Gap assessment against the baseline
Each numbered requirement assessed against evidence, with the shortfalls and a remediation plan carrying owners and dates — which the framework asks for explicitly.
Governance, Risk & Compliance
The RBI Cyber Security Framework is a baseline, which is a polite word for a floor. Inspections do not ask whether you have a policy covering each requirement; they ask to see the requirement working.
The framework sets an indicative baseline of cyber security and resilience requirements, a Cyber Security Operations Centre expectation, and an incident reporting obligation to the Reserve Bank. Larger institutions run it alongside the wider IT governance, risk and assurance expectations; smaller co-operative banks and NBFCs often meet it for the first time under inspection pressure.
Three findings recur. **The cyber security policy is folded into the IT policy** — the framework is explicit that it must be a distinct, board-approved document, and a combined one is a finding on its own. **Logs are collected but not reviewed**, which satisfies the letter of the audit-log requirement and none of its intent. And **backups exist but restoration has never been tested**, which is the difference between a resilience control and a resilience intention.
The fourth, and the one that costs most at inspection, is the C-SOC: it is assessed on functional efficacy. A monitoring contract that has never produced an alert anybody acted on does not evidence the requirement, however much it costs.
Coverage
The Annex-1 baseline, and the three annexures around it.
Each numbered requirement assessed against evidence, with the shortfalls and a remediation plan carrying owners and dates — which the framework asks for explicitly.
Distinct from the IT policy, owned at board level, and reviewed on a cycle you can show.
Whether the monitoring in place actually detects, analyses and drives response — tested, not assumed.
Periodic testing by a competent party, findings tracked to closure and retested. Our engagements evidence this requirement directly.
Collection, retention, protection from alteration, and a review rhythm that produces a record of having reviewed.
Backups protected from the same compromise as production, and restoration exercised with the result written down.
A tested plan, and the reporting path in the prescribed template within the timeline the circular sets.
Security obligations in contracts, assessment before onboarding, and continued monitoring in a register rather than a folder.
Approach
Assess against evidence, close with owners and dates, test what the framework says must be tested.
Every Annex-1 requirement assessed against real evidence. The output is the gap assessment and remediation plan the framework itself asks for.
Remediation with owners and dates, and the artefact for each requirement identified as it is closed rather than reconstructed later.
VAPT, restoration, incident response. The requirements that say "tested" are the ones inspections sample first.
Controls and evidence maintained in SemperWise One™, so the position holds between the assessment and the inspection.
In the platform
Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.
Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.
Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.
Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.
Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Requirement by requirement, with the evidence reviewed and the shortfall stated.
Owners, dates and dependencies — in the form the circular expects.
Findings verified, tracked and retested, mapped to the requirement they evidence.
Each requirement with its state, owner, test date and dated evidence, ready for inspection.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. The framework is a supervisory expectation set by the Reserve Bank, assessed through inspection and audit. There is no RBI cyber security certificate. What we provide is the gap assessment, the remediation, the testing and the evidence that stands up when it is examined.
RBI has extended cyber security expectations across regulated entity types, with requirements scaled to the entity. The practical answer for a smaller institution is that the baseline is the right reference point even where the full circular is not directly applicable — and the gap assessment establishes which requirements apply to you before any work starts.
Institutions subject to the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices should treat the cyber security framework as the cyber-resilience baseline inside that wider programme rather than as a separate exercise. We run both off one control set, which is the advantage of holding them in a single platform instead of two spreadsheets.
We assess C-SOC efficacy and can operate monitoring as a managed service. Where you already have a SOC, the more valuable engagement is usually the efficacy assessment — it is the part inspections probe, and the part most institutions have never had tested.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.