Frameworks · India regulatory
SEBI CSCRF compliance, run as a living system
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is the binding cybersecurity mandate for SEBI-regulated entities. It specifies a control set across governance, identification, protection, detection, response and recovery, an audit cadence, and a 6-hour window for reporting cyber incidents.
Who it applies to
Stock brokers, depository participants, stock exchanges, clearing corporations, depositories, asset management companies, mutual funds, KYC registration agencies, portfolio managers and other SEBI-regulated entities, with obligations tiered by entity category.
What it demands
Governance
Board-approved cyber policy, designated CISO, periodic review and committee oversight.
Protection
Access control, asset inventory, network segmentation, encryption and hardening baselines.
Detection & response
SOC monitoring, incident response plan, and reporting to SEBI within 6 hours of noticing an incident.
Audit & resilience
Periodic VAPT, cyber audits on a defined cadence, DR drills and capacity planning.
How Compli-Once runs it
- 1
CSCRF modelled control by control with owners, evidence requirements and a computed compliance rate.
- 2
The 6-hour reporting window is a live countdown in the incident workflow, timestamped from detection to notification.
- 3
Crosswalk from your ISO 27001 programme quantifies existing coverage before you plan a single task.
- 4
Readiness audits run with the same finding and CAPA machinery as the certification audit.
What you already satisfy
SEBI CSCRF overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
What is SEBI CSCRF?
CSCRF is SEBI's Cybersecurity and Cyber Resilience Framework, the binding cybersecurity mandate for SEBI-regulated entities. It defines controls across governance, protection, detection, response and recovery, requires periodic audits, and mandates reporting cyber incidents to SEBI within 6 hours.
How much of CSCRF does an ISO 27001 programme already cover?
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by an existing ISO 27001 programme. The exact figure is computed per tenant by the crosswalk, with reviewable mappings.
Does Compli-Once handle CSCRF audits?
Yes. CSCRF audits run as engagements with scoped evidence requests through the auditor portal. Findings carry owners and due dates, and closure is evidenced on the same surface the programme manages.
How is the 6-hour reporting requirement met?
The incident workflow starts the jurisdictional countdown at detection. Notification steps, deadlines and timestamps live on the incident record, so the report is assembled from the record rather than reconstructed afterwards.
