The Self-Assessment Trap

SEBI CSCRF requires regulated entities to conduct annual cyber security and cyber resilience maturity assessments and submit them to a SEBI-designated audit firm. The framework uses a 5-level maturity model across 6 domains and 39 controls.

The challenge: self-assessment frameworks invite optimism bias. When the person who designed the incident response process also scores it, Level 3 suddenly seems very achievable — even when the last tabletop was 18 months ago and results were never documented.

CreativeCyber practitioners consistently find a 1–2 level gap between self-assessments and independent audit verification. The gap isn’t usually dishonesty — it’s confusion between “we have this control” and “we have verifiable evidence that this control works.”

“CSCRF Level 3 doesn’t mean your policy is approved and filed. It means your policy is approved, implemented consistently, tested regularly, and the test results are documented. Most organizations have the first part. Few have all four.”

The 5-Level Maturity Ladder

Understanding what each level actually requires — in terms of evidence, not intent — is the single most important step in an honest self-assessment.

5
Optimized TARGET

Continuous improvement cycle. Metrics drive control evolution. Board-level risk quantification integrated.

Evidence required: Real-time dashboards, threat intel feeds, automated exception reporting to board.
4
Managed

Controls measured quantitatively. Deviations detected automatically. Evidence collected continuously.

Evidence required: SIEM integration, automated control testing, KRI dashboards with trend lines.
3
Defined

Documented policies and procedures. Consistent implementation across the enterprise. Regular testing.

Evidence required: Approved policy documents with version control, test results, training completion records.
2
Developing

Controls exist but are inconsistent. Depends on individual effort. No formal testing cadence.

Evidence required: Some policy documents, ad-hoc test results, informal records only.
1
Basic NON-COMPLIANT

Reactive. Controls exist only in response to incidents. No formal program.

Evidence required: Incident reports only. No proactive evidence.

The 6 CSCRF Domains

SEBI CSCRF organizes its 39 controls across six functional domains. The following scores represent typical BFSI self-assessment results — and the pattern is consistent across institutions.

GOV
Govern
3.2
8 controls
Board oversight, CISO mandate, risk appetite framework
IDN
Identify
2.8
7 controls
Asset inventory, risk assessment, vendor risk classification
PRO
Protect
2.6
10 controls
Access control, data security, system hardening, training
DET
Detect
2.1
6 controls
SIEM, anomaly detection, log management, threat intel
RES
Respond
1.9
5 controls
Incident response plan, communication, containment
REC
Recover
1.7
3 controls
BCP, DRP, lessons learned, post-incident review
Key Finding The Detect→Respond→Recover gap is the most common finding. Organizations score 3.0+ in Govern and Identify (paper-heavy) but drop to 1.7–2.1 in Detect, Respond, and Recover (evidence-heavy). SEBI auditors know this pattern.
3.2
Avg score, Govern domain (highest)
1.7
Avg score, Recover domain (weakest)
39
Total controls assessed
L3
SEBI minimum expectation for Qualified REs

Evidence Quality Matrix

The most common cause of audit failure is not missing controls — it is presenting evidence that does not meet auditor expectations. This matrix shows what SEBI-designated auditors accept for six common control areas.

Control Area ✗ Poor (fails audit) ⚠ Acceptable ✓ Strong (audit-ready)
Access Control Policy Policy document only Policy + quarterly access review report Policy + access review + exception log + approval trail
SIEM / Log Management Screenshot of SIEM dashboard SIEM config doc + 90-day alert summary SIEM config + alert KPIs + tuning log + escalation records
Incident Response Plan IRP document in SharePoint IRP + last tabletop exercise report IRP + tabletop results + post-incident review + plan updates
Vulnerability Management List of open vulnerabilities Scan reports + SLA compliance rate Scan reports + SLA data + remediation evidence + exception register
Vendor Risk Assessment Vendor contract with security clause Vendor assessment questionnaire responses Assessment + independent verification + annual review record
BCP / DRP BCP document BCP + last DR test results BCP + DR test + RTO/RPO actuals + lessons learned + updates
Auditor Alert Screenshots of dashboards are not evidence of controls. A screenshot of your SIEM shows the tool exists — not that it is configured to detect relevant threats, that alerts are actioned, or that the tuning process is governed. Auditors will ask for configuration documentation, alert escalation records, and evidence of periodic tuning.

Most Failed Controls

Based on practitioner assessments across BFSI entities. Fail rate = percentage with evidence insufficient to demonstrate Level 3 or above.

DR test with RTO/RPO actualsRecover
82%
Threat intelligence integrationDetect
74%
Incident response tabletop (last 12 months)Respond
71%
Vendor risk re-assessment (annual)Identify
68%
Privileged access review (quarterly)Protect
63%
Board-level risk reporting (quantified)Govern
58%
Security awareness training completionProtect
44%
The DR Test Gap 82% of organizations have a DR test documented on paper. Far fewer have documented the actual RTO and RPO achieved — and fewer still have compared actuals against board-approved targets. SEBI auditors ask: “What RTO did you actually achieve in your last DR test?” If the answer is “we don’t know exactly,” the control fails regardless of the test certificate.

Maker / Checker / Approver

SEBI auditors specifically look for evidence of governance separation in the assessment process. The person who collects evidence cannot be the person who approves the score.

01
Control Owner
Maker
  • Documents control implementation
  • Collects and uploads evidence
  • Scores control per maturity criteria
  • Flags gaps or exceptions
02
Assessment Reviewer
Checker
  • Independently reviews evidence quality
  • Challenges score if evidence is insufficient
  • Approves or returns for remediation
  • Documents review rationale
03
DPO / CISO
Approver
  • Signs off final assessment scores
  • Escalates unresolved disagreements
  • Submits to SEBI-designated auditor
  • Retains records for 3 years
Key Principle The person who collects evidence cannot be the person who approves the score. SEBI auditors specifically look for evidence of this separation in the assessment process.

6-Month Assessment Calendar

The best-performing organizations treat CSCRF assessment as a year-round discipline, not a pre-submission sprint. This calendar reflects practitioner-tested timing for Qualified REs.

M1
Month 1
Governance Setup
  • Appoint Maker/Checker/Approver for each domain
  • Agree on evidence collection templates
  • Baseline current scores against last year
M2
Month 2–3
Evidence Collection
  • Control owners collect and upload evidence
  • Reviewer challenges and returns incomplete items
  • Track completion rate weekly (target: 80% by Month 3)
M4
Month 4
Gap Remediation
  • Prioritise gaps by audit risk (fail rate data)
  • Implement quick wins (documentation, test scheduling)
  • Exception register for controls that need >1 year to close
M5
Month 5
Internal Mock Audit
  • Run internal audit against CSCRF checklist
  • Simulate auditor questions on top 5 failed controls
  • Update scores based on challenge outcomes
M6
Month 6
SEBI Submission
  • CISO and Board sign-off on final scores
  • Submit via SEBI-designated audit firm
  • Retain evidence package for 3 years
Best Practice The best-performing organizations maintain living evidence repositories throughout the year. Every control test, access review, and incident response exercise generates evidence that is immediately filed against the relevant CSCRF control. By the time the annual submission arrives, the assessment is already 80% complete.

“The SEBI auditor is not there to catch you out. They are there to verify that your self-assessment is honest. The fastest way to pass is to score conservatively and show clear evidence for every point you claim.”

Practitioner Toolkit

Built for CSCRF. Not adapted for it.

The Assessment module maps directly to CSCRF’s 6 domains and 39 controls, with built-in Maker/Checker workflow, evidence file attachment at the control level, exception registers, and 5-level maturity scoring.

Explore Practitioner Toolkit →