SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) consolidates cyber requirements for regulated entities into a single, structured mandate organised around six functions: govern, identify, protect, detect, respond and recover. This checklist walks through what you need in place under each function, plus the security-operations, testing, audit and reporting expectations that trip teams up, and how to prove every item when SEBI comes knocking. Use it to scope your program, but remember the depth of each item scales with your entity category. For where you sit, see the applicability guide; for the framework overview, see the SEBI CSCRF framework page.
The SEBI CSCRF checklist at a glance
The six functions map to concrete obligations. This is the shape of a CSCRF program; the sections below expand each one.
| Function | What you need in place |
|---|---|
| Govern | Board-approved policy, an accountable senior officer, cyber risk reported to the board |
| Identify | Asset and data inventory, data classification, critical-service and third-party mapping |
| Protect | Access control and MFA, secure configuration, patching, encryption, SBOM, awareness |
| Detect | Continuous logging and monitoring, SOC coverage, VAPT |
| Respond | Tested incident response plan, incident reporting within SEBI and CERT-In timelines |
| Recover | BCP and DR mapped to critical services, recovery objectives, tested cyber-crisis drills |
1. Govern: accountability at the top
CSCRF elevates governance to a function in its own right (mirroring NIST CSF 2.0). Cyber security has to be owned at board level, not delegated to IT alone. Auditors look for clear ownership, current policy and evidence that leadership actually sees cyber risk.
- A board-approved cyber security and cyber resilience policy, reviewed at a defined cadence.
- A designated senior officer (such as a CISO) accountable for cyber security.
- Periodic reporting of cyber risk posture to the board or a delegated committee.
- A defined cyber crisis management plan and clear decision-making authority during an incident.
2. Identify: know what you are protecting
You cannot protect what you cannot see. The identify function is about an accurate, maintained picture of your assets, data, third parties and the business services they support, so scope is never guesswork.
- A maintained inventory of critical systems, applications and data.
- Classification of data by sensitivity and regulatory impact.
- A mapping of critical business services to the assets and vendors they depend on.
- A third-party and outsourcing register, since CSCRF holds you accountable for the risk your vendors introduce.
3. Protect: reduce your exposure
The protect function is the controls layer. The specifics scale with your category, but the baseline is consistent across entity types.
- Access control on a least-privilege basis, with multi-factor authentication for sensitive access.
- Secure configuration baselines and disciplined patch management.
- Encryption of sensitive data in transit and at rest.
- A Software Bill of Materials (SBOM) for critical applications, so you know what components you run.
- Security awareness training for staff, refreshed regularly.
- Data localisation where it applies to you, a specific CSCRF expectation worth confirming for your category.
4. Detect: monitoring, logging and a SOC
Detection is where CSCRF gets specific about security operations. Larger entities are expected to run fuller monitoring; smaller entities can meet the expectation through a shared facility.
- Continuous logging and monitoring with defined alerting and log-retention periods.
- Security Operations Centre (SOC) coverage appropriate to your category. Smaller entities may use a Market SOC (M-SOC) offered through market infrastructure institutions rather than building their own.
- Vulnerability Assessment and Penetration Testing (VAPT) at the frequency set for your category, with findings tracked to closure.
5. Respond: incident handling and reporting
When something goes wrong, CSCRF expects a coordinated response and prompt reporting. Late or missing incident reports are themselves a compliance failure, separate from the incident.
- A tested incident response plan with clear roles and escalation paths.
- Incident reporting to SEBI and to CERT-In within the timelines they specify.
- Root-cause analysis and a post-incident review that feeds back into your controls.
6. Recover: resilience you can prove
Resilience is the heart of CSCRF, the R that turns a cyber security framework into a cyber resilience one. Regulators want evidence you can keep critical services running through disruption and recover them within defined tolerances.
- Business continuity and disaster recovery plans mapped to critical services.
- Defined recovery objectives (RTO and RPO) for those services.
- Regular, evidenced testing, including cyber-crisis drills and tabletop exercises.
Audit, VAPT and assurance under CSCRF
Beyond the six functions, CSCRF builds in independent assurance. The exact cadence and depth depend on your category, so confirm yours against the current circular.
- Periodic cyber audits by suitably qualified, independent assessors.
- VAPT on the schedule set for your category, with remediation tracked and evidenced.
- For higher categories, a periodic Cyber Capability Index (CCI) assessment to measure and report cyber resilience maturity.
- Auditor and inspection readiness: every applicable control backed by current evidence.
Evidence: the part teams underestimate
Meeting a control is only half the job. You also have to prove it, on demand, during an audit or inspection. The teams that struggle at audit time are rarely the ones with weak controls, they are the ones whose proof is scattered across folders, inboxes and spreadsheets.
A connected evidence approach (where every control is linked to the artefact that demonstrates it) turns audit preparation from a multi-week scramble into a filter. This is exactly what Pelta's Evidence Engine is built for, with SEBI CSCRF available as a first-class framework alongside ISO 27001, PCI DSS and DPDPA.
SEBI CSCRF
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding ISO 27001
~60% carried overAuto-completed from your existing program
Overlap shown is illustrative, the actual carry-over depends on the maturity of your existing program.
It also means your CSCRF work is not single-use. Once you are compliant, Pelta maps that same control and evidence base onto global standards like ISO 27001, so extending from your regional mandate to an international certification is a fraction of the effort of starting over.
How often to run this checklist
CSCRF is an operating rhythm, not a one-off project. Refresh your asset and service inventory continuously, keep controls tied to live evidence, run VAPT and cyber audits on your category's cadence, test response and recovery through drills, and report posture to the board on a regular schedule. Do that and inspections become a demonstration of a program you already run, rather than a fire drill.
Putting it together
The CSCRF checklist comes down to six functions plus assurance and evidence: govern it from the top, know what you hold, protect it, detect problems, respond and report on time, and prove you can recover. Scope each item to your entity category, keep every control tied to evidence, and CSCRF becomes a rhythm you can demonstrate at any time. If you would rather have the program stood up and run for you, see our SEBI CSCRF implementation services.
Frequently asked questions
What is the SEBI CSCRF compliance checklist?+
It is the set of controls and practices a SEBI-regulated entity needs to satisfy the Cyber Security and Cyber Resilience Framework, organised around six functions (govern, identify, protect, detect, respond, recover) plus security operations, VAPT, cyber audit, incident reporting and evidence. The depth of each item scales with your entity category.
What are the six functions of SEBI CSCRF?+
Govern, identify, protect, detect, respond and recover. CSCRF elevates governance to its own function (aligning with NIST CSF 2.0) and puts particular weight on cyber resilience, the ability to keep critical services running through an incident and recover within defined tolerances.
Does SEBI CSCRF require a SOC?+
CSCRF expects security-operations coverage appropriate to your category. Larger entities are expected to run fuller monitoring and a Security Operations Centre, while smaller entities may meet the expectation through a Market SOC (M-SOC) offered via market infrastructure institutions rather than building their own. Confirm what applies to your category.
How often is VAPT required under SEBI CSCRF?+
VAPT is required periodically, at a frequency set by your entity category, with findings tracked to closure. Higher categories test more often and more deeply. Confirm the specific cadence for your class of entity against the current circular.
How is CSCRF different from ISO 27001?+
ISO 27001 is a voluntary international standard for an information security management system. CSCRF is a mandatory regulatory framework with an explicit focus on cyber resilience (detecting, responding to and recovering from incidents) for regulated entities in India. The good news is the control bases overlap heavily, so evidence is reusable across both.
About the author
Nilesh Wagh
Co-Founder, Pelta Technologies
Former CISO · 10+ years in information security & GRC
Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.
Connect on LinkedIn →