Compliance/India/SEBI CSCRF
Six functions and one goal to evolve: ten standards leave evidence in the file.
The CSCRF asks regulated entities to anticipate, withstand, contain, recover and evolve. Vaultize adds records that stay with the data.
- Circular CIR/2024/113 · 20 Aug 2024
- Applicability by RE category
- Capability mapping, not a cyber audit
GV
Governance
1 of 27
- GV.OC.S1
- GV.OC.S2
- GV.OC.S3
- GV.OV.S1
- GV.OV.S2
- GV.OV.S3
- GV.OV.S4
- GV.PO.S1
- GV.PO.S2
- GV.PO.S4
- GV.PO.S5
- GV.RM.S1
- GV.RM.S2
- GV.RM.S3
- GV.RM.S4
- GV.RR.S1
- GV.RR.S3
- GV.RR.S4
- GV.RR.S5
- GV.RR.S6
- GV.SC.S1
- GV.SC.S2
- GV.SC.S3
- GV.SC.S4
- GV.SC.S5
- GV.SC.S6
- GV.SC.S7
ID
Identify
1 of 9
- ID.AM.S1
- ID.AM.S2
- ID.AM.S4
- ID.AM.S6
- ID.RA.S1
- ID.RA.S2
- ID.RA.S3
- ID.RA.S4
- ID.RA.S5
PR
Protect
6 of 37
- PR.AA.S1
- PR.AA.S2
- PR.AA.S3
- PR.AA.S4
- PR.AA.S5
- PR.AA.S6
- PR.AA.S7
- PR.AA.S8
- PR.AA.S9
- PR.AA.S10
- PR.AA.S11
- PR.AA.S12
- PR.AA.S13
- PR.AA.S14
- PR.AA.S15
- PR.AA.S16
- PR.AA.S17
- PR.AT.S1
- PR.AT.S2
- PR.AT.S3
- PR.DS.S1
- PR.DS.S2
- PR.DS.S3
- PR.DS.S4
- PR.DS.S5
- PR.DS.S6
- PR.IP.S1
- PR.IP.S3
- PR.IP.S4
- PR.IP.S6
- PR.IP.S14
- PR.IP.S15
- PR.IP.S16
- PR.IP.S17
- PR.MA.S1
- PR.MA.S2
- PR.MA.S3
DE
Detect
1 of 7
- DE.CM.S1
- DE.CM.S2
- DE.CM.S3
- DE.CM.S4
- DE.CM.S5
- DE.DP.S4
- DE.DP.S5
RS
Respond
1 of 14
- RS.AN.S1
- RS.AN.S2
- RS.AN.S3
- RS.AN.S4
- RS.AN.S5
- RS.CO.S1
- RS.CO.S2
- RS.CO.S3
- RS.IM.S1
- RS.IM.S2
- RS.MA.S1
- RS.MA.S2
- RS.MA.S3
- RS.MA.S5
RC
Recover
1 of 9
- RC.CO.S1
- RC.CO.S2
- RC.CO.S3
- RC.IM.S1
- RC.IM.S2
- RC.RP.S1
- RC.RP.S2
- RC.RP.S3
- RC.RP.S4
EV
Evolve
0 of 4
- EV.ST.S1
- EV.ST.S2
- EV.ST.S3
- EV.ST.S5
GV.SC.S4
Where the systems of a RE are managed by third-party service providers and in case the RE does not have direct control over the implementation of any of the guidelines, the RE shall instruct the third-party service providers to adhere to the applicable guidelines in the CSCRF and shall obtain the necessary cyber audit certifications from them to ensure compliance with the framework.
Vaultize Share · Vaultize Seal
The answer in 30 seconds
Vaultize adds file-level records to ten CSCRF standards under Governance, Identify, Protect, Detect, Respond and Recover. Policy, risk assessment, VAPT, the SOC and the cyber audit belong to the regulated entity and its auditors.
The framework in one view
Five resilience goals. Seven functions. Where file evidence lands.
The CSCRF links its resilience goals to cybersecurity functions and numbers each standard. Select a function to see which of its standards a governed file can evidence.
GV
Governance
Goal Anticipate. Organisational context, roles, oversight, policy, risk management, supply chain.
Outcomes the file can evidence
- How Vaultize contributes
- Files handled by third-party service providers stay recipient-bound, expiring and revocable, with a full recipient audit trail. Governance, policy and oversight remain the RE’s own.
- Evidence to retain
- Per-recipient access records for third parties. Revocation events.
Standard by standard
What each standard asks. What the file can answer.
Standard codes and guideline wording are from CSCRF Version 1.0. Guidelines are quoted or excerpted; applicability varies by RE category and the framework marks each. Each row is a capability mapping, not a cyber audit finding.
Using this page
Where these rows fit under the CSCRF.
The framework grades obligations by RE category and is audited through the cyber audit it prescribes. The rows above are evidence for the standards that touch documents.
- 1
Find your category
MII, Qualified, Mid-size, Small-size or Self-certification RE. Applicability follows the category.
- 2
Map the standards
Which standards and guidelines apply, and which are mandatory.
- 3
Operate and record
Run the controls and keep the evidence. These rows belong here.
Bring the ten rows above as evidence for the standards that cover documents.
- 4
Cyber audit
The audit the framework prescribes, at the periodicity for your category.
- 5
Report to SEBI
Compliance reporting and, for incidents, reporting as the framework requires.
Responsibility boundary
Controls support the audit. A product does not pass it.
Vaultize contributes technical controls and evidence for information held in documents. It does not decide an RE’s category, which standards apply, or the outcome of the cyber audit. Read the framework, SEBI’s later circulars and clarifications, and take qualified advice before relying on this page.
“Data shall be encrypted in motion, at rest and in-use by using strong encryption methods.”
PR.DS guideline 1(a), SEBI CSCRF Version 1.0
Official references
Read the source before relying on the mapping.
Standard codes and guideline wording come from the first item. The others are SEBI’s own circulars.
- CSCRF for SEBI Regulated Entities, 20 August 2024Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 with the framework, Version 1.0. Every guideline quoted on this page is from it.
- Technical Clarifications to CSCRF, 28 August 2025Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119: clarifications on critical systems, asset inventory, patching, cloud, supply chain, and log management and retention.
- SEBI CSCRF FAQsSEBI’s frequently asked questions on the framework.
A practical next step
Bring one document held in fiduciary capacity.
We will show which standards the governed document can evidence today. We will name the control owner responsible for the rest.
