evidence.
The Cyber Capability Index (CCI)
For market infrastructure institutions and Qualified REs, CSCRF introduces the Cyber Capability Index, a structured way to measure and report cyber resilience maturity on a periodic basis. Rather than a pass or fail, the CCI scores your capability across defined parameters, so both you and the regulator can track whether resilience is improving over time. Confirm whether the CCI applies to your category and how often it must be assessed.
| Mechanism | What it tests | Typical performer |
|---|---|---|
| VAPT | Technical vulnerabilities in systems, apps and infrastructure | Independent, qualified testers (often CERT-In empanelled) |
| Cyber audit | The whole program: governance, controls, processes, evidence | Independent, suitably qualified auditors |
| Cyber Capability Index | Cyber resilience maturity, scored over time | Assessed per SEBI's defined method (higher categories) |
Market Infrastructure Institutions
Full VAPT, audit and CCI, most frequent
Qualified REs
VAPT, cyber audit and CCI
Mid-size REs
VAPT and periodic audit
Small-size REs
Proportionate testing and audit
Self-certification REs
Baseline, lighter cadence
Who can perform CSCRF audits and VAPT
Independence and competence are the two tests. VAPT is typically performed by qualified security testers, with CERT-In empanelled providers a common and defensible choice. The cyber audit must be conducted by suitably qualified auditors who are independent of the teams and systems being audited, so an internal team that runs the controls cannot audit its own work. Confirm the specific qualification and empanelment expectations for your category before you appoint anyone.
Common audit and VAPT gaps
- VAPT findings reported but never closed, or closed without retesting.
- An audit scoped to the wrong category, missing obligations that actually apply.
- Using an internal team that lacks independence from the systems it audits.
- No evidence trail linking findings to the remediation that resolved them.
- Treating CCI as a one-off rather than a maturity measure tracked over time.
Putting it together
CSCRF assurance is about proving your program holds up under independent scrutiny. Run VAPT on your category's cadence and close what it finds, undergo a genuine independent cyber audit, track your Cyber Capability Index where it applies, and keep evidence of the whole cycle. Confirm the exact frequencies and qualifications for your category in the current circular, and check where you sit using the applicability guide.
Frequently asked questions
How often is VAPT required under SEBI CSCRF?+
VAPT recurs at a frequency set by your entity category, with larger and more critical entities testing more often and more deeply. Findings must be tracked to closure with retesting. Confirm the specific cadence for your category against the current SEBI circular.
Who can conduct a SEBI CSCRF cyber audit?+
The cyber audit must be performed by suitably qualified auditors who are independent of the teams and systems being audited. An internal function that operates the controls cannot audit its own work. VAPT is typically carried out by qualified testers, with CERT-In empanelled providers a common choice.
What is the Cyber Capability Index (CCI) under SEBI CSCRF?+
The CCI is a structured measure of cyber resilience maturity that CSCRF introduces for market infrastructure institutions and Qualified REs. It scores capability across defined parameters on a periodic basis, so resilience can be tracked over time rather than judged pass or fail. Confirm whether it applies to your category.
What is the difference between a CSCRF cyber audit and VAPT?+
VAPT is a technical test of vulnerabilities in your systems, applications and infrastructure. The cyber audit is a broader independent examination of the whole program, including governance, controls, processes and evidence. Most entities need both, at a cadence set by their category.
About the author
Nilesh Wagh
Co-Founder, Pelta Technologies
Former CISO · 10+ years in information security & GRC
Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.
Connect on LinkedIn →