Home / Frameworks / SEBI CSCRF
Indian Securities Market Compliance

Get SEBI CSCRF Compliant Before Your Next Cyber Audit

Purpose-built for SEBI-regulated entities — stock brokers, mutual funds & AMCs, investment advisors, and market intermediaries. Automated controls mapping, evidence collection, and audit-ready reporting for the Cybersecurity and Cyber Resilience Framework.

Graded by RE category
Audit-ready evidence
🔒No credit card required

Why SEBI-regulated entities choose us for CSCRF

CSCRF consolidates years of SEBI cybersecurity circulars into one framework. We turn it into a checklist you can actually finish.

Category-Aware Compliance

Traditional vendors: One-size-fits-all consultants
LowerPlane: Graded by RE category

CSCRF obligations differ for MIIs, Qualified REs, Mid-size, Small-size, and Self-certification REs. We scope your controls to your category so you never over- or under-implement.

💰

Transparent Pricing

Traditional vendors: ₹15-40 lakh/year consultants
LowerPlane: A fraction of the cost

No hidden fees. Continuous compliance instead of one-off audit scrambles. Reuse the same evidence for CSCRF, ISO 27001, and SOC 2.

👥

Securities Market Context

Traditional vendors: Generic IT security advice
LowerPlane: CSCRF-mapped guidance

Guidance mapped to CSCRF standards — SOC onboarding, Cyber Capability Index (CCI), VAPT cadence, CERT-In reporting timelines, and SEBI cyber audit preparation.

What is SEBI CSCRF?

The Cybersecurity and Cyber Resilience Framework (CSCRF) is SEBI's consolidated cybersecurity mandate for all regulated entities in the Indian securities market, issued in August 2024. It replaces the patchwork of earlier cybersecurity circulars with a single, goal-based framework.

CSCRF is structured around five cyber resiliency goals — Anticipate, Withstand, Contain, Recover, and Evolve — mapped to the functions of Governance, Identify, Protect, Detect, Respond, and Recover. Obligations are graded by entity category: Market Infrastructure Institutions (MIIs), Qualified REs, Mid-size REs, Small-size REs, and Self-certification REs.

Read complete guide to SEBI CSCRF

CSCRF Cyber Resiliency Goals

A
Anticipate & Withstand
Governance, risk assessment, asset classification, protective controls
C
Contain & Recover
SOC monitoring, incident response, CERT-In/SEBI reporting, recovery drills
E
Evolve
Cyber Capability Index, VAPT, cyber audits, continuous improvement

SEBI CSCRF Requirements Checklist

Requirements scale with your RE category — from full SOC and ISO 27001 for MIIs and Qualified REs to simplified self-certification for the smallest intermediaries.

Technical & Operational Controls

Security Operations Centre (own, group, or Market SOC)
Periodic VAPT with closure of findings
MFA and privileged access management
Data classification and encryption
Log collection and retention per CSCRF standards
Endpoint and network security controls
SBOM for critical software systems
Cyber incident reporting (CERT-In within 6 hours)

Governance & Documentation

Board-approved cybersecurity policy
Designated CISO and defined roles
Cyber Capability Index (CCI) assessment
Cyber crisis management plan
Third-party / vendor risk management
Employee security awareness training
Periodic cyber audit by empanelled auditors
ISO 27001 certification (MIIs & Qualified REs)

How LowerPlane Gets You CSCRF Compliant

A proven four-phase process tailored to your RE category.

1

Phase 1: Categorization & Gap Analysis

Determine your RE category and scope the exact CSCRF standards that apply to you.

  • RE categorization (MII / Qualified / Mid-size / Small-size / Self-certification)
  • Gap analysis across all applicable CSCRF standards
  • Connect integrations (AWS, Azure, GCP, Okta, endpoint tools)
  • Asset inventory and data classification baseline
2

Phase 2: Policies & Governance

Stand up the governance layer SEBI auditors look for first.

  • Board-approved cybersecurity and cyber resilience policy
  • CISO designation, roles, and committee structures
  • Cyber crisis management plan and incident runbooks
  • Vendor and third-party risk management program
3

Phase 3: Technical Controls & Monitoring

Implement and evidence the technical standards — continuously, not once a year.

  • SOC onboarding (own, group, or exchange Market SOC)
  • VAPT scheduling and finding remediation tracking
  • Automated evidence collection from your cloud and identity stack
  • Log retention, MFA, and access review automation
4

Phase 4: CCI, Audit & Ongoing Compliance

Walk into your cyber audit with everything already in one place.

  • Cyber Capability Index (CCI) computation and tracking
  • Audit-ready evidence package for empanelled auditors
  • Periodic compliance reporting to exchanges/SEBI
  • Continuous monitoring so next year is easier 🎉

Built for the Indian Securities Market

Brokers, AMCs, advisors, and intermediaries use LowerPlane to stay continuously audit-ready.

📈

CSCRF felt overwhelming until we scoped it to our RE category. The graded checklist meant we implemented exactly what SEBI expects from a mid-size broker — nothing more, nothing less.

Compliance Head
Compliance Head, Stock Broking Firm
Result: Cleared cyber audit with zero major observations
💼

We were maintaining evidence in spreadsheets across three teams. Now VAPT findings, access reviews, and log evidence live in one place, mapped to CSCRF standards.

CISO
CISO, Asset Management Company
Result: Cut audit preparation time from 6 weeks to 1 week
🤝

As a registered investment advisor, we qualify for self-certification — but we still needed to prove it. LowerPlane gave us the structure without enterprise overhead.

Founder
Founder, SEBI-Registered Investment Advisor
Result: Completed self-certification in under 3 weeks

LowerPlane vs Traditional CSCRF Approaches

Continuous compliance instead of an annual fire drill.

FeatureLowerPlaneTraditional ConsultantsSpreadsheets/DIYGeneric GRC Tools
CSCRF-Mapped Controls✅ Graded by RE category⚠️ Manual mapping❌ Build yourself⚠️ Generic templates
Automated Evidence Collection✅ 375+ integrations❌ Manual❌ Manual⚠️ Limited
VAPT & Finding Tracking✅ Built in⚠️ Separate engagement❌ Manual⚠️ Basic
Multi-Framework Reuse✅ Add ISO 27001, SOC 2❌ Per-framework fees❌ Start over⚠️ Extra licensing
Ongoing Compliance✅ Continuous monitoring❌ Point-in-time❌ Point-in-time⚠️ Manual updates

SEBI CSCRF Resources

Related Compliance Frameworks

CSCRF is built on NIST CSF functions and mandates ISO 27001 for larger REs. Reuse your controls across frameworks with multi-framework pricing.

Ready to Get CSCRF Compliant?

Book a free 20-minute assessment. We'll categorize your entity, show you exactly which CSCRF standards apply, and map out your fastest path to audit readiness.

🔒No credit card required
Response within 2 hours
📈Built for SEBI-regulated entities