SEBI CSCRF · CERT-In
SEBI CSCRF compliance, evidenced every cycle.
The implementation deadline has passed. What is live now is the cycle behind it — recurring cyber audits by a CERT-In-empanelled auditor, incident reporting on a short statutory clock, retained logs, and a security operations centre that has to have been watching when someone asks whether it was. PrahiX is the operating layer that produces that evidence continuously, so an audit draws on what actually happened rather than on a reconstruction.
SOC monitoring, scaled to your RE category
CERT-In reporting clock, with the timeline already assembled
audit cycle covered — not just the one you prepared for
Why CSCRF keeps becoming a project.
The framework asks for three things: that you are watching, that you can act within a defined time, and that you can prove both. The proving is where it comes apart, because most regulated entities start assembling evidence once the audit is booked.
The deadline passed; the cycle did not
The implementation date is behind you, but the cyber-audit cycle recurs and each round asks about the period since the last one. Evidence that was not collected at the time cannot be collected afterwards — that window is simply gone.
Your category decides your obligations
CSCRF grades regulated entities from Market Infrastructure Institutions through Qualified, Mid-size and Small-size REs down to self-certification, and the controls scale with that grading. Buying to the strictest tier is the usual way of overspending on this.
A short reporting clock is an operations problem
Reporting a critical incident to SEBI and to CERT-In within hours means the detection, the triage and a defensible timeline have to already exist. It is not a control you can write your way into with a policy document.
The auditor is empanelled; the evidence is yours
A CERT-In-empanelled auditing organisation assesses what you are able to show them. Their empanelment does not produce your monitoring records, your incident timelines or your escalation timings — that half is on you, all year, not in the fortnight before.
What the platform does for the audit.
Not a compliance dashboard bolted onto the side. The operating controls the framework asks for, running continuously, with the record they leave behind as the deliverable.
SOC monitoring, staffed by you or by us
CSCRF puts security operations monitoring at the centre, with the arrangement scaling by category. Run the platform with your own team, or take it as SOC as a Service and let us cover the shifts — the evidence an auditor sees is identical either way.
Detection and escalation against defined SLAs
Severity classification and escalation paths are agreed during onboarding rather than described in the abstract, so "which incidents were critical, who was told, and how quickly" is a question with a timestamped answer.
Incident timelines built while the incident runs
The artefacts a statutory report needs are assembled by the platform as events unfold, not by an analyst reconstructing the night afterwards from four consoles and a memory.
Ready for the assessment your category carries
Cyber Capability Index scoring applies differently by grading — third-party assessment on a six-monthly cadence for MIIs, annual self-assessment for Qualified REs. Continuous operational records are what those assessments read, so the inputs exist before the assessment is scheduled.
Retention configured to your classification
The framework specifies a period of readily searchable logs plus a longer archive, and the figures differ by category. We configure retention to the window you are actually held to — tell us your grading and it is a settings decision, not an architecture one.
Reporting as a by-product
Monitoring coverage, incidents and their timings, response actions, availability, asset inventory and change history export per audit period. The cycle becomes a report rather than a fortnight of everybody's time.
Everything the audit asks, from one platform.
Coverage is itself an audit question. An answer assembled from four tools invites the follow-up about what was not covered — which is a much harder conversation than the one you were expecting to have.
Monitoring coverage is part of the record
What is monitored, what is not, and when each was connected are all in the inventory from day one. "Everything is covered" is a claim; a list with dates against it is evidence.
Network and physical are in scope too
The framework does not stop at the security stack. Availability, configuration drift and access to the physical estate are part of the operational picture, and here they are in the same record rather than in three teams' tools.
Group structures with more than one licence
Several REs under one group are one estate operationally and several filings regulatorily. Reporting is scoped per entity so that distinction is a filter, not a second deployment.
Data stays where you need it
Built in India, deployed where your board and your auditor expect it to sit. For entities in the securities market this is usually the first question asked, and the one that ends evaluations early when the answer is wrong.
The difference when the audit letter arrives
Evidence assembled after the fact
- The audit window is the last six months; the log archive starts four months ago.
- Three people spend two weeks exporting from four consoles.
- Nobody can show when the SOC was watching, only that one exists.
- The gaps that surface are real, and no amount of effort closes them retroactively.
PrahiX — evidence as you operate
- The window is already covered, because collection never stopped.
- Coverage, incidents, actions and changes export as one record.
- Escalation timings are in the timeline, not in somebody's recollection.
- The cycle is a report, not a project.
How the platform maps to what is asked.
Four stages, running continuously. Each one produces an artefact the next cycle will ask you for, which is the entire point of doing it in this order.
Establish continuous monitoring
Connect the estate — identity, perimeter, endpoints, servers, cloud, network devices and the physical layer where you run it. Because coverage is itself an audit question, the inventory of what is and is not monitored becomes part of the record immediately.
Detect and classify against your SLAs
Detections are mapped to MITRE ATT&CK and scored, and severity classification and escalation paths are agreed with you rather than assumed. What counts as critical, and who must know within what period, is settled before it matters.
Respond, and record while responding
Containment playbooks run with their approval model attached, and every enrichment, decision and action is appended to the incident timeline as it happens. By the time a report is due, the material for it already exists.
Report on the cycle
Evidence exports per audit period and per entity: monitoring coverage, incidents and timings, actions taken, availability, asset inventory and change history. Hand it to your empanelled auditor rather than building it for them.
What this replaces.
CSCRF spend usually goes to the audit rather than to the thing being audited. That is backwards, and it is why the same findings reappear every cycle.
| Capability | A consultant per audit cycle | Point tools plus a spreadsheet | PrahiX as the operating layer |
|---|---|---|---|
| Evidence | Assembled retroactively, from whatever survived | Exported per tool and reconciled by hand | Accumulated continuously as the platform operates |
| SOC coverage | Out of scope — that was never the engagement | Your team, which in practice means business hours | On the platform, staffed by you or run by us |
| Short-clock incident report | A scramble, every time | Possible, if the right person happens to be awake | Timeline already assembled when the clock starts |
| Log retention | Whatever each tool happened to keep | Per tool, with a different window on each | One retention policy, set to your category |
| CCI inputs | Gathered in the weeks before assessment | Partial, and inconsistent between tools | Continuous operational records, always current |
| More than one RE in the group | Duplicated effort per entity | Duplicated effort per entity | One estate, reporting scoped per entity |
| Cost shape | Per audit cycle, indefinitely | Licences plus a fortnight of internal time each round | One operating subscription |
What PrahiX is, and is not
PrahiX supplies the operational controls and the evidence a CSCRF audit examines. It does not certify you, it does not replace your CERT-In-empanelled auditor, and it does not absolve the governance obligations the framework places on you — the policy, the risk decisions and the accountability stay where SEBI put them. What changes is that the operating half runs continuously, and the evidence exists before anybody asks for it.
- 24x7 SOC monitoring, detection and response
- Incident timelines aligned to statutory reporting clocks
- Retention configured to your RE category
- Continuous asset, availability and change records
Trusted by operations teams across India

Have Questions? We've Got Answers.
The Cybersecurity and Cyber Resilience Framework, issued by SEBI in August 2024, consolidates cybersecurity requirements for SEBI-regulated entities and grades them by category — from Market Infrastructure Institutions through Qualified, Mid-size and Small-size REs down to self-certification. Obligations scale with that grading, and the implementation dates have passed, so what is live for most entities now is the recurring cyber-audit cycle rather than a one-off readiness push.
No, and be wary of anyone who says their product does. Compliance is an organisational obligation that includes governance, policy, risk decisions and an audit by a CERT-In-empanelled auditing organisation. What a platform can do is run the operational controls — continuous monitoring, detection, response, retention — and produce the evidence that they ran. That is a large share of what the audit examines, and it is the share that cannot be retrofitted.
That depends on your grading, and it is worth establishing before you spend anything. Controls, audit frequency, assessment obligations and retention all scale from MII down to self-certification RE. Tell us which you are and we scope against that rather than against the strictest tier.
Security operations monitoring is central to the framework, with the arrangement varying by category — including shared and market SOC options for smaller entities rather than everyone building their own. PrahiX can be the platform your own team runs, or you can take it as SOC as a Service and we cover the shifts.
The CCI scores an entity's cyber maturity across a defined set of parameters, and its applicability depends on your grading — Market Infrastructure Institutions undergo third-party assessment on a six-monthly cadence, while Qualified REs self-assess annually. Smaller categories are not in scope. Either way the inputs are operational records, which is why they are worth generating continuously rather than gathering the month before.
CERT-In's directions require reporting of specified cyber incidents within six hours of noticing them, and that clock runs in parallel with SEBI's own reporting expectations. The practical constraint is not the form — it is having detection, triage and a defensible timeline inside those hours. The platform assembles that timeline as the incident runs.
No. It is one estate, monitored once, with reporting scoped per entity and per period so each filing draws on the same underlying record — see the RBI cyber security framework page for that side. Groups holding both licences are the case this was built for; the alternative is two sets of tooling that will eventually disagree about the same infrastructure in front of two different auditors.
Yes, and the sensible way to scope one is around your last audit: pick the evidence you struggled to produce, and we will show you it being generated continuously instead. That is a more useful test than a feature demonstration, and it is effectively the one your auditor will run later.
Keep reading
Your next audit cycle has already started.
The evidence it will ask for is being generated right now, or it is not. Show us your estate and your RE category, and we will scope what continuous monitoring and audit-ready reporting look like against the obligations you actually carry.