Live Founding Cohort open, limited seats remaining Back to main site →

The framework shape: five goals, six NIST CSF 2.0 functions

CSCRF is structured around five cyber-resilience goals implemented through six functional domains aligned to NIST CSF 2.0. Get this shape right and every subsequent control in the framework locates itself.

Free preview 8 min read Verified
Legal basis
SEBI CSCRF Master Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024). Full document stack through August 2026: December 2024 PR.DS.S2 abeyance; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45 (28 March 2025 first extension); SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60 (30 April 2025 clarifications); SEBI CSCRF FAQ 11 June 2025 (76 questions in 17 sections); 30 June 2025 second extension; SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 (28 August 2025 Technical Clarifications). Adjacent instruments: SEBI Cloud Framework 2023; SEBI Interoperability Framework November 2024 (live 1 April 2025); SEBI LODR Regulation 30 (September 2023 amendment); SEBI Act 1992 Sections 15A and 15HB; CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); RBI Payment Data Storage Direction (6 April 2018); NCIIPC Section 70 IT Act designations.

Every senior CISO who reads the CSCRF master circular for the first time hits a structural question in the first five pages: is this a NIST-style function-based framework, or is it something else? The answer is both. CSCRF has two dimensions.

Dimension one: five cyber-resilience goals

SEBI adopts CERT-In's five cyber-resilience goals from the National Cyber Crisis Management Plan [L2-C1]. Every control in CSCRF ultimately serves at least one of these five:

  • Anticipate. Situational awareness before an incident. Threat intelligence consumption. Attack surface management. Third-party risk mapping.
  • Withstand. Controls that reduce the blast radius when an incident occurs. Access controls, encryption, network segmentation, secure architecture.
  • Contain. Detection and response controls that stop lateral spread. SIEM correlation, EDR containment, playbook execution.
  • Recover. Business continuity and disaster recovery. RTO / RPO management. Backup integrity. Interoperability invocation.
  • Evolve. Post-incident learning. Threat model updates. Playbook revisions. Board reporting cycles.

Dimension two: six NIST CSF 2.0 functional domains

The five goals are implemented through the six functions of NIST Cybersecurity Framework 2.0 [L2-C2]:

  1. Govern. Board Technology Committee, CISO reporting line, policies, risk appetite, third-party risk governance.
  2. Identify. Asset inventory, data classification, threat identification, vulnerability management planning.
  3. Protect. Access management, awareness training, data security, encryption, secure configuration.
  4. Detect. Continuous monitoring, SIEM, anomaly detection, threat intelligence integration.
  5. Respond. Incident response planning, communications, analysis, mitigation, improvements.
  6. Recover. Recovery planning, improvements, communications.

NIST released CSF 2.0 in February 2024 and CSCRF was written to align to that version. The Govern function was newly elevated to a top-level function in CSF 2.0 (in CSF 1.1 it was a category within Identify). SEBI's decision to align to CSF 2.0 signals that Board governance is not an afterthought.

Standards CSCRF explicitly cross-references

  • NIST CSF 2.0. Functional domain structure.
  • ISO/IEC 27001:2022. Clauses 5 and 6 and Annex A. Certification became voluntary rather than mandatory in the 28 August 2025 Technical Clarifications [L2-C3].
  • CIS Controls v8. Practical control catalogue.
  • ISO 22301. Business Continuity Management.

Where the CCI sits inside this shape

The Cyber Capability Index (Annexure K, covered in depth in Module 2) is a quantitative measurement of a Regulated Entity's maturity across the five goals through the six functions. Its 23 parameters are drawn from every functional domain. A high CCI score means functional coverage across all six functions in service of all five resilience goals. A low CCI score usually reveals concentration risk: an RE has invested heavily in Protect and Detect but has thin Govern or thin Recover, and that imbalance shows up in the score.

Practitioner shortcut

Whenever you read a specific CSCRF control, ask two questions:

  1. Which of the five resilience goals is this control serving?
  2. Which of the six NIST CSF 2.0 functions is this control located in?

Answering both places the control in the framework. This is how a senior CISO reads a 205-page document in an afternoon and comes out with a working mental model.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
SEBI CSCRF 2024, Master Circular 2024/113 (Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities) L2-C2
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. The 205-page master framework that supersedes all prior SEBI cyber circulars (2015 MIIs, 2016 depositories, 2018 stockbrokers/DPs, 2019 MFs/RTAs). Applies to all SEBI Regulated Entities across five categories: MIIs, Qualified REs, Mid-size REs, Small-size REs and Self-Certification REs. Structured around 5 cyber-resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) mapped to 6 NIST CSF 2.0 functions (Governance, Identify, Protect, Detect, Respond, Recover). Cross-references NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8, ISO 22301.
SEBI CSCRF Technical Clarifications Aug 2025, Technical Clarifications 2025/119 (Aug 2025 Technical Clarifications: Principles of Exclusivity + Equivalence, ISO 27001 voluntary) L2-C3
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/119 dated 28 August 2025. Introduces the Principle of Exclusivity (an RE regulated by only one regulator complies with that regulator's framework) and the Principle of Equivalence (an RE regulated by multiple regulators complies with the stricter or equivalent regime, and may rely on one regulator's audit for the equivalent controls). Makes ISO 27001 certification voluntary rather than mandatory. Reaffirms Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes for critical operations. Clarifies M-SOC onboarding, NCIIPC applicability, and confidentiality safeguards for audit reports.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The CSCRF Framework and the 7-Instrument Document Stack
Module 2: The Cyber Capability Index (CCI) Deep Dive
  • What the CCI is and why SEBI cares
  • The 23 CCI parameters and their weightages
  • The submission workflow and the 15-day rule
  • How REs game CCI and what SEBI is doing about it
Module 3: Governance, the CISO Role, and Board Oversight
  • The CISO mandate under CSCRF
  • The Board Technology Committee cadence
  • Cyber Crisis Management Plan and drills
  • CISO career: salary bands, certifications, career map
Module 4: SOC, M-SOC, and Market SOC Architecture
  • The three approved SOC architectures
  • Cost economics: in-house vs M-SOC
  • M-SOC vendor selection and contract
  • SIEM stack selection
Module 5: Cyber Audit, VAPT, and CERT-In Empanelled Auditors
  • Cyber audit cadence and scope
  • VAPT scope and cost bands
  • Named CERT-In empanelled auditors and how to evaluate them
  • Managing findings to closure and the NSE Inspection ATR
Module 6: Incident Reporting, Cloud, Data Localisation, Business Continuity
  • The 6-hour dual clock: SEBI and CERT-In
  • Cloud, MeitY empanelment, and data residency
  • RTO 2 hours, RPO 15 minutes, and the interoperability framework
  • Real incident case studies at SEBI REs
Module 7: Cross-Regulator Crosswalk and Category-Specific Playbooks
  • The Principle of Exclusivity and the Principle of Equivalence
  • The single-view cross-regulator crosswalk
  • Category-specific playbooks: broker vs AMC vs KRA vs Depository vs MII
  • SBOM and the quarterly board deck template
Module 8: Final Exam and Certificate