A structured matrix mapping SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) to NIST CSF 2.0 tiers, with maturity scoring per function and the mandatory gate items for CISO dashboard reporting.
Published 7 Apr 2026Updated 7 Apr 2026Read time 8 minCategory MatrixBy CreativeCyber
SEBI CSCRF: 6 NIST CSF 2.0 domains — amber = Tier 2 minimum, teal = Tier 3 mandatory, red badge = 4-hour SEBI reporting obligation on RESPOND
SEBI incident reporting window (tighter than CERT-In 6h)
CEO
Declaration required — Board direct accountability
SEBI CSCRF — MAKER/CHECKER EVIDENCE WORKFLOW TO CEO DECLARATION
Maker/Checker workflow enforces dual-control on every CSCRF control — rejection loops back for re-submission; locked assessments feed CEO Declaration then Board Report for SEBI