The Declaration Is Personal, Not Organisational
When a CEO signs the SEBI CSCRF compliance declaration, they are personally attesting that the organisation has assessed its cyber security posture and that the declared posture is accurate.
This distinction matters. A compliance function filing a routine regulatory return is an organisational act. A CEO declaring compliance posture is a personal one. Many CEOs receive the declaration for signature without adequate visibility into the assessment that underlies it — that is a governance failure.