Regulation · Capital markets · India
SEBI CSCRF compliance means meeting the Cybersecurity and Cyber Resilience Framework that SEBI issued on 20 August 2024 for all regulated entities. Requirements scale across five categories, from MIIs to self-certification REs, and cover governance, SBOMs, VAPT, SOC monitoring, a 2-hour RTO and periodic cyber audits.
Every SEBI-regulated entity, with requirements that depend on its category.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
SEBI CSCRF requires regulated entities to govern cyber risk under a qualified CISO, manage supply chain and SBOMs, test and patch, monitor through a SOC, report incidents, recover within set targets, and pass periodic cyber audits.
Board oversight, CISO standing, category, CCI.
In QULDEX: Roles and approvals trackedSBOMs and accountable outsourcing.
In QULDEX: SBOM per applicationClose findings within three months.
In QULDEX: Three-month CAPA timersMFA, logs, certified sites.
In QULDEX: ISO 27001 evidence reusedOwn SOC or Market SOC.
In QULDEX: SOC efficacy metricsReport incidents; RTO 2 h, RPO 15 min.
In QULDEX: Drill results storedBy qualifying auditors, per category.
In QULDEX: Controlled auditor accessThese 18 standards and rules carry the work most REs face, grouped by CSCRF function. Select any one to see what it asks for, typical evidence and the matching ISO 27001 reference.
Showing up to 6 per group. Search, filter, or open a group to see all 18.
GV.RRCISO and governanceAppoint a full-time CISO (at least CTO or CIO standing for MIIs and Qualified REs) and board-level oversight of cyber risk; a group-level or dedicated remote CISO is allowed in some cases.
In QULDEXGovernance roles and approvals are recorded per entity.
CategoriesRE categorisationREs fall into five categories: MIIs, Qualified, Mid-size, Small-size and Self-certification, decided at the start of each financial year from the previous year's data.
In QULDEXCategory and thresholds are recorded each financial year.
GV.OVCyber Capability Index (CCI)Frequent audit findingMIIs assess their cyber resilience using the CCI half-yearly through a third party; Qualified REs self-assess yearly.
In QULDEXCCI parameters are tracked with evidence and scores.
GV.SCSupply chain and SBOMManage cybersecurity supply chain risk and obtain an SBOM for all software needed for core and critical business operations.
In QULDEXSBOMs are stored per application with review dates.
OutsourcingOutsourcing and cloudREs stay accountable for outsourced services and must meet SEBI's cloud adoption framework for cloud and hosted services.
In QULDEXEach provider is assessed against the outsourcing and cloud rules.
ID.AMAsset inventory and classificationKeep an inventory of IT assets and classify systems as critical or non-critical.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
ID.RAVAPT and patch managementFrequent audit findingRun vulnerability assessment and penetration testing at the frequency for your category, and close findings within three months of the VAPT report.
In QULDEXVAPT findings become CAPA items with a three-month due date.
PR.AAIdentity and access managementStrong identity, authentication and access control, including MFA and privileged access management.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
PR.IPISO 27001 certificationHold ISO 27001 certification covering the primary and DR data centres, near-DR site, SOC and co-location, including outsourced providers of these.
In QULDEXISO 27001 evidence is reused directly.
PR.DSData security and logsProtect data and logs, with log management feeding the SOC.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
PR.PTCOTS and application testingTest COTS and in-house software (SAST/DAST as applicable) before deployment.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
DE.CMSecurity Operations CentreRun a SOC with continuous monitoring and report its efficacy; smaller REs can use the Market SOC set up by NSE and BSE.
In QULDEXSOC efficacy metrics are tracked on the dashboard.
DE.TIThreat intelligenceCollect and act on threat intelligence relevant to your environment.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
RS.MAIncident classification and reportingClassify cybersecurity incidents and report them to SEBI and CERT-In within the prescribed timelines.
In QULDEXIncidents carry reporting timers and classification records.
RC.RPRecovery: RTO 2 hours, RPO 15 minutesDeclare a disaster within 30 minutes of disruption to critical systems; recover with an RTO of 2 hours and an RPO of 15 minutes.
In QULDEXRTO and RPO are tested in DR drills with results stored.
RC.RP.S1Golden images and spare hardwareMIIs and Qualified REs keep updated golden images of critical systems and isolated spare hardware (or cloud high availability).
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
DrillsScenario-based cyber drillsRun live scenario-based drills to test response and recovery, separate from red and blue teaming.
In QULDEXQULDEX gives this standard an owner, evidence requests and a review date, and maps it to ISO 27001 and NIST CSF 2.0.
AuditCyber auditFrequent audit findingCyber audits are run against CSCRF by auditors meeting SEBI's selection norms, at the frequency for your category, based on the financial year.
In QULDEXAudit evidence and findings are shared through controlled, logged access.
Nothing matches that search.
Codes follow CSCRF's Govern, Identify, Protect, Detect, Respond and Recover structure. Summaries are QULDEX paraphrases of the circular and SEBI's FAQs, not legal advice.
Confirm your category for the financial year, close the gaps for it, set up SOC monitoring and recovery, then evidence everything for the cyber audit. Most REs need 3 to 9 months, depending on category.
Apply the thresholds to last year's data and record the category.
Assess each standard for your category, reusing ISO 27001 evidence.
CISO standing, board oversight, SBOMs and outsourcing contracts.
Onboard to a SOC or Market SOC; run VAPT and close findings within three months.
Meet RTO 2 hours and RPO 15 minutes for critical systems and run live drills.
Periodicities follow the financial year. Durations are QULDEX planning ranges.
Auditors and SEBI expect these records.
| Document | Standard | Where it lives in QULDEX |
|---|---|---|
| Category assessment for the year | Thresholds | Risk register |
| Cyber security and resilience policy | GV | Policy library |
| CISO appointment and board reviews | GV.RR | Policy library |
| Asset inventory with criticality | ID.AM | Risk register |
| SBOMs for critical software | GV.SC | Evidence vault |
| VAPT reports and closure evidence | ID.RA | CAPA automation |
| ISO 27001 certificate and scope | PR.IP | Evidence vault |
| SOC efficacy reports | DE.CM | Evidence vault |
| Incident reports | RS.MA | CAPA automation |
| DR drill reports (RTO/RPO) | RC.RP | Evidence vault |
| Cyber audit report and CCI | Audit, GV.OV | Audit workspace |
Document names follow CSCRF and SEBI's FAQs; storage locations are QULDEX recommendations.
Most REs need 3 to 9 months. Category, the number of critical systems, and whether you already hold ISO 27001 and a SOC drive the effort.
Bars show the upper end of each range on one scale (9 months = full width).
Check these eight things first. Nothing you enter leaves this page.
CSCRF follows NIST CSF 2.0 functions and expects ISO 27001 for key sites. Banks that also hold SEBI licences meet RBI's 2026 Directions too, so one control set should serve both.
| SEBI CSCRF | NIST CSF 2.0 | ISO 27001:2022 | RBI Directions 2026 | Shared evidence |
|---|---|---|---|---|
| GV.RR CISO | GV.RR | 5.3 | CISO and ISC | Appointments |
| GV.SC SBOM | GV.SC | A.5.19–A.5.22 | Third-party arrangements | SBOMs, vendor reviews |
| ID.AM Inventory | ID.AM | A.5.9 | IT asset management | Asset inventory |
| ID.RA VAPT | ID.RA | A.8.8 | VA and PT | Test reports |
| PR.AA Access | PR.AA | A.5.15–A.5.18 | User access management | Access reviews |
| DE.CM SOC | DE.CM | A.8.16 | C-SOC | SOC reports |
| RS.MA Incidents | RS.MA | A.5.24–A.5.26 | Incident reporting | Incident reports |
| RC.RP Recovery | RC.RP | A.5.30 | BCP and DR | Drill reports |
Indicative mapping for planning, not legal advice. RBI vs SEBI requirements are compared in full on the blog.
QULDEX is SEBI CSCRF compliance and audit management software built from EGV Group's audit delivery, used by regulated entities, their advisors and the cyber auditors who test them. Pick your role to see who does what.
For MIIs, brokers, AMCs, DPs and other REs.
For CSCRF consultants and internal audit.
For auditors meeting SEBI's selection norms.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →All SEBI-regulated entities, including MIIs, stock brokers, depository participants, mutual funds and AMCs, portfolio managers, KRAs and RTAs. Requirements depend on the entity's category.
Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The category is set at the start of each financial year from the previous year's data.
MIIs assess their cyber resilience using the CCI through a third party every half-year; Qualified REs self-assess every year.
For critical systems, declare a disaster within 30 minutes of disruption and recover with an RTO of 2 hours and an RPO of 15 minutes.
Yes, for the primary and DR data centres, near-DR site, SOC and co-location facility, including third parties providing those services.
DPDP, CERT-In, RBI and SEBI coverage.
blog.quldex.comThe RBI rules that apply alongside CSCRF for banks.
blog.quldex.comA file-naming scheme cyber auditors can follow.
blog.quldex.comHow many samples auditors look at.
Reviewed by
Answer a short readiness check and get a gap summary by function. No sales call needed to see the result.