Compliance

SEBI CSCRF Compliance Checklist: What Regulated Entities Need

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) raises the bar for regulated entities. Here's a plain-English checklist of what you need in place — and how to prove it.

The Pelta Team8 min readUpdated Part of SEBI CSCRF

SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) consolidates cyber requirements for regulated entities into a single, structured mandate. It borrows the familiar functions of identify, protect, detect, respond and recover, and adds explicit expectations around governance and continuous resilience. If you are a regulated entity in India's securities market, this checklist gives you a practical starting point.

This article is a general guide, not legal advice. Always confirm the current requirements against the official SEBI circulars applicable to your entity class.

1. Governance and accountability

CSCRF expects cyber security to be owned at the top of the organisation, not delegated to IT alone. Auditors will look for clear roles, documented policies, and board-level visibility of cyber risk.

  • A board-approved cyber security and cyber resilience policy, reviewed at a defined cadence.
  • Defined roles and responsibilities, including a designated senior officer accountable for cyber security.
  • Periodic reporting of cyber risk posture to the board or a delegated committee.

2. Identify: know what you're protecting

You cannot protect what you cannot see. The identification function is about maintaining an accurate picture of your assets, data, third parties and the business services they support.

  • A maintained inventory of critical systems, applications and data.
  • Classification of data by sensitivity and regulatory impact.
  • A mapping of critical business services to the assets and vendors they depend on.

3. Protect: controls that reduce exposure

  • Access control with least-privilege and strong authentication.
  • Secure configuration baselines and patch management.
  • Encryption of sensitive data in transit and at rest.
  • Security awareness training for staff.

4. Detect, respond and recover

Resilience is where CSCRF goes further than a traditional controls checklist. Regulators want evidence that you can detect an incident quickly, respond in a coordinated way, and recover critical services within defined tolerances.

  • Continuous monitoring and logging with defined alerting.
  • A tested incident response plan with clear escalation paths.
  • Business continuity and disaster recovery plans mapped to critical services, with recovery time objectives.
  • Post-incident review and reporting aligned to regulatory timelines.

5. Evidence: the part teams underestimate

Meeting a control is only half the job — you also have to prove it, on demand, during an audit or inspection. The teams that struggle at audit time are usually the ones whose evidence lives in scattered folders and inboxes.

A connected evidence approach — where every control is linked to the artefact that demonstrates it — turns audit preparation from a multi-week scramble into a filter. This is exactly the problem Pelta's Evidence Engine is built to solve, with SEBI CSCRF available as a first-class framework alongside ISO 27001, PCI DSS and DPDPA.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

SEBI CSCRF

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding ISO 27001

~60% carried over
Carried over from SEBI CSCRF New work for your team

Auto-completed from your existing program

GovernanceRisk assessmentAccess controlIncident responseBusiness continuityLogging & monitoring

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

It also means your CSCRF work isn't single-use. Once you're compliant, Pelta maps that same control and evidence base onto global standards like ISO 27001 — so extending from your regional mandate to an international certification is a fraction of the effort of starting over.

Putting it together

Treat CSCRF not as a one-off project but as an operating rhythm: maintain your asset and service inventory, keep controls mapped to evidence, test your response and recovery, and report posture to leadership on a regular cadence. Do that, and inspections become a demonstration of a program you already run — not a fire drill.

Frequently asked questions

Who does SEBI CSCRF apply to?+

CSCRF applies to SEBI-regulated entities in the securities market. The specific requirements and timelines vary by entity category, so confirm the applicable SEBI circular for your class of entity.

How is CSCRF different from ISO 27001?+

ISO 27001 is a voluntary international standard for an information security management system. CSCRF is a mandatory regulatory framework with an explicit focus on cyber resilience — detecting, responding to and recovering from incidents — for regulated entities in India.

What's the hardest part of CSCRF compliance?+

For most teams it is evidencing controls continuously and demonstrating resilience — showing you can recover critical services within defined tolerances — rather than the controls themselves.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.