A SEBI CSCRF readiness assessment answers one blunt question before it is asked for you: against the Cyber Security and Cyber Resilience Framework obligations that apply to your entity category, where do you actually stand? It is a structured gap-check across the six CSCRF functions that produces a prioritised list of what is missing and a roadmap to close it, run on your own terms rather than discovered during a formal cyber audit or a SEBI inspection. This guide explains what a readiness assessment covers, when to run one, how to self-assess function by function, and how to turn the result into a plan. For the framework itself, see the SEBI CSCRF framework overview.
What is a SEBI CSCRF readiness assessment?
It is an internal, structured evaluation of your current state against the CSCRF requirements for your category. Think of it as a dress rehearsal: you measure each expected outcome, record the evidence that proves it (or note that it is missing), and score the gap. It is not the same as the formal cyber audit, which is independent and comes later; the readiness assessment is the honest pre-check you do so that the audit holds no surprises.
When should you run one?
- Before your compliance date, with enough runway to close the gaps it finds.
- Ahead of a scheduled cyber audit or VAPT, so findings do not catch you cold.
- After a material change: a new product, a major system, an acquisition, or moving into a heavier entity category.
- On a regular cadence, because CSCRF compliance is a live state, not a one-off.
What a readiness assessment covers
A complete assessment walks the six CSCRF functions, plus the assurance and evidence layers, scoped to the depth your category requires. It mirrors the SEBI CSCRF compliance checklist, but scored against your actual posture rather than read as a to-do list.
Confirm category
Scope to your tier
Assess
Each of the six functions
Score gaps
Have it / partial / missing
Prioritise
By risk and effort
Roadmap
Plan to close
Evidence
Prove each control
Self-assessment: the questions to ask, function by function
Work through these honestly. For each, the real test is not 'do we do this?' but 'can we show evidence that we do?'
| Function | Ask yourself | Evidence to check |
|---|---|---|
| Govern | Is there a board-approved cyber policy and an accountable officer? | Signed policy, board minutes, role definition |
| Identify | Do we have a current asset, data and critical-service inventory? | Inventory, data classification, service-dependency map |
| Protect | Are access control, patching, encryption and awareness in place? | Access reviews, patch records, config baselines, training logs |
| Detect | Do we have logging, monitoring and SOC coverage for our tier? | Log sources, SIEM alerts, SOC or M-SOC arrangement |
| Respond | Is the incident response plan tested, with reporting timelines mapped? | IR plan, drill records, SEBI/CERT-In reporting process |
| Recover | Are BCP/DR and recovery objectives defined and tested? | RTO/RPO per critical service, tested recovery, drill evidence |
Any row where the answer is 'we do it but cannot evidence it' is a gap, because at audit time an unprovable control is a missing one. For the assurance layer (VAPT, cyber audit, CCI), see the audit and VAPT guide.
If you would rather have the assessment run for you, scoped, scored and turned into a roadmap, see our SEBI CSCRF compliance services.
Turning the assessment into a roadmap
The output of a readiness assessment is not a score, it is a plan. Rank the gaps by risk and effort, assign owners and dates, and sequence the work back from your compliance date so evidence has time to accumulate. The gaps that take longest to close (standing up logging and a SOC, testing recovery, building an evidence base) should start first, because they cannot be crammed the week before an audit.
Common gaps a readiness assessment surfaces
- Controls that exist in practice but have no evidence to prove them.
- No mapped critical services, so scope and recovery objectives are guesswork.
- Logging and SOC coverage below what the category expects.
- Business continuity plans that have never been tested against a real scenario.
- Category placement assumed rather than documented against current thresholds.
Putting it together
A readiness assessment is how you replace 'we think we are compliant' with 'here is exactly where we stand and what is left'. Confirm your category, score each function against real evidence, prioritise the gaps into a roadmap, and start the long-lead items early. Do that and the formal audit becomes a confirmation of what you already know, not a reckoning. Start from the applicability guide to pin your category, then work the checklist.
Frequently asked questions
What is a SEBI CSCRF readiness assessment?+
It is an internal, structured evaluation of where your organisation stands against the CSCRF obligations for your entity category. It scores each of the six functions against your actual posture and evidence, produces a prioritised gap list, and feeds a roadmap to close those gaps before a formal audit or inspection.
How is a readiness assessment different from a CSCRF cyber audit?+
A readiness assessment is your own internal pre-check, done on your terms to find and fix gaps. The cyber audit is a formal, independent examination required by CSCRF that comes later. The point of the readiness assessment is to make sure the audit holds no surprises.
When should I run a CSCRF readiness assessment?+
Before your compliance date with enough runway to fix what it finds, ahead of a scheduled audit or VAPT, after any material change to your systems or category, and then on a regular cadence, since CSCRF compliance is a live state rather than a one-off.
Can I self-assess my CSCRF readiness?+
Yes, and you should, as a first step. Work through each of the six functions asking not just whether you do something but whether you can evidence it. Use the self-assessment table in this guide as a starting point, then confirm the exact depth your category requires against the current circular.
How long does a CSCRF readiness assessment take?+
The assessment itself can be quick, days to a few weeks depending on size. Closing the gaps it surfaces is the longer part, often months, because evidence and capabilities like logging, a SOC and tested recovery accumulate over time. That is why running the assessment early matters.
About the author
Vishal Shinde
GRC Product Specialist, Pelta Technologies
GRC · Privacy & Information Security
Vishal Shinde is a GRC Product Specialist at Pelta Technologies, focused on governance, risk and compliance, privacy and information security. He works hands-on with regulated organisations to turn framework requirements into managed controls with linked evidence.
Connect on LinkedIn →