In August 2024, the Securities and Exchange Board of India quietly redrew the rules of cybersecurity compliance for every entity it regulates. The Cybersecurity and Cyber Resilience Framework (CSCRF) — a single consolidated directive replacing a patchwork of earlier circulars — introduced a tiered, risk-proportionate model that finally acknowledges what practitioners have known for years: a stock exchange is not the same threat surface as a small registered investment adviser.

The problem is that the nuance the framework introduced is exactly where most regulated entities are stumbling. SEBI's five-tier classification system, its overlapping VAPT mandates, and its distinction between automated scanning and manual penetration testing are creating genuine confusion in compliance departments and boardrooms of Asset Management Companies that assumed a single annual third-party audit was still sufficient.

It is not. Deadlines have passed. Inspections are ongoing. And the most common gaps SEBI examiners are surfacing are not exotic or technical — they are definitional misunderstandings hiding in plain sight within the circular's annexures.

What CSCRF Actually Requires

SEBI's CSCRF is not a single mandate but a layered framework with obligations that scale proportionally with an entity's systemic risk. The framework defines five categories of Regulated Entities (REs):

Market Infrastructure Institutions (MIIs) — stock exchanges, depositories, clearing corporations. These carry the highest systemic risk and face the most stringent requirements. Qualified REs — large brokers, AMCs with AUM above SEBI's defined thresholds, custodians. Mid-size REs — brokers and intermediaries of moderate scale with significant retail investor exposure. Small REs — smaller intermediaries with limited operational footprint. Self-certification REs — the smallest category, permitted to self-attest compliance against a simplified checklist.

Apr '25
Original compliance deadline — now passed for most entity tiers
5
Entity tiers under CSCRF, each with distinct VAPT and SOC obligations
24/7
SOC coverage mandatory for Market Infrastructure Institutions

Across all tiers, the CSCRF mandates VAPT at minimum annually. However, the framework also introduces event-triggered VAPT — entities must conduct additional testing following any significant change to their technology environment, including major application releases, infrastructure migrations, or any security incident meeting defined severity thresholds. This is the first place most compliance teams miss the mark: they treat VAPT as a calendar obligation rather than a continuous security hygiene practice.

For Qualified REs and above, the framework goes further. It mandates the operation of a formal Security Operations Centre (SOC) with defined detection, triage, and escalation capabilities. MIIs must maintain a 24/7 SOC with guaranteed response SLAs. For higher tiers, the CSCRF also introduces requirements for Red Team exercises — adversarial simulations that go beyond vulnerability scanning to test whether security controls actually hold against sophisticated, targeted attack scenarios. These are distinct from VAPT in both methodology and reporting format, and many entities are conflating the two.

The Three Gaps SEBI Inspectors Find Most Often

A clear pattern has emerged from post-inspection communications and industry feedback. The gaps cluster around three predictable misunderstandings of what the framework's language actually means.

Gap 1: Scope gaps in VAPT engagements. Most regulated entities commission VAPT reports that cover their public-facing web applications but omit internal network segments, API gateways, cloud infrastructure, and third-party integrations. CSCRF's language explicitly requires testing of the entire technology environment — including vendor-hosted components where the entity retains data or processing responsibility. A report that tests only the investor portal while leaving the order management system, back-office APIs, and data lake untouched will not satisfy an inspector's inquiry.

Gap 2: Conflating automated scanning with manual penetration testing. Vulnerability scanners — even good ones — are not penetration tests. SEBI's framework uses the term VAPT deliberately to require both components: an automated vulnerability assessment phase followed by manual exploitation and validation by a qualified tester. Many entities are submitting scanner outputs as their VAPT evidence, which represents a fundamental category error. Inspectors are trained to distinguish scanner reports from genuine penetration test findings, and the absence of manual exploitation evidence is a red flag that triggers deeper scrutiny.

Gap 3: Missing remediation evidence. SEBI's framework does not consider the test complete when the report is delivered — it considers it complete when identified vulnerabilities have been remediated and retested. Entities must maintain a documented remediation workflow with timestamps, owner assignments, closure evidence, and a follow-up assessment confirming that fixes did not introduce new vulnerabilities. Many firms can produce the initial test report but cannot produce any evidence of what happened to the findings afterward.

Regulators want proof of remediation, not just proof of testing.

Where Continuous Validation Fits Under CSCRF

The traditional model of annual VAPT engagement was always a compromise between cost and coverage — not a genuine reflection of how threat actors operate. CSCRF, by introducing event-triggered testing alongside annual minimums, is implicitly acknowledging this reality: security posture changes with every deployment, and the testing cadence must reflect the pace of change.

Continuous validation addresses several CSCRF requirements simultaneously. It generates a persistent log that satisfies both the annual requirement and the event-triggered requirement automatically when infrastructure changes. When integrated with a SOC's detection stack, every simulated attack also tests whether detection and alerting controls are functioning. It maintains a vulnerability lifecycle from discovery through closure — generating the documented remediation trail that inspectors request.

Arxiis maps your entire technology surface — web applications, APIs, internal networks, cloud environments, and third-party integrations — ensuring no asset falls outside your VAPT scope. Every finding is tracked through its complete lifecycle, from discovery to assigned owner to remediation to verification, producing the closed-loop evidence trail that satisfies the most common inspector documentation requests. Reports are structured around the CSCRF control framework, not generic security frameworks, making the gap between test results and compliance evidence zero.

Compliance with CSCRF is not a one-time project. It is a continuous operational posture. The entities that will emerge from the current inspection cycle with clean records are those that built a programme capable of generating evidence as a natural byproduct of doing security well.

Close your security gaps — continuously.

Arxiis is an autonomous AI penetration-testing platform that runs a coordinated crew of specialist agents through a full engagement in hours, not weeks — continuously, not annually. Every finding is CVSS-scored, MITRE ATT&CK-tagged, and auto-mapped to RBI CSF, CERT-In and nine more frameworks. It runs entirely on your own infrastructure. Nothing leaves the perimeter.