{"id":1049,"date":"2026-08-31T16:07:39","date_gmt":"2026-08-31T16:07:39","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1049"},"modified":"2026-08-31T16:08:29","modified_gmt":"2026-08-31T16:08:29","slug":"sebi-cscrf-compliance","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/sebi-cscrf-compliance\/","title":{"rendered":"SEBI CSCRF Compliance: Guide for Regulated Entities"},"content":{"rendered":"\n<style>\n.osto-cscrf{\n  --osto-blue:#1C267A;\n  --osto-blue-2:#3445C5;\n  --text:#15172A;\n  --body:#45495A;\n  --muted:#707589;\n  --line:#E7E9F2;\n  --soft:#F8F9FC;\n  --soft-blue:#F0F4FF;\n  --pastel-blue:#EAF1FF;\n  --pastel-mint:#EAF8F4;\n  --pastel-lilac:#F2ECFF;\n  --pastel-peach:#FFF2E8;\n  color:var(--text);\n  font-family:Inter, ui-sans-serif, -apple-system, BlinkMacSystemFont, \"Segoe UI\", sans-serif;\n  font-size:17px;\n  line-height:1.72;\n  max-width:900px;\n  margin:0 auto;\n}\n.osto-cscrf *{box-sizing:border-box}\n.osto-cscrf p{margin:0 0 18px;color:var(--body)}\n.osto-cscrf strong{color:var(--text)}\n.osto-cscrf h2{\n  margin:48px 0 16px;\n  font-size:30px;\n  line-height:1.24;\n  letter-spacing:-.02em;\n  font-weight:700;\n  color:var(--text);\n}\n.osto-cscrf h3{\n  margin:0 0 7px;\n  font-size:20px;\n  line-height:1.35;\n  font-weight:700;\n  color:var(--text);\n}\n.osto-cscrf a{color:var(--osto-blue);text-decoration:underline;text-decoration-thickness:1px;text-underline-offset:3px}\n.osto-cscrf .lead{font-size:19px;line-height:1.65;color:#333744;margin:0 0 30px}\n\n\/* Osto-style short summary block *\/\n.osto-cscrf .tldr{border:1px solid #DDE4FF;border-radius:14px;padding:24px 26px;margin:30px 0;background:linear-gradient(135deg,#F8FAFF 0%,#F1F5FF 100%)}\n.osto-cscrf .tldr h2{font-size:20px;line-height:1.3;color:var(--osto-blue);margin:0 0 9px;letter-spacing:0}\n.osto-cscrf .tldr p{margin-bottom:10px}\n.osto-cscrf .tldr p:last-child{margin-bottom:0}\n\n\/* Same restrained contents pattern used across Osto resources *\/\n.osto-cscrf .toc{margin:32px 0 38px;padding:20px 0;border-top:1px solid var(--line);border-bottom:1px solid var(--line)}\n.osto-cscrf .toc-title{font-size:14px;font-weight:700;color:var(--text);margin-bottom:10px}\n.osto-cscrf .toc ol{margin:0;padding-left:20px;columns:2;column-gap:38px}\n.osto-cscrf .toc li{margin:6px 0;break-inside:avoid;color:var(--body)}\n.osto-cscrf .toc a{text-decoration:none;color:#34384A}\n.osto-cscrf .toc a:hover{color:var(--osto-blue)}\n\n\/* Inline editorial diagrams, kept visual and low-text *\/\n.osto-cscrf .diagram{margin:26px 0 36px;padding:24px;border:1px solid #E1E5F4;border-radius:16px;background:linear-gradient(180deg,#FFFFFF 0%,#FBFCFF 100%);overflow:hidden;box-shadow:0 8px 28px rgba(28,38,122,.05)}\n.osto-cscrf .diagram-kicker{font-size:12px;line-height:1.2;font-weight:700;text-transform:uppercase;letter-spacing:.08em;color:var(--osto-blue);margin-bottom:7px}\n.osto-cscrf .diagram-title{font-size:18px;line-height:1.35;font-weight:700;color:var(--text);margin-bottom:18px}\n.osto-cscrf .diagram-note{font-size:13px;color:var(--muted);margin-top:14px;margin-bottom:0}\n\n\/* Five resilience outcomes *\/\n.osto-cscrf .outcomes{display:grid;grid-template-columns:repeat(5,minmax(0,1fr));gap:8px}\n.osto-cscrf .outcome{position:relative;text-align:center;padding:17px 8px 15px;background:var(--soft);border-radius:9px;min-height:92px}\n.osto-cscrf .outcome .num{display:flex;align-items:center;justify-content:center;width:28px;height:28px;border-radius:50%;background:var(--osto-blue);color:#fff;font-size:11px;font-weight:700;margin:0 auto 8px}\n.osto-cscrf .outcome span{font-size:13px;font-weight:700;color:#262A38}\n\n\/* Six CSCRF functions *\/\n.osto-cscrf .functions{display:grid;grid-template-columns:repeat(6,minmax(0,1fr));gap:0;border:1px solid var(--line);border-radius:10px;overflow:hidden}\n.osto-cscrf .function{position:relative;padding:15px 7px;text-align:center;background:#fff;border-right:1px solid var(--line)}\n.osto-cscrf .function:last-child{border-right:0}\n.osto-cscrf .function svg{display:block;width:22px;height:22px;margin:0 auto 8px;stroke:var(--osto-blue)}\n.osto-cscrf .function span{display:block;font-size:12px;font-weight:700;color:#313546}\n\n\/* Entity category strip *\/\n.osto-cscrf .category-wrap{display:flex;gap:8px;flex-wrap:wrap;margin:22px 0 28px}\n.osto-cscrf .category-pill{padding:9px 12px;border:1px solid #DDE1F5;border-radius:999px;background:var(--soft-blue);font-size:13px;line-height:1.3;font-weight:650;color:#303A7F}\n\n\/* Compact numbered implementation flow *\/\n.osto-cscrf .steps{margin:22px 0 10px;border-top:1px solid var(--line)}\n.osto-cscrf .step{display:grid;grid-template-columns:48px 1fr;gap:14px;padding:18px 0;border-bottom:1px solid var(--line)}\n.osto-cscrf .step-no{font-size:14px;font-weight:700;color:var(--osto-blue);padding-top:3px}\n.osto-cscrf .step p{font-size:15px;line-height:1.62;margin:0;color:var(--body)}\n\n\/* Timeline infographic *\/\n.osto-cscrf .timeline{display:grid;grid-template-columns:repeat(3,1fr);gap:10px;margin-top:8px}\n.osto-cscrf .milestone{padding:18px;border:1px solid var(--line);border-radius:10px;background:var(--soft)}\n.osto-cscrf .milestone strong{display:block;font-size:24px;line-height:1.1;color:var(--osto-blue);margin-bottom:6px}\n.osto-cscrf .milestone span{display:block;font-size:13px;line-height:1.48;color:#555B69}\n\n\/* Osto-style tables *\/\n.osto-cscrf .table-wrap{overflow-x:auto;margin:22px 0 32px;border:1px solid var(--line);border-radius:10px}\n.osto-cscrf table{width:100%;border-collapse:collapse;font-size:14px;line-height:1.5;background:#fff;margin:0}\n.osto-cscrf th,.osto-cscrf td{padding:13px 14px;border-bottom:1px solid var(--line);vertical-align:top;text-align:left}\n.osto-cscrf th{background:var(--soft);font-size:13px;font-weight:700;color:#272A36}\n.osto-cscrf tr:last-child td{border-bottom:0}\n\n\/* Short mistakes list *\/\n.osto-cscrf .mistakes{list-style:none;padding:0;margin:20px 0 10px;border-top:1px solid var(--line);counter-reset:item}\n.osto-cscrf .mistakes li{counter-increment:item;display:grid;grid-template-columns:34px 1fr;gap:10px;padding:14px 0;border-bottom:1px solid var(--line);font-size:15px;color:var(--body)}\n.osto-cscrf .mistakes li:before{content:counter(item,decimal-leading-zero);font-size:12px;font-weight:700;color:var(--osto-blue);padding-top:3px}\n\n\/* Osto platform section *\/\n.osto-cscrf .osto-path{margin:46px 0 20px;padding:0}\n.osto-cscrf .eyebrow{font-size:12px;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:var(--osto-blue);margin-bottom:7px}\n.osto-cscrf .osto-path h2{margin:0 0 14px}\n\n\/* CTA aligned to Osto resource pages *\/\n.osto-cscrf .cta{margin:26px 0 46px;padding:28px 30px;border-radius:12px;background:var(--osto-blue);color:#fff}\n.osto-cscrf .cta .cta-kicker{font-size:12px;line-height:1.2;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:#DDE1FF;margin-bottom:8px}\n.osto-cscrf .cta h3{font-size:24px;line-height:1.25;color:#fff;margin:0 0 10px}\n.osto-cscrf .cta p{max-width:680px;color:#F3F4FF;margin-bottom:17px}\n.osto-cscrf .cta a{display:inline-flex;align-items:center;background:#fff;color:var(--osto-blue);text-decoration:none;font-size:14px;font-weight:700;padding:10px 15px;border-radius:8px}\n\n\/* FAQs *\/\n.osto-cscrf .faq{border-top:1px solid var(--line)}\n.osto-cscrf details{border-bottom:1px solid var(--line);padding:15px 0}\n.osto-cscrf summary{cursor:pointer;list-style:none;position:relative;padding-right:32px;font-size:16px;line-height:1.45;font-weight:700;color:var(--text)}\n.osto-cscrf summary::-webkit-details-marker{display:none}\n.osto-cscrf summary:after{content:'+';position:absolute;right:2px;top:-4px;color:var(--osto-blue);font-size:24px;font-weight:400}\n.osto-cscrf details[open] summary:after{content:'\u2212'}\n.osto-cscrf details p{font-size:15px;margin:10px 0 0;color:var(--body)}\n.osto-cscrf .sources{margin-top:34px;padding-top:18px;border-top:1px solid var(--line);font-size:13px;line-height:1.6;color:var(--muted)}\n.osto-cscrf .sources a{font-size:13px}\n\n@media(max-width:760px){\n  .osto-cscrf{font-size:16px;line-height:1.68}\n  .osto-cscrf .lead{font-size:17px}\n  .osto-cscrf h2{font-size:25px;margin-top:40px}\n  .osto-cscrf .toc ol{columns:1}\n  .osto-cscrf .outcomes{grid-template-columns:repeat(2,1fr)}\n  .osto-cscrf .outcome:last-child{grid-column:1\/-1}\n  .osto-cscrf .functions{grid-template-columns:repeat(2,1fr)}\n  .osto-cscrf .function{border-bottom:1px solid var(--line)}\n  .osto-cscrf .function:nth-child(2n){border-right:0}\n  .osto-cscrf .function:nth-last-child(-n+2){border-bottom:0}\n  .osto-cscrf .timeline{grid-template-columns:1fr}\n  .osto-cscrf .step{grid-template-columns:36px 1fr;gap:10px}\n  .osto-cscrf .cta{padding:24px 22px}\n}\n\n.osto-cscrf .outcome:nth-child(1){background:var(--pastel-blue)}\n.osto-cscrf .outcome:nth-child(2){background:var(--pastel-mint)}\n.osto-cscrf .outcome:nth-child(3){background:var(--pastel-lilac)}\n.osto-cscrf .outcome:nth-child(4){background:var(--pastel-peach)}\n.osto-cscrf .outcome:nth-child(5){background:var(--pastel-blue)}\n\n.osto-cscrf .function:nth-child(1),\n.osto-cscrf .function:nth-child(4){background:#F6F8FF}\n.osto-cscrf .function:nth-child(2),\n.osto-cscrf .function:nth-child(5){background:#F2FBF8}\n.osto-cscrf .function:nth-child(3),\n.osto-cscrf .function:nth-child(6){background:#F8F4FF}\n\n.osto-cscrf .milestone:nth-child(1){background:var(--pastel-blue);border-color:#D9E5FF}\n.osto-cscrf .milestone:nth-child(2){background:var(--pastel-mint);border-color:#D8EFE8}\n.osto-cscrf .milestone:nth-child(3){background:var(--pastel-lilac);border-color:#E5DBFF}\n\n.osto-cscrf .category-pill:nth-child(3n+1){background:var(--pastel-blue);border-color:#D9E5FF}\n.osto-cscrf .category-pill:nth-child(3n+2){background:var(--pastel-mint);border-color:#D8EFE8}\n.osto-cscrf .category-pill:nth-child(3n){background:var(--pastel-lilac);border-color:#E5DBFF}\n\n.osto-cscrf .table-wrap{box-shadow:0 7px 24px rgba(28,38,122,.04)}\n.osto-cscrf th{background:#F2F5FF;color:#22284D}\n.osto-cscrf tr:nth-child(even) td{background:#FCFCFE}\n\n.osto-cscrf .cta{\n  background:linear-gradient(135deg,#1C267A 0%,#3445C5 100%);\n  box-shadow:0 14px 36px rgba(28,38,122,.18)\n}\n.osto-cscrf .cta a{border-radius:999px;padding:11px 18px}\n\n.osto-cscrf .visual-divider{\n  height:1px;\n  margin:42px 0;\n  background:linear-gradient(90deg,transparent,#CBD4FF 20%,#D9F0E8 50%,#E7DFFF 80%,transparent);\n}\n\n<\/style>\n\n<article class=\"osto-cscrf\">\n  <p class=\"lead\"><strong>SEBI CSCRF Compliance<\/strong> is now an operating requirement for regulated entities, covering governance, critical systems, continuous monitoring, VAPT, incident response, recovery and evidence. The practical challenge is not reading one circular. It is keeping the right controls live and proving that they work.<\/p>\n\n  <section class=\"tldr\">\n    <h2>TL;DR<\/h2>\n    <p><strong>SEBI CSCRF Compliance<\/strong> requires a regulated entity to confirm its category, maintain current asset and risk inventories, operate appropriate security controls and SOC monitoring, conduct prescribed VAPT and cyber audits, report incidents on time, test recovery and retain audit-ready evidence.<\/p>\n    <p>Start with applicability. SEBI uses a graded model, so the exact control depth and assurance cadence depend on the entity type and category.<\/p>\n  <\/section>\n\n  <nav class=\"toc\" aria-label=\"On this page\">\n    <div class=\"toc-title\">On this page<\/div>\n    <ol>\n      <li><a href=\"#meaning\">What SEBI CSCRF Compliance means<\/a><\/li>\n      <li><a href=\"#covered\">Who is covered<\/a><\/li>\n      <li><a href=\"#steps\">9 critical compliance steps<\/a><\/li>\n      <li><a href=\"#vapt\">VAPT and audit timelines<\/a><\/li>\n      <li><a href=\"#checklist\">Readiness checklist<\/a><\/li>\n      <li><a href=\"#mistakes\">Common mistakes<\/a><\/li>\n      <li><a href=\"#osto\">How Osto helps<\/a><\/li>\n      <li><a href=\"#faq\">FAQs<\/a><\/li>\n    <\/ol>\n  <\/nav>\n\n  <h2 id=\"meaning\">What SEBI CSCRF Compliance actually means<\/h2>\n  <p>The <a href=\"https:\/\/www.osto.one\/resources\/?p=1010\">Cybersecurity and Cyber Resilience Framework<\/a> gives SEBI-regulated entities a common cybersecurity structure. It links governance, asset management, identity and access, application and API security, cloud and supplier risk, vulnerability management, monitoring, incident response and recovery.<\/p>\n  <p>The framework is designed around five resilience outcomes. A regulated entity should be able to anticipate risk, withstand disruption, contain an incident, recover critical services and improve after the event.<\/p>\n\n  <div class=\"diagram\" aria-label=\"Five cyber resilience outcomes under CSCRF\">\n    <div class=\"diagram-kicker\">Cyber resilience goals<\/div>\n    <div class=\"diagram-title\">The five outcomes CSCRF expects an RE to build for<\/div>\n    <div class=\"outcomes\">\n      <div class=\"outcome\"><div class=\"num\">01<\/div><span>Anticipate<\/span><\/div>\n      <div class=\"outcome\"><div class=\"num\">02<\/div><span>Withstand<\/span><\/div>\n      <div class=\"outcome\"><div class=\"num\">03<\/div><span>Contain<\/span><\/div>\n      <div class=\"outcome\"><div class=\"num\">04<\/div><span>Recover<\/span><\/div>\n      <div class=\"outcome\"><div class=\"num\">05<\/div><span>Evolve<\/span><\/div>\n    <\/div>\n  <\/div>\n\n  <p>This is why <strong>SEBI CSCRF Compliance<\/strong> cannot be demonstrated with policies alone. An access-control policy needs operating evidence such as MFA configuration, access reviews and privileged-access records. A vulnerability policy needs asset coverage, testing results, remediation and verified closure.<\/p>\n\n  <div class=\"diagram\" aria-label=\"Six CSCRF operating functions\">\n    <div class=\"diagram-kicker\">CSCRF operating model<\/div>\n    <div class=\"diagram-title\">Six functions organise the security programme<\/div>\n    <div class=\"functions\">\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><path d=\"M12 3l8 4v5c0 5-3.5 8-8 9-4.5-1-8-4-8-9V7l8-4z\"\/><\/svg><span>Governance<\/span><\/div>\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><circle cx=\"11\" cy=\"11\" r=\"6\"\/><path d=\"M20 20l-4.5-4.5\"\/><\/svg><span>Identify<\/span><\/div>\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><path d=\"M12 3l7 3v5c0 4.5-3 7.5-7 9-4-1.5-7-4.5-7-9V6l7-3z\"\/><path d=\"M9 12l2 2 4-5\"\/><\/svg><span>Protect<\/span><\/div>\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><path d=\"M2 12s3.5-6 10-6 10 6 10 6-3.5 6-10 6S2 12 2 12z\"\/><circle cx=\"12\" cy=\"12\" r=\"2.5\"\/><\/svg><span>Detect<\/span><\/div>\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><path d=\"M5 12h10\"\/><path d=\"M11 8l4 4-4 4\"\/><path d=\"M19 5v14\"\/><\/svg><span>Respond<\/span><\/div>\n      <div class=\"function\"><svg viewBox=\"0 0 24 24\" fill=\"none\" stroke-width=\"1.8\"><path d=\"M4 12a8 8 0 111.6 4.8\"\/><path d=\"M4 17v-5h5\"\/><\/svg><span>Recover<\/span><\/div>\n    <\/div>\n    <p class=\"diagram-note\">On mobile, the same diagram stacks into two columns for readability.<\/p>\n  <\/div>\n\n  <h2 id=\"covered\">Who is covered by SEBI CSCRF?<\/h2>\n  <p>The framework applies across a wide range of securities-market participants. This includes market infrastructure institutions and intermediaries such as stock brokers, mutual funds, portfolio managers, investment advisers, custodians and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-depository-participant\/\">Depository Participants<\/a>. The exact obligations depend on how the entity is classified.<\/p>\n\n  <div class=\"category-wrap\" aria-label=\"CSCRF entity categories\">\n    <span class=\"category-pill\">Market Infrastructure Institutions<\/span>\n    <span class=\"category-pill\">Qualified REs<\/span>\n    <span class=\"category-pill\">Mid-size REs<\/span>\n    <span class=\"category-pill\">Small-size REs<\/span>\n    <span class=\"category-pill\">Self-certification REs<\/span>\n  <\/div>\n\n  <p>Classification affects control depth, audit frequency and the assurance route. Before building a checklist, confirm the current category against SEBI&#8217;s latest circulars and any entity-specific instructions. The Osto glossary on <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-sebi-regulated-entity\/\">SEBI Regulated Entities<\/a> explains the distinction between entity type and CSCRF category.<\/p>\n\n  <h2 id=\"steps\">9 critical steps for SEBI CSCRF Compliance<\/h2>\n  <div class=\"steps\">\n    <section class=\"step\"><div class=\"step-no\">01<\/div><div><h3>Confirm applicability and category<\/h3><p>Record the legal entity, SEBI registration, RE type, CSCRF category, reporting route and applicable assurance cadence. This becomes the basis for the rest of the programme.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">02<\/div><div><h3>Map critical assets and dependencies<\/h3><p>Maintain an inventory covering applications, APIs, cloud workloads, endpoints, networks, databases, third-party services and critical business dependencies.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">03<\/div><div><h3>Assign governance and ownership<\/h3><p>Define accountable owners for cybersecurity risk, IT Committee review, policy approval, exceptions, audit findings, incidents and regulatory reporting.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">04<\/div><div><h3>Protect identities, systems and data<\/h3><p>Translate the framework into operating controls such as MFA, least privilege, secure configuration, endpoint protection, encryption, application security, API protection and software-supply-chain controls.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">05<\/div><div><h3>Operate continuous security monitoring<\/h3><p>Use the SOC model applicable to the entity and ensure critical telemetry is connected. The <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-soc-market-soc\/\">SOC and Market SOC<\/a> glossary explains the recognised operating models and the accountability that remains with the RE.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">06<\/div><div><h3>Run vulnerability management continuously<\/h3><p>Keep scanning, patching and configuration review active throughout the year so critical findings do not accumulate between formal assurance cycles.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">07<\/div><div><h3>Complete VAPT and revalidation<\/h3><p>Test the full in-scope attack surface, track findings by severity, close them within the applicable timeline and retain evidence of retesting. See the Osto glossary on <a href=\"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-sebi-vapt-requirements\/\">SEBI VAPT requirements<\/a> for scope and process detail.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">08<\/div><div><h3>Prepare incident reporting before an incident<\/h3><p>Define who decides whether an event is reportable, who approves notification, which authorities must be contacted and what evidence must be preserved.<\/p><\/div><\/section>\n    <section class=\"step\"><div class=\"step-no\">09<\/div><div><h3>Keep evidence audit-ready<\/h3><p>Retain approvals, inventories, access reviews, SOC records, VAPT reports, cyber-audit findings, remediation evidence, incident records and recovery-test results as the work happens.<\/p><\/div><\/section>\n  <\/div>\n\n  <h2 id=\"vapt\">VAPT and cyber-audit timelines under SEBI CSCRF Compliance<\/h2>\n  <p>VAPT is one of the most visible assurance requirements, but a compliant cycle includes more than a scanner report. Scope, auditor route, management review, remediation and revalidation all matter.<\/p>\n\n  <div class=\"diagram\" aria-label=\"SEBI VAPT reporting and remediation timeline\">\n    <div class=\"diagram-kicker\">VAPT timeline<\/div>\n    <div class=\"diagram-title\">Three milestones to keep visible after testing finishes<\/div>\n    <div class=\"timeline\">\n      <div class=\"milestone\"><strong>1 month<\/strong><span>Submit the approved VAPT report after completion.<\/span><\/div>\n      <div class=\"milestone\"><strong>3 months<\/strong><span>Close observations from report submission using the graded approach.<\/span><\/div>\n      <div class=\"milestone\"><strong>5 months<\/strong><span>Complete revalidation from the original VAPT completion date.<\/span><\/div>\n    <\/div>\n  <\/div>\n\n  <p>A cyber audit is separate from VAPT. VAPT tests weaknesses and exploitability. The cyber audit tests compliance with the applicable control framework. Frequency depends on the RE category and, for some entities, the services they provide.<\/p>\n\n  <h2 id=\"checklist\">Practical SEBI CSCRF Compliance checklist<\/h2>\n  <div class=\"table-wrap\">\n    <table>\n      <thead><tr><th>Area<\/th><th>What to verify<\/th><th>Evidence<\/th><\/tr><\/thead>\n      <tbody>\n        <tr><td>Applicability<\/td><td>Correct RE category and reporting route<\/td><td>Applicability note and classification rationale<\/td><\/tr>\n        <tr><td>Assets<\/td><td>Complete inventory and critical-system mapping<\/td><td>Asset register, owners, architecture<\/td><\/tr>\n        <tr><td>Access<\/td><td>MFA, least privilege and periodic reviews<\/td><td>Configurations, approvals, review logs<\/td><\/tr>\n        <tr><td>Monitoring<\/td><td>Critical telemetry reaches the selected SOC model<\/td><td>Coverage, alerts, cases, escalation records<\/td><\/tr>\n        <tr><td>VAPT<\/td><td>Scope, frequency, remediation and revalidation<\/td><td>Reports, tickets, retest evidence<\/td><\/tr>\n        <tr><td>Cyber audit<\/td><td>Applicable controls tested at the right cadence<\/td><td>Audit report and closure register<\/td><\/tr>\n        <tr><td>Incidents<\/td><td>Escalation and reporting workflow is usable<\/td><td>IR plan, exercises, notifications<\/td><\/tr>\n        <tr><td>Recovery<\/td><td>Critical services can be restored and tested<\/td><td>BCP\/DR results and action items<\/td><\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n\n  <h2 id=\"mistakes\">Five mistakes that weaken SEBI CSCRF Compliance<\/h2>\n  <ol class=\"mistakes\">\n    <li><div><strong>Starting with a generic checklist.<\/strong> The entity category should determine the requirement set, not the other way around.<\/div><\/li>\n    <li><div><strong>Buying tools without proving coverage.<\/strong> A SIEM, EDR or scanner is useful only when it covers the in-scope systems, is monitored and produces usable evidence.<\/div><\/li>\n    <li><div><strong>Testing an incomplete attack surface.<\/strong> A clean report is misleading if APIs, cloud assets or critical integrations were missing from scope.<\/div><\/li>\n    <li><div><strong>Closing findings without retesting.<\/strong> Remediation is stronger when closure is independently revalidated and retained as evidence.<\/div><\/li>\n    <li><div><strong>Preparing evidence only before an audit.<\/strong> Reconstructing months of approvals and logs creates avoidable gaps and slows remediation.<\/div><\/li>\n  <\/ol>\n\n  <section class=\"osto-path\" id=\"osto\">\n    <div class=\"eyebrow\">The operating layer<\/div>\n    <h2>Turn CSCRF from a checklist into a working security programme<\/h2>\n    <p>For lean security and compliance teams, the hard part is usually fragmentation. One tool protects applications, another monitors endpoints, another scans cloud posture, a separate vendor runs VAPT, and evidence is rebuilt in spreadsheets before every audit.<\/p>\n    <p>Osto brings security and compliance into one operating layer across cloud, code, endpoints, networks, applications and evidence. That gives teams a clearer path from requirement to live control, finding, owner and verified closure.<\/p>\n  <\/section>\n\n  <section class=\"cta\">\n    <div class=\"cta-kicker\">SEBI CSCRF readiness<\/div>\n    <h3>Make SEBI CSCRF Compliance easier to operate.<\/h3>\n    <p>See how Osto can connect security controls, VAPT, remediation and audit-ready evidence across one platform.<\/p>\n    <a href=\"https:\/\/www.osto.one\/book-demo\">Book a Demo&nbsp;\u2192<\/a>\n  <\/section>\n\n  <h2 id=\"faq\">Frequently asked questions<\/h2>\n  <div class=\"faq\">\n    <details><summary>What is SEBI CSCRF Compliance?<\/summary><p><strong>SEBI CSCRF Compliance<\/strong> is the process of implementing and evidencing the cybersecurity and cyber-resilience requirements that apply to a SEBI-regulated entity under the CSCRF and subsequent clarifications.<\/p><\/details>\n    <details><summary>What are the five CSCRF categories?<\/summary><p>The broad categories are Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The applicable requirements vary by category.<\/p><\/details>\n    <details><summary>Does every regulated entity need a SOC?<\/summary><p>CSCRF requires appropriate security monitoring. Depending on category and operating model, an RE may use its own SOC, a group SOC, the Market SOC or another managed SOC route, subject to current SEBI instructions.<\/p><\/details>\n    <details><summary>How often is VAPT required?<\/summary><p>The frequency depends on applicability and criticality. Most covered REs have an annual cycle, while protected systems or Critical Information Infrastructure can have higher-frequency requirements. Always verify the current SEBI instructions for the entity.<\/p><\/details>\n    <details><summary>Is VAPT the same as a cyber audit?<\/summary><p>No. VAPT tests vulnerabilities and exploitability across technical assets. A cyber audit assesses whether the regulated entity meets the applicable CSCRF control requirements.<\/p><\/details>\n    <details><summary>How quickly must certain cyber incidents be reported?<\/summary><p>For incidents falling under CERT-In cybersecurity directions, CSCRF includes a six-hour notification requirement to SEBI and CERT-In after detection or notice. Teams should also use SEBI&#8217;s current Cyber Incident Reporting Portal process.<\/p><\/details>\n    <details><summary>Is ISO 27001 enough for SEBI CSCRF Compliance?<\/summary><p>No. ISO 27001 can support the management-system layer, but it does not replace direct mapping, implementation and evidence against the CSCRF requirements that apply to the RE.<\/p><\/details>\n  <\/div>\n\n  <div class=\"sources\">\n    <strong>Primary regulatory references:<\/strong>\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI CSCRF circular, August 20, 2024<\/a>,\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/apr-2025\/clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_93734.html\" target=\"_blank\" rel=\"noopener\">SEBI clarification, April 30, 2025<\/a> and\n    <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2025\/technical-clarifications-to-cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_96329.html\" target=\"_blank\" rel=\"noopener\">SEBI technical clarification, August 28, 2025<\/a>. Applicability should be confirmed for the entity and current date. This guide is not legal advice.\n  <\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>SEBI CSCRF Compliance is now an operating requirement for regulated entities, covering governance, critical systems, continuous monitoring, VAPT, incident response,\u2026<\/p>\n","protected":false},"author":8,"featured_media":1050,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[492,491,493],"class_list":["post-1049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-sebi-cscrf-compliance","tag-sebi-cscrf-compliance-for-regulated-entities","tag-sebi-cybersecurity-compliance"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1049"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1049\/revisions"}],"predecessor-version":[{"id":1051,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1049\/revisions\/1051"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1050"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}