SEBI CSCRF · Regulated Entities
CSCRF compliance, implemented - not just assessed.
SEBI's Cybersecurity and Cyber Resilience Framework is mandatory for brokers, AMCs, depository participants and other REs - and inspections are underway. We take you from gap assessment to implemented controls to inspection-ready evidence, sized to your RE category.
What we deliver
The full CSCRF lifecycle, one team.
Gap Assessment
Your current state against every applicable CSCRF requirement for your RE category - scored, prioritised, with effort estimates and a dated remediation plan.
Policy & Governance
Board-approved cybersecurity policy, roles and CISO designation support, risk assessment methodology, and the reporting cadence the framework expects.
Technical Controls
MFA, access reviews, encryption, logging, patch discipline - implemented by engineers, mapped requirement-by-requirement to the framework.
VAPT
Vulnerability assessment and penetration testing with findings closed to timelines, plus re-test evidence your auditor will accept.
SOC Strategy
Own SOC, market SOC or managed - an honest cost-and-obligation comparison for your category, then setup or integration support for the route you choose.
Incident & Audit Readiness
Response playbook, SEBI/CERT-In reporting formats prepared in advance, drills, CCI support where applicable, and an evidence pack for inspections.
Engagement models
Assessment, implementation, or ongoing retainer.
A gap assessment starts at ₹1,50,000 and takes two to three weeks. Implementation is scoped from the assessment - smaller REs on the market-SOC route are often inspection-ready within a quarter. A quarterly compliance retainer then keeps evidence current, runs the periodic reviews and drills the framework requires, and handles SEBI circular updates - which is where most REs quietly fall out of compliance a year after their first push.
Start with the free self-assessment - it takes ten minutes and gives you the same gap structure our paid assessment expands on: run the CSCRF readiness check.
Why REs pick us
- Engineers and security testers on one team - controls get built, not just recommended
- Sized for mid and small REs that Big-4 pricing leaves behind
- Fixed-price assessments, written scopes, no surprise billing
- Clean separation from your empanelled auditor