RE categorisation and applicability
Which category you fall into and which obligations therefore apply. Done first, because applying MII requirements to a Small-size RE produces a programme nobody can finish and findings that are not real.
Governance, Risk & Compliance
SEBI's Cybersecurity and Cyber Resilience Framework replaced a decade of separate circulars with one structure built on the six NIST CSF 2.0 functions — and, unusually for an Indian circular, it measures capability rather than documentation.
CSCRF organises its standards under Governance, Identify, Protect, Detect, Respond and Recover, and applies them differently across five categories of regulated entity — Market Infrastructure Institutions, Qualified REs, Mid-size, Small-size and Self-certification REs. The first piece of work on any CSCRF engagement is establishing which category you are in, because it determines everything that follows.
Two elements make it harder than what came before. The **Cyber Capability Index** turns cyber resilience into a measured number for the larger categories rather than a self-assessment narrative. And the framework brings in requirements that did not appear in the older circulars at all: **Software Bill of Materials for critical systems**, explicit **API security** controls, data localisation, and SOC assessed on functional efficacy rather than existence.
The classification of critical systems is where most of the risk sits. A system wrongly left out of that classification takes its entire control set with it, quietly, and the omission is not visible until somebody audits the classification itself.
Coverage
Scaled to your RE category — not the same programme for a stock exchange and a small intermediary.
Which category you fall into and which obligations therefore apply. Done first, because applying MII requirements to a Small-size RE produces a programme nobody can finish and findings that are not real.
What counts as critical, and the defensible reasoning for what does not. The single highest-leverage decision in a CSCRF programme.
Preparation and measurement for the categories it applies to, and the evidence behind each contributing element.
Own, group or market SOC — assessed on whether it actually detects and drives response, which is how the framework assesses it.
Scope, frequency, closure and retest. Our engagements evidence this directly, and the findings map themselves to the CSCRF controls they affect.
Generated, maintained through releases, and actually used for dependency risk rather than filed.
Authentication, authorisation, rate limiting, and an inventory that includes the endpoints nobody documented.
Two regulators, two timelines, one incident record. Plan to the tighter clock.
Approach
Category first, then critical systems, then the six functions. In that order, because everything depends on the first two.
RE category, critical systems, and the resulting applicability matrix. Everything else depends on this being right.
Governance, Identify, Protect, Detect, Respond, Recover — against evidence, function by function.
Remediation, VAPT, SOC efficacy, and CCI preparation where it applies.
Controls, evidence and the reporting cycle held in SemperWise One™, so the next submission is a export rather than a project.
In the platform
Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.
Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.
Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.
Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.
Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Your RE category, your critical systems, and exactly which obligations follow — with the reasoning for the exclusions.
Evidence-based, with the shortfalls ranked by regulatory exposure.
Each finding mapped to the control it affects, tracked to closure and retested.
A live control register with dated artefacts, so the reporting cycle stops being a scramble.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. It is a regulatory framework, assessed through audit and reporting to SEBI. There is no CSCRF certificate. Note however that CSCRF *requires* ISO 27001 certification of the critical systems estate for Market Infrastructure Institutions and Qualified REs — and that certificate is issued by an accredited certification body, never by us. We run the readiness and the evidence; the certification body certifies.
That is the first deliverable, not an assumption. The categories run from Market Infrastructure Institutions through Qualified, Mid-size and Small-size REs to Self-certification REs, and obligations differ substantially between them. Applying the wrong category is expensive in both directions — over-scoping produces a programme you cannot finish, under-scoping produces findings.
CSCRF was issued to consolidate and supersede the earlier cybersecurity and cyber resilience circulars for regulated entities, and to align them to a single structure. Where an entity is subject to transitional arrangements, the applicability work at the start of the engagement establishes what currently binds you.
It converts cyber resilience into a measured index rather than a narrative self-assessment, across defined capability areas. The practical consequence is that evidence quality matters directly to the score — which is the reason to hold the evidence in a system that dates and expires it rather than in a shared drive.
Yes, and that is the advantage of running both in one platform. A finding from a SemperWise engagement arrives mapped to the CSCRF controls it affects — alongside ISO 27001 and anything else you track — so remediation and control status move together instead of being reconciled by hand.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.