Compliance · SEBI-regulated entities

How ready are you for SEBI's CSCRF?

SEBI's Cybersecurity and Cyber Resilience Framework applies to brokers, AMCs, depository participants and other regulated entities. Twenty-four questions across governance and the framework's resilience goals — you get a weighted score and a gap list ordered by how much it matters, in about ten minutes.

Your RE category (optional)

0 of 24 answered

Governance

Has the board (or partners/proprietor) approved a cybersecurity and cyber resilience policy aligned to CSCRF, reviewed in the last year?

Is a senior officer (CISO or equivalent) designated with clear responsibility for CSCRF compliance?

Do you know your RE category under CSCRF and the specific obligations and timelines that follow from it?

Are cybersecurity risks reported to the board/management on a defined cadence with metrics?

Anticipate — identify & assess

Do you maintain a current inventory of IT assets, and have you classified your critical systems?

Is a documented cyber risk assessment performed at least annually and after major changes?

Are third parties and vendors with access to your systems or data risk-assessed, with cybersecurity clauses in contracts?

Do you track software components you depend on (including an SBOM for critical applications where required)?

Withstand — protect

Is multi-factor authentication enforced for all remote access, privileged accounts and critical applications?

Is access role-based, reviewed periodically, and revoked the same day a person exits?

Is sensitive and regulatory data encrypted in transit and at rest?

Is patch management defined with timelines, and are end-of-life systems isolated or replaced?

Is periodic VAPT conducted by qualified auditors, with findings closed within defined timelines?

Do all employees receive cybersecurity awareness training at least annually, with phishing simulations?

Contain — detect & monitor

Are security logs from critical systems collected centrally and retained per regulatory requirements?

Do you have SOC coverage appropriate to your category — own SOC, market SOC, or a managed third-party SOC?

Are alerts triaged against defined severity levels with documented escalation paths?

Recover — respond & restore

Is there a documented cyber incident response plan, tested through a drill in the last 12 months?

Can you report incidents to SEBI and CERT-In within the mandated timelines, with the reporting formats ready?

Are backups maintained offline/immutable for critical systems, with a tested restoration in the last year?

Are RTO/RPO defined for critical operations and validated through DR drills?

Evolve — audit & improve

Is a cyber audit conducted at your category's mandated frequency by empanelled/qualified auditors?

If you are an MII or Qualified RE: is your Cyber Capability Index computed and reported as required?

Are lessons from incidents, drills and audits tracked to closure and fed back into policy?

Everything runs in your browser — your answers never leave this page unless you choose to email yourself the report. CSCRF is a framework published by SEBI; Karleesh is an independent company and this self-assessment is not an official SEBI or auditor evaluation.

Preparing for an audit or building your SOC? See our cyber security services →