Loading Vaultize
Skip to main content

Compliance/India/SEBI CSCRF

Six functions and one goal to evolve: ten standards leave evidence in the file.

The CSCRF asks regulated entities to anticipate, withstand, contain, recover and evolve. Vaultize adds records that stay with the data.

  • Circular CIR/2024/113 · 20 Aug 2024
  • Applicability by RE category
  • Capability mapping, not a cyber audit

GV

Governance

1 of 27

  • GV.OC.S1
  • GV.OC.S2
  • GV.OC.S3
  • GV.OV.S1
  • GV.OV.S2
  • GV.OV.S3
  • GV.OV.S4
  • GV.PO.S1
  • GV.PO.S2
  • GV.PO.S4
  • GV.PO.S5
  • GV.RM.S1
  • GV.RM.S2
  • GV.RM.S3
  • GV.RM.S4
  • GV.RR.S1
  • GV.RR.S3
  • GV.RR.S4
  • GV.RR.S5
  • GV.RR.S6
  • GV.SC.S1
  • GV.SC.S2
  • GV.SC.S3
  • GV.SC.S4
  • GV.SC.S5
  • GV.SC.S6
  • GV.SC.S7

ID

Identify

1 of 9

  • ID.AM.S1
  • ID.AM.S2
  • ID.AM.S4
  • ID.AM.S6
  • ID.RA.S1
  • ID.RA.S2
  • ID.RA.S3
  • ID.RA.S4
  • ID.RA.S5

PR

Protect

6 of 37

  • PR.AA.S1
  • PR.AA.S2
  • PR.AA.S3
  • PR.AA.S4
  • PR.AA.S5
  • PR.AA.S6
  • PR.AA.S7
  • PR.AA.S8
  • PR.AA.S9
  • PR.AA.S10
  • PR.AA.S11
  • PR.AA.S12
  • PR.AA.S13
  • PR.AA.S14
  • PR.AA.S15
  • PR.AA.S16
  • PR.AA.S17
  • PR.AT.S1
  • PR.AT.S2
  • PR.AT.S3
  • PR.DS.S1
  • PR.DS.S2
  • PR.DS.S3
  • PR.DS.S4
  • PR.DS.S5
  • PR.DS.S6
  • PR.IP.S1
  • PR.IP.S3
  • PR.IP.S4
  • PR.IP.S6
  • PR.IP.S14
  • PR.IP.S15
  • PR.IP.S16
  • PR.IP.S17
  • PR.MA.S1
  • PR.MA.S2
  • PR.MA.S3

DE

Detect

1 of 7

  • DE.CM.S1
  • DE.CM.S2
  • DE.CM.S3
  • DE.CM.S4
  • DE.CM.S5
  • DE.DP.S4
  • DE.DP.S5

RS

Respond

1 of 14

  • RS.AN.S1
  • RS.AN.S2
  • RS.AN.S3
  • RS.AN.S4
  • RS.AN.S5
  • RS.CO.S1
  • RS.CO.S2
  • RS.CO.S3
  • RS.IM.S1
  • RS.IM.S2
  • RS.MA.S1
  • RS.MA.S2
  • RS.MA.S3
  • RS.MA.S5

RC

Recover

1 of 9

  • RC.CO.S1
  • RC.CO.S2
  • RC.CO.S3
  • RC.IM.S1
  • RC.IM.S2
  • RC.RP.S1
  • RC.RP.S2
  • RC.RP.S3
  • RC.RP.S4

EV

Evolve

0 of 4

  • EV.ST.S1
  • EV.ST.S2
  • EV.ST.S3
  • EV.ST.S5

GV.SC.S4

Where the systems of a RE are managed by third-party service providers and in case the RE does not have direct control over the implementation of any of the guidelines, the RE shall instruct the third-party service providers to adhere to the applicable guidelines in the CSCRF and shall obtain the necessary cyber audit certifications from them to ensure compliance with the framework.

Vaultize Share · Vaultize Seal

Read againstSEBI Cybersecurity and Cyber Resilience Framework for Regulated Entities, Version 1.0SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 · 20 August 2024
10standards across 5 of 7 functions

The answer in 30 seconds

Vaultize adds file-level records to ten CSCRF standards under Governance, Identify, Protect, Detect, Respond and Recover. Policy, risk assessment, VAPT, the SOC and the cyber audit belong to the regulated entity and its auditors.

The framework in one view

Five resilience goals. Seven functions. Where file evidence lands.

The CSCRF links its resilience goals to cybersecurity functions and numbers each standard. Select a function to see which of its standards a governed file can evidence.

GVIDPRDERSRCEV

GV

Governance

Goal Anticipate. Organisational context, roles, oversight, policy, risk management, supply chain.

Outcomes the file can evidence

How Vaultize contributes
Files handled by third-party service providers stay recipient-bound, expiring and revocable, with a full recipient audit trail. Governance, policy and oversight remain the RE’s own.
Evidence to retain
Per-recipient access records for third parties. Revocation events.

Standard by standard

What each standard asks. What the file can answer.

Standard codes and guideline wording are from CSCRF Version 1.0. Guidelines are quoted or excerpted; applicability varies by RE category and the framework marks each. Each row is a capability mapping, not a cyber audit finding.

Using this page

Where these rows fit under the CSCRF.

The framework grades obligations by RE category and is audited through the cyber audit it prescribes. The rows above are evidence for the standards that touch documents.

  1. 1

    Find your category

    MII, Qualified, Mid-size, Small-size or Self-certification RE. Applicability follows the category.

  2. 2

    Map the standards

    Which standards and guidelines apply, and which are mandatory.

  3. 3

    Operate and record

    Run the controls and keep the evidence. These rows belong here.

    Bring the ten rows above as evidence for the standards that cover documents.

  4. 4

    Cyber audit

    The audit the framework prescribes, at the periodicity for your category.

  5. 5

    Report to SEBI

    Compliance reporting and, for incidents, reporting as the framework requires.

Responsibility boundary

Controls support the audit. A product does not pass it.

Vaultize contributes technical controls and evidence for information held in documents. It does not decide an RE’s category, which standards apply, or the outcome of the cyber audit. Read the framework, SEBI’s later circulars and clarifications, and take qualified advice before relying on this page.

“Data shall be encrypted in motion, at rest and in-use by using strong encryption methods.”

PR.DS guideline 1(a), SEBI CSCRF Version 1.0

A practical next step

Bring one document held in fiduciary capacity.

We will show which standards the governed document can evidence today. We will name the control owner responsible for the rest.

Request a compliance mapping session