Governance, Risk & Compliance

CSCRF asks what you can do, not what you have written down.

SEBI's Cybersecurity and Cyber Resilience Framework replaced a decade of separate circulars with one structure built on the six NIST CSF 2.0 functions — and, unusually for an Indian circular, it measures capability rather than documentation.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
6Framework functions
5RE categories
CCIMeasured capability
SBOMFor critical systems

Why CSCRF is a different kind of circular

CSCRF organises its standards under Governance, Identify, Protect, Detect, Respond and Recover, and applies them differently across five categories of regulated entity — Market Infrastructure Institutions, Qualified REs, Mid-size, Small-size and Self-certification REs. The first piece of work on any CSCRF engagement is establishing which category you are in, because it determines everything that follows.

Two elements make it harder than what came before. The **Cyber Capability Index** turns cyber resilience into a measured number for the larger categories rather than a self-assessment narrative. And the framework brings in requirements that did not appear in the older circulars at all: **Software Bill of Materials for critical systems**, explicit **API security** controls, data localisation, and SOC assessed on functional efficacy rather than existence.

The classification of critical systems is where most of the risk sits. A system wrongly left out of that classification takes its entire control set with it, quietly, and the omission is not visible until somebody audits the classification itself.

Coverage

What we work on

Scaled to your RE category — not the same programme for a stock exchange and a small intermediary.

RE categorisation and applicability

Which category you fall into and which obligations therefore apply. Done first, because applying MII requirements to a Small-size RE produces a programme nobody can finish and findings that are not real.

Critical system classification

What counts as critical, and the defensible reasoning for what does not. The single highest-leverage decision in a CSCRF programme.

Cyber Capability Index

Preparation and measurement for the categories it applies to, and the evidence behind each contributing element.

SOC efficacy

Own, group or market SOC — assessed on whether it actually detects and drives response, which is how the framework assesses it.

VAPT on the prescribed cycle

Scope, frequency, closure and retest. Our engagements evidence this directly, and the findings map themselves to the CSCRF controls they affect.

SBOM for critical systems

Generated, maintained through releases, and actually used for dependency risk rather than filed.

API security

Authentication, authorisation, rate limiting, and an inventory that includes the endpoints nobody documented.

Incident reporting to SEBI and CERT-In

Two regulators, two timelines, one incident record. Plan to the tighter clock.

Approach

How the engagement runs

Category first, then critical systems, then the six functions. In that order, because everything depends on the first two.

  1. 01 · Categorise and scope

    RE category, critical systems, and the resulting applicability matrix. Everything else depends on this being right.

  2. 02 · Gap assessment across the six functions

    Governance, Identify, Protect, Detect, Respond, Recover — against evidence, function by function.

  3. 03 · Close, test and measure

    Remediation, VAPT, SOC efficacy, and CCI preparation where it applies.

  4. 04 · Maintain

    Controls, evidence and the reporting cycle held in SemperWise One™, so the next submission is a export rather than a project.

In the platform

What SemperWise One carries for this framework.

Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.

31
Clauses in the library

Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.

6
Artefacts collected automatically

Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.

22
Control subjects it spans

Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.

How the framework divides up

  • 9 Protect
  • 6 Governance
  • 4 Identify
  • 4 Detect
  • 4 Respond
  • 4 Recover

Evidence the platform gathers by itself

  • Who had access
  • Policies in force
  • Audit trail continuity
  • Security safeguards in force
  • Processors engaged
  • Where personal data goes

Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.

Already hold another framework? Most of the subjects here are ones your existing programme already covers. SemperWise One works out which, clause by clause, and proposes them — it never marks anything verified on your behalf, because verified means evidenced, and the evidence has to be pointed at this framework deliberately.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Applicability matrix

Your RE category, your critical systems, and exactly which obligations follow — with the reasoning for the exclusions.

Gap assessment across the six functions

Evidence-based, with the shortfalls ranked by regulatory exposure.

VAPT report mapped to CSCRF

Each finding mapped to the control it affects, tracked to closure and retested.

Submission-ready evidence

A live control register with dated artefacts, so the reporting cycle stops being a scramble.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You are a SEBI regulated entity and have not yet established which CSCRF category you fall into.
  • Your critical system classification has never been reviewed by anyone outside the team that wrote it.
  • You need a Cyber Capability Index measurement and do not know what feeds it.
  • You have no SBOM for systems the framework considers critical.
  • Your SOC exists on paper and has never been assessed for efficacy.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

SEBI CSCRF — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Is CSCRF a certification?

No. It is a regulatory framework, assessed through audit and reporting to SEBI. There is no CSCRF certificate. Note however that CSCRF *requires* ISO 27001 certification of the critical systems estate for Market Infrastructure Institutions and Qualified REs — and that certificate is issued by an accredited certification body, never by us. We run the readiness and the evidence; the certification body certifies.

Which RE category are we?

That is the first deliverable, not an assumption. The categories run from Market Infrastructure Institutions through Qualified, Mid-size and Small-size REs to Self-certification REs, and obligations differ substantially between them. Applying the wrong category is expensive in both directions — over-scoping produces a programme you cannot finish, under-scoping produces findings.

Does CSCRF replace the older SEBI cyber circulars?

CSCRF was issued to consolidate and supersede the earlier cybersecurity and cyber resilience circulars for regulated entities, and to align them to a single structure. Where an entity is subject to transitional arrangements, the applicability work at the start of the engagement establishes what currently binds you.

What is the Cyber Capability Index actually measuring?

It converts cyber resilience into a measured index rather than a narrative self-assessment, across defined capability areas. The practical consequence is that evidence quality matters directly to the score — which is the reason to hold the evidence in a system that dates and expires it rather than in a shared drive.

Can our findings from a penetration test feed the framework directly?

Yes, and that is the advantage of running both in one platform. A finding from a SemperWise engagement arrives mapped to the CSCRF controls it affects — alongside ISO 27001 and anything else you track — so remediation and control status move together instead of being reconciled by hand.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.