The Hidden Scale of CSCRF Evidence Failures
When SEBI released the Cyber Security and Cyber Resilience Framework (CSCRF) through its circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024), it fundamentally changed the compliance landscape for every Market Infrastructure Institution (MII), Qualified Registrar and Transfer Agent (QRTA), KYC Registration Agency (KRA), and regulated intermediary in India's capital markets ecosystem.
The framework's ambition is clear: move from checkbox compliance to demonstrable cyber resilience. But in practice many regulated entities cannot produce audit-grade evidence for even half their applicable controls.