01Program
SEBI CSCRF compliance services for regulated entities in the Indian securities market
Readiness for the Cybersecurity and Cyber Resilience Framework (CSCRF) issued by the Securities and Exchange Board of India: categorization, gap assessment against the standards and guidelines, implementation of the required controls, VAPT (vulnerability assessment and penetration testing) and the evidence a cyber audit expects. For stock brokers, depository participants, asset managers, portfolio managers, investment advisers, research analysts and market infrastructure institutions.
- Name
- SEBI CSCRF Compliance
- Line
- 01 · Cybersecurity
- Type
- Outcome program, combines several practices
01The problem
The CSCRF consolidates years of circulars into one framework with hard timelines.
SEBI issued the CSCRF in August 2024 to replace the cybersecurity circulars that had accumulated for each class of regulated entity. It is built on five cyber resilience goals, Anticipate, Withstand, Contain, Recover and Evolve, and organizes its standards under the functions Governance, Identify, Protect, Detect, Respond and Recover. Obligations are graded by category: market infrastructure institutions, qualified, mid-size, small-size and self-certification regulated entities.
The framework asks for things many regulated entities have never run as a program: a classification of critical systems, periodic VAPT with closure of findings, security operations through a SOC (own, group, third-party or the market SOC), a Cyber Capability Index for the larger categories, incident reporting on SEBI’s timelines, and a cyber audit by an eligible auditor with the evidence to support it.
02Scope
What the SEBI CSCRF program covers.
Categorization and applicability
Confirming the regulated entity’s category from SEBI’s thresholds, and listing the standards and guidelines that apply to it and the ones that do not.
Gap assessment against the CSCRF
Standard-by-standard review of policies, technical controls and evidence under each function, with a sequenced remediation plan sized to the category.
Governance and policy
Cybersecurity and cyber resilience policy, the roles the framework names, committee cadence and board reporting, written to be operated rather than filed.
Critical system identification and SBOM
Identification and classification of critical systems, data classification and the software bill of materials the framework expects for them.
VAPT and remediation
Vulnerability assessment and penetration testing of the in-scope systems on the framework’s cadence, closure of findings and the retest evidence.
Security operations and logging
Log sources, retention and monitoring through an own, third-party or market SOC, with detections, escalation and the records the framework requires.
Cyber Capability Index
For the categories that must report it: measuring the CCI parameters, assembling the evidence behind each and preparing for the assessment.
Incident response and reporting
Response plans and playbooks aligned to SEBI and CERT-In reporting timelines, with tabletop exercises for the people who would report.
Cyber audit preparation
Evidence organized by standard ahead of the periodic cyber audit, auditor liaison and a closure plan for observations.
03Approach
How a SEBI CSCRF engagement runs.
The CSCRF maps closely to ISO/IEC 27001 and the NIST Cybersecurity Framework, so controls built for it are mapped once across [ISO 27001](/services/cybersecurity/iso-27001), the RBI and IRDAI requirements and the [DPDP Act](/services/cybersecurity/dpdp-compliance). Testing is delivered by our [penetration testing](/services/cybersecurity/penetration-testing) practice and monitoring by our [managed SOC](/services/cybersecurity/managed-soc). Related Indian requirements are listed under [compliance frameworks](/services/cybersecurity/compliance-frameworks).
Categorize and scope
Fix the category, the in-scope systems and the standards that apply. Many obligations turn on this step, so it is documented and signed off first.
Assess
Measure the current state against every applicable standard and guideline. Findings are rated by regulatory exposure and by the work needed to close them.
Implement
Policies, technical controls, monitoring and testing put into operation with your technology team. Where engineering is needed, Onion cloud security, IT and security operations teams can carry it out.
Evidence and audit
Evidence collected per standard on a calendar, an internal review before the cyber audit, and support while the auditor works.
Sustain
Periodic VAPT, CCI reporting where required, incident drills and the periodic submissions kept on a schedule, so the next audit starts from a known position.
04Outcomes
What the SEBI CSCRF program is built to achieve.
- A documented category, scope and applicability statement
- A gap assessment against every applicable CSCRF standard, with a dated plan
- Policies, roles and committee records that the framework names
- Critical system inventory, data classification and SBOM for critical systems
- VAPT reports with closure evidence, and monitoring records from the SOC
- A cyber audit entered with the evidence organized by standard
When this work fits
- Stock brokers, depository participants and other intermediaries preparing for or recovering from a cyber audit
- Asset management companies, portfolio managers, investment advisers and research analysts newly in scope
- Market infrastructure institutions and qualified regulated entities reporting the Cyber Capability Index
- Regulated entities that also face RBI, IRDAI or DPDP Act requirements and want one control set
05Questions
SEBI CSCRF: questions we are asked
All SEBI-regulated entities, including market infrastructure institutions (stock exchanges, clearing corporations and depositories), stock brokers, depository participants, mutual funds and asset management companies, portfolio managers, investment advisers, research analysts, registrars and transfer agents, KYC registration agencies and the other intermediaries named in the framework. Obligations are graded by category, from market infrastructure institutions and qualified regulated entities through mid-size and small-size to self-certification regulated entities, based on thresholds SEBI defines.
Commonly: a documented classification of critical systems, a software bill of materials for them, VAPT on the framework’s cadence with closure of findings, security monitoring through a SOC with defined log retention, an incident response plan aligned to SEBI and CERT-In reporting timelines, and, for the larger categories, a Cyber Capability Index assessment. The gap assessment shows which of these apply to your category.
The framework provides for smaller regulated entities to use a market SOC offered through the stock exchanges, as well as own, group or third-party SOCs. Which model fits depends on category, systems and budget. We help you choose, onboard log sources and keep the records the framework expects, and our managed SOC is one of the third-party options.
No. The periodic cyber audit is performed by an auditor who meets SEBI’s eligibility criteria and is independent of the implementation. We prepare you for it: closing gaps, organizing evidence by standard and supporting the auditor’s requests. We also deliver the VAPT the framework requires through our penetration testing practice.
The CSCRF borrows its structure from the NIST Cybersecurity Framework, overlaps heavily with ISO/IEC 27001 controls, and refers to ISO 27001 directly for the larger categories. Entities regulated by both SEBI and the RBI, or also subject to the DPDP Act, implement each control once and map it to every requirement, so evidence serves several submissions. See ISO 27001 consulting and DPDP Act compliance.
Often alongside
Related services, industries and guides
- DPDP Act Compliance
- Penetration Testing & VAPT
- Managed SOC & MDR
- GRC & Compliance
- All cybersecurity services
Industries where this matters most
Working with us
What every engagement rests on.
- Non-disclosure agreements
- Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
- Least-privilege access
- The minimum access the work requires, tied to named individuals and removed when the work ends.
- Telemetry stays in your tenant
- In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
- End of engagement
- Access is handed back, and your information is returned or deleted as agreed with you.
Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India
