Why SEBI CSCRF Gap Assessment Has Become Non-Negotiable?
Since SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) came into force in August 2024, cybersecurity compliance for regulated entities in India’s securities market has moved from a policy-onpaper exercise to an evidence-driven regulatory obligation.
Stock exchanges, depositories, clearing corporations, brokers, AMCs, custodians, RTAs, portfolio managers, AIFs, and a dozen other categories of SEBI regulated entities are now expected to demonstrate not just declare cyber resilience.
That shift is exactly why a SEBI CSCRF gap assessment has become the first serious step every entity takes before a statutory cyber audit. A gap assessment answers one question with precision: where does the entity’s current cybersecurity posture diverge from what SEBI’s regulatory expectations actually require, tier by tier, clause by clause?
Without that answer, policy alignment work is guesswork, and audit season becomes a scramble.
What a Gap Assessment Actually Measures?
A proper SEBI CSCRF gap assessment is not a generic cybersecurity health check. It is a structured comparison between two things: the CSCRF control baseline applicable to the entity’s specific tier — MII,Qualified RE, Mid-size RE, Small-size RE, or Selfcertified RE — and the entity’s current, evidenced state of implementation.
This baseline is built from the Terms of Reference (TOR) that map to CSCRF’s six cybersecurity functions, borrowed from NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, and Recover.
Each function ladders up to SEBI’s five cyber resilience goals Anticipate, Withstand, Contain, Recover, Evolve which is the language SEBI itself uses when it evaluates regulatory expectations across the securities market.
A credible gap assessment classifies every control into one of three states, not a simple pass/fail: Absent the control does not exist. Exists but ineffective the control is implemented on paper but does not operate as intended in practice. Exists but undocumented the control functions, but there is no audit trail proving it.
That third category is where most SEBI regulated entities lose points during a formal cyber audit. CSCRF is fundamentally an evidence-based framework, and undocumented controls carry almost the same regulatory risk as absent ones.
Mapping Gaps to Regulatory Expectations, Not Generic Best Practice
One of the most common mistakes in CSCRF gap assessment work is benchmarking against generic cybersecurity best practice instead of SEBI’s specific, tiered regulatory expectations. CSCRF compliance is not a one-size-fits-all standard.
A Self-certified RE and a Market Infrastructure Institution (MII) face entirely different obligations for VAPT frequency, cyber audit cadence, IT committee structure, HSM deployment, and Cyber Capability Index (CCI) reporting.
This is why the first output of any credible SEBI CSCRF gap assessment must be tier confirmation. Get the tier wrong a stock broker misclassified under the pre-April-2025 AUM-only rule, or a KRA still treated as MII instead of its current Qualified RE status and every subsequent gap finding is measured against the wrong regulatory expectations entirely.
Once tier is confirmed, the gap assessment should be run clause-by-clause against the applicable TOR set, cross-referenced with SEBI’s amendment trail.
CSCRF has already been amended twice since its August 2024 master circular in April 2025 and August 2025 and several requirements that were originally mandatory (ISO 27001 for Qualified REs, mobile application security testing, data localisation under PR.DS.S2) were subsequently revised to recommendatory status or placed in abeyance.
A gap assessment that flags these as non-compliant findings, without checking the current regulatory position, produces a report that misrepresents the entity’s actual compliance standing.
Where Policy Alignment Breaks Down
Policy alignment is the second half of the exercise, and it is where most regulated entities discover the widest gaps. It is entirely possible for an entity to hold a comprehensive-looking cybersecurity policy document while operating a materially different reality on the ground. Common policy-to-practice gaps that surface during CSCRF alignment work include:
Governance documentation that doesn’t match committee behaviour.
CSCRF requires a functioning IT committee with a genuine cybersecurity expert as a member, meeting quarterly for most tiers. Entities frequently have a board-approved cyber policy but cannot produce minutes proving the committee actually convened, discussed cyber risk, or reviewed the entity’s risk register in the period under review.
Vendor and supply-chain policy that stops at the contract.
SEBI has made clear that regulated entities remain solely accountable for their third-party vendors’ CSCRF compliance. A policy that references vendor risk management in principle, without an active monitoring mechanism, materiality assessment for cloud service provider subcontractors, or periodic vendor audits, will not satisfy regulatory expectations around supply chain risk.
Incident response policy without a tested SLA trail.
CSCRF’s incident reporting obligation six hours to SEBI’s portal and CERT-In is uniform across every tier. Policy language describing this timeline is common; evidence of the timeline actually being met during a real incident is far rarer, and that gap becomes a significant finding.
Data classification and localisation policy that hasn’t been updated for the current regulatory position.
With Regulatory Data localisation still in force but a specific sub-clause on IT and Cybersecurity Data in abeyance since December 2024, policies written against the original August 2024 circular often overstate or misstate the current obligation.
SBOM and asset management policy gaps.
Software Bill of Materials requirements now apply broadly across core and critical business software, including legacy and SaaS applications. Policies that don’taddress the board-approval exception process for legacy systems that genuinely cannot produce an SBOM leave a documented compliance gap.
Building the Remediation Roadmap
Once gaps and policy misalignments are identified and risk-rated, the practical value of the exercise lies in the remediation roadmap. Each finding needs a named owner, a realistic closure date benchmarked against SEBI’s own hard SLAs three months for general VAPT-identified vulnerabilities, one week for high-severity patch-related issues and a re-test trigger to confirm closure before the next audit cycle.
Entities that treat the gap register as a living document, rather than a point-in-time report, consistently perform better in subsequent cyber audits. The gap assessment from one cycle should directly feed the scoping of the next, with aging tracked on every open item and anything unresolved across two consecutive cycles escalated formally to the IT committee or board.
The Bottom Line for Regulated Entities
CSCRF gap assessment and policy alignment work only delivers regulatory value when it is tier-specific,evidence-based, and current against SEBI’s latest circulars and clarifications. Generic cybersecurity checklists, outdated requirement lists, or policy documents that were never updated after the April 2025 and August 2025 amendments will not withstand scrutiny from a CERT-In empanelled auditor or from SEBI itself.
For SEBI regulated entities preparing for their next cyber audit cycle, the sequence that consistently works is: confirm the tier, build the current TOR baseline, run the three-state gap classification, align policy language to operational reality, and convert every finding into a dated, owned remediation action. That is what regulatory alignment with CSCRF actually looks like in practice not a policy binder, but a live, auditable trail of evidence.
Mail us at info@zorixx.com or ajay.bhandari@zorixx.com
