{"id":1010,"date":"2026-08-24T19:00:39","date_gmt":"2026-08-24T19:00:39","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1010"},"modified":"2026-08-24T19:00:39","modified_gmt":"2026-08-24T19:00:39","slug":"resources-glossary-cscrf","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-cscrf\/","title":{"rendered":"CSCRF: SEBI Cybersecurity and Cyber Resilience Framework"},"content":{"rendered":"\n<!-- OSTO GLOSSARY: CSCRF. Paste into one Custom HTML block. No H1. -->\n<style>\n.og{--navy:#1c267a;--text:#0f1538;--divider:#eceef5;--white:#fff;--peri-50:#f4f5fd;--peri-100:#e9ecfa;--peri-200:#cfd5f2;--peri-700:#4a52a8;--sage-50:#f2f8f5;--sage-100:#e3f0e9;--sage-200:#c3ddce;--sage-700:#3a6f5d;--apri-50:#fdf6f0;--apri-100:#fbe9dc;--apri-200:#f2cdb2;--apri-700:#a2603a;--plum-50:#f8f3f9;--plum-100:#f0e6f3;--plum-200:#dcc6e2;--plum-700:#6b4576;--sky-50:#f1f7fb;--sky-100:#e2eff7;--sky-200:#bfd9e9;--sky-700:#2f6a89;--shadow:0 6px 22px rgba(15,21,56,.05);--font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-family:var(--font);font-size:17px;line-height:1.75;color:var(--text)}\n.og p{margin:0 0 22px}.og h2{font:700 clamp(25px,3vw,31px)\/1.25 var(--font);letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}.og h2:after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}.og h2.c-sage:after{background:var(--sage-200)}.og h2.c-apri:after{background:var(--apri-200)}.og h2.c-plum:after{background:var(--plum-200)}.og h2.c-sky:after{background:var(--sky-200)}.og h3{font:700 20px\/1.4 var(--font);color:var(--navy);margin:28px 0 8px}.og ul,.og ol{padding-left:22px;margin:0 0 24px}.og li{margin-bottom:9px}.og strong{font-weight:600}.og a{color:var(--navy);text-underline-offset:3px}\n.og .dek{font-size:20px;line-height:1.6;margin:0 0 18px}.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}.og .tags li{margin:0}.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}.og .t-peri{background:var(--peri-100);color:var(--peri-700)}.og .t-sage{background:var(--sage-100);color:var(--sage-700)}.og .t-apri{background:var(--apri-100);color:var(--apri-700)}\n.og .short{background:linear-gradient(135deg,var(--peri-100),var(--sage-100));border-radius:22px;padding:28px 32px;margin:0 0 30px}.og .short .k,.og .toc .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}.og .short p{font-size:19px;line-height:1.65;margin:0}.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}.og .toc a{text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}.og .callout p:last-child{margin-bottom:0}.og .callout.c-plum,.og .callout.c-apri{border:none;border-radius:20px}.og .callout.c-plum{background:var(--plum-50)}.og .callout.c-plum .k{color:var(--plum-700)}.og .callout.c-apri{background:var(--apri-50)}.og .callout.c-apri .k{color:var(--apri-700)}\n.og figure{margin:0 0 30px}.og .sx{overflow-x:auto;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}.og .sx svg{display:block;width:100%;height:auto;min-width:650px}.og figcaption{font-size:14px;line-height:1.6;margin-top:12px}.og .swipe{display:none}\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}.og tr:last-child td{border-bottom:none}.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}.og .h-apri th{background:var(--apri-100);color:var(--apri-700)}\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}.og .tcard{border-radius:18px;padding:20px 22px}.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}.og .tcard p{font-size:14px;line-height:1.55;margin:0}.og .tcard.a{background:var(--sky-50)}.og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}.og .tcard.b{background:var(--sage-50)}.og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}.og .tcard.c{background:var(--plum-50)}.og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}.og .p-six{background:var(--apri-100);color:var(--apri-700)}.og .p-day{background:var(--plum-100);color:var(--plum-700)}.og .p-month{background:var(--sage-100);color:var(--sage-700)}\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px}.og summary::-webkit-details-marker{display:none}.og summary:after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700)}.og details[open] summary:after{content:\"\\2013\"}.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}.og .related{font-size:15px;border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n@media(max-width:700px){.og{font-size:16px}.og .dek{font-size:18px}.og .short p{font-size:17px}.og .short,.og .toc,.og .callout{padding:22px 20px}.og .toc ol{columns:1}.og .trio{grid-template-columns:1fr}.og .swipe{display:inline;font-weight:600;color:var(--peri-700)}.og table{font-size:14px}.og th,.og td{padding:11px 12px}}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">CSCRF is SEBI&#8217;s common cybersecurity rulebook for regulated entities in India&#8217;s securities market, covering governance, protection, monitoring, incident response, recovery, audits and reporting.<\/p>\n<ul class=\"tags\"><li><span class=\"tag t-peri\">Glossary<\/span><\/li><li><span class=\"tag t-sage\">SEBI compliance<\/span><\/li><li><span class=\"tag t-apri\">Cyber resilience<\/span><\/li><\/ul>\n<div class=\"short\"><p class=\"k\">The short answer<\/p><p>CSCRF stands for <strong>Cybersecurity and Cyber Resilience Framework<\/strong>. Issued by SEBI in August 2024, it replaces multiple earlier cybersecurity circulars with one standards-based framework for SEBI-regulated entities. Requirements vary by the entity&#8217;s category, but the framework expects every entity to govern cyber risk, identify assets, protect systems, detect attacks, respond quickly and recover services.<\/p><\/div>\n<p>CSCRF is not only an IT checklist. It connects board oversight, vendor risk, application and API security, SOC monitoring, incident reporting, cyber audits, VAPT and recovery testing. The evidence must show that these controls operate, not merely that policies exist.<\/p>\n<div class=\"toc\"><p class=\"k\">On this page<\/p><ol><li><a href=\"#meaning\">What CSCRF means<\/a><\/li><li><a href=\"#applies\">Who CSCRF applies to<\/a><\/li><li><a href=\"#model\">The CSCRF operating model<\/a><\/li><li><a href=\"#controls\">What the framework requires<\/a><\/li><li><a href=\"#reporting\">Reporting and audit timelines<\/a><\/li><li><a href=\"#readiness\">Practical readiness checklist<\/a><\/li><li><a href=\"#osto\">How Osto supports CSCRF<\/a><\/li><li><a href=\"#faq\">FAQ<\/a><\/li><\/ol><\/div>\n\n<h2 id=\"meaning\">What CSCRF means<\/h2>\n<div class=\"trio\"><div class=\"tcard a\"><p class=\"n\">Cybersecurity<\/p><p class=\"g\">Prevent and detect<\/p><p>Protect systems, applications, networks, data and users against unauthorised access, disruption and attack.<\/p><\/div><div class=\"tcard b\"><p class=\"n\">Cyber resilience<\/p><p class=\"g\">Continue and recover<\/p><p>Maintain critical services during an incident and restore them safely within defined objectives.<\/p><\/div><div class=\"tcard c\"><p class=\"n\">Compliance evidence<\/p><p class=\"g\">Prove and report<\/p><p>Use standard reporting, audits, VAPT, incident records and closure evidence to show that controls work.<\/p><\/div><\/div>\n<p>The framework is standards-based and aligns cyber resilience with CERT-In&#8217;s Cyber Crisis Management Plan. It also standardises how regulated entities report compliance and audit outcomes.<\/p>\n\n<h2 id=\"applies\" class=\"c-plum\">Who does CSCRF apply to?<\/h2>\n<p>CSCRF covers a wide set of SEBI-regulated entities, including stock exchanges, clearing corporations, depositories, stock brokers, depository participants, mutual funds and AMCs, AIFs, portfolio managers, investment advisers, research analysts, merchant bankers, credit rating agencies, custodians, KRAs, RTAs, debenture trustees and other securities-market intermediaries named by SEBI.<\/p>\n<table class=\"h-plum\"><thead><tr><th>CSCRF category<\/th><th>How the framework treats it<\/th><\/tr><\/thead><tbody><tr><td><strong>Market Infrastructure Institutions<\/strong><\/td><td>The most systemically important market institutions, subject to the broadest requirements and CCI assessment.<\/td><\/tr><tr><td><strong>Qualified REs<\/strong><\/td><td>Larger regulated entities crossing the relevant operational thresholds, also covered by CCI requirements.<\/td><\/tr><tr><td><strong>Mid-size REs<\/strong><\/td><td>Entities in the middle threshold band, with requirements scaled to their size and exposure.<\/td><\/tr><tr><td><strong>Small-size REs<\/strong><\/td><td>Smaller entities with a reduced but still substantive control baseline.<\/td><\/tr><tr><td><strong>Self-certification REs<\/strong><\/td><td>The smallest category, allowed a simplified compliance route but still required to complete applicable controls and VAPT.<\/td><\/tr><\/tbody><\/table>\n<div class=\"callout c-plum\"><p class=\"k\">The category changes the depth, not the need for security<\/p><p>CSCRF follows a graded approach based on factors such as client count, trading volume and assets under management. Smaller entities receive proportionate requirements; they are not exempt from cybersecurity or resilience.<\/p><\/div>\n\n<h2 id=\"model\" class=\"c-sage\">The CSCRF operating model<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 350\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"CSCRF operating model linking six cybersecurity functions to five cyber resilience goals.\"><defs><marker id=\"ca\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#4a52a8\"\/><\/marker><\/defs><text x=\"390\" y=\"34\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">SIX CYBERSECURITY FUNCTIONS<\/text><g font-family=\"Inter\" font-size=\"12\" font-weight=\"700\" text-anchor=\"middle\"><rect x=\"25\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#e9ecfa\"\/><text x=\"77\" y=\"87\" fill=\"#4a52a8\">Governance<\/text><rect x=\"150\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#e2eff7\"\/><text x=\"202\" y=\"87\" fill=\"#2f6a89\">Identify<\/text><rect x=\"275\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#e3f0e9\"\/><text x=\"327\" y=\"87\" fill=\"#3a6f5d\">Protect<\/text><rect x=\"400\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#fbe9dc\"\/><text x=\"452\" y=\"87\" fill=\"#a2603a\">Detect<\/text><rect x=\"525\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#f0e6f3\"\/><text x=\"577\" y=\"87\" fill=\"#6b4576\">Respond<\/text><rect x=\"650\" y=\"58\" width=\"105\" height=\"48\" rx=\"12\" fill=\"#e9ecfa\"\/><text x=\"702\" y=\"87\" fill=\"#4a52a8\">Recover<\/text><\/g><line x1=\"390\" y1=\"125\" x2=\"390\" y2=\"165\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ca)\"\/><text x=\"390\" y=\"196\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">FIVE RESILIENCE GOALS<\/text><g font-family=\"Inter\" font-size=\"12\" font-weight=\"700\" text-anchor=\"middle\"><rect x=\"52\" y=\"222\" width=\"122\" height=\"52\" rx=\"26\" fill=\"#f4f5fd\"\/><text x=\"113\" y=\"253\" fill=\"#4a52a8\">Anticipate<\/text><rect x=\"191\" y=\"222\" width=\"122\" height=\"52\" rx=\"26\" fill=\"#f1f7fb\"\/><text x=\"252\" y=\"253\" fill=\"#2f6a89\">Withstand<\/text><rect x=\"330\" y=\"222\" width=\"122\" height=\"52\" rx=\"26\" fill=\"#fdf6f0\"\/><text x=\"391\" y=\"253\" fill=\"#a2603a\">Contain<\/text><rect x=\"469\" y=\"222\" width=\"122\" height=\"52\" rx=\"26\" fill=\"#f8f3f9\"\/><text x=\"530\" y=\"253\" fill=\"#6b4576\">Recover<\/text><rect x=\"608\" y=\"222\" width=\"122\" height=\"52\" rx=\"26\" fill=\"#f2f8f5\"\/><text x=\"669\" y=\"253\" fill=\"#3a6f5d\">Evolve<\/text><\/g><text x=\"390\" y=\"322\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"12.5\" fill=\"#0f1538\">Security is a cycle: prepare, resist, limit impact, restore service and improve.<\/text><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The six operating functions organise the controls; the five goals describe the resilience outcome.<\/figcaption><\/figure>\n<p><strong>Governance<\/strong> assigns ownership and oversight. <strong>Identify<\/strong> maps assets, data and risks. <strong>Protect<\/strong> deploys controls. <strong>Detect<\/strong> monitors for anomalies. <strong>Respond<\/strong> contains and manages incidents. <strong>Recover<\/strong> restores services and feeds lessons back into the programme.<\/p>\n\n<h2 id=\"controls\" class=\"c-sky\">What the framework requires<\/h2>\n<table class=\"h-peri\"><thead><tr><th>Control area<\/th><th>What implementation looks like<\/th><\/tr><\/thead><tbody><tr><td><strong>Governance and risk<\/strong><\/td><td>Board and IT Committee oversight, named accountability, policies, a current <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">cyber risk assessment<\/a>, risk treatment and periodic review.<\/td><\/tr><tr><td><strong>Asset and data management<\/strong><\/td><td>Inventories of hardware, software, information assets and dependencies; data classification, retention and localisation controls.<\/td><\/tr><tr><td><strong>Identity and access<\/strong><\/td><td>Least privilege, segregation of duties, privileged-access governance, periodic access review and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a>.<\/td><\/tr><tr><td><strong>Application and API security<\/strong><\/td><td>Secure development, separated production and non-production environments, change controls, testing, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a>.<\/td><\/tr><tr><td><strong>Vulnerability management<\/strong><\/td><td>Scanning, patching, configuration review and <a href=\"https:\/\/www.osto.one\/resources\/blog\/what-is-vapt\/\">VAPT<\/a> covering infrastructure, web applications, APIs, mobile apps, cloud and segmentation.<\/td><\/tr><tr><td><strong>Cloud, SaaS and suppliers<\/strong><\/td><td>Due diligence, contractual responsibilities, hosted-service controls, supply-chain risk management and continuous <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture monitoring<\/a>.<\/td><\/tr><tr><td><strong>Software supply chain<\/strong><\/td><td>Maintain a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">software bill of materials<\/a>, manage dependencies and address third-party component risk.<\/td><\/tr><tr><td><strong>Data protection<\/strong><\/td><td>Encryption, backups, access controls and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a> appropriate to the data classification.<\/td><\/tr><tr><td><strong>Security monitoring<\/strong><\/td><td>Continuous event monitoring through an own, group, market or managed SOC, supported by endpoint and network telemetry such as <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a>.<\/td><\/tr><tr><td><strong>Incident and recovery<\/strong><\/td><td>Documented response, containment, communications, evidence preservation, recovery plans, exercises and post-incident improvement.<\/td><\/tr><\/tbody><\/table>\n<div class=\"callout\"><p class=\"k\">Every regulated entity needs monitoring<\/p><p>CSCRF requires appropriate security monitoring through a Security Operations Centre. The entity may use its own SOC, a group SOC, a market SOC or another managed SOC, depending on its category and operating model.<\/p><\/div>\n\n<h3>Where the framework goes beyond a basic security policy<\/h3>\n<div class=\"trio\"><div class=\"tcard a\"><p class=\"n\">Coverage<\/p><p class=\"g\">Critical systems first<\/p><p>Cyber audits must cover 100% of critical systems and document the sampling approach for non-critical systems.<\/p><\/div><div class=\"tcard b\"><p class=\"n\">Testing<\/p><p class=\"g\">Not only web apps<\/p><p>VAPT scope includes infrastructure, APIs, mobile apps, Wi-Fi, databases, cloud implementation and segmentation.<\/p><\/div><div class=\"tcard c\"><p class=\"n\">Evidence<\/p><p class=\"g\">Keep the proof<\/p><p>Audit evidence, observations, remediation decisions and closure records may be scrutinised during regulatory inspection.<\/p><\/div><\/div>\n\n<h2 id=\"reporting\" class=\"c-apri\">Incident reporting and cyber audit timelines<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 270\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"CSCRF incident and audit timeline showing six hours, 24 hours, one month, three months and five months.\"><line x1=\"70\" y1=\"132\" x2=\"710\" y2=\"132\" stroke=\"#cfd5f2\" stroke-width=\"6\" stroke-linecap=\"round\"\/><g font-family=\"Inter\" text-anchor=\"middle\"><circle cx=\"90\" cy=\"132\" r=\"16\" fill=\"#1c267a\"\/><text x=\"90\" y=\"76\" font-size=\"21\" font-weight=\"700\" fill=\"#1c267a\">6 hours<\/text><text x=\"90\" y=\"101\" font-size=\"11.5\" fill=\"#0f1538\">specified incidents<\/text><text x=\"90\" y=\"179\" font-size=\"11.5\" fill=\"#0f1538\">SEBI and CERT-In<\/text><circle cx=\"245\" cy=\"132\" r=\"16\" fill=\"#a2603a\"\/><text x=\"245\" y=\"76\" font-size=\"21\" font-weight=\"700\" fill=\"#a2603a\">24 hours<\/text><text x=\"245\" y=\"101\" font-size=\"11.5\" fill=\"#0f1538\">portal detail \/ other<\/text><text x=\"245\" y=\"179\" font-size=\"11.5\" fill=\"#0f1538\">reportable incidents<\/text><circle cx=\"400\" cy=\"132\" r=\"16\" fill=\"#4a52a8\"\/><text x=\"400\" y=\"76\" font-size=\"21\" font-weight=\"700\" fill=\"#4a52a8\">1 month<\/text><text x=\"400\" y=\"101\" font-size=\"11.5\" fill=\"#0f1538\">after audit completion<\/text><text x=\"400\" y=\"179\" font-size=\"11.5\" fill=\"#0f1538\">submit final report<\/text><circle cx=\"555\" cy=\"132\" r=\"16\" fill=\"#3a6f5d\"\/><text x=\"555\" y=\"76\" font-size=\"21\" font-weight=\"700\" fill=\"#3a6f5d\">3 months<\/text><text x=\"555\" y=\"101\" font-size=\"11.5\" fill=\"#0f1538\">after report submission<\/text><text x=\"555\" y=\"179\" font-size=\"11.5\" fill=\"#0f1538\">close findings<\/text><circle cx=\"700\" cy=\"132\" r=\"16\" fill=\"#6b4576\"\/><text x=\"700\" y=\"76\" font-size=\"21\" font-weight=\"700\" fill=\"#6b4576\">5 months<\/text><text x=\"700\" y=\"101\" font-size=\"11.5\" fill=\"#0f1538\">after cyber audit<\/text><text x=\"700\" y=\"179\" font-size=\"11.5\" fill=\"#0f1538\">follow-on audit<\/text><text x=\"390\" y=\"238\" font-size=\"12.5\" fill=\"#0f1538\">The incident and audit clocks are separate; both require evidence and named ownership.<\/text><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full timeline. <\/span>Exact applicability and reporting route depend on the incident and the RE category.<\/figcaption><\/figure>\n<table class=\"h-apri\"><thead><tr><th>Event<\/th><th>Core CSCRF timeline<\/th><\/tr><\/thead><tbody><tr><td><strong>CERT-In Directions incident<\/strong><\/td><td><span class=\"pill p-six\">6 hours<\/span> Notify SEBI and CERT-In after noticing, detecting or being informed of the incident.<\/td><\/tr><tr><td><strong>SEBI incident portal detail<\/strong><\/td><td><span class=\"pill p-day\">24 hours<\/span> Submit the necessary incident details through the prescribed portal.<\/td><\/tr><tr><td><strong>Other cybersecurity incidents<\/strong><\/td><td><span class=\"pill p-day\">24 hours<\/span> Report to SEBI, CERT-In and NCIIPC where applicable.<\/td><\/tr><tr><td><strong>Final cyber audit report<\/strong><\/td><td><span class=\"pill p-month\">1 month<\/span> Submit after cyber-audit completion and IT Committee approval.<\/td><\/tr><tr><td><strong>Audit finding closure<\/strong><\/td><td><span class=\"pill p-month\">3 months<\/span> Close observations after report submission, following a graded criticality approach.<\/td><\/tr><tr><td><strong>Follow-on audit<\/strong><\/td><td><span class=\"pill p-month\">5 months<\/span> Complete after the original cyber audit.<\/td><\/tr><\/tbody><\/table>\n<div class=\"callout c-apri\"><p class=\"k\">Do not wait for the reporting clock to start<\/p><p>Six-hour reporting is impossible without a defined severity model, monitored alert sources, current contact details, an escalation matrix and pre-approved reporting steps. Build and rehearse that workflow before an incident.<\/p><\/div>\n\n<h3>Cyber Capability Index<\/h3><p>MIIs and Qualified REs use the Cyber Capability Index (CCI) to assess cybersecurity preparedness and resilience periodically. The index uses weighted parameters to turn maturity into a measurable score, so progress can be tracked rather than described only in narrative form.<\/p>\n\n<h2 id=\"readiness\">Practical CSCRF readiness checklist<\/h2>\n<ol><li><strong>Confirm the entity category.<\/strong> Record why the RE is an MII, Qualified, Mid-size, Small-size or Self-certification entity and map the applicable standards.<\/li><li><strong>Build a compliance matrix.<\/strong> Assign an owner, implementation, evidence source and review frequency to every applicable standard and mandatory guideline.<\/li><li><strong>Inventory assets and data.<\/strong> Include cloud accounts, endpoints, applications, APIs, databases, network devices, vendors, SaaS systems and critical dependencies.<\/li><li><strong>Complete cyber risk assessment.<\/strong> Link priority risks to controls, budgets, owners, due dates and accepted residual risk.<\/li><li><strong>Deploy prevention and detection.<\/strong> Cover identity, endpoints, networks, applications, APIs, cloud posture, email, data and logs.<\/li><li><strong>Establish SOC coverage.<\/strong> Define monitoring scope, alert severity, triage ownership, escalation and evidence retention.<\/li><li><strong>Run complete VAPT.<\/strong> Use the applicable CERT-In-empanelled audit route and cover the entire required scope, not only the public website.<\/li><li><strong>Test response and recovery.<\/strong> Exercise a realistic incident, measure detection and recovery, and record what changed afterwards.<\/li><li><strong>Prepare reporting.<\/strong> Keep SEBI, CERT-In, NCIIPC, exchange and depository routes current, with a workflow capable of meeting six-hour and 24-hour deadlines.<\/li><li><strong>Track audit closure.<\/strong> Route findings through the IT Committee, preserve remediation proof and close observations before the next audit.<\/li><\/ol>\n\n<h2 id=\"osto\" class=\"c-sage\">How Osto supports CSCRF readiness<\/h2>\n<p>Osto brings the technical controls behind CSCRF into one operating view across cloud, applications, APIs, code, endpoints, identities, data and networks. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">Web application protection<\/a>, API protection, CSPM, SAST, SBOM, DLP, endpoint detection and vulnerability testing generate evidence while they run.<\/p>\n<p>That evidence can be mapped to the applicable CSCRF standards, assigned to owners and tracked through remediation. Instead of reconstructing the audit trail from separate dashboards and vendor reports, the RE can connect the requirement, the live control, the finding and the closure record.<\/p>\n<p class=\"related\"><strong>Primary sources:<\/strong> <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI CSCRF Circular, 20 August 2024<\/a> and subsequent SEBI clarifications. This glossary is an operational overview, not legal advice.<\/p>\n\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center\"><p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#fff;font:700 11px Inter,sans-serif;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px\">Free CSCRF readiness assessment<\/p><p style=\"color:#fff;font:700 26px\/1.3 Inter,sans-serif;letter-spacing:-.4px;margin:0 0 12px\">Turn CSCRF controls into live evidence<\/p><p style=\"color:#cfd3ea;font:16px\/1.65 Inter,sans-serif;margin:0 auto 26px;max-width:520px\">Map the applicable requirements, deploy the security controls and keep audit-ready evidence across one platform.<\/p><a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#fff;color:#1c267a;font:700 16px Inter,sans-serif;text-decoration:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px\" target=\"_blank\" rel=\"noopener\">Get a free security assessment<\/a><a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#fff;font:600 16px Inter,sans-serif;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px\" target=\"_blank\" rel=\"noopener\">Book a platform walkthrough<\/a><p style=\"color:#b3b8d8;font:13px Inter,sans-serif;margin:14px 0 0\">Security controls \u00b7 Audit evidence \u00b7 One platform, everything<\/p><\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details><summary>What does CSCRF stand for?<\/summary><p>CSCRF stands for Cybersecurity and Cyber Resilience Framework. It is SEBI&#8217;s consolidated cybersecurity framework for regulated entities in India&#8217;s securities market.<\/p><\/details><details><summary>Who must comply with CSCRF?<\/summary><p>SEBI-regulated entities covered by the framework, including market infrastructure institutions and securities-market intermediaries. The exact requirements depend on the RE&#8217;s category and applicable thresholds.<\/p><\/details><details><summary>What are the six CSCRF functions?<\/summary><p>Governance, Identify, Protect, Detect, Respond and Recover. Together they organise the cybersecurity controls across the full lifecycle.<\/p><\/details><details><summary>What are the five cyber resilience goals?<\/summary><p>Anticipate, Withstand, Contain, Recover and Evolve. They describe how an entity should prepare for an attack, limit its effect, restore services and improve afterwards.<\/p><\/details><details><summary>Does every regulated entity need a SOC?<\/summary><p>Every RE needs appropriate security monitoring through a SOC mechanism. Depending on its category and model, it may use its own SOC, a group SOC, a market SOC or a third-party managed SOC.<\/p><\/details><details><summary>Does CSCRF require VAPT?<\/summary><p>Yes, for applicable entities. The prescribed scope extends beyond a website to infrastructure, applications, APIs, mobile applications, Wi-Fi, network segmentation, operating systems, databases, cloud implementation and configuration.<\/p><\/details><details><summary>How quickly must a cyber incident be reported?<\/summary><p>Specified incidents falling under CERT-In directions must be notified to SEBI and CERT-In within six hours. Necessary portal details follow within 24 hours, while other cybersecurity incidents generally have a 24-hour reporting requirement. The exact route depends on the entity and incident.<\/p><\/details><details><summary>What is the Cyber Capability Index?<\/summary><p>CCI is SEBI&#8217;s index for rating the cybersecurity preparedness and resilience of MIIs and Qualified REs using weighted maturity parameters.<\/p><\/details><details><summary>Is ISO 27001 enough for CSCRF compliance?<\/summary><p>No. ISO 27001 provides a strong security-management foundation, but CSCRF adds SEBI-specific categorisation, mandatory controls, reporting formats, incident timelines, audit rules, SOC expectations and CCI requirements.<\/p><\/details>\n<p class=\"related\"><strong>Continue reading:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/blog\/what-is-vapt\/\">What Is VAPT?<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CSCRF is SEBI&#8217;s common cybersecurity rulebook for regulated entities in India&#8217;s securities market, covering governance, protection, monitoring, incident response, recovery,\u2026<\/p>\n","protected":false},"author":8,"featured_media":1011,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[460,461,462],"class_list":["post-1010","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-cscrf","tag-cyber-security-and-cyber-resilience-framework","tag-sebi-cscrf"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1010"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1010\/revisions"}],"predecessor-version":[{"id":1012,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1010\/revisions\/1012"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1011"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}