Frameworks · India regulatory

SEBI CSCRF compliance, run as a living system

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is the binding cybersecurity mandate for SEBI-regulated entities. It specifies a control set across governance, identification, protection, detection, response and recovery, an audit cadence, and a 6-hour window for reporting cyber incidents.

Who it applies to

Stock brokers, depository participants, stock exchanges, clearing corporations, depositories, asset management companies, mutual funds, KYC registration agencies, portfolio managers and other SEBI-regulated entities, with obligations tiered by entity category.

What it demands

Governance

Board-approved cyber policy, designated CISO, periodic review and committee oversight.

Protection

Access control, asset inventory, network segmentation, encryption and hardening baselines.

Detection & response

SOC monitoring, incident response plan, and reporting to SEBI within 6 hours of noticing an incident.

Audit & resilience

Periodic VAPT, cyber audits on a defined cadence, DR drills and capacity planning.

How Compli-Once runs it

  • 1

    CSCRF modelled control by control with owners, evidence requirements and a computed compliance rate.

  • 2

    The 6-hour reporting window is a live countdown in the incident workflow, timestamped from detection to notification.

  • 3

    Crosswalk from your ISO 27001 programme quantifies existing coverage before you plan a single task.

  • 4

    Readiness audits run with the same finding and CAPA machinery as the certification audit.

What you already satisfy

SEBI CSCRF overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

What is SEBI CSCRF?

CSCRF is SEBI's Cybersecurity and Cyber Resilience Framework, the binding cybersecurity mandate for SEBI-regulated entities. It defines controls across governance, protection, detection, response and recovery, requires periodic audits, and mandates reporting cyber incidents to SEBI within 6 hours.

How much of CSCRF does an ISO 27001 programme already cover?

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by an existing ISO 27001 programme. The exact figure is computed per tenant by the crosswalk, with reviewable mappings.

Does Compli-Once handle CSCRF audits?

Yes. CSCRF audits run as engagements with scoped evidence requests through the auditor portal. Findings carry owners and due dates, and closure is evidenced on the same surface the programme manages.

How is the 6-hour reporting requirement met?

The incident workflow starts the jurisdictional countdown at detection. Notification steps, deadlines and timestamps live on the incident record, so the report is assembled from the record rather than reconstructed afterwards.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.