Compliance

SEBI CSCRF Compliance Checklist: What Regulated Entities Need

SEBI's CSCRF raises the bar for regulated entities across six functions. Here's a plain-English, item-by-item checklist of what you need in place, plus the SOC, VAPT and audit expectations, and how to prove each one.

Nilesh Wagh · Co-Founder, Pelta Technologies12 min readUpdated Part of SEBI CSCRF

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) consolidates cyber requirements for regulated entities into a single, structured mandate organised around six functions: govern, identify, protect, detect, respond and recover. This checklist walks through what you need in place under each function, plus the security-operations, testing, audit and reporting expectations that trip teams up, and how to prove every item when SEBI comes knocking. Use it to scope your program, but remember the depth of each item scales with your entity category. For where you sit, see the applicability guide; for the framework overview, see the SEBI CSCRF framework page.

This article is a general guide, not legal advice. CSCRF requirements, thresholds and timelines are set by SEBI, vary by entity category, and have been revised over time. Always confirm the current requirements against the official SEBI circulars applicable to your entity class.

The SEBI CSCRF checklist at a glance

The six functions map to concrete obligations. This is the shape of a CSCRF program; the sections below expand each one.

SEBI CSCRF checklist by function
FunctionWhat you need in place
GovernBoard-approved policy, an accountable senior officer, cyber risk reported to the board
IdentifyAsset and data inventory, data classification, critical-service and third-party mapping
ProtectAccess control and MFA, secure configuration, patching, encryption, SBOM, awareness
DetectContinuous logging and monitoring, SOC coverage, VAPT
RespondTested incident response plan, incident reporting within SEBI and CERT-In timelines
RecoverBCP and DR mapped to critical services, recovery objectives, tested cyber-crisis drills

1. Govern: accountability at the top

CSCRF elevates governance to a function in its own right (mirroring NIST CSF 2.0). Cyber security has to be owned at board level, not delegated to IT alone. Auditors look for clear ownership, current policy and evidence that leadership actually sees cyber risk.

  • A board-approved cyber security and cyber resilience policy, reviewed at a defined cadence.
  • A designated senior officer (such as a CISO) accountable for cyber security.
  • Periodic reporting of cyber risk posture to the board or a delegated committee.
  • A defined cyber crisis management plan and clear decision-making authority during an incident.

2. Identify: know what you are protecting

You cannot protect what you cannot see. The identify function is about an accurate, maintained picture of your assets, data, third parties and the business services they support, so scope is never guesswork.

  • A maintained inventory of critical systems, applications and data.
  • Classification of data by sensitivity and regulatory impact.
  • A mapping of critical business services to the assets and vendors they depend on.
  • A third-party and outsourcing register, since CSCRF holds you accountable for the risk your vendors introduce.

3. Protect: reduce your exposure

The protect function is the controls layer. The specifics scale with your category, but the baseline is consistent across entity types.

  • Access control on a least-privilege basis, with multi-factor authentication for sensitive access.
  • Secure configuration baselines and disciplined patch management.
  • Encryption of sensitive data in transit and at rest.
  • A Software Bill of Materials (SBOM) for critical applications, so you know what components you run.
  • Security awareness training for staff, refreshed regularly.
  • Data localisation where it applies to you, a specific CSCRF expectation worth confirming for your category.

4. Detect: monitoring, logging and a SOC

Detection is where CSCRF gets specific about security operations. Larger entities are expected to run fuller monitoring; smaller entities can meet the expectation through a shared facility.

  • Continuous logging and monitoring with defined alerting and log-retention periods.
  • Security Operations Centre (SOC) coverage appropriate to your category. Smaller entities may use a Market SOC (M-SOC) offered through market infrastructure institutions rather than building their own.
  • Vulnerability Assessment and Penetration Testing (VAPT) at the frequency set for your category, with findings tracked to closure.

5. Respond: incident handling and reporting

When something goes wrong, CSCRF expects a coordinated response and prompt reporting. Late or missing incident reports are themselves a compliance failure, separate from the incident.

  • A tested incident response plan with clear roles and escalation paths.
  • Incident reporting to SEBI and to CERT-In within the timelines they specify.
  • Root-cause analysis and a post-incident review that feeds back into your controls.

6. Recover: resilience you can prove

Resilience is the heart of CSCRF, the R that turns a cyber security framework into a cyber resilience one. Regulators want evidence you can keep critical services running through disruption and recover them within defined tolerances.

  • Business continuity and disaster recovery plans mapped to critical services.
  • Defined recovery objectives (RTO and RPO) for those services.
  • Regular, evidenced testing, including cyber-crisis drills and tabletop exercises.

Audit, VAPT and assurance under CSCRF

Beyond the six functions, CSCRF builds in independent assurance. The exact cadence and depth depend on your category, so confirm yours against the current circular.

  • Periodic cyber audits by suitably qualified, independent assessors.
  • VAPT on the schedule set for your category, with remediation tracked and evidenced.
  • For higher categories, a periodic Cyber Capability Index (CCI) assessment to measure and report cyber resilience maturity.
  • Auditor and inspection readiness: every applicable control backed by current evidence.

Evidence: the part teams underestimate

Meeting a control is only half the job. You also have to prove it, on demand, during an audit or inspection. The teams that struggle at audit time are rarely the ones with weak controls, they are the ones whose proof is scattered across folders, inboxes and spreadsheets.

A connected evidence approach (where every control is linked to the artefact that demonstrates it) turns audit preparation from a multi-week scramble into a filter. This is exactly what Pelta's Evidence Engine is built for, with SEBI CSCRF available as a first-class framework alongside ISO 27001, PCI DSS and DPDPA.

Comply once, reuse everywhere, in PeltaSee how the crosswalk works
Compliant

SEBI CSCRF

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding ISO 27001

~60% carried over
Carried over from SEBI CSCRF New work for your team

Auto-completed from your existing program

GovernanceRisk assessmentAccess controlIncident responseBusiness continuityLogging & monitoring

Overlap shown is illustrative, the actual carry-over depends on the maturity of your existing program.

It also means your CSCRF work is not single-use. Once you are compliant, Pelta maps that same control and evidence base onto global standards like ISO 27001, so extending from your regional mandate to an international certification is a fraction of the effort of starting over.

How often to run this checklist

CSCRF is an operating rhythm, not a one-off project. Refresh your asset and service inventory continuously, keep controls tied to live evidence, run VAPT and cyber audits on your category's cadence, test response and recovery through drills, and report posture to the board on a regular schedule. Do that and inspections become a demonstration of a program you already run, rather than a fire drill.

Putting it together

The CSCRF checklist comes down to six functions plus assurance and evidence: govern it from the top, know what you hold, protect it, detect problems, respond and report on time, and prove you can recover. Scope each item to your entity category, keep every control tied to evidence, and CSCRF becomes a rhythm you can demonstrate at any time. If you would rather have the program stood up and run for you, see our SEBI CSCRF implementation services.

Frequently asked questions

What is the SEBI CSCRF compliance checklist?+

It is the set of controls and practices a SEBI-regulated entity needs to satisfy the Cyber Security and Cyber Resilience Framework, organised around six functions (govern, identify, protect, detect, respond, recover) plus security operations, VAPT, cyber audit, incident reporting and evidence. The depth of each item scales with your entity category.

What are the six functions of SEBI CSCRF?+

Govern, identify, protect, detect, respond and recover. CSCRF elevates governance to its own function (aligning with NIST CSF 2.0) and puts particular weight on cyber resilience, the ability to keep critical services running through an incident and recover within defined tolerances.

Does SEBI CSCRF require a SOC?+

CSCRF expects security-operations coverage appropriate to your category. Larger entities are expected to run fuller monitoring and a Security Operations Centre, while smaller entities may meet the expectation through a Market SOC (M-SOC) offered via market infrastructure institutions rather than building their own. Confirm what applies to your category.

How often is VAPT required under SEBI CSCRF?+

VAPT is required periodically, at a frequency set by your entity category, with findings tracked to closure. Higher categories test more often and more deeply. Confirm the specific cadence for your class of entity against the current circular.

How is CSCRF different from ISO 27001?+

ISO 27001 is a voluntary international standard for an information security management system. CSCRF is a mandatory regulatory framework with an explicit focus on cyber resilience (detecting, responding to and recovering from incidents) for regulated entities in India. The good news is the control bases overlap heavily, so evidence is reusable across both.

About the author

N

Nilesh Wagh

Co-Founder, Pelta Technologies

Former CISO · 10+ years in information security & GRC

Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.

Connect on LinkedIn →

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.