Every senior CISO who reads the CSCRF master circular for the first time hits a structural question in the first five pages: is this a NIST-style function-based framework, or is it something else? The answer is both. CSCRF has two dimensions.
Dimension one: five cyber-resilience goals
SEBI adopts CERT-In's five cyber-resilience goals from the National Cyber Crisis Management Plan [L2-C1]. Every control in CSCRF ultimately serves at least one of these five:
- Anticipate. Situational awareness before an incident. Threat intelligence consumption. Attack surface management. Third-party risk mapping.
- Withstand. Controls that reduce the blast radius when an incident occurs. Access controls, encryption, network segmentation, secure architecture.
- Contain. Detection and response controls that stop lateral spread. SIEM correlation, EDR containment, playbook execution.
- Recover. Business continuity and disaster recovery. RTO / RPO management. Backup integrity. Interoperability invocation.
- Evolve. Post-incident learning. Threat model updates. Playbook revisions. Board reporting cycles.
Dimension two: six NIST CSF 2.0 functional domains
The five goals are implemented through the six functions of NIST Cybersecurity Framework 2.0 [L2-C2]:
- Govern. Board Technology Committee, CISO reporting line, policies, risk appetite, third-party risk governance.
- Identify. Asset inventory, data classification, threat identification, vulnerability management planning.
- Protect. Access management, awareness training, data security, encryption, secure configuration.
- Detect. Continuous monitoring, SIEM, anomaly detection, threat intelligence integration.
- Respond. Incident response planning, communications, analysis, mitigation, improvements.
- Recover. Recovery planning, improvements, communications.
NIST released CSF 2.0 in February 2024 and CSCRF was written to align to that version. The Govern function was newly elevated to a top-level function in CSF 2.0 (in CSF 1.1 it was a category within Identify). SEBI's decision to align to CSF 2.0 signals that Board governance is not an afterthought.
Standards CSCRF explicitly cross-references
- NIST CSF 2.0. Functional domain structure.
- ISO/IEC 27001:2022. Clauses 5 and 6 and Annex A. Certification became voluntary rather than mandatory in the 28 August 2025 Technical Clarifications
[L2-C3]. - CIS Controls v8. Practical control catalogue.
- ISO 22301. Business Continuity Management.
Where the CCI sits inside this shape
The Cyber Capability Index (Annexure K, covered in depth in Module 2) is a quantitative measurement of a Regulated Entity's maturity across the five goals through the six functions. Its 23 parameters are drawn from every functional domain. A high CCI score means functional coverage across all six functions in service of all five resilience goals. A low CCI score usually reveals concentration risk: an RE has invested heavily in Protect and Detect but has thin Govern or thin Recover, and that imbalance shows up in the score.
Practitioner shortcut
Whenever you read a specific CSCRF control, ask two questions:
- Which of the five resilience goals is this control serving?
- Which of the six NIST CSF 2.0 functions is this control located in?
Answering both places the control in the framework. This is how a senior CISO reads a 205-page document in an afternoon and comes out with a working mental model.