Skip to main content
India

SEBI Cybersecurity & Cyber Resilience Framework

SEBI's CSCRF is a 5-tier framework covering 22 entity types, mandating VAPT, cyber audit, red teaming, threat hunting, a Market-SOC, ISO 27001, a CISO, incident reporting and the full NIST CSF 2.0 control catalogue. We take you from tier classification to audited compliance.

Overview

SEBI's CSCRF is a 5-tier framework covering 22 entity types, mandating VAPT, cyber audit, red teaming, threat hunting, a Market-SOC, ISO 27001, a CISO, incident reporting and the full NIST CSF 2.0 control catalogue. We take you from tier classification to audited compliance.

Who Needs to Comply?

SEBI-regulated entities - stock exchanges, depositories, brokers, AMCs, RTAs and more.

Key Requirements

Full framework

VAPT, red team, threat hunting, M-SOC, governance and NIST CSF 2.0 controls.

Tier-based scoping

We determine your tier and tailor obligations accordingly.

Cyber audit & evidence

Audit report and evidence pack for SEBI submission.

Discuss compliance

Need help with SEBI CSCRF?

Prove both before launch.

Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.

A5 Cardinal character in a futuristic chair