Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
📈
BetaSEBI CSCRF 2024

SEBI Cyber Compliance Readiness

Quarterly Score Card preparation. A 15-control sampler drawn from the 65-control CSCRF set. Category auto-derivation. Registration risk detection. IS Audit pre-brief.

15
Controls assessed
10
Score Card metrics
5
Entity categories
8
CSCRF domains
30d
Score Card window
₹0
To start
Before you start — what to have ready for SEBI CSCRF

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What SEBI CSCRF is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Board-approved cyber security and cyber resilience policy
  • Cyber Capability Index (CCI) supporting evidence
  • IAM policy and access review records
  • VAPT (vulnerability assessment and penetration testing) reports
  • Incident response and SOC monitoring evidence
  • Business continuity and disaster recovery plan

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. VAPT reports name real hosts and findings, and access records name staff. Mask internal IPs, hostnames and personal contact details before uploading — the policies and report structure are what is assessed.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
sebi_cscrf_readiness_2025.1SEBI CSCRF 2024 · SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113

SEBI CSCRF 2024 readiness — category derivation, 15-control assessment, and quarterly Score Card

SEBI's Cyber Security and Cyber Resilience Framework 2024 mandates a quarterly Cyber Score Card (SC-01 through SC-10) and annual IS Audit for all registered entities. Missing a quarterly Score Card submission, or scoring below 3 on mandatory controls, risks SEBI registration suspension. This assessment maps your entity to its correct SEBI category, surfaces registration risk controls, and previews your quarterly Score Card — free tier included.

15
Controls assessed
across 8 SEBI CSCRF domains
10
Score Card metrics
SC-01 through SC-10, quarterly
5
Entity categories
MII / QRE / Mid-RE / Small-RE / Self-Cert
₹0
To start
All 15 controls + 4 Score Card metrics

Why SEBI compliance is unlike other frameworks

Quarterly Score Card — mandatory every quarter

Every SEBI-registered entity must submit SC-01 through SC-10 to SEBI within 30 days of each quarter end. Missing even one quarter is a compliance failure. This product tracks your Score Card readiness live.

Category derivation — your classification can surprise you

Entities often self-declare a lower category than their actual turnover, clients, or AUM implies. A stock broker with turnover >₹50,000 crore is a QRE with PR and DE maturity 4 requirements — regardless of self-declaration.

Registration risk — mandatory controls below 3

Mandatory controls scored below 3 risk SEBI registration suspension or cancellation under Intermediaries Regulations 2008 Reg 27/28. This is not a warning — it is a regulatory trigger.

Algo kill switch and data localisation — SEBI-specific technical controls

PR-10 requires an annually tested kill switch with ms-level halt proof. TC-04 requires all investor and trading data to stay in India. Neither appears in generic GRC tools.

SEBI CSCRF 2024 entity categories

CategoryWhoThresholdMin maturity
MIIStock Exchange, Depository, Clearing CorpBy entity type4 on all 8 domains
QREBroker, DP, AMC, PMSTurnover >₹50,000cr OR clients >1L OR AUM >₹2,000cr4 on PR, DE, RC, RG
Mid-REMid-size broker/AMC/DPTurnover >₹500cr OR clients >10,000 OR AUM >₹100cr3 on all domains
Small-RESmall intermediariesBetween Mid-RE and Self-Cert2–3 on most domains
Self-CertRIA, small RA, micro-brokerTurnover <₹100cr AND clients <1,000 AND AUM <₹10cr1–2 on most domains

Meeting ANY single threshold is sufficient for QRE or Mid-RE classification. This product derives your category automatically from your inputs.

This is an IjyaLabs SEBI CSCRF readiness self-assessment (framework version sebi_cscrf_readiness_2025.1). It does not represent SEBI's assessment of your compliance status, does not constitute a legal or regulatory opinion, and does not satisfy any mandatory SEBI reporting obligation. Quarterly Score Card must be submitted via the official SEBI Reporting Portal. IS Audit must be conducted by a CERT-In empanelled firm.