SEBI Cybersecurity & Cyber Resilience Framework
SEBI's CSCRF is a 5-tier framework covering 22 entity types, mandating VAPT, cyber audit, red teaming, threat hunting, a Market-SOC, ISO 27001, a CISO, incident reporting and the full NIST CSF 2.0 control catalogue. We take you from tier classification to audited compliance.
Overview
SEBI's CSCRF is a 5-tier framework covering 22 entity types, mandating VAPT, cyber audit, red teaming, threat hunting, a Market-SOC, ISO 27001, a CISO, incident reporting and the full NIST CSF 2.0 control catalogue. We take you from tier classification to audited compliance.
Who Needs to Comply?
SEBI-regulated entities - stock exchanges, depositories, brokers, AMCs, RTAs and more.
Key Requirements
Full framework
VAPT, red team, threat hunting, M-SOC, governance and NIST CSF 2.0 controls.
Tier-based scoping
We determine your tier and tailor obligations accordingly.
Cyber audit & evidence
Audit report and evidence pack for SEBI submission.
How we help you comply
Cyber Governance & Audit
SEBI CSCRF Compliance
End-to-end SEBI CSCRF readiness: VAPT, cyber audit, red team, M-SOC, NIST CSF 2.0 controls and reporting.
Defensive & Managed SOC
MDR & Managed SOC
24/7 managed detection & response and SOC-as-a-service with alert triage, hunting and response.
Offensive Security & VAPT
Red Team Assessment
Goal-oriented adversary simulation that tests detection and response, mapped to MITRE ATT&CK.
Need help with SEBI CSCRF?
Prove both before launch.
Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.

