The Self-Assessment Trap
SEBI CSCRF requires regulated entities to conduct annual cyber security and cyber resilience maturity assessments and submit them to a SEBI-designated audit firm. The framework uses a 5-level maturity model across 6 domains and 39 controls.
The challenge: self-assessment frameworks invite optimism bias. When the person who designed the incident response process also scores it, Level 3 suddenly seems very achievable — even when the last tabletop was 18 months ago and results were never documented.
CreativeCyber practitioners consistently find a 1–2 level gap between self-assessments and independent audit verification. The gap isn’t usually dishonesty — it’s confusion between “we have this control” and “we have verifiable evidence that this control works.”
“CSCRF Level 3 doesn’t mean your policy is approved and filed. It means your policy is approved, implemented consistently, tested regularly, and the test results are documented. Most organizations have the first part. Few have all four.”
The 5-Level Maturity Ladder
Understanding what each level actually requires — in terms of evidence, not intent — is the single most important step in an honest self-assessment.
Continuous improvement cycle. Metrics drive control evolution. Board-level risk quantification integrated.
Controls measured quantitatively. Deviations detected automatically. Evidence collected continuously.
Documented policies and procedures. Consistent implementation across the enterprise. Regular testing.
Controls exist but are inconsistent. Depends on individual effort. No formal testing cadence.
Reactive. Controls exist only in response to incidents. No formal program.
The 6 CSCRF Domains
SEBI CSCRF organizes its 39 controls across six functional domains. The following scores represent typical BFSI self-assessment results — and the pattern is consistent across institutions.
Evidence Quality Matrix
The most common cause of audit failure is not missing controls — it is presenting evidence that does not meet auditor expectations. This matrix shows what SEBI-designated auditors accept for six common control areas.
| Control Area | ✗ Poor (fails audit) | ⚠ Acceptable | ✓ Strong (audit-ready) |
|---|---|---|---|
| Access Control Policy | Policy document only | Policy + quarterly access review report | Policy + access review + exception log + approval trail |
| SIEM / Log Management | Screenshot of SIEM dashboard | SIEM config doc + 90-day alert summary | SIEM config + alert KPIs + tuning log + escalation records |
| Incident Response Plan | IRP document in SharePoint | IRP + last tabletop exercise report | IRP + tabletop results + post-incident review + plan updates |
| Vulnerability Management | List of open vulnerabilities | Scan reports + SLA compliance rate | Scan reports + SLA data + remediation evidence + exception register |
| Vendor Risk Assessment | Vendor contract with security clause | Vendor assessment questionnaire responses | Assessment + independent verification + annual review record |
| BCP / DRP | BCP document | BCP + last DR test results | BCP + DR test + RTO/RPO actuals + lessons learned + updates |
Most Failed Controls
Based on practitioner assessments across BFSI entities. Fail rate = percentage with evidence insufficient to demonstrate Level 3 or above.
Maker / Checker / Approver
SEBI auditors specifically look for evidence of governance separation in the assessment process. The person who collects evidence cannot be the person who approves the score.
- Documents control implementation
- Collects and uploads evidence
- Scores control per maturity criteria
- Flags gaps or exceptions
- Independently reviews evidence quality
- Challenges score if evidence is insufficient
- Approves or returns for remediation
- Documents review rationale
- Signs off final assessment scores
- Escalates unresolved disagreements
- Submits to SEBI-designated auditor
- Retains records for 3 years
6-Month Assessment Calendar
The best-performing organizations treat CSCRF assessment as a year-round discipline, not a pre-submission sprint. This calendar reflects practitioner-tested timing for Qualified REs.
- Appoint Maker/Checker/Approver for each domain
- Agree on evidence collection templates
- Baseline current scores against last year
- Control owners collect and upload evidence
- Reviewer challenges and returns incomplete items
- Track completion rate weekly (target: 80% by Month 3)
- Prioritise gaps by audit risk (fail rate data)
- Implement quick wins (documentation, test scheduling)
- Exception register for controls that need >1 year to close
- Run internal audit against CSCRF checklist
- Simulate auditor questions on top 5 failed controls
- Update scores based on challenge outcomes
- CISO and Board sign-off on final scores
- Submit via SEBI-designated audit firm
- Retain evidence package for 3 years
“The SEBI auditor is not there to catch you out. They are there to verify that your self-assessment is honest. The fastest way to pass is to score conservatively and show clear evidence for every point you claim.”
Built for CSCRF. Not adapted for it.
The Assessment module maps directly to CSCRF’s 6 domains and 39 controls, with built-in Maker/Checker workflow, evidence file attachment at the control level, exception registers, and 5-level maturity scoring.
Explore Practitioner Toolkit →