Meet the Cyber Security and Cyber Resilience Framework, without the guesswork.
SEBI's Cyber Security and Cyber Resilience Framework doesn't apply the same way to every regulated entity — the depth of compliance expected scales with the category you fall into. We start by confirming exactly where you sit, then scope the engagement to match.
From policy documentation through to technical controls and board-level reporting, we build a compliance program that holds up under SEBI's actual audit expectations, not a generic checklist.
Confirm Your CSCRF CategoryCSCRF applies differently depending on which category your entity falls into.
A complete compliance program, not just a one-time policy document.
Cyber security and cyber resilience policy drafted to match your RE category's requirements.
Vulnerability assessment and audit cycles scheduled and coordinated to meet CSCRF timelines.
A response plan that meets CSCRF's incident reporting and escalation requirements.
Vendor and outsourcing risk assessed and documented as CSCRF requires.
Backup, retention and data localisation practices reviewed against the framework.
Reporting structured for board and designated officer sign-off, as CSCRF expects.
Every gap in your assessment is rated, mapped to the specific CSCRF requirement it relates to, and paired with a remediation step.
Below is an illustrative example of how a single gap is presented in your assessment report.
The organisation has informal breach response practices, but no board-approved incident response plan meeting CSCRF's documentation and reporting timelines.
Illustrative example only — for demonstration of report format, not an actual finding from a client engagement.
The same structured path, scoped to your specific RE category.
Review current practices against CSCRF requirements for your category.
Draft or update the policies CSCRF specifically requires.
Implement or verify the technical safeguards the framework expects.
VAPT and control testing scheduled to meet CSCRF timelines.
Compile the reporting and sign-off your category requires.
CSCRF compliance often overlaps with these — we account for all of them where relevant.
It depends on your size, business type and the systems you operate — we'll assess this with you as the first step, since it determines the scope of everything that follows.
Frequency varies by category — larger, more critical entities face more frequent requirements. We'll confirm your specific cycle.
Yes — even self-certification REs have baseline requirements under CSCRF, though the depth expected is lower than for market infrastructure institutions.
Yes — this is a common trigger for engagement, and we scope the work around closing the specific findings raised.
VAPT is often a required component — we coordinate it as part of the broader compliance program, not as a separate disconnected exercise.
Tell us your entity type and we'll confirm your category and next steps.